Thibault CHÂTIRON

Cybersecurity

Microsoft Defender for Cloud Apps: Files page retires September 1, 2024

Microsoft will be retiring the Files page from Microsoft Defender for Cloud Apps on September 1, 2024. Information Protection policies can be created, modified and explored via the Policy Management page. You can explore malware files on the Policy Management page.

Use sensitivity labels in Microsoft 365 apps when connected experiences are disabled

Your organization can now disable connected experiences for privacy concerns without impacting data security policies, such as sensitivity labels. Services associated with Microsoft Purview (sensitivity labels, rights management, and so on) are no longer controlled by policy settings to manage privacy controls for Microsoft 365 apps. Instead, these services will rely on their existing security admin controls in Purview …

Decoupling Microsoft Purview Data Loss Prevention (DLP) Process form Microsoft Defender for Endpoint on Windows Devices

If you use a Firewall (Windows or 3rd party), non-Microsoft anti-malware, or application control solution and had to add the Microsoft Defender for Endpoint process to an allowlist to run, then an additional process (“MpDlpService.exe”) will need to be added to your allowlist. Starting June 2024, we will be decoupling the Microsoft Purview Data Loss …

New eDiscovery Hold reports

Coming soon: For Microsoft Purview, Microsoft will release a tenant-wide Hold report in eDiscovery (Premium). When this will happen: General Availability (Worldwide): Microsoft will begin rolling out mid-May 2024 and expect to complete by early June 2024. How this will affect your organization: The Hold report in eDiscovery (Premium) will let users with eDiscovery Administrator …

Enhanced content extraction and file type coverage for DLP on Windows devices

Microsoft Purview: Microsodt announced upcoming enhancements to Microsoft Purview Data Loss Prevention (DLP). With the forthcoming update, the capability to scan, classify, and protect sensitive content on Windows endpoint devices will be significantly expanded. The number of supported file types will increase from approximately 40 to over 100, aligning endpoint coverage with other platforms like …

Reported mailbox notifications messages subject change

Currently, in Microsoft Defender for Office 365, when a notification message is reported by an end user and arrives at the reporting mailbox, the subject lines begin with: Moving forward, the subject lines of notification messages reported by end users will start with This change is being made to ensure readability and enable you to create better …

Enhanced incident communication with DLP email templates

Coming soon for Microsoft Purview Data Loss Prevention (DLP): Enhance your DLP incident management with the new send email notification remediation action and customize email templates in Purview DLP and Defender. Use dynamic variables and tokens to easily create and maintain consistent and efficient email communications, complete with an audit trail. Utilize these email templates to take …

Exfiltration of business sensitive data to free public domain emails

Coming soon, Microsoft Purview Insider Risk Management will roll out exfiltration of business sensitive data to free public domain emails. When this will happen: Public Preview: Microsoft will begin rolling out mid-May 2024 and expect to complete by late May 2024. General Availability: Microsoft will begin rolling out late June 2024 and expect to complete …

Enhanced Submissions experience from Email entity and Summary panel

In Microsoft Defender XDR for Office 365, Microsoft is enhancing the Submit to Microsoft for review options on the Email entity page and Summary panel so admins can convey whether they are submitting for a second opinion or submitting to confirm a clean or a malicious verdict. In the same workflow, we are also introducing the Entities allow option that Security …

Microsoft Copilot in Outlook: Logging and Microsoft Purview eDiscovery support

Microsoft Outlook has added additional logging and Microsoft Purview eDiscovery support for Copilot in Outlook features that have already been released, and future Copilot in Outlook features as well. These features will be available in Outlook for Mac, web, iOS, Android, and the new Outlook for Windows. When this will happen: General Availability (Worldwide): Microsoft …

Azure Information Protection Add-in for Office – it is the end

The Azure Information Protection (AIP) Unified Labeling add-in for Office is retired on April 11th, 2024. When this will happen: Important retirement milestones are: How this will affect your organization: To continue using sensitivity labels powered by Microsoft Purview Information Protection in Office applications, you must transition to the built-in labeling experience in Microsoft 365 …

Microsoft Teams: New tenant federation setting to block all subdomains of domains in blocklist

In Microsoft Teams, Microsoft has introduced a new Tenant Federation setting to block all subdomains of domains in the federation Block list. If your organization is using a Block list to protect your users from malicious or other domains, you should enable this new setting to also protect users from all related subdomains without manually …

Password protected download for quarantined emails from Email Entity

Microsoft is introducing password protected downloads of email messages from the Email Entity Summary Panel in Microsoft Defender for Office 365. Today, password protected downloads are available from the Quarantine experience.  When this will happen: General Availability: Microsoft will begin rolling out mid-March 2024 and expect to complete by late March 2024. How this will …

Microsoft Defender for Office 365: New Quarantine release details

In Microsoft Defender for Office 365, Microsoft is rolling out new details on who or what is responsible for releasing a message from quarantine. These details will now be included in the email summary flyout panel accessible from the Quarantine page. When this will happen: General Availability : Microsoft will begin rolling out late March …

[Public Preview] Insider Risk Management: Global exclusions

Microsoft Purview Insider Risk Management will be rolling out public preview of Global exclusions in the in the Microsoft Purview compliance portal. When this will happen: Public Preview: Microsoft will begin rolling out early May 2024 and expect to complete by mid-May 2024. General Availability: Microsoft will begin rolling out mid-August 2024 and expect to complete by …

[Public Preview] Support all Microsoft Defender for Cloud Apps users by Microsoft Defender XDR portal

As part of the transition to the Microsoft Defender XDR portal, the entire Microsoft Defender for Cloud Apps experience in the Microsoft 365 Defender XDR portal will be available for all supported by Defender for Cloud Apps admin roles. How this will affect your organization: For Public Preview customers, the entire Defender for Cloud Apps …

Microsoft Defender Antivirus: Changes to “engine update” support plans

Microsoft Defender Antivirus is rolling out an update to the support plan for the anti-malware scan “engine update” (MpEngine.dll). To align with the current Defender Antivirus platform update, only N-2 versions will be supported. Reasons: When this will happen: General Availability : The changes will take effect May 1, 2024. How this will affect your …

Updates to resolve Windows Server domain controller issue

Microsoft has identified an issue that affects Windows Server domain controllers (DCs), and has expedited a resolution that can be applied to affected devices. Out-of-band (OOB) updates have been released for some versions of Windows today, March 22, 2024, to addresses this issue related to a memory leak in the Local Security Authority Subsystem Service (LSASS). …

Microsoft Purview Insider Risk Management- policy wizard enhancements [Public Preview]

Coming soon, Microsoft Purview Insider Risk Management will be rolling out a public preview of policy wizard enhancements. Microsoft Purview Insider Risk Management correlates various signals to identify potential malicious or inadvertent insider risks, such as IP theft, data leakage, and security violations. Insider Risk Management enables customers to create policies based on their own …

Data Loss Prevention – Enriched Data Loss Prevention (DLP) alert email notifications for DLP admins

There is now increased information in the alert email notification sent to the Data Loss Prevention (DLP) admins upon a DLP policy match. Previously a DLP alert email only included the user activity and the type of sensitive information matched in the alert. Now, DLP admins will get additional context such as alert ID, policy …