DSE security knowledge hub

Microsoft 365 & Identity
Knowledge

Clear guidance for Microsoft 365, Entra identity, account protection, collaboration, endpoint policy, and lifecycle changes.

DSE-authoredOfficial sourcesReviewed guidance
Explore this topic

Microsoft 365 & Identity knowledge center

Clear guidance for Microsoft 365, Entra identity, account protection, collaboration, endpoint policy, and lifecycle changes.

Start with the cornerstone guide
DSE post stream

Microsoft 365 & Identity

47 articles
DSE visual briefCyber defense

CVE-2026-70329 in Outlook: What the 8.8 RCE Means and How to Respond

Microsoft has fixed CVE-2026-70329, an Outlook integer-overflow vulnerability rated CVSS 8.8. Exploitation requires a user to open a malicious Office file. Review the exact affected editions, deploy the August 11 security release, and verify the installed build by servicing channel.

Published Reviewed 5 min readBy Gavin Stewart
Read the briefing
DSE visual briefIdentity & cloud

Microsoft Entra Retires Native SMS and Voice MFA in 2027—Prepare for Passkeys Now

Beginning September 1, 2026, Microsoft will start auto-enabling passkeys and registration nudges for SMS- and voice-enabled users in public-cloud Microsoft Entra ID tenants. On February 1, 2027, Microsoft-provided SMS and voice delivery ends; organizations must migrate affected users to a phishing-resistant method or configure a customer-managed telecom provider.

Published Reviewed 5 min readBy Gavin Stewart
Read the briefing
DSE visual briefIdentity & cloud

Make identity proofing recoverable, equitable, and evidence-based

Identity proofing establishes which real-world person is being enrolled; authentication later proves control of an authenticator. Select the needed assurance, protect proofing data, offer workable paths, and build redress for mistakes and fraud.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the guide
DSE visual briefIdentity & cloud

Move Exchange Online SMTP AUTH clients off Basic authentication with evidence

Microsoft now plans to disable SMTP AUTH Basic authentication by default for existing Exchange Online tenants at the end of December 2026. Find every sender, choose a supported replacement, pilot it, and prove the legacy path is quiet.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefIdentity & cloud

Raise Active Directory functional levels only after every domain controller earns the change

The Windows Server 2025 AD DS functional level permits only Windows Server 2025 domain controllers. Inventory every domain and DC, prove replication and recovery, remove incompatible controllers, and validate dependencies before raising either level.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the checklist
DSE visual briefIdentity & cloud

Choose Microsoft 365 Apps update channels by job, then manage the exceptions

Microsoft 365 Apps channels are device settings with different feature and support cadences. Put preview users, representative production pilots, general users, and exception devices on deliberate paths—and monitor the build actually installed.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the guide
DSE visual briefIdentity & cloud

Run Teams Rooms as managed room systems, not oversized desktops

Teams Rooms has its own supported app, Windows, device, peripheral, license, and maintenance lifecycle. Inventory every room, respect Microsoft’s Windows validation delay, preserve nightly maintenance, and plan hardware replacement before a meeting fails.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the checklist