The November 2025 Windows security update is now available


App centric management introduces new admin settings to control who in the tenant can install Teams apps. First, admins can set a default value for new apps that are published to Teams app store. Second, admins can edit the availability of an app to ‘All users can install’, ‘Specific users and groups can install’, or ‘No user can install’. This feature evolves the existing app permission policies and provides admins with the ability to manage access to the app individually. The app permission policies for existing customers are migrated to maintain existing app availability in the tenant.

Microsoft Purview Data Loss Prevention end-user email notification is getting advanced incident remediation capabilities: actionable email notifications. This new feature allows end users to take remediation actions directly from their mailbox, streamlining the remediation process. The end users will be able take remediation actions on files on OneDrive and SharePoint that caused a policy match. Key actions now available in our email notifications include – stop sharing file, delete file, apply label, override the policy, report false positive and unable to take action.

Empower tenant admins to centrally manage SharePoint site branding using PowerShell scripts. This feature enables organizations to enforce consistent branding, apply enterprise themes to individual sites, disable custom branding on specific sites, and audit branding changes – ensuring branding compliance and a unified brand experience across all SharePoint sites.

Copilot can now automatically reschedule flexible 1:1 meetings and personal events based on user preferences to resolve scheduling conflicts. This feature, requiring a Copilot license, will roll out from mid to late November 2025 and helps save time by reducing manual rescheduling.

Outlook for Android will have a new, separate Copilot Chat button for users with a M365 Copilot license, improving access and clarity. The rollout starts and completes in early December 2025. No functionality changes or admin actions are needed, but helpdesk and documentation updates are recommended.

Name Pronunciation and Pronoun controls in Microsoft 365 admin center will move to People settings under Org Settings by mid-December 2025. No new features or opt-in needed. Admins should update documentation and inform support teams about the new location.

Microsoft Defender for O365 now allows triggering new remediation actions—Submit to Microsoft, add to allow/block list, and initiate automated investigation—directly from the Advanced Hunting interface. This feature, rolled out since November 10, 2025, is enabled by default and supports improved threat response without policy changes.

The legacy SharePoint Online CDN domain publiccdn.sharepointonline.com will be retired by late April 2026. Update all hardcoded references to the new domain public-cdn.sharepointonline.com to avoid 404 errors. Validate changes before March 31, 2026, to ensure uninterrupted access to SharePoint resources.

Microsoft is introducing a dynamic onboarding wizard for frontline workers using personal Android or iOS devices to set up Microsoft Teams securely with MFA and mobile app management. Public preview starts late November, general availability by January 2026. The tool is optional and adapts to organizational policies.
