Exchange Online – Cloud managed remote mailboxes

When the move to the cloud, customers had on-premises footprint with especially messaging systems – such as Exchange Server, which leaded to implement Exchange hybrid configuration with directory synchronization. Years later, there is still need to maintain a low level Exchange on-premises footprint to manage remote mailboxes. Even if Microsoft has made so progress by […]

Exchange Online – Cloud managed remote mailboxes Read More »

Teams – New authentication requirements for Teams PowerShell

If you use an Entra ID application to authenticate against Teams when using PowerShell you need to update the permissions granted to the application. Starting September 15th, 2025, authenticating with Entra ID application when using PowerShell will require the following additional permissions: GroupMember.Read.All RoleManagement.Read.Directory To update the permissions, connect to your Entra ID tenant (Microsoft

Teams – New authentication requirements for Teams PowerShell Read More »

Exchange – Transition to dedicated Exchange Hybrid application

You may have missed the announcement earlier in April (Released: April 2025 Exchange Server Hotfix Updates | Microsoft Community Hub) but Exchange Hybrid configuration is transitioning to a dedicated Exchange Hybrid app in Entra instead of using Exchange Web Services (EWS). It is important to start transitioning now as starting August 19th 2025, Microsoft is

Exchange – Transition to dedicated Exchange Hybrid application Read More »

Entra ID – You can now change the source of authority for synced groups (preview)

With the release of the latest version of Entra ID Connect (2.5.76.0, available for download from the Entra ID portal )Microsoft Entra Connect – Microsoft Entra admin center) (and Entra ID Cloud Sync – 1.1.1370.0), you can now change the source of authority for synchronized groups. With the move to ‘cloud first’ approach, there has

Entra ID – You can now change the source of authority for synced groups (preview) Read More »

Teams – You can now restrict bilateral chat with maximum 2 organizations

Bilateral chat policy is a new type of policy for restricting external group chats in Microsoft Teams to maximum of two organizations. When enabled it will prohibit users from adding external users from more than 2 organizations to external group chats. It applies to all Teams client – for Windows, MacOS, Android and iOS. It

Teams – You can now restrict bilateral chat with maximum 2 organizations Read More »

Windows / Intune – Phone Link has been blocked by your system administrator

Phone Link, previously known as Your Phone, is a Windows app that allows connecting Android or iOS phones to Windows computers. It enables access and manage various phone features directly from their PC, such as texts, calls, notifications, and photos. Well, recently, I faced the “This feature has been blocked by your system administrator” error

Windows / Intune – Phone Link has been blocked by your system administrator Read More »

Intune – New attributes and S/MIME baseline requirements for SCEP certificate profiles

If you use Intune SCEP to generate and deliver user certificate, you need to review and update accordingly before July 16 your SCEP profile to use new required attributes for the certificate subject name: Given name – G={{GivenName}} Surname – SN={{SurName}} This new requirement is following the enforcement new S/MIME baseline requirements for public certificate

Intune – New attributes and S/MIME baseline requirements for SCEP certificate profiles Read More »

Teams – You will (finally) be able to share files in external 1:1 or group chats

This has been a long awaited capability and painful user experience. As you know, it has been impossible to share files in external chats as shared files are saved in user’s OneDrive. Well, starting early July (targeted release tenant – aka preview) and mid July, you will now be able to share files in external

Teams – You will (finally) be able to share files in external 1:1 or group chats Read More »

Intune / Windows – Hotpatching now enabled by default for new Windows quality update policies

By now, you are probably aware about the hotpatching for Windows 11 and Windows Server (see Hotpatch updates | Microsoft Learn and Hotpatch for Windows Server | Microsoft Learn). As hotpatch has been available for Windows 11 clients for few months already, Microsoft has announced that it will now be enable by default for all

Intune / Windows – Hotpatching now enabled by default for new Windows quality update policies Read More »

Entra ID – Known issue (but undocumented) with conditional access

Now I got your attention, this sounds alarming but in fact it is not and you will see below. As you know Entra ID Conditional Access policies allow you to protect access to your resources linked with Microsoft authentication platform (Entra ID). Well, let dig into the issue. First a bit of context. Requirements Block

Entra ID – Known issue (but undocumented) with conditional access Read More »