EWS is going away

๐Ÿ”’ Secure Bits ๐Ÿ’ก ๐—˜๐˜…๐—ฐ๐—ต๐—ฎ๐—ป๐—ด๐—ฒ ๐—ช๐—ฒ๐—ฏ ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐—ฐ๐—ฒ๐˜€ (๐—˜๐—ช๐—ฆ) ๐—ถ๐—ป ๐—˜๐˜…๐—ฐ๐—ต๐—ฎ๐—ป๐—ด๐—ฒ ๐—ข๐—ป๐—น๐—ถ๐—ป๐—ฒ ๐—ถ๐˜€ ๐—ผ๐—ณ๐—ณ๐—ถ๐—ฐ๐—ถ๐—ฎ๐—น๐—น๐˜† ๐—ด๐—ผ๐—ถ๐—ป๐—ด ๐—ฎ๐˜„๐—ฎ๐˜†. Microsoft will start disabling EWS in Exchange Online from October 1, 2026, with ๐—ณ๐˜‚๐—น๐—น ๐—ฎ๐—ป๐—ฑ ๐—ฝ๐—ฒ๐—ฟ๐—บ๐—ฎ๐—ป๐—ฒ๐—ป๐˜ ๐—ฟ๐—ฒ๐˜๐—ถ๐—ฟ๐—ฒ๐—บ๐—ฒ๐—ป๐˜ ๐—ผ๐—ป ๐—”๐—ฝ๐—ฟ๐—ถ๐—น ๐Ÿญ, ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿณ. If any of your apps still rely on EWS, they ๐‘ค๐‘–๐‘™๐‘™ break unless you act. This often goes unnoticed […]

SMTP AUTH is officially going away

๐Ÿ”’ Secure Bits ๐Ÿ’ก ๐—ฆ๐— ๐—ง๐—ฃ ๐—”๐—จ๐—ง๐—› ๐—ถ๐—ป ๐—˜๐˜…๐—ฐ๐—ต๐—ฎ๐—ป๐—ด๐—ฒ ๐—ข๐—ป๐—น๐—ถ๐—ป๐—ฒ ๐—ถ๐˜€ ๐—ผ๐—ณ๐—ณ๐—ถ๐—ฐ๐—ถ๐—ฎ๐—น๐—น๐˜† ๐—ด๐—ผ๐—ถ๐—ป๐—ด ๐—ฎ๐˜„๐—ฎ๐˜† โ€” ๐˜๐—ต๐—ฒ ๐˜๐—ถ๐—บ๐—ฒ๐—น๐—ถ๐—ป๐—ฒ ๐—ถ๐˜€ ๐—ป๐—ผ๐˜„ ๐˜‚๐—ฝ๐—ฑ๐—ฎ๐˜๐—ฒ๐—ฑ. Microsoft has published an ๐˜‚๐—ฝ๐—ฑ๐—ฎ๐˜๐—ฒ๐—ฑ ๐—ฑ๐—ฒ๐—ฝ๐—ฟ๐—ฒ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐˜๐—ถ๐—บ๐—ฒ๐—น๐—ถ๐—ป๐—ฒ ๐—ณ๐—ผ๐—ฟ ๐—ฆ๐— ๐—ง๐—ฃ ๐—”๐—จ๐—ง๐—› ๐˜‚๐˜€๐—ถ๐—ป๐—ด ๐—•๐—ฎ๐˜€๐—ถ๐—ฐ ๐—”๐˜‚๐˜๐—ต๐—ฒ๐—ป๐˜๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป in Exchange Online – and it will end fairly soon. If you still rely on SMTP AUTH for: – Applications and scripts – […]

Deactive an app in Entra ID

๐Ÿ”’ Secure Bits ๐Ÿ’ก ๐—ฆ๐˜๐—ผ๐—ฝ๐—ฝ๐—ถ๐—ป๐—ด ๐—ฎ๐—ป ๐—ฎ๐—ฝ๐—ฝ ๐—ถ๐—ป ๐—˜๐—ป๐˜๐—ฟ๐—ฎ ๐—œ๐—— ๐—ป๐—ผ ๐—น๐—ผ๐—ป๐—ด๐—ฒ๐—ฟ ๐—บ๐—ฒ๐—ฎ๐—ป๐˜€ ๐—ฑ๐—ฒ๐—น๐—ฒ๐˜๐—ถ๐—ป๐—ด ๐—ถ๐˜. ๐—”๐—ป๐—ฑ ๐˜๐—ต๐—ฎ๐˜โ€™๐˜€ ๐—ฎ ๐—ฏ๐—ถ๐—ด ๐—ฑ๐—ฒ๐—ฎ๐—น. A new feature is coming to Microsoft Entra ID that finally gives admins a safer option: ๐—ฑ๐—ฒ๐—ฎ๐—ฐ๐˜๐—ถ๐˜ƒ๐—ฎ๐˜๐—ฒ ๐—ฎ๐—ป ๐—ฒ๐—ป๐˜๐—ฒ๐—ฟ๐—ฝ๐—ฟ๐—ถ๐˜€๐—ฒ ๐—ฎ๐—ฝ๐—ฝ๐—น๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ถ๐—ป๐˜€๐˜๐—ฒ๐—ฎ๐—ฑ ๐—ผ๐—ณ ๐—ฑ๐—ฒ๐—น๐—ฒ๐˜๐—ถ๐—ป๐—ด ๐—ถ๐˜. Until now, disabling an app usually meant deleting it entirely โ€” […]

Microsoft 365 Business 300-user limit

๐Ÿ”’ Secure Bits ๐Ÿ’ก ๐—ง๐—ต๐—ฒ ๐— ๐—ถ๐—ฐ๐—ฟ๐—ผ๐˜€๐—ผ๐—ณ๐˜ ๐Ÿฏ๐Ÿฒ๐Ÿฑ ๐—•๐˜‚๐˜€๐—ถ๐—ป๐—ฒ๐˜€๐˜€ ๐Ÿฏ๐Ÿฌ๐Ÿฌ-๐˜‚๐˜€๐—ฒ๐—ฟ ๐—น๐—ถ๐—บ๐—ถ๐˜ ๐—ถ๐˜€ ๐—ผ๐—ณ๐˜๐—ฒ๐—ป ๐—บ๐—ถ๐˜€๐˜‚๐—ป๐—ฑ๐—ฒ๐—ฟ๐˜€๐˜๐—ผ๐—ผ๐—ฑ. I still hear this form admins all the time: โ€œ๐˜ž๐˜ฆโ€™๐˜ญ๐˜ญ ๐˜ซ๐˜ถ๐˜ด๐˜ต ๐˜ฎ๐˜ช๐˜น ๐˜‰๐˜ถ๐˜ด๐˜ช๐˜ฏ๐˜ฆ๐˜ด๐˜ด ๐˜‰๐˜ข๐˜ด๐˜ช๐˜ค, ๐˜š๐˜ต๐˜ข๐˜ฏ๐˜ฅ๐˜ข๐˜ณ๐˜ฅ, ๐˜ข๐˜ฏ๐˜ฅ ๐˜—๐˜ณ๐˜ฆ๐˜ฎ๐˜ช๐˜ถ๐˜ฎ โ€” ๐˜ธ๐˜ฆ ๐˜ฉ๐˜ข๐˜ท๐˜ฆ ๐˜ญ๐˜ช๐˜ฌ๐˜ฆ 450 ๐˜ฐ๐˜ง ๐˜ต๐˜ฉ๐˜ฆ๐˜ฎ ๐˜ค๐˜ฐ๐˜ฎ๐˜ฃ๐˜ช๐˜ฏ๐˜ฆ๐˜ฅ.โ€ Feels relatable? But that is not how it should be. ๐Ÿค” ๐—›๐—ฒ๐—ฟ๐—ฒโ€™๐˜€ ๐˜๐—ต๐—ฒ ๐—ฐ๐—ฎ๐˜๐—ฐ๐—ต The 300-user limit […]

Microsoft Entra Connect

๐Ÿ”’Secure Bits๐Ÿ’ก Do you use ๐— ๐—ถ๐—ฐ๐—ฟ๐—ผ๐˜€๐—ผ๐—ณ๐˜ ๐—˜๐—ป๐˜๐—ฟ๐—ฎ ๐—–๐—ผ๐—ป๐—ป๐—ฒ๐—ฐ๐˜ /๐—”๐˜‡๐˜‚๐—ฟ๐—ฒ ๐—”๐—— ๐—–๐—ผ๐—ป๐—ป๐—ฒ๐—ฐ๐˜? There are some best practices you should follow. ๐Ÿ›ก๏ธSynchronize only what you need in Entra ID – No need to synchronize service accounts and nonpresonal accounts – No need to synchronize on-premise privileged accounts – No need to synchronize on-premise groups, if for AD […]

Microsoft 365 Admin Portals MFA

๐Ÿ”’ Secure Bits ๐Ÿ’ก ๐— ๐—ถ๐—ฐ๐—ฟ๐—ผ๐˜€๐—ผ๐—ณ๐˜ ๐˜„๐—ถ๐—น๐—น ๐—ฏ๐—น๐—ผ๐—ฐ๐—ธ ๐—ฎ๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€ ๐— ๐—ถ๐—ฐ๐—ฟ๐—ผ๐˜€๐—ผ๐—ณ๐˜ ๐Ÿฏ๐Ÿฒ๐Ÿฑ ๐—ฎ๐—ฑ๐—บ๐—ถ๐—ป ๐—ฝ๐—ผ๐—ฟ๐˜๐—ฎ๐—น๐˜€ ๐˜„๐—ถ๐˜๐—ต๐—ผ๐˜‚๐˜ ๐— ๐—™๐—”. Are you ready? Microsoft announced that sign-ins to the Microsoft 365 Admin Center ๐˜„๐—ถ๐—น๐—น ๐—ฟ๐—ฒ๐—พ๐˜‚๐—ถ๐—ฟ๐—ฒ ๐— ๐—™๐—” โ€” ๐Ÿ“… rollout startedย Feb 3, 2025, andย from Feb 9, 2026ย password-only sign-ins will be blocked. Accounts without MFA will simply ๐—ฏ๐—ฒ ๐—ฑ๐—ฒ๐—ป๐—ถ๐—ฒ๐—ฑ ๐—ฎ๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€. โš ๏ธ This may […]

Azure AD Connect Server

๐Ÿ”’Secure Bits๐Ÿ’ก Ever wondered if your Azure AD Connect server is truly secure? If this server isnโ€™t restricted to Domain Administrators and protected as a Tier 0 asset, youโ€™re at risk. Attackers can exploit this server to compromise both your on-premise AD and Azure AD environments. From this server, plaintext passwords of MSOL* and Sync_* […]

Disable Entra Connect Seamless SSO

๐Ÿ”’ Secure Bits ๐Ÿ’ก ๐—ฌ๐—ผ๐˜‚ ๐—บ๐—ถ๐—ด๐—ต๐˜ ๐˜„๐—ฎ๐—ป๐˜ ๐˜๐—ผ ๐˜๐˜‚๐—ฟ๐—ป ๐—ผ๐—ณ๐—ณ ๐—˜๐—ป๐˜๐—ฟ๐—ฎ ๐—–๐—ผ๐—ป๐—ป๐—ฒ๐—ฐ๐˜ ๐—ฆ๐—ฒ๐—ฎ๐—บ๐—น๐—ฒ๐˜€๐˜€ ๐—ฆ๐—ฆ๐—ข. ๐—›๐—ฒ๐—ฟ๐—ฒ’๐˜€ ๐˜„๐—ต๐˜†. In many hybrid Microsoft 365 tenants, Seamless SSO is still enabled โ€” even though itโ€™s no longer needed in modern Entra ID environments. Nothing looks broken. Users sign in just fine. And thatโ€™s exactly why this often goes unnoticed. […]