Generated by Rank Math SEO, this is an llms.txt file designed to help LLMs better understand and index this website. # #site_title ## Sitemaps - [XML Sitemap](https://mrmicrosoft.com/sitemap_index.xml): Includes all crawlable and indexable pages. ## Posts - [How to Configure OneDrive Pay-as-You-Go Storage](https://mrmicrosoft.com/how-to-configure-onedrive-pay-as-you-go-storage/): For as long as most of us have managed Microsoft 365 storage, running out of OneDrive space has usually meant one of two things: asking users to clean up their files or purchasing additional OneDrive storage capacity in advance.  - [Reduce SharePoint Storage Costs with Retention-Based Archiving](https://mrmicrosoft.com/reduce-sharepoint-storage-costs-with-retention-based-archiving/): Microsoft Purview now lets admins add an Archive action to SharePoint retention policies and retention labels. This moves eligible inactive files to Microsoft 365 Archive while keeping them subject to retention and legal hold requirements. - [How to Disable Chat With People Who Don’t Use Teams Feature ](https://mrmicrosoft.com/how-to-disable-chat-with-people-who-dont-use-teams-feature/): Microsoft Teams now allows any tenant user to initiate a direct chat with an external email address, even when the recipient has no Teams license, Microsoft 365 tenant, or prior collaboration relationship.  - [How to Configure Conditional Access for AI Agents](https://mrmicrosoft.com/how-to-configure-conditional-access-for-ai-agents/): Microsoft Entra Conditional Access for agents extends Conditional Access policies to agent identities and agent user accounts, allowing admins to control access based on factors such as agent risk, execution environment, device, network, and the resource being accessed. - [Account Correlation Rules in Microsoft Defender  ](https://mrmicrosoft.com/account-correlation-rules-in-microsoft-defender/): Microsoft Defender for Identity can automatically correlate accounts when they share strong identifiers such as the account ID, SID, object ID, or UPN. However, these identifiers may not always be available or consistent, particularly in environments with established account-naming conventions. Custom account correlation rules become useful here.  - [OneDrive File Exclusion Policies: DisableChangesToODIgnoreList and DisableDefaultODIgnoreList ](https://mrmicrosoft.com/disablechangestoodignorelist-and-disabledefaultodignorelist/): OneDrive is giving users more control over what gets synchronized. With the latest update, users with work or school accounts on Windows and macOS can exclude specific files from syncing to OneDrive or SharePoint. Microsoft is rolling out this capability gradually, with General Availability expected to complete in early September 2026.  - [Microsoft Purview Priority Cleanup: Balancing Retention and Permanent Deletion](https://mrmicrosoft.com/microsoft-purview-priority-cleanup-balancing-retention-and-permanent-deletion/): Microsoft Purview Priority Cleanup introduces a controlled way to handle this scenario. Administrators can create a cleanup policy for specific OneDrive and SharePoint content and choose Delete data permanently, allowing the targeted items to be permanently removed instead of following the usual retention and deletion path. - [Hero Links in SharePoint Online and OneDrive](https://mrmicrosoft.com/hero-links-in-sharepoint-online-and-onedrive/): Overall, the purpose of hero links is: - [Register a Passkey as First Multifactor Authentication Method in Entra ](https://mrmicrosoft.com/register-passkey-as-first-multifactor-authentication-method-in-microsoft-entra/): Under the current model, a password-only user who wants to register a passkey, Windows Hello for Business, or macOS Platform SSO first has to configure SMS or voice as a fallback. Consider a new employee with an Entra account and no MFA registered yet. The onboarding path looked like this:  - [Microsoft Intune Adds Registry Inventory for Windows Devices](https://mrmicrosoft.com/microsoft-intune-adds-registry-inventory-for-windows-devices/): Microsoft Intune’s new Registry Inventory capability helps admins verify the configuration directly from the device. - [Microsoft Entra Account Discovery: Finding the Hidden Users Living in Your Applications](https://mrmicrosoft.com/microsoft-entra-account-discovery-finding-the-hidden-users-living-in-your-applications/): Microsoft Entra Account Discovery helps solve this problem by identifying all existing user accounts in a connected application and categorizing them based on their relationship with Microsoft Entra ID. - [How to Customize OneDrive Storage Limits Without Disrupting Your Organization](https://mrmicrosoft.com/how-to-customize-onedrive-storage-limits/): OneDrive for Business provides every licensed Microsoft 365 user with generous cloud storage for collaboration, file synchronization, and secure document access. By default, most organizations assign 1 TB of OneDrive storage per user, with eligible subscription plans supporting even larger quotas.  - [SharePoint Restricted Access Control Now Secures Microsoft 365 Search](https://mrmicrosoft.com/sharepoint-restricted-access-control-now-secures-microsoft-365-search/): Organizations using Restricted Access Control (RAC) for SharePoint Online and OneDrive will soon benefit from a more consistent security experience. Microsoft is extending RAC enforcement beyond site access to Microsoft 365 Search, ensuring that users can only discover content they are authorized to access.  - [Exchange Online -Credential Parameter Retirement Extended](https://mrmicrosoft.com/exchange-online-credential-parameter-retirement-extended/): Earlier this year, Microsoft announced that the -Credential parameter in Exchange Online PowerShell would be retired in July 2026. - [How to Automatically Accept SSO Permissions on Managed Windows 11 Devices ](https://mrmicrosoft.com/how-to-automatically-accept-sso-permissions-on-managed-windows-11-devices/): Starting with KB5101650 for Windows 11 24H2 and 25H2, Microsoft introduced a registry-based policy that lets admins automatically accept SSO permissions on eligible managed Windows devices.  - [How to Migrate from SMS and Voice MFA to Passkeys ](https://mrmicrosoft.com/how-to-migrate-from-sms-and-voice-mfa-to-passkeys/): SMS and voice-based authentication have quietly remained in use for years. They are familiar, require little user training, and work on almost any phone. Because of this convenience, they often stay enabled even after stronger authentication methods become available.  - [How to Investigate an Active Directory Domain in Microsoft Defender](https://mrmicrosoft.com/how-to-investigate-an-active-directory-domain-in-microsoft-defender/): To simplify this process, Microsoft Defender now offers a dedicated Active Directory Domain page. It brings together domain health, security policies, trust relationships, incidents, and Active Directory objects into a single workspace, making it easier to assess your environment and identify potential risks. - [Assign Sensitivity Labels to Security Groups in Microsoft 365](https://mrmicrosoft.com/assign-sensitivity-labels-to-security-groups-in-microsoft-365/): When organizations consider sensitivity labels, they usually focus on protecting documents, emails, Teams, or SharePoint sites. But the question that's often overlooked:  - [Microsoft 365 2026 Licensing Update Security Features: What to Configure First](https://mrmicrosoft.com/microsoft-365-2026-licensing-update-security-features-what-to-configure-first/): Microsoft's 2026 Microsoft 365 packaging update is more than a licensing refresh. Several security and endpoint management capabilities that previously required separate licenses are now included with eligible Microsoft 365, Office 365, and EMS subscriptions.  - [Migrate from Restricted SharePoint Search to Restricted Content Discovery](https://mrmicrosoft.com/migrate-from-restricted-sharepoint-search-to-restricted-content-discovery/): This requires a review of existing content discovery controls and a planned transition to alternative governance mechanisms such as Restricted Content Discovery (RCD). Since Microsoft will not migrate existing RSS configurations automatically, administrators must assess their current implementation and take appropriate action before the retirement deadline.  - [Retirment of Custom Controls in Entra ID ](https://mrmicrosoft.com/retirment-of-custom-controls-in-entra-id/): If your organization relies on Microsoft Entra Custom Controls to integrate third-party MFA providers such as Duo or RSA, it's time to start planning for a transition.  - [Full Workload Backup for SharePoint, OneDrive, and Exchange](https://mrmicrosoft.com/full-workload-backup-for-sharepoint-onedrive-and-exchange/): Thats where you need Microsoft 365 Backup. - [Microsoft Purview Priority Cleanup: New Level of Control Over OneDrive and SharePoint Data](https://mrmicrosoft.com/microsoft-purview-priority-cleanup-new-level-of-control-over-onedrive-and-sharepoint-data/): Data retention has long been a cornerstone of Microsoft 365 compliance. It ensures that important information remains available for legal, regulatory, and organizational needs—even when users attempt to remove it. But as data volumes continue to explode, especially with the rise of AI-powered collaboration, organizations are encountering a different challenge: not every piece of retained data should remain indefinitely accessible. - [SSPR Will Require Registered Authentication Methods](https://mrmicrosoft.com/sspr-will-require-registered-authentication-methods/): And when that happens, Self-Service Password Reset (SSPR) becomes the quickest way to get back to work without calling the helpdesk.   - [How to Restore Deleted Devices in Microsoft Entra ID Using Soft Delete](https://mrmicrosoft.com/how-to-restore-deleted-devices-in-microsoft-entra-id-using-soft-delete/): Among the many objects stored in Microsoft Entra ID, device records have always been surprisingly unforgiving.  - [How to Enable File Requests in SharePoint and OneDrive](https://mrmicrosoft.com/how-to-enable-file-requests-in-sharepoint-and-onedrive/): Microsoft 365 offers a lesser-known solution called File Requests. - [Intune Suite Features Included in Microsoft 365 E3 and E5 in 2026 ](https://mrmicrosoft.com/intune-suite-features-included-in-microsoft-365-e3-and-e5-in-2026/): For years, getting the best of Microsoft Intune meant paying extra. Features like Remote Help, Advanced Analytics, Endpoint Privilege Management, and Cloud PKI sat behind the Intune Suite add-on, a separate purchase that many organizations skipped due to cost. That changes in 2026.  - [How to Manage Frontier Admin Control in Microsoft 365 Admin Center ](https://mrmicrosoft.com/how-to-manage-frontier-admin-control-in-microsoft-365-admin-center/): With that early access comes the responsibility of controlling exposure, evaluating readiness, and governing adoption carefully. Rather than enabling preview AI experiences across the entire tenant, Microsoft provides Frontier Admin Control in the Microsoft 365 admin center to help administrators selectively manage access and run controlled pilot programs safely.  - [Exchange Online Tightens DNS Security for Mail Flow](https://mrmicrosoft.com/exchange-online-tightens-dns-security-for-mail-flow/): Microsoft continues to improve the security foundations of Exchange Online, this time by focusing on DNS — a core but often overlooked part of email transport. In an April 2026 update, Microsoft outlined progress on introducing modern DNS protections for Exchange Online mail flow, including support for DNSSEC, SMTP DANE, and MTA-STS. - [Microsoft Viva Connections is Now the SharePoint App](https://mrmicrosoft.com/microsoft-viva-connections-is-now-the-sharepoint-app/): Along with the rename, Microsoft SharePoint home sites are getting a few updates that simplify intranet management. - [Lock-free Coauthoring in Microsoft Word](https://mrmicrosoft.com/lock-free-coauthoring-in-microsoft-word/): Lock-free coauthoring allows multiple users to edit the same paragraph simultaneously, improving real-time collaboration in Word. - [Why Disable Direct Send in Exchange Online](https://mrmicrosoft.com/why-disable-direct-send-in-exchange-online/): For years, Direct Send in Exchange Online operated quietly in the background as a widely adopted convenience feature. It became a common solution for printers, scan-to-email devices, legacy applications, monitoring platforms, scripts, and various internal notification systems. Because it worked reliably with minimal configuration, it was often treated as a low-maintenance operational dependency across many Microsoft 365 environments.  - [How to Detect and Block Shadow AI in Microsoft 365 Admin Center ](https://mrmicrosoft.com/shadow-ai-in-microsoft-365-admin-center/): For years, IT teams have had a playbook for Shadow IT.  - [OneDrive Sync Limit Increase to 1 Million Items on Windows](https://mrmicrosoft.com/onedrive-sync-limit-increase-to-1-million-items-on-windows/): The OneDrive sync limit increase to 1 million items is a significant step forward, but it is not a universal upgrade. - [AI Skills in SharePoint Online – Repetitive Workflows Into Reusable Automation ](https://mrmicrosoft.com/ai-skills-in-sharepoint-online/): Microsoft's AI Skills feature in SharePoint Online is introduced as part of the AI in SharePoint public preview (previously called Knowledge Agent), Skills lets you encode a repeatable, multi-step workflow into a reusable asset, built entirely through natural language chat, stored directly on the site, and executable by any user with the right permissions.   - [How to Restrict a User’s OneDrive Content to a Security Group ](https://mrmicrosoft.com/how-to-restrict-a-users-onedrive-content-to-a-security-group/): When an employee leaves the company, their OneDrive still has shared links floating around. Someone, a contractor, a former colleague, or even a wrong email address, still has access. - [What Microsoft’s New Change Management Model Means for Your Organization](https://mrmicrosoft.com/what-microsofts-new-change-management-model-means-for-your-organization/): Microsoft is fundamentally transforming how organizations manage change in Microsoft 365. After years of feedback from IT administrators struggling to balance innovation with stability, Microsoft has introduced a modernized change management framework that gives you unprecedented control over when and how updates reach your organization. - [Measure Data Protection with Microsoft Purview Posture Reports](https://mrmicrosoft.com/measure-data-protection-with-microsoft-purview-posture-reports/): That stops with Posture Reports. After working with these in production environments, here's my honest take on what they do, where they shine, and what you should know before you lean on them too hard. - [Microsoft Entra Passkey on Windows (Public Preview)](https://mrmicrosoft.com/microsoft-entra-passkey-on-windows-public-preview/): 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐄𝐧𝐭𝐫𝐚 𝐩𝐚𝐬𝐬𝐤𝐞𝐲 𝐨𝐧 𝐖𝐢𝐧𝐝𝐨𝐰𝐬 𝐣𝐮𝐬𝐭 𝐡𝐢𝐭 𝐩𝐮𝐛𝐥𝐢𝐜 𝐩𝐫𝐞𝐯𝐢𝐞𝐰 - [Microsoft Copilot Cowork vs Claude Cowork](https://mrmicrosoft.com/copilot-cowork-vs-claude-cowork/): Copilot Cowork changes that dynamic.  - [How to Share Files in External Chats in Microsoft Teams](https://mrmicrosoft.com/how-to-share-files-in-external-chats-microsoft-teams/): Whether it's vendors, clients, or cross-tenant teams, most conversations in Microsoft Teams today extend beyond organizational boundaries. But while chat has evolved to support this seamlessly, file sharing has traditionally lagged behind—introducing friction at the worst possible moments.  - [Microsoft Entra Tenant Governance for Multi-Tenant Management](https://mrmicrosoft.com/microsoft-entra-tenant-governance-for-multi-tenant-management/):  Microsoft is now doing something about it and announced that Microsoft Entra Tenant Governance is in public preview.  - [Enable Third-Party AI Model Access for Specific Users in Microsoft 365 Copilot](https://mrmicrosoft.com/enable-third-party-ai-model-access-for-specific-users/): The ability to scope Microsoft 365 Copilot third-party AI model access at the group level isn't just a convenience feature. It directly addresses one of the most common barriers to Copilot adoption in regulated industries. - [How to Enable Co-authoring for Encrypted Sensitivity-Labeled Files](https://mrmicrosoft.com/how-to-enable-co-authoring-for-encrypted-sensitivity-labeled-files/): Microsoft Purview includes a tenant-level setting that directly addresses the collaboration gap in encrypted file workflows. When you enable co-authoring for files with sensitivity labels, the experience changes significantly for end users and the underlying file-handling infrastructure alike.  - [Microsoft Teams Detects External Meeting Assistant Bots Joining Meetings ](https://mrmicrosoft.com/microsoft-teams-detects-external-meeting-assistant-bots-joining-meetings/):  AI meeting bots, tools that transcribe, summarize, or record your conversations, have quietly become a fixture in online meetings. Many are genuinely useful. But the problem is not all of them are invited, and until now, most organizations have had no reliable way to know they were even there.  - [Quick Step in SharePoint Online: Automate Without Building a Single Flow ](https://mrmicrosoft.com/quick-step-in-sharepoint-online/): If you wanted to automate a simple status change, say, moving a policy from "Draft" to "Final," you had two choices.   - [OneDrive & SharePoint Online Plans Retirement](https://mrmicrosoft.com/sharepoint-online-onedrive-plan-1-2-retirement/): This isn't a surprise move. It's been coming for a while. - [What to Do When SharePoint Storage Is Full ](https://mrmicrosoft.com/what-to-do-when-sharepoint-storage-is-full/): An email from Microsoft with the subject line that makes every SharePoint admin's stomach drop:  - [How to Clean Up Recurring Meetings from Former Employees](https://mrmicrosoft.com/how-to-clean-up-recurring-meetings-from-former-employees/): An employee leaves, but their recurring meetings live on: daily stand-ups, weekly syncs, and monthly reviews. All are still sitting on everyone’s calendar, blocking rooms, confusing attendees, and quietly wasting time. - [Preservation Lock in Microsoft 365 ](https://mrmicrosoft.com/preservation-lock-in-microsoft-365/): This is exactly why I recommend Preservation Lock. I often describe Preservation Lock not just as a feature, but as a "final guardrail." It is the architectural equivalent of a one-way ratchet, you can tighten it, but you can never loosen it.   ## Pages - [Contact](https://mrmicrosoft.com/contact/): Have a question, collaboration idea, or just want to connect? I would love to hear from you. The best way to reach me is via LinkedIn. - [Books](https://mrmicrosoft.com/books/): Discover books by Mezbaul Anam on Microsoft AI, Copilot Studio, and Azure AI Foundry. Published by Apress, these practical guides help business leaders and technical professionals build intelligent AI agents and drive digital transformation. - [Terms and Conditions](https://mrmicrosoft.com/terms-and-conditions/): Welcome to mrmicrosoft.com. By accessing this website, you agree to comply with and be bound by the following terms and conditions of use. - [About](https://mrmicrosoft.com/about/): Hi, I’m Mezba Uddin, an Apress Author, Microsoft MVP, MCT, and Digital Transformation evangelist with a passion for simplifying complex IT challenges. - [Home](https://mrmicrosoft.com/): Accelerate your digital transformation journey with expert Microsoft 365 insights and solutions - [Blogs](https://mrmicrosoft.com/blogs/) - [Privacy Policy](https://mrmicrosoft.com/privacy-policy/): An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment. ## Tips - [Windows 11 Cloud Rebuild Adds Remote Recovery & Drive Sanitization](https://mrmicrosoft.com/tips/windows-11-cloud-rebuild-adds-remote-recovery-drive-sanitization/): Cloud rebuild was already useful for Windows recovery. The latest update makes it much more relevant for IT admins. - [Email Recall in Exchange Online: Should You Allow 365 Days?](https://mrmicrosoft.com/tips/email-recall-in-exchange-online-should-you-allow-365-days/): Would you allow users to recall an email for 365 days? You may not expect it, but 365 days is the maximum recall period in Exchange Online. At first, a longer recall window sounds useful. But after looking at how Message Recall actually works, I think this is one setting admins should review rather than simply accept. Message Recall is an error-correction feature, not a compliance control. It's built for situations like sending the wrong attachment or emailing the wrong recipient. But as the recall window gets longer, we should stop and ask: How long do users actually need to correct an email mistake? A 365-day window doesn’t make an organization more secure. And recall shouldn’t be treated as a way to completely erase an email after it has been sent. It also doesn’t replace controls such as DLP, retention, eDiscovery, or other compliance mechanisms. A sensible starting point could be to restrict recall to 1–5 days, long enough to fix a genuine mistake, but short enough that nobody mistakes it for a way to rewrite email history. If this setting has been sitting at 365 days because it was never reviewed, review and update it based on your organization’s requirements. - [Entra ID Is Retiring the memberOf Operator on November 3, 2026](https://mrmicrosoft.com/tips/entra-id-is-retiring-the-memberof-operator-on-november-3-2026/): If your Dynamic Groups, administrative units, or entitlement management policies use the memberOf operator, the clock is running out. Microsoft is retiring it on November 3, 2026, and rules built on it will stop recalculating membership entirely. - [Microsoft Admin App Retirement Affects Small Businesses](https://mrmicrosoft.com/tips/microsoft-admin-app-retirement-affects-small-businesses/): The Admin app was designed to simplify Microsoft 365 administration for very small businesses by bringing a focused set of common admin capabilities into Teams, Outlook, and Microsoft365.com. Microsoft is now retiring that experience, with the change rolling out in two stages. Phase 1 — August 2026: The Admin app will no longer be pre-pinned or pre-installed in Teams for new very small business admins. Existing users may continue to access it if the app is already installed. Phase 2: October 2026: The Admin app will be retired completely and will no longer be supported or available in Teams, Outlook, or Microsoft365.com. For organizations that have incorporated the app into their day-to-day administration workflow, it’s time to move those tasks to Microsoft’s dedicated management experiences. Alternative for Admin App for Small Businesses We should fall back to: Microsoft 365 Admin Center: tenant administration, users, licenses, billing, service health, and broader Microsoft 365 management. Teams Admin Center: Teams policies and configuration, users, apps, meetings, messaging, voice, and Teams service management. Microsoft 365 Admin Agent: an AI-assisted administration experience that can help admins perform and streamline certain management tasks. To be clear: this is a retirement of the Admin app, not of Microsoft 365 or Teams administration. Microsoft is effectively moving admins away from the simplified, consolidated app experience and back toward the dedicated admin centers and newer AI-assisted administration capabilities. If your tenant still runs on the Admin app, this is the window to migrate before October. Do you currently use the Admin app for Microsoft 365 administration? Was its consolidated experience useful, or do you prefer working directly from the dedicated admin centers? - [Teams to Restrict External Messaging Limits for onmicrosoft Domains](https://mrmicrosoft.com/tips/teams-to-restrict-external-messaging-limits-for-onmicrosoft-domains/): From mid-September 2026, Teams will introduce outbound external messaging limits for organizations that haven't configured a custom domain. - [AI-powered Regulatory Templates in Purview Compliance Manager](https://mrmicrosoft.com/tips/ai-powered-regulatory-templates-in-purview-compliance-manager/): AI-powered regulatory templates in Purview Compliance Manager introduce a new way to turn regulatory documents into structured, actionable controls. - [Calendar Sync Between Microsoft Teams and Google Workspace is Being Retired](https://mrmicrosoft.com/tips/calendar-sync-between-microsoft-teams-and-google-workspace-is-being-retired/): Calendar Sync Between Microsoft Teams and Google Workspace is Being Retired in October 2026. - [How to Block External Bots in Microsoft Teams Meetings](https://mrmicrosoft.com/tips/how-to-block-external-bots-in-microsoft-teams-meetings/): The strongest control available was to detect these bots and send them to the lobby for organizer approval. - [Azure PST Import for Exchange Online: PowerShell Workflow](https://mrmicrosoft.com/tips/azure-pst-import-for-exchange-online-powershell-workflow/): Microsoft is rolling out Azure PST Import, which lets 𝐄𝐱𝐜𝐡𝐚𝐧𝐠𝐞 𝐎𝐧𝐥𝐢𝐧𝐞 𝐚𝐝𝐦𝐢𝐧𝐬 𝐢𝐦𝐩𝐨𝐫𝐭 𝐏𝐒𝐓 𝐟𝐢𝐥𝐞𝐬 𝐟𝐫𝐨𝐦 𝐀𝐳𝐮𝐫𝐞 𝐁𝐥𝐨𝐛 𝐒𝐭𝐨𝐫𝐚𝐠𝐞 𝐢𝐧𝐭𝐨 𝐮𝐬𝐞𝐫 𝐨𝐫 𝐚𝐫𝐜𝐡𝐢𝐯𝐞 𝐦𝐚𝐢𝐥𝐛𝐨𝐱𝐞𝐬. - [SharePoint Admin Center Time Zone Display Settings](https://mrmicrosoft.com/tips/sharepoint-time-zone-display-settings/): SharePoint admin tip: Be careful when changing the time zone in the SharePoint admin center. - [Microsoft Entra ID SMS First-Factor Sign-In Retirement](https://mrmicrosoft.com/tips/microsoft-entra-id-sms-first-factor-sign-in-retirement/): Microsoft is retiring SMS first-factor sign-in for Entra ID Free tenants. - [What-if Tool for Lifecycle Workflows in Microsoft Entra](https://mrmicrosoft.com/tips/what-if-tool-for-lifecycle-workflows-in-entra/): First Conditional Access. Now Lifecycle Workflows. Microsoft has announced the What-if Tool for Lifecycle Workflows too.  Conditional Access has had its What If tool for years to test how policies evaluate for a specific user, app, location, and other sign-in conditions before enforcing a policy that could unexpectedly block access. Now, Lifecycle Workflows gets a similar capability for identity lifecycle automation. The new What-if tool lets admins check: Who is actually in scope? See which users currently meet the workflow’s execution conditions. What could fail? Identify workflow tasks that may fail based on the current configuration. What would the execution look like? Select up to 10 users and simulate the workflow without actually processing them. The last capability is particularly useful when workflows automate actions across onboarding, employee movement, or offboarding. You can validate the expected behavior with a small set of users before letting the workflow execute more broadly. There is an important limitation, though: the What-if tool currently doesn't support workflows triggered by attribute changes or group membership changes. But conceptually, this is a useful evolution in the Entra admin experience. Before you let an identity policy make a decision or an automation take an action, ask “What if?” first. https://learn.microsoft.com/en-us/entra/id-governance/simulate-workflow-execution - [SharePoint Everyone and EEEU Permissions Report](https://mrmicrosoft.com/tips/sharepoint-everyone-and-eeeu-permissions-report/): Microsoft is rolling out a new report in the SharePoint admin center that gives item-level visibility into permissions granted through the "Everyone" and "Everyone except external users" (EEEU) groups. Previously, administrators could identify sites where these broad-access groups were being used. But there was a practical limitation: we can’t identify which specific files or items were actually exposed through that access. We knew the risk existed at the site level, but pinpointing it required manual digging through every item inside. The new report addresses that limitation by surfacing the individual files and items that inherit access through Everyone or EEEU. Admins can now see the exact files and items shared through these two special groups, across both SharePoint and OneDrive. Instead of starting with a site and manually tracing permissions to determine what content is exposed, administrators can identify the affected items directly and assess whether that access is intentional. This is a SharePoint Advanced Management capability, and it provides read-only visibility. You can pull this through the admin center UI or PowerShell. The rollout begins in early August 2026 and is expected to complete by mid-August 2026. - [Copilot in SharePoint Gets More Powerful: Live Dashboards and One-Click Prompts](https://mrmicrosoft.com/tips/copilot-in-sharepoint-gets-more-powerful-live-dashboards-and-one-click-prompts/): Microsoft is expanding Copilot in SharePoint with two useful capabilities that make it easier to work with data and use AI directly from SharePoint pages. - [Microsoft Purview Expands DLP to Non-Microsoft Applications](https://mrmicrosoft.com/tips/microsoft-purview-expands-dlp-to-non-microsoft-applications/): Microsoft is addressing this by extending Microsoft Purview Data Loss Prevention (DLP) and auto-labeling support to supported non-Microsoft applications through Microsoft Defender for Cloud Apps connectors. - [Microsoft Entra Retires the memberOf Rule Operator](https://mrmicrosoft.com/tips/microsoft-entra-retires-the-memberof-rule-operator/): Microsoft has announced the retirement of the Public Preview of the memberOf rule operator in Microsoft Entra dynamic groups. The feature will be retired on November 3, 2026, meaning organizations that still rely on it should begin planning their migration. - [Microsoft Intune’s New Device Sync Status Experience](https://mrmicrosoft.com/tips/microsoft-intunes-new-device-sync-status-experience/): 𝐅𝐢𝐧𝐚𝐥𝐥𝐲, 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐫𝐞𝐥𝐞𝐚𝐬𝐞𝐝 𝐃𝐞𝐯𝐢𝐜𝐞 𝐒𝐲𝐧𝐜 𝐒𝐭𝐚𝐭𝐮𝐬 𝐢𝐧 𝐈𝐧𝐭𝐮𝐧𝐞. - [Microsoft Entra Cloud Sync Now Supports Device Synchronization (Preview](https://mrmicrosoft.com/tips/microsoft-entra-cloud-sync-now-supports-device-synchronization-preview/): Microsoft has introduced a new AD2AADDeviceSync synchronization job in Microsoft Entra Cloud Sync. It synchronizes Active Directory computer objects to Microsoft Entra ID, enabling those devices to become Microsoft Entra hybrid joined. - [Private Channels in Microsoft Teams: 5,000 Members and Scheduled Meetings](https://mrmicrosoft.com/tips/private-channels-in-microsoft-teams-5000-members-and-scheduled-meetings/): One of the more persistent limitations of Microsoft Teams private channels has finally been addressed. - [How Microsoft Entra ID Custom CSS Retirement Impacts Company Branding](https://mrmicrosoft.com/tips/entra-custom-css-positioning-properties-retiring-impacts-company-branding/): If your organization has customized the Microsoft Entra ID sign-in page using custom CSS, it's time to review those configurations. - [Cross-Tenant Group Synchronization in Microsoft Entra ID](https://mrmicrosoft.com/tips/cross-tenant-group-synchronization-in-microsoft-entra-id/): Cross-Tenant Group Synchronization extends this model by allowing groups and their memberships to be synchronized between a source and a target tenant. The capability became generally available a few months ago and can be particularly relevant for organizations managing access across multiple tenants - [SharePoint Admin Agent: Simplify SharePoint Content Governance](https://mrmicrosoft.com/tips/sharepoint-admin-agent-simplify-sharepoint-content-governance/): Use the SharePoint Admin Agent for a conversational way to assess governance posture and investigate risks across SharePoint and OneDrive. - [Get-MailDetailTransportRuleReport and Get-MailTrafficPolicyReport Require EventType Parameter](https://mrmicrosoft.com/tips/getmaildetailtransportrulereport-and-getmailtrafficpolicyreport-require-eventtype-parameter/): This change affects only Get-MailDetailTransportRuleReport and Get-MailTrafficPolicyReport. Other Exchange Online cmdlets are not impacted. If your organization depends on transport rule reporting, updating your scripts should be a priority to ensure reporting continues to work as expected. - [Microsoft Teams to Require Owner Approval for Joining Private Teams](https://mrmicrosoft.com/tips/microsoft-teams-to-require-owner-approval-for-joining-private-teams/): 𝐉𝐨𝐢𝐧𝐢𝐧𝐠 𝐚 𝐩𝐫𝐢𝐯𝐚𝐭𝐞 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐓𝐞𝐚𝐦 𝐰𝐢𝐭𝐡 𝐚 𝐭𝐞𝐚𝐦 𝐜𝐨𝐝𝐞 𝐰𝐢𝐥𝐥 𝐧𝐨𝐰 𝐫𝐞𝐪𝐮𝐢𝐫𝐞 𝐨𝐰𝐧𝐞𝐫 𝐚𝐩𝐩𝐫𝐨𝐯𝐚𝐥. - [Microsoft Entra Introduces Password Reset Using Passkeys and Windows Hello](https://mrmicrosoft.com/tips/microsoft-entra-introduces-password-reset-using-passkeys-and-windows-hello/): 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐄𝐧𝐭𝐫𝐚 𝐰𝐢𝐥𝐥 𝐬𝐨𝐨𝐧 𝐥𝐞𝐭 𝐞𝐥𝐢𝐠𝐢𝐛𝐥𝐞 𝐮𝐬𝐞𝐫𝐬 𝐜𝐡𝐚𝐧𝐠𝐞 𝐭𝐡𝐞𝐢𝐫 𝐩𝐚𝐬𝐬𝐰𝐨𝐫𝐝 𝐰𝐢𝐭𝐡𝐨𝐮𝐭 𝐤𝐧𝐨𝐰𝐢𝐧𝐠 𝐭𝐡𝐞𝐢𝐫 𝐜𝐮𝐫𝐫𝐞𝐧𝐭 𝐩𝐚𝐬𝐬𝐰𝐨𝐫𝐝. - [Microsoft 365 Admin Agent General Availability](https://mrmicrosoft.com/tips/microsoft-365-admin-agent-general-availability/): 𝐓𝐡𝐞 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 365 𝐀𝐝𝐦𝐢𝐧 𝐚𝐠𝐞𝐧𝐭 𝐢𝐬 𝐧𝐨𝐰 𝐠𝐞𝐧𝐞𝐫𝐚𝐥𝐥𝐲 𝐚𝐯𝐚𝐢𝐥𝐚𝐛𝐥𝐞 𝐟𝐨𝐫 𝐚𝐥𝐥 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐄𝐧𝐭𝐫𝐚 𝐛𝐮𝐢𝐥𝐭-𝐢𝐧 𝐚𝐝𝐦𝐢𝐧𝐬! - [Custom CSS Positioning Properties in Company Branding Retiring](https://mrmicrosoft.com/tips/custom-css-positioning-properties-in-company-branding-retiring/): Starting October 26, 2026, Microsoft will no longer honor custom CSS positioning properties used in Microsoft Entra ID company branding. - [New Built-in Role in Microsoft Entra: SOC Identity Responder](https://mrmicrosoft.com/tips/new-built-in-role-in-microsoft-entra-soc-identity-responder/): Microsoft has introduced a new built-in SOC Identity Responder role in Microsoft Entra to help Security Operations Center (SOC) analysts respond to identity-based security incidents without requiring broader administrative privileges. This role is designed to strengthen the principle of least privilege while enabling faster incident response. - [Microsoft Entra Kerberos Key Rotation Gets Improved Reliability](https://mrmicrosoft.com/tips/microsoft-entra-kerberos-key-rotation-gets-improved-reliability/): Kerberos key rotation for Microsoft Entra hybrid environments just became more resilient! - [Exclude Specific Folders from OneDrive Sync](https://mrmicrosoft.com/tips/exclude-specific-folders-from-onedrive-sync/): OneDrive is getting a useful update that lets us exclude specific folders from syncing while keeping them available locally on users' devices. Developers and IT admins often end up with the folders below inside OneDrive. 📂 node_modules 📂 PowerShell modules 📂 Visual Studio configuration folders None of that needs to live in the cloud. It's machine-specific, it's disposable, and yet OneDrive has been faithfully syncing every byte of it, eating into storage quotas. In August 2026, that changes. Admins will be able to define exclusion rules through Group Policy, and any folder matching those rules stays local. It never touches OneDrive cloud storage. The feature is off by default.  Users have zero control here. This is entirely an admin-side setting, which honestly makes sense given the storage and governance implications. Existing synced folders won't stop syncing automatically; they'll need to be moved out of OneDrive manually after the policy is applied. For organizations managing developer workstations or devices with machine-specific application data, this  can really help reduce unnecessary cloud storage usage. This doc will be updated with details about the new folder exclusion policy ahead of the August 2026 rollout. https://learn.microsoft.com/en-us/sharepoint/use-group-policy - [Disable Activation Lock for Apple Devices Using Microsoft Intune](https://mrmicrosoft.com/tips/disable-activation-lock-for-apple-devices-using-microsoft-intune/): Administrators can either disable Activation Lock remotely or retrieve the device's Activation Lock bypass code, eliminating the need to contact the previous user for their Apple Account credentials. - [Automate Agent Identity Sponsorship Transitions in Entra](https://mrmicrosoft.com/tips/automate-agent-identity-sponsorship-transitions-in-entra/): Microsoft Entra ID Governance can automate agent identity sponsorship transitions using three Lifecycle Workflows tasks. - [Microsoft 365 Backup Gets Configurable Recovery Windows](https://mrmicrosoft.com/tips/microsoft-365-backup-gets-configurable-recovery-windows/): Until now, every Microsoft 365 Backup policy came with a fixed 1-year recovery window. That worked well for many organizations, but not for everyone. - [Cross-Tenant Message Recall in Exchange Online](https://mrmicrosoft.com/tips/cross-tenant-message-recall-in-exchange-online/): Exchange Online is expanding Message Recall with the introduction of 𝐂𝐫𝐨𝐬𝐬-𝐓𝐞𝐧𝐚𝐧𝐭 𝐌𝐞𝐬𝐬𝐚𝐠𝐞 𝐑𝐞𝐜𝐚𝐥𝐥. - [Time-Limited Role Group Assignments in Microsoft Purview](https://mrmicrosoft.com/tips/time-limited-role-group-assignments-in-microsoft-purview/): Many organizations grant elevated permissions for investigations, migrations, or compliance projects and then forget to remove them. - [Invoke-ChangeMeetingOrganizer: Transfer Meeting Ownership with PowerShell](https://mrmicrosoft.com/tips/invoke-changemeetingorganizer-transfer-meeting-ownership-with-powershell/): Changing the organizer of an existing meeting or recurring meeting series has traditionally meant recreating the meeting from scratch. Exchange Online now introduces a new PowerShell cmdlet that enables administrators to transfer meeting ownership without recreating the meeting or series: Invoke-ChangeMeetingOrganizer - [Exchange Online Is Retiring TLS 1.0 and TLS 1.1 for POP3 and IMAP4 Connections](https://mrmicrosoft.com/tips/exchange-online-is-retiring-tls-1-0-and-tls-1-1-for-pop3-and-imap4-connections/): Starting August 1, 2026, Microsoft will begin rolling out this security update worldwide, with completion expected by December 31, 2026. - [Advanced Intune Capabilities Are Now Included with Microsoft 365 E3 and E5](https://mrmicrosoft.com/tips/advanced-intune-capabilities-are-now-included-with-microsoft-365-e3-and-e5/): You may no longer need Intune Suite for some advanced Intune capabilities. - [New in SharePoint Advanced Management: Create Custom Groups of Sites](https://mrmicrosoft.com/tips/new-in-sharepoint-advanced-management-create-custom-groups-of-sites/): If your organization has hundreds or thousands of SharePoint sites, keeping them organized can be difficult. - [Teams Private Channel Migration: Fix Ownerless Channels Before July Ends](https://mrmicrosoft.com/tips/teams-private-channel-migration-fix-ownerless-channels-before-july-ends/): To migrate them successfully, admins must add at least one in-tenant user as the channel owner. - [SharePoint Remote Event Receivers Retirement: Timeline and Migration](https://mrmicrosoft.com/tips/sharepoint-remote-event-receivers-retirement-timeline-and-migration/): Microsoft has confirmed that all SharePoint Remote Event Receivers will be fully retired by July 1, 2027. - [Microsoft Entra Backup and Recovery is Generally Available](https://mrmicrosoft.com/tips/microsoft-entra-backup-and-recovery-is-generally-available/): For years, recovering from accidental changes or misconfigurations in Entra meant leaning on audit logs, PowerShell scripts, or third-party backup tools, because native recovery did not exist in any meaningful way. That changes now! - [Microsoft Edge Blocks Screen Capture in OneDrive and SharePoint Web Viewers](https://mrmicrosoft.com/tips/microsoft-edge-blocks-screen-capture-in-onedrive-and-sharepoint-web-viewers/): If you work with Purview sensitivity labels, you've probably run into this one. - [Microsoft Purview DLP: User-Based Alert Aggregation](https://mrmicrosoft.com/tips/microsoft-purview-dlp-user-based-alert-aggregation/): One of the most frustrating parts of investigating DLP incidents isn't always the policy itself; it's the flood of alerts. When the same user triggers multiple DLP events in a short period, we often end up piecing together several separate alerts to understand a single incident. It adds noise, slows investigations, and makes it harder to focus on what actually matters. Microsoft is addressing this with a new user-based alert aggregation capability in DLP. Instead of creating a separate alert for every event, related DLP events from the same user can be grouped into a single alert within a configurable time window, even if they match different DLP rules. The result is less alert fatigue and a better investigation context. Once the feature rolls out in mid-August 2026, you can enable it from Settings > DLP settings > Alert settings > Event aggregation into alerts, choose User-based aggregation, configure the aggregation window, and save the settings.   It doesn't affect DLP policy enforcement; the policies continue to work as configured. This update only changes how related alerts are grouped for investigation. - [New & Refreshed Library View in OneDrive for Web](https://mrmicrosoft.com/tips/new-refreshed-library-view-in-onedrive-for-web/): Microsoft is introducing a refreshed Libraries experience in Microsoft OneDrive for the web, replacing the existing More places view. This update improves how users discover and access document libraries across Microsoft SharePoint and Microsoft Teams. - [Defender for Office Plan 1 Now Included in E3](https://mrmicrosoft.com/tips/defender-for-office-plan-1-now-included-in-e3/): 𝐃𝐞𝐟𝐞𝐧𝐝𝐞𝐫 𝐟𝐨𝐫 𝐎𝐟𝐟𝐢𝐜𝐞 365 𝐏𝐥𝐚𝐧 1 𝐢𝐬 𝐧𝐨𝐰 𝐛𝐞𝐢𝐧𝐠 𝐚𝐝𝐝𝐞𝐝 𝐭𝐨 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 365 𝐄3 𝐚𝐧𝐝 𝐎𝐟𝐟𝐢𝐜𝐞 365 𝐄3. - [Microsoft Removes CAPTCHA from SSPR](https://mrmicrosoft.com/tips/microsoft-removes-captcha-from-sspr/): 👉 Here's the thing : CAPTCHA was already losing the battle. Automated solvers have gotten good enough that a CAPTCHA challenge isn't really a meaningful barrier for a determined attacker. That's a bad deal. - [New Role Group UI for Microsoft Purview Compliance Portal](https://mrmicrosoft.com/tips/new-role-group-ui-for-microsoft-purview-compliance-portal/): With this update, Microsoft is introducing new views that allow admins to look up Role Group assignments: - [OneDrive Migrating to cloud.microsoft Domain](https://mrmicrosoft.com/tips/onedrive-migrating-to-cloud-microsoft-domain/): 𝐎𝐧𝐞𝐃𝐫𝐢𝐯𝐞 𝐢𝐬 𝐦𝐢𝐠𝐫𝐚𝐭𝐢𝐧𝐠 𝐭𝐨 𝐭𝐡𝐞 𝐜𝐥𝐨𝐮𝐝.𝐦𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐝𝐨𝐦𝐚𝐢𝐧 𝐬𝐭𝐚𝐫𝐭𝐢𝐧𝐠 𝐉𝐮𝐥𝐲 2026. - [Microsoft Entra Connect v2.6.79.0: Advancing Passwordless Security](https://mrmicrosoft.com/tips/microsoft-entra-connect-v2-6-79-0-advancing-passwordless-security/): Microsoft Entra Connect v2.6.79.0 has been released, and although it doesn’t introduce architectural changes, it delivers several targeted improvements that strengthen both the security and operational resilience of hybrid identity deployments. ## Tools - [Stellar Migrator for Exchange – Hands on review](https://mrmicrosoft.com/tools/stellar-migrator-for-exchange-hands-on-review/): Migrating mailboxes between Exchange Server and Microsoft 365 tenants is one of those tasks that tends to surface during company mergers, divestitures or when moving from on‑premises infrastructure to the cloud. Without automation, you’re left juggling PowerShell scripts, manual mailbox mapping and a great deal of downtime. To see if Stellar Migrator for Exchange could simplify this process, I tested the tool in a live environment and this review walks through the setup, performance, and features I found most useful. - [Stellar Converter for EDB Hands-On Review of a Reliable Exchange Mailbox Conversion Tool](https://mrmicrosoft.com/tools/stellar-converter-for-edb/): As an Exchange admin, you're bound to face situations where converting mailboxes from an EDB file becomes urgent. Whether due to offline database, or planned migrations, having a dependable tool can save hours of manual effort and reduce downtime. I recently put Stellar Converter for EDB to the test in a live Exchange environment, and in this review, I’ll walk you through the actual experience, performance, and results.