
What is ConsentFix Attack and How to Mitigate it in Microsoft 365
Explore how ConsentFix attack abuses trusted Microsoft 365 first-party app access and learn mitigations to prevent OAuth token misuse.
15 min read
Microsoft Teams will soon detect and label third-party AI meeting assistant bots attempting to join meetings. These bots will be automatically flagged by Microsoft Teams in the meeting lobby, so organizers can admit, deny, or remove them. It'll be available from mid-May 2026.
Microsoft has announced Microsoft 365 E7, its newest premium bundle for the AI-driven enterprise. It combines Microsoft 365 E5, Copilot, Entra Suite, and Microsoft Agent 365 into a single offering. The suite is priced at $99 per user/month and will be generally available starting May 1, 2026.
Microsoft 365 Backup has extended its support to restore individual files and folders in SharePoint and OneDrive, which is currently available in public preview. With this update, admins can easily browse, search, and recover specific files or folders directly from restore points, eliminating the need to restore an entire site or drive.
Microsoft is retiring One-Time Passcode (SPO OTP) authentication and transitioning to Entra B2B guest accounts for external users. This ensures that SharePoint and OneDrive external collaboration is governed by the same security and compliance standards as internal access. SPO OTP method will be fully retired by August 31, 2026, following rollout beginning in May 2026.
Microsoft now allows admins to enforce a default expiration period for “People in your organization” sharing links in SharePoint Online and OneDrive. By configuring maximum and recommended expiration values, admins can prevent internal links from staying active indefinitely. This update helps reduce stale access while maintaining flexible and secure collaboration.
Starting March 3, 2026, Microsoft is introducing a completely reimagined SharePoint experience in Microsoft 365, designed to make collaboration smarter, faster, and more intuitive. The new experience features a redesigned app bar categorized into three core jobs - Discover, Publish, and Build along with AI-powered tools and a neutral theme.
Struggling to automate secure monitor manage M365?
Try AdminDroid for Free!One stop place for comprehensive Microsoft 365 security checklists, covering all services.

Explore how ConsentFix attack abuses trusted Microsoft 365 first-party app access and learn mitigations to prevent OAuth token misuse.
15 min read

Explore step-by-step methods to identify insecure RC4 usage in Active Directory Kerberos tickets and disable them to strengthen security.
16 min read

Discover 15 SharePoint permissions best practices to prevent unauthorized access, manage permissions efficiently, and stay in control.
13 min read

Learn how to prevent Teams sprawl with 10 proven strategies to improve governance and reduce security risks.
12 min read

Discover the top Microsoft 365 admin blogs of 2025, featuring the latest tips and best practices to help you manage your M365 environment.
15 min read

Explore the crucial Microsoft Teams governance strategies to improve collaboration and ensure compliant use of Teams across the organization.
11 min read

Cybersecurity Month wrap-up: Strengthen IT environments and secure Microsoft 365, Active Directory, hybrid, and AI platforms.
11 min read

Explore key strategies to safeguard employee personal data across apps, devices, and cloud services in modern hybrid workplaces.
8 min read

Local admin accounts can make or break security. Learn all risks and practical steps to secure local admins and protect devices from privilege abuse.
7 min read

Protect your remote work environment by implementing 11 remote desktop access best practices to prevent data leaks caused by unauthorized access.
8 min read

Learn how to defend against Microsoft hybrid identity attacks such as Entra Connect compromise, Pass-the-PRT, and more.
10 min read

Explore 10 best practices to secure admin accounts in a hybrid environment to reduce the attack surface & safeguard against evolving threats.
7 min read