You will no longer will need to register another MFA method for Windows Hello for Business, but its recommended > https://t.co/D9QqcpPW57
So, Microsoft just made Passwordless MFA registration easier by enabling phishing-resistant methods (Including WHfB and PSSO) to be registered first, while the user doesn't have any other MFA methods on their account!
Right now, in the Cloud Experience Host screen during WHfB registration, the user is prompted to authenticate with MFA, then only after successful MFA the user can complete WHfB registration, but that may not be the case for long.
WHfB will also be identified as MFA capable in Microsoft Authentication Methods reports! But while this means less onboarding friction and admin overhead, there is still a catch!
#Microsoft #Entra #News
Microsoft just gave admins a domain blocklist for Copilot web grounding.
Up to 1,000 websites can now be excluded from Microsoft 365 Copilot and Copilot Chat responses.
It is tenant-wide.
It is PowerShell-managed.
It is opt-in.
Important catch: excluded domains could still appear through news results.
Useful governance control. Not a complete web firewall.
Read more here: https://t.co/yJHDN4jGsH
A major Microsoft 365 change is coming soon, and organizations that ignore it could end up exposing more information than they intended. #Microsoft365 https://t.co/i2ebYZYhRD
Maak alles open source.
AI vindt vulnerabilities toch wel, en AI maakt features in een handomdraai na.
Als code geen moat meer is, wat dan wel?
Netwerkeffect, distributie, reputatie, vertrouwen, en vooral: smaak.
Microsoft Defender protects AI apps and agents as their own attack surface.
The big picture:
Every agent you deploy is a new identity attackers can target.
See how to defend them in the Securing AI & Agents playlist: https://t.co/OQOsX9PYlH
Manage Copilot and agents directly from the Microsoft 365 Admin Center, Purview, and Power Platform—no new consoles needed.
See how in a free live training hosted by Jeremy Chapman, Microsoft’s lead technical storyteller and product director for Microsoft 365 Copilot.
Choose a Date and Register Now: https://t.co/qTMrNUgfAv
𝗠𝗗𝗢: 💬𝗣𝗿𝗼𝗺𝗽𝘁 𝗜𝗻𝗷𝗲𝗰𝘁𝗶𝗼𝗻 𝗧𝗵𝗿𝗲𝗮𝘁 𝗠𝗼𝗻𝗶𝘁𝗼𝗿𝗶𝗻𝗴
Microsoft Defender for Office 365 is now detecting 𝗽𝗿𝗼𝗺𝗽𝘁 𝗶𝗻𝗷𝗲𝗰𝘁𝗶𝗼𝗻 𝗮𝘁𝘁𝗲𝗺𝗽𝘁𝘀. The real question is — are you monitoring 𝘸𝘩𝘰 is sending them? Which sender domains or IPs are pushing 𝗽𝗿𝗼𝗺𝗽𝘁 𝗶𝗻𝗷𝗲𝗰𝘁𝗶𝗼𝗻 𝗨𝗥𝗟𝘀 designed to lure your users into triggering AI workflows for data exfiltration?
What flavor of malicious URLs are landing in your users’ inboxes? This isn’t theoretical — it’s happening right now. Defenders need to start mapping and closing this new attack surface before it becomes the next blind spot.
Food for thought 🫡
#Cybersecurity #PromptInjection #MicrosoftDefender
Microsoft finally lets IT admins suppress the Entra SSO prompt on managed Windows devices - one registry key as of the July 2026 security update. GPO and ConfigMgr ready, Intune path hasn't surfaced yet.
https://t.co/PxxWxfZCMj
#MicrosoftIntune#EntraID#Windows11
The best time to set up security tests for your Entra tenant is when you create it
The next best time is today 😉
I'm spinning up Entra External ID tenants for https://t.co/WIylWUFKGE (my SaaS solution), & every one gets Maester baked in from day one
🔥 Maester monitoring Maester Cloud. As it should be
1/3
Microsoft spent $13B on OpenAI. Now it's building the exit.
It just shipped 7 of its own MAI models into Copilot and Office, and claims one runs 10x cheaper than GPT-5.5. The licence to OpenAI's tech still runs through 2032.
https://t.co/tnbdeYplag
I've said this before: everyone who has any M365 administrative role in your organization that is not a reader role should be required to prove they have SC-300 level skills.
In my opinion, you should have the following skill levels before ever touching M365 administraive roles in a big org:
SC-300 - IAM
MS-102 - Administrator expert
MD-102 - Intune
AZ-500 - Azure
All of them. You CANNOT work effectively in M365 without knowing how all of M365 works in large enterprise. You will not be able to make effective decisions for the organization. Also, these are MINIMUM skills. MINIMUM. They won't give you all that you need to do the job. They are a baseline of skills that you must have to be able to solve the problems that occur above and beyond the information in those certs.
I have a great Microsoft team. Even they cannot help you in most things. Thats why you need to know how to troubleshoot and how the tenant functions AS A WHOLE. You cannot troubleshoot effectively without these skills and understanding what logs to look at where when stuff is going wrong.
MDM certificate renewal failures are breaking Intune management on some devices.
After renewal, affected devices end up with **zero usable MDM certificates** (while healthy devices consistently show one). This is showing up with:
- RenewStatus = 3
- RenewErrorCode = 0x80180018
- LinkedEnrollment LastError = 0x8018000B
As a result, the Intune Management Extension and ClientCertCheck report no MDM certificate, which breaks Win32 app deployment, scripts, and remediation workloads.
The FREE Intune Dashboard’s new **Management Health** tab now surfaces these certificate lifecycle issues, making it easier to identify affected devices.
@Mister_MDM@MSIntune #Intune