Action Required: Update firewall configurations to include new network endpoints

By December 2, 2025, update firewall allowlists to include Azure Front Door IP addresses or the service tag “AzureFrontDoor.MicrosoftSecurity” for Microsoft Intune and Basic Mobility and Security for Microsoft 365. Do not remove existing endpoints; add new ranges from the provided Azure IP range files.

(more…)

Action Required – Configure Browser Policy to Preserve OneDrive and SharePoint Web Performance and Offline Capability

Chromium browsers will restrict local network access, prompting users for permission when accessing OneDrive, SharePoint, and Microsoft Lists. Without configuring the LocalNetworkAccessAllowedForUrls policy to pre-authorize trusted domains, users will face slower performance and loss of offline capabilities. Admins must deploy this policy before the change rolls out in Chromium 141 at September’s end.

(more…)

Hardening changes for Windows Server Update Services in Windows Server 2025

Important hardening changes are here. Starting with the September 2025 security update, WSUS running on Windows Server 2025 is removing dependencies on old code that’s no longer supported. This means that Windows operating systems (OS) that reached the end of their lifecycle will no longer qualify to receive extended security updates (ESU), unless you take additional action. Short-term and long-term next steps are available for Windows Server 2012 and Windows Server 2012 R2 that still need to receive ESUs. 

(more…)

Microsoft Copilot Studio – Use up to 1,000 files per agent for SharePoint and OneDrive uploads

We are announcing the ability to use up to 1,000 files per agent for SharePoint and OneDrive uploads in Microsoft Copilot Studio. This feature will reach general availability on October 6, 2025.

(more…)

The September 2025 Windows security update is now available

The September 2025 security update is now available for all supported versions of Windows. We recommend that you install these updates promptly. For more information about the contents of this update, see the release notes, which are easily accessible from the Windows 11 and Windows 10 update history pages. To learn more about the different types of monthly quality updates, see Windows monthly updates explained.

(more…)

Certificate-based authentication changes following installation of Windows updates released September 9, 2025

Windows updates released September 9, 2025 and later, introduce security hardening changes to certificate mapping requirements in Windows Servers. The is the final milestone of a rollout that has gradually been taking place since 2023. IT administrators need to take action to ensure normal operations in accordance with the new certificate mapping criteria, and install the September 9, 2025 updates.

(more…)

Microsoft Defender for Office 365: Agentic AI Phish Submission Analysis & Response

We are introducing Advanced Agentic AI grading system integrated into the native MDO submission analysis and response workflow. This integration allows for prompt, detailed verdicts with natural language explanations when customers report phishing messages to Microsoft.

(more…)

Microsoft Copilot (Microsoft 365): Microsoft Graph APIs for App & Agent Inventory and Details

Microsoft 365 will introduce new Graph API endpoints designed to empower IT administrators and developers with robust programmatic access to app and agent management across Copilot, Teams, Outlook, and other MetaOS hosts.
Key Features:
• Inventory API: Retrieve a comprehensive inventory of all apps and agents within your tenant, with advanced filtering by type (1P, 3P, LOB, Shared), host (Copilot, Outlook, Teams, Office), last updated date, and more. This enables bulk management, compliance checks, and streamlined governance for large organizations.
• Details API: Access detailed metadata for any specific app or agent, including availability, deployment status, supported hosts, creator information, version, sensitivity, categories, and capabilities (such as Graph connectors, knowledge sources, and plugin actions). This supports auditing, lifecycle management, and integration into existing IT workflows.

(more…)

Microsoft Teams: Improvements in call transfer experience on Teams Phone devices

New call controls and streamlined transitions enable simple and seamless transfers for Teams Phone users on Android devices.

(more…)

Microsoft Intune: Recovery Lock management for macOS

This feature adds the ability to manage the password used to access the macOS recovery partition. Configuring a recovery OS password prevents users from booting company-owned devices into recovery mode, reinstalling macOS, and bypassing remote management.

(more…)


I've been working with Microsoft Technologies over the last ten years, mainly focused on creating collaboration and productivity solutions that drive the adoption of Microsoft Modern Workplace.