Vue normale

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
À partir d’avant-hier4sysops

Exchange ActiveSync CBA ending: avoid “Can’t Connect” errors by migrating now

Par : IT Experts
22 mai 2026 à 23:45
Configuration steps for migrating to Entra-based CBA (image Microsoft)
Microsoft announced on May 8, 2026, that it will retire direct certificate-based authentication (CBA) for Exchange ActiveSync (EAS) by the end of 2026. If your organization uses certificates to authenticate mobile devices against Exchange Online, you must migrate to a new method before the deadline, or your users' mobile email will stop working. This article explains what the change means, who is affected, and what steps you need to take.

Source

New Windows Autopatch Secure Boot status report in Intune admin center

Par : IT Experts
19 mai 2026 à 21:46
Secure Boot status report in Intune admin center (image Microsoft)
Windows Autopatch in the Intune admin center now includes an updated Secure Boot status report that provides device-level visibility into certificate readiness ahead of the 2026 expiry deadline. The report shows which devices have Secure Boot enabled, whether their certificates are up to date, and whether automatic or manual deployment applies. New columns for trust configuration, confidence level, and alerts help you make targeted decisions instead of broad deployments.

Source

Windows 11 SecureBoot folder: PowerShell scripts explained

Par : IT Experts
19 mai 2026 à 21:44
Secure Boot certificate status dashboard (image Microsoft)
The May 2026 cumulative update KB5089549 added a new C:\Windows\SecureBoot\ExampleRolloutScripts folder containing seven PowerShell scripts. These scripts are part of Microsoft's sample toolkit for managing Secure Boot certificate migration across enterprise environments. This article explains what each script does, how to run it, and its limitations.

Source

Automate Platform SSO setup during macOS enrollment with Microsoft Intune

Par : IT Experts
18 mai 2026 à 21:11
Enabling Secure Enclave biometric authentication for passwordless sign-in
Microsoft has made Platform Single Sign-On (PSSO) during Automated Device Enrollment (ADE) generally available for macOS. The new EnableRegistrationDuringSetup setting in Microsoft Intune completes device registration and SSO configuration automatically during Setup Assistant — the initial macOS setup wizard — before the user ever reaches the desktop. This article explains what PSSO is, why the new setting matters, what you need to configure it, and what limitations to expect.

Source

Sensitivity labels now in Microsoft 365 web apps

Par : IT Experts
7 mai 2026 à 21:08
Specify who can do what (image Microsoft)
Microsoft is rolling out a long-overdue change to the browser-based versions of Word, Excel, and PowerPoint: you can now apply sensitivity labels with user-defined permissions directly in the web apps without switching to the desktop client. Sensitivity labels are classification tags you attach to a file to control who can read, edit, or print it. They are configured centrally in Microsoft Purview (Microsoft's compliance and information protection platform) and enforced by the Rights Management Service (RMS), which is the encryption engine built into Microsoft 365. This update started rolling out in mid-April 2026 and is expected to be completed worldwide by early May 2026. It requires enabling coauthoring on encrypted files in your tenant beforehand.

Source

Microsoft LiteBox: a library OS for secure sandboxing and running Linux apps on Windows

Par : IT Experts
24 avril 2026 à 21:39
A Library OS embeds operating system services as libraries
Microsoft has released LiteBox, an open-source Library Operating System (Library OS) designed to strengthen security through application sandboxing. LiteBox minimizes the attack surface by restricting application access to system resources. While the core relies on Rust, the project includes specific low-level components written in C and Assembly. Additionally, LiteBox enables running Linux applications on Windows.

Source

Microsoft Sentinel Logstash output plugin: DCR-based log ingestion

Par : IT Experts
22 avril 2026 à 21:35
End to end architecture logstash > dce > dcr > log analytics workspace, authenticated with entra id (image microsoft)
Microsoft has released a new version of the Logstash output plugin for Microsoft Sentinel in public preview. The plugin replaces the older authentication method—a shared workspace key—with Microsoft Entra ID app-based authentication and routes data through Azure Monitor's Data Collection Rules. This article explains how the plugin works, what you need to set it up, and its current limitations.

Source

Exchange 2016/2019 ESU Period 2: paid security updates until October 2026

Par : IT Experts
22 avril 2026 à 21:31
Exchange 2016_2019 ESU Period 2 (image Microsoft)
Microsoft announced on April 15, 2026, a second paid security update period—called "Period 2"—for Exchange Server 2016 and 2019. This extends coverage from May through October 2026 for organizations unable to complete their migration to Exchange Server Subscription Edition (SE). The program covers only security-related patches and requires a separate purchase via a Microsoft Enterprise Agreement. This article explains what the program includes, who qualifies, and the practical limitations.

Source

New Windows RDP phishing warning: Caution: Unknown remote connection

Par : IT Experts
21 avril 2026 à 21:24
Caution: Unknown remote connection (image Microsoft)
The April 2026 Patch Tuesday updates add anti-phishing protection to the Windows Remote Desktop client (mstsc.exe). The change — assigned CVE-2026-26151 — means that opening an .rdp file now triggers a security dialog that lists all requested resource-sharing settings, each disabled by default. Files without a verifiable publisher show a red "Caution: Unknown remote connection" banner. The update affects Windows 10 and Windows 11 versions 23H2 and later.

Source

Microsoft 365 Copilot security: Purview DLP, oversharing controls, and dashboard analytics

Par : IT Experts
15 avril 2026 à 16:00
Microsoft Purview Data Loss Prevention for web queries
Microsoft released new security and governance controls for Microsoft 365 Copilot, introducing Data Loss Prevention (DLP) policies that inspect prompts before Copilot processes them, protecting web searches from leaking sensitive data, and enabling bulk remediation of overshared SharePoint files. The Copilot Dashboard gained expanded access, user satisfaction tracking, and CSV export. This article explains what each feature does technically, how to configure the relevant policies, and where the current limitations are.

Source

Microsoft Entra SCIM 2.0: Now with bidirectional provisioning

Par : IT Experts
14 avril 2026 à 14:53
Entra now supports bidirectional scim provisioning
Microsoft introduced new SCIM 2.0 APIs for Microsoft Entra. The APIs now support bidirectional provisioning, which allows external identity systems to provision users and groups directly into Entra. SCIM (System for Cross-domain Identity Management) is an open internet standard that defines a common HTTP-based protocol for managing user accounts across different systems. Previously, Entra could only push user data to other applications via SCIM. Now, it also accepts incoming SCIM requests. The APIs follow a consumption-based pricing model, require an Azure subscription, and are generally available in the Microsoft public cloud.

Source

Entra ID Conditional Access Optimization Agent: AI-driven policy gap detection

Par : IT Experts
13 avril 2026 à 15:40
Creating a phased rollout plan (image Microsoft)
Microsoft's Conditional Access Optimization Agent uses AI to continuously scan your Microsoft Entra ID environment for policy gaps and recommend remediations. It requires a Microsoft Entra ID P1 license and a Microsoft Security Copilot subscription. Several new features are in public preview, including context-aware recommendations, deep gap analysis across all policies, and phased policy rollouts. This article explains what Conditional Access policies are, how the agent works, what you need to run it, and where its limitations lie.

Source

Microsoft Entra March 2026: Passkeys GA, backup preview, and Hybrid Security Fix

Par : IT Experts
8 avril 2026 à 17:52
Microsoft entra backup and recovery in admin center (image microsoft)
Microsoft's March 2026 Entra update promotes passkey authentication to general availability, introduces a built-in tenant backup feature in public preview, and announces a breaking security change for hybrid environments, taking effect June 1, 2026. Additional changes enforce TLS 1.2 for Entra Connect Health agents and bring several multi-tenant governance capabilities into preview. This article covers changes relevant to administrators managing Microsoft 365 tenants and hybrid Active Directory environments.

Source

Mail-Advanced.ReadWrite permissions required to change sensitive email properties in Exchange Online via Graph API

Par : IT Experts
6 avril 2026 à 17:54
Mail-Advanced.ReadWrite allows you to modify sensitive properties in Exchange Online
Microsoft announced a breaking change to the Microsoft Graph API affecting Exchange Online: from December 31, 2026, applications that modify sensitive email properties -- such as the subject, body, or recipients -- on delivered messages must hold elevated Mail-Advanced.ReadWrite permissions. Until now, the standard Mail.ReadWrite permission was sufficient for these operations. The new permissions require explicit approval from the tenant administrator ("admin consent"). If you operate Microsoft 365 and have custom applications or third-party tools that interact with email via the Graph API, you need to audit and potentially update these apps before the enforcement date.

Source

Windows 11 Insider builds: Administrator Protection, NPU monitoring, console updates

Par : IT Experts
31 mars 2026 à 16:27
Enabling administrator protection
Microsoft released new preview builds across three Windows Insider channels. The Dev and Beta channels (Builds 26300.8142 and 26220.8138, both based on Windows 11 25H2) introduce the most notable changes: continued rollout of Administrator Protection—a new security feature that limits what admin accounts can do by default—plus Task Manager improvements for monitoring the Neural Processing Unit (NPU) and a new touchpad setting. The Canary Channel receives Build 29558, which primarily introduces Windows Console Host improvements but also includes other fixes.

Source

Windows Kerberos RC4 deprecation: what will break in Active Directory and how to fix it

Par : IT Experts
30 mars 2026 à 15:34
Windows kerberos rc4 deprecation might break active directory authentication
Starting in April 2026, Windows updates will change the default Kerberos ticket issuance behavior to AES-SHA1 for accounts without explicit encryption settings, while RC4 can still be used where explicitly enabled. This change, driven by CVE-2026-20833, affects every Windows Server environment where service accounts or devices still rely on RC4. Any service account, NAS device, or legacy application not explicitly configured for AES-SHA1 encryption may lose authentication capability. This article explains what Kerberos and RC4 are, what will break in April 2026, and what you must do to prevent outages.

Source

What is Microsoft Defender for Cloud Apps?

Par : IT Experts
27 mars 2026 à 15:50
Microsoft Defender for Cloud Apps protects SaaS applications (image Microsoft)
Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) solution that delivers comprehensive security for Software as a Service (SaaS) applications across your organization. This security platform provides visibility into shadow IT, threat protection, data loss prevention capabilities, and security posture management for cloud-based applications. The tool integrates with Microsoft Defender XDR to offer extended detection and response across the full attack chain. Recent updates include March 2026 changes to Secure Score category calculations that reclassify some recommendations from the Cloud apps category to Identity, more accurately reflecting where controls apply without changing the overall Secure Score.

Source

New SMTP DANE and MTA-STS connector modes in Exchange Online

Par : IT Experts
27 mars 2026 à 15:47
SMTP DANE and MTA-STS modes in Exchange Online
Exchange Online now lets you choose, per outbound connector, whether SMTP DANE and MTA-STS are enforced opportunistically, mandatorily (for DANE), or not at all. These new connector modes give you granular control over how strictly Exchange Online enforces modern email security standards when sending mail to external domains.

Source

❌
❌