Generated by Rank Math SEO, this is an llms.txt file designed to help LLMs better understand and index this website. # #site_title ## Sitemaps [XML Sitemap](https://mrmicrosoft.com/sitemap_index.xml): Includes all crawlable and indexable pages. ## Posts - [How to Migrate from SMS and Voice MFA to Passkeys ](https://mrmicrosoft.com/how-to-migrate-from-sms-and-voice-mfa-to-passkeys/): SMS and voice-based authentication have quietly remained in use for years. They are familiar, require little user training, and work on almost any phone. Because of this convenience, they often stay enabled even after stronger authentication methods become available.  - [How to Investigate an Active Directory Domain in Microsoft Defender](https://mrmicrosoft.com/how-to-investigate-an-active-directory-domain-in-microsoft-defender/): To simplify this process, Microsoft Defender now offers a dedicated Active Directory Domain page. It brings together domain health, security policies, trust relationships, incidents, and Active Directory objects into a single workspace, making it easier to assess your environment and identify potential risks. - [Assign Sensitivity Labels to Security Groups in Microsoft 365](https://mrmicrosoft.com/assign-sensitivity-labels-to-security-groups-in-microsoft-365/): When organizations consider sensitivity labels, they usually focus on protecting documents, emails, Teams, or SharePoint sites. But the question that's often overlooked:  - [Microsoft 365 2026 Licensing Update Security Features: What to Configure First](https://mrmicrosoft.com/microsoft-365-2026-licensing-update-security-features-what-to-configure-first/): Microsoft's 2026 Microsoft 365 packaging update is more than a licensing refresh. Several security and endpoint management capabilities that previously required separate licenses are now included with eligible Microsoft 365, Office 365, and EMS subscriptions.  - [Migrate from Restricted SharePoint Search to Restricted Content Discovery](https://mrmicrosoft.com/migrate-from-restricted-sharepoint-search-to-restricted-content-discovery/): This requires a review of existing content discovery controls and a planned transition to alternative governance mechanisms such as Restricted Content Discovery (RCD). Since Microsoft will not migrate existing RSS configurations automatically, administrators must assess their current implementation and take appropriate action before the retirement deadline.  - [Retirment of Custom Controls in Entra ID ](https://mrmicrosoft.com/retirment-of-custom-controls-in-entra-id/): If your organization relies on Microsoft Entra Custom Controls to integrate third-party MFA providers such as Duo or RSA, it's time to start planning for a transition.  - [Full Workload Backup for SharePoint, OneDrive, and Exchange](https://mrmicrosoft.com/full-workload-backup-for-sharepoint-onedrive-and-exchange/): Thats where you need Microsoft 365 Backup. - [Microsoft Purview Priority Cleanup: New Level of Control Over OneDrive and SharePoint Data](https://mrmicrosoft.com/microsoft-purview-priority-cleanup-new-level-of-control-over-onedrive-and-sharepoint-data/): Data retention has long been a cornerstone of Microsoft 365 compliance. It ensures that important information remains available for legal, regulatory, and organizational needs—even when users attempt to remove it. But as data volumes continue to explode, especially with the rise of AI-powered collaboration, organizations are encountering a different challenge: not every piece of retained data should remain indefinitely accessible. - [SSPR Will Require Registered Authentication Methods](https://mrmicrosoft.com/sspr-will-require-registered-authentication-methods/): And when that happens, Self-Service Password Reset (SSPR) becomes the quickest way to get back to work without calling the helpdesk.   - [How to Restore Deleted Devices in Microsoft Entra ID Using Soft Delete](https://mrmicrosoft.com/how-to-restore-deleted-devices-in-microsoft-entra-id-using-soft-delete/): Among the many objects stored in Microsoft Entra ID, device records have always been surprisingly unforgiving.  - [How to Enable File Requests in SharePoint and OneDrive](https://mrmicrosoft.com/how-to-enable-file-requests-in-sharepoint-and-onedrive/): Microsoft 365 offers a lesser-known solution called File Requests. - [Intune Suite Features Included in Microsoft 365 E3 and E5 in 2026 ](https://mrmicrosoft.com/intune-suite-features-included-in-microsoft-365-e3-and-e5-in-2026/): For years, getting the best of Microsoft Intune meant paying extra. Features like Remote Help, Advanced Analytics, Endpoint Privilege Management, and Cloud PKI sat behind the Intune Suite add-on, a separate purchase that many organizations skipped due to cost. That changes in 2026.  - [How to Manage Frontier Admin Control in Microsoft 365 Admin Center ](https://mrmicrosoft.com/how-to-manage-frontier-admin-control-in-microsoft-365-admin-center/): With that early access comes the responsibility of controlling exposure, evaluating readiness, and governing adoption carefully. Rather than enabling preview AI experiences across the entire tenant, Microsoft provides Frontier Admin Control in the Microsoft 365 admin center to help administrators selectively manage access and run controlled pilot programs safely.  - [Exchange Online Tightens DNS Security for Mail Flow](https://mrmicrosoft.com/exchange-online-tightens-dns-security-for-mail-flow/): Microsoft continues to improve the security foundations of Exchange Online, this time by focusing on DNS — a core but often overlooked part of email transport. In an April 2026 update, Microsoft outlined progress on introducing modern DNS protections for Exchange Online mail flow, including support for DNSSEC, SMTP DANE, and MTA-STS. - [Microsoft Viva Connections is Now the SharePoint App](https://mrmicrosoft.com/microsoft-viva-connections-is-now-the-sharepoint-app/): Along with the rename, Microsoft SharePoint home sites are getting a few updates that simplify intranet management. - [Lock-free Coauthoring in Microsoft Word](https://mrmicrosoft.com/lock-free-coauthoring-in-microsoft-word/): Lock-free coauthoring allows multiple users to edit the same paragraph simultaneously, improving real-time collaboration in Word. - [Why Disable Direct Send in Exchange Online](https://mrmicrosoft.com/why-disable-direct-send-in-exchange-online/): For years, Direct Send in Exchange Online operated quietly in the background as a widely adopted convenience feature. It became a common solution for printers, scan-to-email devices, legacy applications, monitoring platforms, scripts, and various internal notification systems. Because it worked reliably with minimal configuration, it was often treated as a low-maintenance operational dependency across many Microsoft 365 environments.  - [How to Detect and Block Shadow AI in Microsoft 365 Admin Center ](https://mrmicrosoft.com/shadow-ai-in-microsoft-365-admin-center/): For years, IT teams have had a playbook for Shadow IT.  - [OneDrive Sync Limit Increase to 1 Million Items on Windows](https://mrmicrosoft.com/onedrive-sync-limit-increase-to-1-million-items-on-windows/): The OneDrive sync limit increase to 1 million items is a significant step forward, but it is not a universal upgrade. - [AI Skills in SharePoint Online – Repetitive Workflows Into Reusable Automation ](https://mrmicrosoft.com/ai-skills-in-sharepoint-online/): Microsoft's AI Skills feature in SharePoint Online is introduced as part of the AI in SharePoint public preview (previously called Knowledge Agent), Skills lets you encode a repeatable, multi-step workflow into a reusable asset, built entirely through natural language chat, stored directly on the site, and executable by any user with the right permissions.   - [How to Restrict a User’s OneDrive Content to a Security Group ](https://mrmicrosoft.com/how-to-restrict-a-users-onedrive-content-to-a-security-group/): When an employee leaves the company, their OneDrive still has shared links floating around. Someone, a contractor, a former colleague, or even a wrong email address, still has access. - [What Microsoft’s New Change Management Model Means for Your Organization](https://mrmicrosoft.com/what-microsofts-new-change-management-model-means-for-your-organization/): Microsoft is fundamentally transforming how organizations manage change in Microsoft 365. After years of feedback from IT administrators struggling to balance innovation with stability, Microsoft has introduced a modernized change management framework that gives you unprecedented control over when and how updates reach your organization. - [Measure Data Protection with Microsoft Purview Posture Reports](https://mrmicrosoft.com/measure-data-protection-with-microsoft-purview-posture-reports/): That stops with Posture Reports. After working with these in production environments, here's my honest take on what they do, where they shine, and what you should know before you lean on them too hard. - [Microsoft Entra Passkey on Windows (Public Preview)](https://mrmicrosoft.com/microsoft-entra-passkey-on-windows-public-preview/): 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐄𝐧𝐭𝐫𝐚 𝐩𝐚𝐬𝐬𝐤𝐞𝐲 𝐨𝐧 𝐖𝐢𝐧𝐝𝐨𝐰𝐬 𝐣𝐮𝐬𝐭 𝐡𝐢𝐭 𝐩𝐮𝐛𝐥𝐢𝐜 𝐩𝐫𝐞𝐯𝐢𝐞𝐰 - [Microsoft Copilot Cowork vs Claude Cowork](https://mrmicrosoft.com/copilot-cowork-vs-claude-cowork/): Copilot Cowork changes that dynamic.  - [How to Share Files in External Chats in Microsoft Teams](https://mrmicrosoft.com/how-to-share-files-in-external-chats-microsoft-teams/): Whether it's vendors, clients, or cross-tenant teams, most conversations in Microsoft Teams today extend beyond organizational boundaries. But while chat has evolved to support this seamlessly, file sharing has traditionally lagged behind—introducing friction at the worst possible moments.  - [Microsoft Entra Tenant Governance for Multi-Tenant Management](https://mrmicrosoft.com/microsoft-entra-tenant-governance-for-multi-tenant-management/):  Microsoft is now doing something about it and announced that Microsoft Entra Tenant Governance is in public preview.  - [Enable Third-Party AI Model Access for Specific Users in Microsoft 365 Copilot](https://mrmicrosoft.com/enable-third-party-ai-model-access-for-specific-users/): The ability to scope Microsoft 365 Copilot third-party AI model access at the group level isn't just a convenience feature. It directly addresses one of the most common barriers to Copilot adoption in regulated industries. - [How to Enable Co-authoring for Encrypted Sensitivity-Labeled Files](https://mrmicrosoft.com/how-to-enable-co-authoring-for-encrypted-sensitivity-labeled-files/): Microsoft Purview includes a tenant-level setting that directly addresses the collaboration gap in encrypted file workflows. When you enable co-authoring for files with sensitivity labels, the experience changes significantly for end users and the underlying file-handling infrastructure alike.  - [Microsoft Teams Detects External Meeting Assistant Bots Joining Meetings ](https://mrmicrosoft.com/microsoft-teams-detects-external-meeting-assistant-bots-joining-meetings/):  AI meeting bots, tools that transcribe, summarize, or record your conversations, have quietly become a fixture in online meetings. Many are genuinely useful. But the problem is not all of them are invited, and until now, most organizations have had no reliable way to know they were even there.  - [Quick Step in SharePoint Online: Automate Without Building a Single Flow ](https://mrmicrosoft.com/quick-step-in-sharepoint-online/): If you wanted to automate a simple status change, say, moving a policy from "Draft" to "Final," you had two choices.   - [OneDrive & SharePoint Online Plans Retirement](https://mrmicrosoft.com/sharepoint-online-onedrive-plan-1-2-retirement/): This isn't a surprise move. It's been coming for a while. - [What to Do When SharePoint Storage Is Full ](https://mrmicrosoft.com/what-to-do-when-sharepoint-storage-is-full/): An email from Microsoft with the subject line that makes every SharePoint admin's stomach drop:  - [How to Clean Up Recurring Meetings from Former Employees](https://mrmicrosoft.com/how-to-clean-up-recurring-meetings-from-former-employees/): An employee leaves, but their recurring meetings live on: daily stand-ups, weekly syncs, and monthly reviews. All are still sitting on everyone’s calendar, blocking rooms, confusing attendees, and quietly wasting time. - [Preservation Lock in Microsoft 365 ](https://mrmicrosoft.com/preservation-lock-in-microsoft-365/): This is exactly why I recommend Preservation Lock. I often describe Preservation Lock not just as a feature, but as a "final guardrail." It is the architectural equivalent of a one-way ratchet, you can tighten it, but you can never loosen it.   - [The New Message Trace Experience in Microsoft Graph API ](https://mrmicrosoft.com/the-new-message-trace-experience-in-microsoft-graph-api/): Microsoft has introduced native Message Trace and Message Trace Detail capabilities within the Microsoft Graph API, currently available in Public Preview, as part of its ongoing modernization of Exchange Online administrative and automation interfaces.  - [How to Deactivate Enterprise Applications in Microsoft Entra ID](https://mrmicrosoft.com/how-to-deactivate-enterprise-applications-in-microsoft-entra-id/): Security teams frequently encounter situations where they need to immediately stop an application's access to organizational resources. Whether it's suspicious API activity, a compromised integration, or a compliance requirement, administrators need a solution that blocks access instantly without destroying configuration data that took weeks to set up. - [New Content Management Assessment Tool in SharePoint](https://mrmicrosoft.com/new-content-management-assessment-tool-in-sharepoint/): That’s why Microsoft’s Content Management Assessment in SharePoint Advanced Management (SAM) is such a relief. I will explain more about it further in the blog. - [IDCRL Authentication Is Retiring SharePoint Online & OneDrive  ](https://mrmicrosoft.com/idcrl-authentication-is-retiring-sharepoint-online-onedrive/): Microsoft has clearly defined deadlines for retiring IDCRL authentication, and these dates are critical for avoiding service disruptions in SharePoint Online and OneDrive for Business.  - [New Unified External Collaboration Settings in Microsoft Teams Admin Center ](https://mrmicrosoft.com/unified-external-collaboration-settings-in-teams-admin-center/): Microsoft is addressing this fragmentation with the launch of the Unified External Collaboration Settings management experience (currently in preview).   - [Manage User Access to Copilot Agents in Microsoft 365 ](https://mrmicrosoft.com/manage-user-access-to-copilot-agents-in-microsoft-365/): As Copilot agents become more common across Microsoft 365, controlling who can access and use these agents is no longer optional; it’s a governance requirement.   - [Manage Application Management Policies in Microsoft Entra ](https://mrmicrosoft.com/manage-application-management-policies-in-microsoft-entra/): Microsoft finally gave us a proper way to close them using Application Management Policies in Entra ID.   - [New: Manage Version Expiration for Audio and Video Files in SharePoint Online ](https://mrmicrosoft.com/new-manage-version-expiration-for-audio-and-video-files-in-sharepoint-online/): So, from mid-December 2025, SharePoint Online will introduce file-type-specific version expiration policies for audio and video files.  - [Microsoft Retires Legacy IDCRL Authentication: Modern Auth Becomes Mandatory in 2026](https://mrmicrosoft.com/microsoft-retires-legacy-idcrl-authentication-modern-auth-becomes-mandatory-in-2026/): Microsoft has announced the retirement of the IDCRL authentication protocol in SharePoint Online and OneDrive for Business as part of the Secure Future Initiative. - [How to Delegate Workflow Management in Microsoft Entra ID](https://mrmicrosoft.com/how-to-delegate-workflow-management-in-microsoft-entra-id/): Before you can delegate workflow management, ensure your organization meets the following requirements: - [How to Manage Reauthentication Prompts Effectively in Microsoft Entra ID  ](https://mrmicrosoft.com/how-to-manage-reauthentication-prompts-effectively-in-microsoft-entra-id/): Nobody wants constant sign-in interruptions. You’re moving between Outlook, SharePoint, Teams, OneDrive, Planner, and suddenly another authentication challenge stops your workflow.  - [How to Configure App Instance Property Lock in Microsoft Entra ID ](https://mrmicrosoft.com/how-to-configure-app-instance-property-lock-in-microsoft-entra-id/): This is why the App Instance Property Lock isn't just a nice-to-have; it's a foundational security mandate for any robust Software as a Service (SaaS) provider operating in a shared identity environment.  - [How to Restrict M365 PowerShell Access to Managed Devices Using Conditional Access](https://mrmicrosoft.com/how-to-restrict-m365-powershell-access-to-managed-devices-using-conditional-access/): PowerShell remains one of the most powerful and essential tools for Microsoft 365 administration. However, this immense power inherently carries significant security risks. The reality is that a compromised admin account with unrestricted PowerShell access can lead to catastrophic data breaches, sweeping configuration changes, or a complete tenant takeover. - [SharePoint Admin Agent in Public Preview](https://mrmicrosoft.com/sharepoint-admin-agent-in-public-preview/): The SharePoint Admin Agent — now in Public Preview.  - [The New Exchange Online Admin API](https://mrmicrosoft.com/the-new-exchange-online-admin-api/): That deadlock finally breaks now. Microsoft has finally announced the Public Preview of the Exchange Online Admin API, the modern, API-first admin layer.   ## Pages - [Contact](https://mrmicrosoft.com/contact/): Have a question, collaboration idea, or just want to connect? I would love to hear from you. The best way to reach me is via LinkedIn. - [Books](https://mrmicrosoft.com/books/): Discover books by Mezbaul Anam on Microsoft AI, Copilot Studio, and Azure AI Foundry. Published by Apress, these practical guides help business leaders and technical professionals build intelligent AI agents and drive digital transformation. - [Terms and Conditions](https://mrmicrosoft.com/terms-and-conditions/): Welcome to mrmicrosoft.com. By accessing this website, you agree to comply with and be bound by the following terms and conditions of use. - [About](https://mrmicrosoft.com/about/): Hi, I’m Mezba Uddin, an Apress Author, Microsoft MVP, MCT, and Digital Transformation evangelist with a passion for simplifying complex IT challenges. - [Home](https://mrmicrosoft.com/): Accelerate your digital transformation journey with expert Microsoft 365 insights and solutions - [Blogs](https://mrmicrosoft.com/blogs/) - [Privacy Policy](https://mrmicrosoft.com/privacy-policy/): An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment. ## Tips - [Disable Activation Lock for Apple Devices Using Microsoft Intune](https://mrmicrosoft.com/tips/disable-activation-lock-for-apple-devices-using-microsoft-intune/): Administrators can either disable Activation Lock remotely or retrieve the device's Activation Lock bypass code, eliminating the need to contact the previous user for their Apple Account credentials. - [Cross-Tenant Message Recall in Exchange Online](https://mrmicrosoft.com/tips/cross-tenant-message-recall-in-exchange-online/): Exchange Online is expanding Message Recall with the introduction of 𝐂𝐫𝐨𝐬𝐬-𝐓𝐞𝐧𝐚𝐧𝐭 𝐌𝐞𝐬𝐬𝐚𝐠𝐞 𝐑𝐞𝐜𝐚𝐥𝐥. - [Time-Limited Role Group Assignments in Microsoft Purview](https://mrmicrosoft.com/tips/time-limited-role-group-assignments-in-microsoft-purview/): Many organizations grant elevated permissions for investigations, migrations, or compliance projects and then forget to remove them. - [Invoke-ChangeMeetingOrganizer: Transfer Meeting Ownership with PowerShell](https://mrmicrosoft.com/tips/invoke-changemeetingorganizer-transfer-meeting-ownership-with-powershell/): Changing the organizer of an existing meeting or recurring meeting series has traditionally meant recreating the meeting from scratch. Exchange Online now introduces a new PowerShell cmdlet that enables administrators to transfer meeting ownership without recreating the meeting or series: Invoke-ChangeMeetingOrganizer - [Exchange Online Is Retiring TLS 1.0 and TLS 1.1 for POP3 and IMAP4 Connections](https://mrmicrosoft.com/tips/exchange-online-is-retiring-tls-1-0-and-tls-1-1-for-pop3-and-imap4-connections/): Starting August 1, 2026, Microsoft will begin rolling out this security update worldwide, with completion expected by December 31, 2026. - [Advanced Intune Capabilities Are Now Included with Microsoft 365 E3 and E5](https://mrmicrosoft.com/tips/advanced-intune-capabilities-are-now-included-with-microsoft-365-e3-and-e5/): You may no longer need Intune Suite for some advanced Intune capabilities. - [New in SharePoint Advanced Management: Create Custom Groups of Sites](https://mrmicrosoft.com/tips/new-in-sharepoint-advanced-management-create-custom-groups-of-sites/): If your organization has hundreds or thousands of SharePoint sites, keeping them organized can be difficult. - [Teams Private Channel Migration: Fix Ownerless Channels Before July Ends](https://mrmicrosoft.com/tips/teams-private-channel-migration-fix-ownerless-channels-before-july-ends/): To migrate them successfully, admins must add at least one in-tenant user as the channel owner. - [SharePoint Remote Event Receivers Retirement: Timeline and Migration](https://mrmicrosoft.com/tips/sharepoint-remote-event-receivers-retirement-timeline-and-migration/): Microsoft has confirmed that all SharePoint Remote Event Receivers will be fully retired by July 1, 2027. - [Microsoft Entra Backup and Recovery is Generally Available](https://mrmicrosoft.com/tips/microsoft-entra-backup-and-recovery-is-generally-available/): For years, recovering from accidental changes or misconfigurations in Entra meant leaning on audit logs, PowerShell scripts, or third-party backup tools, because native recovery did not exist in any meaningful way. That changes now! - [Microsoft Edge Blocks Screen Capture in OneDrive and SharePoint Web Viewers](https://mrmicrosoft.com/tips/microsoft-edge-blocks-screen-capture-in-onedrive-and-sharepoint-web-viewers/): If you work with Purview sensitivity labels, you've probably run into this one. - [Microsoft Purview DLP: User-Based Alert Aggregation](https://mrmicrosoft.com/tips/microsoft-purview-dlp-user-based-alert-aggregation/): One of the most frustrating parts of investigating DLP incidents isn't always the policy itself; it's the flood of alerts. When the same user triggers multiple DLP events in a short period, we often end up piecing together several separate alerts to understand a single incident. It adds noise, slows investigations, and makes it harder to focus on what actually matters. Microsoft is addressing this with a new user-based alert aggregation capability in DLP. Instead of creating a separate alert for every event, related DLP events from the same user can be grouped into a single alert within a configurable time window, even if they match different DLP rules. The result is less alert fatigue and a better investigation context. Once the feature rolls out in mid-August 2026, you can enable it from Settings > DLP settings > Alert settings > Event aggregation into alerts, choose User-based aggregation, configure the aggregation window, and save the settings.   It doesn't affect DLP policy enforcement; the policies continue to work as configured. This update only changes how related alerts are grouped for investigation. - [New & Refreshed Library View in OneDrive for Web](https://mrmicrosoft.com/tips/new-refreshed-library-view-in-onedrive-for-web/): Microsoft is introducing a refreshed Libraries experience in Microsoft OneDrive for the web, replacing the existing More places view. This update improves how users discover and access document libraries across Microsoft SharePoint and Microsoft Teams. - [Defender for Office Plan 1 Now Included in E3](https://mrmicrosoft.com/tips/defender-for-office-plan-1-now-included-in-e3/): 𝐃𝐞𝐟𝐞𝐧𝐝𝐞𝐫 𝐟𝐨𝐫 𝐎𝐟𝐟𝐢𝐜𝐞 365 𝐏𝐥𝐚𝐧 1 𝐢𝐬 𝐧𝐨𝐰 𝐛𝐞𝐢𝐧𝐠 𝐚𝐝𝐝𝐞𝐝 𝐭𝐨 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 365 𝐄3 𝐚𝐧𝐝 𝐎𝐟𝐟𝐢𝐜𝐞 365 𝐄3. - [Microsoft Removes CAPTCHA from SSPR](https://mrmicrosoft.com/tips/microsoft-removes-captcha-from-sspr/): 👉 Here's the thing : CAPTCHA was already losing the battle. Automated solvers have gotten good enough that a CAPTCHA challenge isn't really a meaningful barrier for a determined attacker. That's a bad deal. - [New Role Group UI for Microsoft Purview Compliance Portal](https://mrmicrosoft.com/tips/new-role-group-ui-for-microsoft-purview-compliance-portal/): With this update, Microsoft is introducing new views that allow admins to look up Role Group assignments: - [OneDrive Migrating to cloud.microsoft Domain](https://mrmicrosoft.com/tips/onedrive-migrating-to-cloud-microsoft-domain/): 𝐎𝐧𝐞𝐃𝐫𝐢𝐯𝐞 𝐢𝐬 𝐦𝐢𝐠𝐫𝐚𝐭𝐢𝐧𝐠 𝐭𝐨 𝐭𝐡𝐞 𝐜𝐥𝐨𝐮𝐝.𝐦𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐝𝐨𝐦𝐚𝐢𝐧 𝐬𝐭𝐚𝐫𝐭𝐢𝐧𝐠 𝐉𝐮𝐥𝐲 2026. - [Microsoft Entra Connect v2.6.79.0: Advancing Passwordless Security](https://mrmicrosoft.com/tips/microsoft-entra-connect-v2-6-79-0-advancing-passwordless-security/): Microsoft Entra Connect v2.6.79.0 has been released, and although it doesn’t introduce architectural changes, it delivers several targeted improvements that strengthen both the security and operational resilience of hybrid identity deployments. - [Manual Incident and Alert Creation in Microsoft Defender](https://mrmicrosoft.com/tips/manual-incident-and-alert-creation-in-microsoft-defender/): Until now, incidents and alerts in Defender were primarily created through automated detections. With this new capability, SOC teams can create them on demand and track security activities that don't originate from a Defender alert. - [Headroom: Reduce AI Agent Token Usage by 95%](https://mrmicrosoft.com/tips/headroom-reduce-ai-agent-token-usage-by-95/): Headroom solves this in a refreshingly simple way. This is an interesting open-source project that approaches this challenge from a practical and scalable perspective. - [Teams Transcript Access via Microsoft Graph Now Requires Explicit Admin Approval](https://mrmicrosoft.com/tips/teams-transcript-access-via-microsoft-graph-now-requires-explicit-admin-approval/): Teams transcript retrieval through Microsoft Graph is gaining an additional authorization layer. - [Create and Publish Organization Prompts to Copilot Chat](https://mrmicrosoft.com/tips/create-and-publish-organization-prompts-to-copilot-chat/): To help organizations address this challenge, Microsoft is introducing Organization Prompts to Copilot Chat. - [Copilot Cowork is Generally Available](https://mrmicrosoft.com/tips/copilot-cowork-is-generally-available/): Copilot Cowork is generally available for Microsoft 365 Copilot customers worldwide. The interesting part isn't the announcement, it's the billing and execution model underneath it. Quick context for anyone who's only seen the chat experience: Cowork isn't a Copilot Chat feature with extra steps. It's a separate agentic runtime. You give it a task, it plans, calls tools, retrieves context from Work IQ, runs across multiple turns without you babysitting it, and hands back a finished artifact. Closer to handing work to a junior analyst than prompting a chatbot. A few things M365 admins and architects should actually internalize before rolling this out: Cost isn't per-seat anymore — it's per-execution, and the meter has four inputs. Cost is driven by factors such as model selection, context retrieval, tool usage, and execution complexity, all of which influence Copilot Credit consumption. That means the same "task" phrased two different ways can cost very differently depending on how much it forces the agent to search, call connectors, or iterate. If you're scoping this for a team, you're not estimating "how many users" — you're estimating prompt shape (light/medium / heavy) per persona, because a heavy task (broad aggregation, deep reasoning, many outputs) can burn credits at a completely different rate than a light one. Model choice is now a cost lever, not just a capability one. GA introduces support for Anthropic Opus 4.8 and Sonnet 4.6, with Microsoft also previewing its upcoming Cowork 1 model. The implication: once Cowork 1 lands, you'll want routing logic (or at least guidance to your users) on when a task needs frontier reasoning versus when a cheaper fine-tuned model is enough. Unless you're on Frontier, model selection options are currently more limited, reducing the ability to actively optimize cost versus capability. PayGo vs P3 is a real commitment decision, not boilerplate pricing copy. PayGo is $0.01/credit, no commitment. P3 introduces prepaid/committed consumption economics, making it more like a cloud capacity-planning decision than a traditional software license purchase. Browser use via Edge is currently Frontier-only, and it's the part to watch. Cowork can drive a local Edge session under the existing enterprise policy. That's a meaningfully larger attack/exposure surface than a tool-call-based agent — it's effectively giving an agent a browser session with your policies applied. Worth testing in Frontier before it hits GA broadly, not after. The "off by default" design is the right call, but plan the rollout like a phased feature flag, not a license assignment. Tenant admins have to explicitly turn it on, and you get group/user-level spend caps plus usage alerts before usage even starts. - [Microsoft 365 eSignature Recipient Groups: Multiple Signers for a Single Approval Step](https://mrmicrosoft.com/tips/microsoft-365-esignature-recipient-groups-multiple-signers-for-a-single-approval-step/): eSignature workflows in Microsoft 365 are gaining a useful enhancement with the introduction of Recipient Groups. - [DLP Policy Sync Time Reduced from 2 Hours to 30 Minutes](https://mrmicrosoft.com/tips/dlp-policy-sync-time-reduced-from-2-hours-to-30-minutes/): Previously, after updating a DLP policy, organizations could wait up to 2 hours for that protection to be fully enforced. - [Microsoft Teams Introduces Dedicated Governance for Built-in AI Agents](https://mrmicrosoft.com/tips/microsoft-teams-introduces-dedicated-governance-for-built-in-ai-agents/): Previously, built-in agents were governed alongside traditional Teams apps. But agents such as Channel Agent, Facilitator, and Copilot Agent are different—they are deeply integrated into Teams and do not require installation from the Teams app store. - [Staged Retention Enforcement for Unlicensed OneDrive Accounts](https://mrmicrosoft.com/tips/staged-retention-enforcement-for-unlicensed-onedrive-accounts/): Managing inactive OneDrive accounts can be challenging for organizations, especially when former employees’ data remains stored without an active Microsoft 365 license. To improve storage management and provide administrators with clearer visibility and control, Microsoft is introducing a new staged retention enforcement lifecycle for unlicensed OneDrive accounts. - [AI Assets (Preview) in Microsoft Defender](https://mrmicrosoft.com/tips/ai-assets-preview-in-microsoft-defender/): 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐃𝐞𝐟𝐞𝐧𝐝𝐞𝐫’𝐬 𝐧𝐞𝐰 𝐀𝐈 𝐀𝐬𝐬𝐞𝐭𝐬 (𝐏𝐫𝐞𝐯𝐢𝐞𝐰) 𝐞𝐱𝐩𝐞𝐫𝐢𝐞𝐧𝐜𝐞 𝐛𝐫𝐢𝐧𝐠𝐬 𝐥𝐨𝐜𝐚𝐥 𝐀𝐈 𝐚𝐠𝐞𝐧𝐭𝐬 𝐢𝐧𝐭𝐨 𝐭𝐡𝐞 𝐬𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐢𝐧𝐯𝐞𝐧𝐭𝐨𝐫𝐲. - [Sensitivity Lables for Microsoft Entra Security Groups](https://mrmicrosoft.com/tips/sensitivity-lables-for-microsoft-entra-security-groups/): Security groups have always been one of the most critical pieces of access control in Microsoft Entra. - [Update User Attributes in Lifecycle Workflows (Preview) for Microsoft Entra](https://mrmicrosoft.com/tips/update-user-attributes-in-lifecycle-workflows-preview-for-microsoft-entra/): Employee lifecycle doesn't stop at onboarding and offboarding. Employees get promoted, switch departments, relocate, and take on new responsibilities. When those changes aren't reflected in Microsoft Entra ID quickly, identity-driven processes such as dynamic group membership, application assignments, and governance controls can drift out of sync. Microsoft Entra Lifecycle Workflows now introduces a new Update user attributes task (Preview). Workflows can now modify user attributes: department, job title, city, extension attributes, as part of the same joiner, mover, or leaver execution, without requiring separate scripts, custom automation, or manual administrative updates. For example, when an employee moves from Sales to Marketing, a single workflow can update their profile attributes, such as department, job title, location, or extension attributes, while continuing with other lifecycle actions. A few things to note before rolling it out: Up to 10 attributes can be updated per task instance Cloud-managed users only; on-prem synced users are not supported Custom security attributes are currently out of scope Lifecycle Workflows is steadily evolving from a task automation engine into a more complete identity lifecycle management platform. - [Microsoft Scout Autopilot Agent: A New Era of AI-Powered Work](https://mrmicrosoft.com/tips/microsoft-scout-autopilot-agent/): We've spent the last year learning how to work with AI assistants. Microsoft Scout suggests the next phase may be letting AI work alongside us. At first glance, it's easy to think Scout is simply another version of Copilot. It's not! The difference is less about intelligence and more about the operating model. Copilot is primarily interaction-driven. You ask a question, request a summary, generate content, or complete a task, and Copilot responds. Scout is designed as a persistent agent. Instead of waiting for the next prompt, it maintains awareness of the work you've entrusted to it and continuously works toward defined goals. What caught my attention is Microsoft's use of the term "Autopilot agent." An agent capable of understanding context across emails, meetings, chats, documents, tasks, and schedules, then using that context to help move work forward. For example, instead of repeatedly asking AI to summarize meetings, track action items, gather supporting information, and prepare follow-ups, Scout can continuously monitor those workflows and surface what needs attention at the right time. 👉🏻The real innovation isn't that Scout can generate content. Most AI tools can already do that. 👉🏻The innovation is that Scout is being positioned to manage ongoing work rather than individual requests. Of course, this is also where the enterprise conversation becomes important. As organizations evaluate agent-based AI, questions around governance become just as important as the technology itself: What permissions does the agent have? Which data sources can it access? How are actions monitored and audited? What controls exist to prevent unintended actions? The success of autonomous agents won't be determined solely by their capabilities. It will depend on how effectively organizations can govern, secure, and trust them. If you're interested in testing Scout, Microsoft is currently offering it through a limited private preview and the Frontier program, with setup requiring Frontier enrollment, Intune policy configuration, and user attestation. You can learn more about the onboarding process here: https://learn.microsoft.com/en-us/microsoft-scout/get-started - [Purview DLP External User Blocking in SharePoint and OneDrive](https://mrmicrosoft.com/tips/purview-dlp-external-user-blocking-in-sharepoint-and-onedrive/): DLP is finally getting a capability many admins have been waiting for. This is really a much-needed enhancement to DLP for SharePoint Online and OneDrive. Purview DLP External User Blocking Microsoft Purview DLP is adding domain- and user-level blocking for SharePoint Online and OneDrive. This means organizations will be able to block access to sensitive files based on a specific external domain or individual email address. Until now, controlling external access meant fairly blunt options: allow or block sharing broadly. This changes that! Going further, we'll be able to configure DLP rules to explicitly block access by domain (partner.com) or by specific user (user@partner.com), and optionally set allow lists for trusted collaborators. If someone lands on both lists, the block wins. Blocked users see an access denied message and can't open or download the file. The configuration is: DLP → Policies → Actions → Restrict access → Block by domain or user. This is purely admin-driven; nothing changes unless configured. Will roll out in public preview from late May to early June, with GA in July 2026. I feel this is highly useful for organizations that collaborate with multiple partners, vendors, contractors, or customers. Instead of broadly allowing external access, we can explicitly block high-risk domains or individual external users while continuing to support legitimate business collaboration. That's the kind of granular control enterprise DLP should have had for a while. - [Teams PowerShell WAM Becomes the Default Authentication Broker](https://mrmicrosoft.com/tips/teams-powershell-wam-becomes-the-default-authentication-broker/): Microsoft Teams PowerShell Is Switching to WAM Authentication by Default - [Convert PDF to Markdown to Reduce AI Token Usage](https://mrmicrosoft.com/tips/convert-pdf-to-markdown-to-reduce-ai-token-usage/): Instead of feeding raw PDFs into AI, convert PDF to Markdown first. - [Microsoft Teams Guest Invitation Emails Will Now Come From the Inviter](https://mrmicrosoft.com/tips/microsoft-teams-guest-invitation-emails-will-now-come-from-the-inviter/): Surprisingly, that's not how Microsoft Teams guest invitations worked before. - [Conditional Access Now Applies to WHfB Registration](https://mrmicrosoft.com/tips/conditional-access-now-applies-to-whfb-registration/): Starting July 6, 2026, users registering WHfB or macOS Platform SSO credentials will need to satisfy your Conditional Access requirements before enrollment can complete. - [Microsoft 365 Usage Analytics Power BI Template App Retiring](https://mrmicrosoft.com/tips/microsoft-365-usage-analytics-power-bi-template-app-retiring/): Many Microsoft 365 admins use the Microsoft 365 Usage Analytics Power BI template app to track adoption, usage trends, collaboration activity, and service-level insights across Teams, Exchange, SharePoint, and OneDrive from a centralized dashboard. - [Microsoft Defender Expands ZAP Protection to Deleted Items](https://mrmicrosoft.com/tips/microsoft-defender-expands-zap-protection-to-deleted-items/): Microsoft is strengthening post-delivery email protection in Microsoft Defender for Office 365 by expanding Zero-hour Auto Purge (ZAP) capabilities. - [Outlook Inbox Rules Now Support External Email Tag](https://mrmicrosoft.com/tips/outlook-inbox-rules-now-support-external-email-tag/): 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐢𝐬 𝐞𝐱𝐭𝐞𝐧𝐝𝐢𝐧𝐠 𝐎𝐮𝐭𝐥𝐨𝐨𝐤 𝐈𝐧𝐛𝐨𝐱 𝐑𝐮𝐥𝐞𝐬 𝐰𝐢𝐭𝐡 𝐬𝐮𝐩𝐩𝐨𝐫𝐭 𝐟𝐨𝐫 𝐭𝐡𝐞 𝐄𝐱𝐭𝐞𝐫𝐧𝐚𝐥 𝐞𝐦𝐚𝐢𝐥 𝐭𝐚𝐠. - [Authentication Policy Logs Get Cleaner Change Tracking](https://mrmicrosoft.com/tips/authentication-policy-logs-get-cleaner-change-tracking/): Microsoft is finally cleaning up one of the most frustrating parts of Entra audit logs. - [High Volume Email in Microsoft 365 is Generally Available](https://mrmicrosoft.com/tips/high-volume-email-in-microsoft-365-is-generally-available/): After nearly two years in Public Preview, High Volume Email(HVE) in Microsoft 365 is Generally Available - [LDAP Support for S/MIME Certificate Lookup in New Outlook for Windows](https://mrmicrosoft.com/tips/ldap-support-for-s-mime-certificate-lookup-in-new-outlook-for-windows/): Introducing LDAP Support for S/MIME Certificate Lookup in New Outlook for Windows - [Determine Resource Mailbox Usage with PowerShell](https://mrmicrosoft.com/tips/determine-resource-mailbox-usage-with-powershell/): If you’ve ever tried cleaning up resource mailboxes in Exchange Online, you’ve probably hit the same problem: there’s no native report that shows which room or resource mailboxes are actually being used. That means mailbox count alone doesn’t tell the full story. The better approach is to look at the calendar and folder activity through PowerShell to understand real usage patterns. Here are the cmdlets worth knowing: Get-CalendarViewDiagnostics: A strong starting point for usage analysis. Queries calendar activity across a time range so you can identify actual booking patterns and spot stale or inactive resources. Get-Mailbox -RecipientTypeDetails RoomMailbox: Enumerates all room mailboxes in the tenant. Typically used first to build the resource inventory before running deeper analysis. Get-EXOMailboxFolderStatistics: Returns folder-level counts and size metrics (including Calendar) to validate whether booking activity is actually happening. Get-CalendarDiagnosticObjects: Useful for investigating individual meeting issues, but not ideal for tenant-wide usage reporting because of the volume of diagnostic output. No single cmdlet gives you a complete utilization view. The practical approach is combining Get-Mailbox to enumerate resources with Get-CalendarViewDiagnostics or Get-EXOMailboxFolderStatistics to measure activity, and then deciding upfront what "actively used" actually means in your tenant before acting on the data. Using this approach helps you: Identify underused or abandoned meeting rooms. Validate demand before making resource changes. Improve workspace and resource governance. Reduce unnecessary mailbox sprawl. Learn how to use the cmdlets here: https://techcommunity.microsoft.com/blog/exchange/how-to-determine-which-resource-mailboxes-are-being-actively-used/4521577 - [New Lock-free Coauthoring in Microsoft Word](https://mrmicrosoft.com/tips/new-lock-free-coauthoring-in-microsoft-word/): With the new lock-free coauthoring experience, that changes. - [Copilot in SharePoint (AI in SharePoint)](https://mrmicrosoft.com/tips/copilot-in-sharepoint-ai-in-sharepoint/): Copilot in SharePoint (formerly called AI in SharePoint) is officially moving to an opt-out preview starting mid-June 2026. The experience will automatically appear for users with a Microsoft 365 Copilot license unless admins proactively disable it at the tenant or site level. What makes this announcement important is that Microsoft is finally bringing together years of investments across: Project Cortex (Precessor) SharePoint Syntex Microsoft Syntex SharePoint Premium AI in SharePoint …into a much more operational AI experience inside SharePoint itself. Copilot in SharePoint Users will see a floating Copilot button across SharePoint sites, pages, document libraries, and lists. The experience is fully permission-trimmed; Copilot only accesses content users are already authorized to view or edit within SharePoint. The capabilities go far beyond simple AI chat: Build and edit pages, sites, and HTML reports using prompts Organize libraries and populate metadata automatically Create and update lists through natural language instructions Find and remediate missing or incomplete content Encode organization-specific processes as reusable “skills” so Copilot follows your team’s operational playbook The existing Site Agents experience will also transition into Copilot in SharePoint for licensed users automatically. Pay-as-you-go billing remains applicable only for custom SharePoint agents. Another notable detail: Microsoft confirmed the rollout will initially use OpenAI’s GPT-5.4 Reasoning model, with no customer-controlled model selection available at this stage. SharePoint is steadily evolving from a content repository into an AI-powered business process and knowledge platform, and Copilot in SharePoint feels like one of the biggest steps in that transition so far. Official announcement: https://admin.cloud.microsoft/?#/MessageCenter/:/messages/MC1311968 - [New Targeting Experience for Sensitivity Label Policies](https://mrmicrosoft.com/tips/new-targeting-experience-for-sensitivity-label-policies/): Microsoft is updating how admins assign sensitivity label policies with a new targeting experience. - [Security Detection Report in Teams Admin Center](https://mrmicrosoft.com/tips/security-detection-report-in-teams-admin-center/): A new Security Detection Report is coming to the Microsoft Teams admin center, giving admins centralized visibility into messaging-based threats. - [Authoritative Sites for SharePoint in Microsoft Copilot](https://mrmicrosoft.com/tips/authoritative-sites-for-sharepoint-in-microsoft-copilot/): The feature, called 𝐀𝐮𝐭𝐡𝐨𝐫𝐢𝐭𝐚𝐭𝐢𝐯𝐞 𝐒𝐢𝐭𝐞𝐬, gives organizations a way to influence which internal content Copilot surfaces first when answering user prompts. - [Microsoft Entra ID Enables App Instance Lock by Default](https://mrmicrosoft.com/tips/microsoft-entra-id-enables-app-instance-lock-by-default/): Most security discussions in Microsoft 365 focus on users. - [Microsoft Graph Mailbox Import and Export APIs Now Generally Available](https://mrmicrosoft.com/tips/microsoft-graph-mailbox-import-and-export-apis-now-generally-available/): Microsoft just reached another important milestone in the Exchange Online modernization journey. The Mailbox Import and Export APIs for Microsoft Graph are now Generally Available. For organizations and solution developers modernizing mailbox data workflows, this release introduces a production-ready approach to programmatically import and export mailbox content directly through Microsoft Graph. With GA, organizations now have a production-ready way to: Import and export Exchange Online mailbox data with full fidelity Build migration and mailbox movement workflows on Microsoft Graph Apply more granular access controls through Graph permissions Support primary and shared mailboxes in production scenarios This release also reinforces Microsoft’s broader direction toward Graph-first development and continued movement away from legacy Exchange Web Services (EWS) dependencies. Exported content is designed to preserve mailbox fidelity and should be treated as an export/import stream rather than a reusable interchange format. If you tested this during preview, moving to GA should be straightforward for supported mailbox scenarios. Another clear signal that Microsoft’s Exchange ecosystem continues shifting deeper into Graph-first experiences. Read the official announcement: https://devblogs.microsoft.com/microsoft365dev/announcing-general-availability-of-the-mailbox-import-and-export-microsoft-graph-apis/ ## Tools - [Stellar Migrator for Exchange – Hands on review](https://mrmicrosoft.com/tools/stellar-migrator-for-exchange-hands-on-review/): Migrating mailboxes between Exchange Server and Microsoft 365 tenants is one of those tasks that tends to surface during company mergers, divestitures or when moving from on‑premises infrastructure to the cloud. Without automation, you’re left juggling PowerShell scripts, manual mailbox mapping and a great deal of downtime. To see if Stellar Migrator for Exchange could simplify this process, I tested the tool in a live environment and this review walks through the setup, performance, and features I found most useful. - [Stellar Converter for EDB Hands-On Review of a Reliable Exchange Mailbox Conversion Tool](https://mrmicrosoft.com/tools/stellar-converter-for-edb/): As an Exchange admin, you're bound to face situations where converting mailboxes from an EDB file becomes urgent. Whether due to offline database, or planned migrations, having a dependable tool can save hours of manual effort and reduce downtime. I recently put Stellar Converter for EDB to the test in a live Exchange environment, and in this review, I’ll walk you through the actual experience, performance, and results.