Loading...

Microsoft 365 Upcoming Secure by Default Settings Changes

Microsoft 365 Upcoming Secure by Default Settings Changes

Microsoft 365 will update default settings to enhance security by blocking legacy authentication protocols and requiring admin consent for third-party app access. Changes start mid-July 2025 and complete by August 2025. Organizations should assess configurations, notify stakeholders, update documentation, and configure the Admin Consent workflow. As part of the Microsoft Secure Future Initiative (SFI) and in alignment with the “Secure by Default” principle, we are updating default settings in Microsoft 365 to help you meet the minimum security benchmark and harden your tenant’s security posture. These changes target legacy authentication protocols and app access permissions that may expose organizations to unnecessary risk. This is the first step in a broader effort to evaluate and evolve Microsoft 365 defaults through the lens of security best practices. When this will happen: These changes will begin rolling out in mid-July 2025 and are expected to complete by August 2025. How this affects your organization The following settings will be updated: Settings Impact Block legacy browser authentication to SharePoint and OneDrive using RPS (Relying Party Suite) Legacy authentication protocols like RPS (Relying Party Suite) are vulnerable to brute-force and phishing attacks due to non-modern authentication. Blocking this prevents applications that are using outdated methods from accessing SharePoint and OneDrive via browser. To use PowerShell to block legacy browser authentication, see Set-SPOTenant. Block FPRPC (FrontPage Remote Procedure Call) protocol for Office file opens FrontPage Remote Procedure Call (FPRPC) is a legacy protocol used for remote web page authoring. While no longer widely used, Legacy protocols such as FPRPC can be more susceptible to compromise and blocking FPRPC helps reduce exposure to vulnerabilities. With this change, FPRPC will be blocked for opening files, preventing the use of this non-modern protocol in Microsoft 365 clients. To learn how to block the FPRPC protocol, see turn on web content filtering. Require admin consent for third-party apps accessing files and sites Users allowing third-party apps to access file and site content can lead to overexposure of an organization’s content. Requiring admins to consent to this access can help reduce overexposure. With this change, Microsoft managed App Consent Policies will […]

The post Microsoft 365 Upcoming Secure by Default Settings Changes appeared first on M365 Admin.

Published on:

Learn more
M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Stop Being Slowed Down: How We Make Technology Simple, Affordable, and Useful for Your Teams

For years, housing associations have been trapped. You are forced to rely on rigid, legacy systems that are expensive and fail to evolve with ...

16 hours ago

Exciting new capabilities and enhancements for M365 Developer Program – October 2025

We are excited to share updates on the Microsoft 365 Developer Program with new capabilities and upcoming changes. The post Exciting new capab...

2 days ago

Exciting new capabilities and enhancements for M365 Developer Program – October 2025

We are excited to share updates on the Microsoft 365 Developer Program with new capabilities and upcoming changes. The post Exciting new capab...

2 days ago

Microsoft 365 & Power Platform Community Call (SPFx) – October 16th, 2025 – Screenshot Summary

Call Highlights   SharePoint Quicklinks: Primary PnP Website: https://aka.ms/m365pnp Documentation & Guidance SharePoint Dev Videos I...

2 days ago

Microsoft Viva: Community feeds improvements

Align the community feeds default experience with expected user behaviors; support triage and content review for users who want to read every ...

3 days ago

Microsoft Teams: Chat with anyone who has an email address

Start a chat with anyone who has an email address, even if they’re not on Teams! They’ll receive an email inviting them to join yo...

3 days ago

Microsoft Teams trials in the EEA duration limit updates

Starting November 1, 2025, Microsoft Teams trials in the EEA will be limited to 31 days to comply with regulatory changes. Existing trials ove...

3 days ago

Learners can now unfurl Learning Paths directly in Viva Learning Academy 2.0

Viva Learning Academy 2.0 now allows learners to unfurl Learning Paths directly within the Academy interface, improving access and navigation....

3 days ago

Microsoft Dynamics 365 Customer Experience Analyst : Configure Teams collaboration

Teams Collaboration in Dynamics 365 Sales enables seamless communication and teamwork directly within the sales process, allowing sellers to c...

4 days ago
Stay up to date with latest Microsoft Dynamics 365 and Power Platform news!
* Yes, I agree to the privacy policy