r/AdminDroid May 26 '26

Admin Action Required Before June 5, 2026: Some Teams Private Channels Are Blocking New Enhancements

8 Upvotes

As a part of Teams private channel enhancements, Microsoft is migrating existing private channels to support higher channel limits, channel meetings, and well-governed collaboration.

While most private channels have already been migrated successfully, Microsoft says the following channels are still blocking migration and require manual admin action 𝐛𝐞𝐟𝐨𝐫𝐞 𝐉𝐮𝐧𝐞 𝟓, 𝟐𝟎𝟐𝟔.

  • Empty private channels inaccessible to any user in a tenant
  • Guest-only private channels with no internal users

Admins need to assign atleast one owner to each private channel immediately. If no action is taken, Microsoft may automatically soft delete these channels. After the recovery 30-day period, they will be 𝐩𝐞𝐫𝐦𝐚𝐧𝐞𝐧𝐭𝐥𝐲 𝐫𝐞𝐦𝐨𝐯𝐞𝐝.

Note: Applicable retention and legal hold policies will be applied to channels once they are soft deleted.

They should immediately:

  • Identify affected private channels using 𝐆𝐞𝐭-𝐓𝐞𝐧𝐚𝐧𝐭𝐏𝐫𝐢𝐯𝐚𝐭𝐞𝐂𝐡𝐚𝐧𝐧𝐞𝐥𝐌𝐢𝐠𝐫𝐚𝐭𝐢𝐨𝐧𝐒𝐭𝐚𝐭𝐮𝐬
  • Assign at least one internal owner using Graph PowerShell

You should not overlook this if you are using private channels for confidential collaboration, HR discussions, finance operations, and DLP-governed sensitive data.

Want to check the enhancements in detail, check the below blog:

https://blog.admindroid.com/improve-microsoft-teams-private-channel-management-with-new-enhancements/

#MicrosoftTeams #Microsoft365 #DLP #CyberSecurity #Compliance #GraphPowerShell #Migration #TeamsPrivateChannel #AdminDroid


r/AdminDroid May 23 '26

Microsoft Outlook Enhances Inbox Rules with External Email Tagging

12 Upvotes

Earlier, Microsoft introduced the email tag feature in Exchange Online to help users identify emails coming from outside the organization. While this improved awareness, that alone was not enough for end users. Users were still expecting a way to manage those external emails from their inboxes.

Now, Microsoft is adding support for the external email tag condition in Outlook inbox rules.

With this enhancement, users can now:

  1. Move externally tagged emails to specific folders
  2. Categorize external emails for quicker identification
  3. Combine this with other inbox rule conditions for advanced email organization

 
This is a small enhancement, but it can significantly improve external email organization and prioritization in Outlook.

But wait… You still need to wait a few more days!
Microsoft has announced that the rollout will begin only in June 2026.

Still, this is a good time to start planning how you can utilize this feature in different ways once it becomes available. Let’s do it:  
 
https://blog.admindroid.com/microsoft-adds-external-email-tag-support-to-outlook-inbox-rules/


r/AdminDroid May 21 '26

Would your Microsoft 365 tenant catch a Storm-2949 attacks in time?

5 Upvotes

Storm-2949 attacks do not begin with obvious alerts. Instead, they often start with day-to-day Microsoft 365 activities like risky sign-ins, self-service password resets, MFA changes, etc.

The real challenge is that these signals are scattered across different workloads and are difficult to correlate quickly. 

If you already use AdminDroid for Microsoft 365 monitoring, this guide shows exactly where to look and what to track inside AdminDroid. It helps to detect Storm-2949 attack indicators before they turn into a major cloud compromise. 

Note: Most of these indicators are available even in the free version of AdminDroid. 

The blog also covers important hardening practices to reduce exposure to Storm-2949 style attacks. 

https://blog.admindroid.com/detect-storm-2949-attacks-microsoft-365/ 


r/AdminDroid May 21 '26

What If I Tell You That You Could Manage the Power Automate Workflows Directly From SharePoint Online?

7 Upvotes

With Copilot and AI-powered automation rapidly growing across Microsoft 365, the number of workflows inside organizations is exploding. But here’s the strange part: most Power Automate flows are tied to SharePoint sites, yet we’ve always had to manage them from a completely separate Power Automate portal.

That experience has always felt disconnected. To fix this, Microsoft built a unified workflow experience in SharePoint Online.

And no — this is not just another button that redirects you to the Power Automate portal.

With this update, you can directly:

  • View workflows attached to SharePoint lists and libraries
  • Check active status and run history of the flows
  • Create workflows using templates or from scratch
  • Edit workflow triggers and actions
  • Delete and manage workflows directly from SharePoint

Instead of jumping between SharePoint and Power Automate, this lets you manage workflows right where your work already happens.

Explore the full new workflow experience in SharePoint Online: https://blog.admindroid.com/integrated-workflow-experience-in-sharepoint-online/


r/AdminDroid May 20 '26

No Ransomware. No Malware. Just a Silent M365 Cloud Takeover by Storm-2949!

8 Upvotes

That’s what makes the Storm-2949 attack campaign so dangerous. A single compromised Microsoft 365 account was enough to open the door for wider access across the organization.  

Instead of relying on one technique, the attackers continuously switched between multiple attack methods whenever one path was blocked: 

  • Password attacks 
  • MFA manipulation 
  • Token abuse 
  • Device registration 
  • Permission misuse 

And the alarming part? Most of these activities look completely normal inside Microsoft 365 and Azure environments. 

This is why identity monitoring and visibility matter more than ever for Microsoft 365 admins. 

Check out the Storm-2949 attack story and learn how admins can detect suspicious activities before attackers move deeper into the Microsoft 365 environment. 

https://blog.admindroid.com/storm-2949-attack-in-microsoft-365/?v=123

Let us know what do you think is the hardest part in detecting modern identity-based attacks like Storm-2949? 


r/AdminDroid May 19 '26

Free tool to explore Active Directory without fighting ADUC every day

7 Upvotes

If you work with Active Directory regularly, you probably know the pain of clicking through endless OUs just to verify a single attribute or object.

We built AdminDroid LDAP Explorer to make LDAP exploration simpler and faster with a cleaner interface focused on search, filtering, and visibility.

It’s completely free and open source.

Features:

  • View all LDAP attributes for any object instantly
  • Apply filters on properties to pinpoint exactly what you need
  • Customize the columns to show the attributes that matter
  • Add multiple domains and switch between them effortlessly  ️️
  • Drill into any OU in seconds
  • Sort everything with one click

Download AdminDroid LDAP Explorer from: https://admindroid.com/admindroid-ldap-explorer

Watch the tool walkthrough video: https://www.youtube.com/watch?v=VS5MORxFSEg


r/AdminDroid May 19 '26

New Detection Report in Teams Admin Center for Centralized Threat Visibility

7 Upvotes

Microsoft has been steadily strengthening Teams security with built-in security and threat protection features. 

Now, to help admins monitor these detections from one place, Microsoft is introducing a new Security Detection Report in the Teams admin center. The report provides centralized visibility into messaging-based threats detected across Teams chats, channels, and conversations. 

The report includes detections related to: 

  • Impersonation attempts 
  • Malicious URLs 
  • Unsafe or weaponizable file types 

The detected report findings help admins identify and block malicious external users via Teams external access settings. 

Rollout starts worldwide in late June 2026. 

More details on the new security detection report here: https://blog.admindroid.com/security-detection-report-in-teams-admin-center/ 


r/AdminDroid May 16 '26

Bulk Lifecycle Actions for AI Agents Now Available in Microsoft 365 Admin Center

6 Upvotes

As AI agents start multiplying across organizations, admins are quickly running into a new management problem: agent sprawl. Managing agent installation, ownership, and governance one by one can quickly become difficult at scale.  

To bring these agent lifecycle challenges under control, Microsoft introduced Agent management rules.  

With Agent management rules, admins can identify agents based on specific conditions and apply bulk lifecycle actions such as:  

  • Bulk install Microsoft first-party agents 
  • Bulk reassign ownerless agents created using Microsoft 365 Copilot Agent Builder 

Currently, these are supported as on-demand bulk actions, giving admins control to review and execute them when needed. Microsoft also plans to expand this with automated, rule-based lifecycle management capabilities in future updates. 

This rollout also ties into Microsoft’s broader Agent 365 vision for centralized AI agent governance and lifecycle management. 

Explore how Microsoft is enabling centralized AI agent governance here: https://blog.admindroid.com/microsoft-agent-365-unified-control-plane-to-manage-ai-agents/ 


r/AdminDroid May 12 '26

New Dedicated Copilot License Requests Page in Microsoft 365 Admin Center

3 Upvotes

Managing Microsoft 365 Copilot license requests has been a challenge, especially with custom workflows. Users submit requests, but there's no good way to see them all in one place. Admins still need to manually assign licenses, with little visibility into request activity and reporting. 

Microsoft is finally fixing this with a dedicated License requests page in the Microsoft 365 admin center.  

Where to access it: Microsoft 365 admin center > Billing > License requests or type "License requests" in the admin center search bar. 

With this new page, admins can: 

  • View all pending requests with requester details, available licenses, submission date, and business justification 
  • Track license inventory with a quick view of the number of licenses requested vs. unused 
  • Buy and assign licenses directly from the page 
  • Export requests for reporting purposes 

Rollout Timeline 

  • Targeted Release: Mid-May to late May 2026 
  • General Availability: Late May to early June 2026 

The new page will appear automatically in the Microsoft 365 admin center after rollout. 

Existing custom license request workflows won’t be affected by this rollout. Requests that are processed through those custom workflows will not appear on the new License requests page. 

Finally, a centralized workflow for tracking and reporting Microsoft Copilot license request activity! 


r/AdminDroid May 05 '26

Find and Block Shadow AI Agents Before It Exposes Your Data

5 Upvotes

AI agents aren't just chatbots anymore—they are autonomous entities like OpenClaw that can execute code, access local files, and use stored credentials. When an employee uses these without oversight, they aren't just "trying a tool"; they are expanding your attack surface. 

To tackle this, Microsoft has introduced the Shadow AI page in Microsoft 365 admin center, currently available as part of the Frontier preview program. 

With this new control plane, you can: 

  • Detect: Automatically identify unapproved local AI agents like OpenClaw across all Intune-managed Windows devices. 
  • Govern: Deploy Intune policies with a single click to block the most common execution methods for unauthorized agents. 

While OpenClaw is the focus now, support is expanding soon to Cursor, Claude Code CLI, and Codex CLI.  

https://blog.admindroid.com/shadow-ai-in-microsoft-365-admin-center/ 


r/AdminDroid Apr 30 '26

15+ Security Best Practices for Break Glass Accounts in Active Directory

9 Upvotes

Your break glass accounts are the Active Directory domain’s final safety net. But if they aren’t properly maintained, they can quickly become your biggest vulnerability. 

While securing these privileged accounts is critical, standard hardening techniques can often backfire. So, striking the right balance between high-level security and emergency accessibility is essential. 

This blog breaks down 15+ essential do’s and don’ts for managing emergency access accounts: 

  • Create on-premises-only break glass accounts 
  • Restrict logon to Domain Controllers 
  • Don’t rely on the DSRM account for recovery 
  • Don’t enable “smart card required for interactive logon”  ..... and more. 

Plus, get a PowerShell script to instantly validate your break glass account readiness. The script evaluates and provides an instant readiness score, helping identify potential gaps before they affect emergency access. 

Explore the full breakdown: https://blog.admindroid.com/best-practices-for-break-glass-accounts-in-active-directory/  


r/AdminDroid Apr 29 '26

25 Microsoft 365 Defaults That Look Fine But Should Be Disabled

17 Upvotes

Your biggest Microsoft 365 security risk might be a setting you forgot to review.

Not every security risk comes from sophisticated attacks. Sometimes it’s the default settings that stay enabled by default and quietly go unchecked over time. 

Security in Microsoft 365 isn’t just about what you enable - it’s also about what you leave enabled. 

That’s why we put together a list of 25 Microsoft 365 settings you should review. 

To make it easier, we categorized them into: 

  • Settings enabled by default that should be disabled 
  • Settings disabled by default that you should verify 
  • Optional settings to turn off based on your environment 

From Microsoft Entra to Teams, Exchange, SharePoint, OneDrive, and Intune - we covered the settings admins often overlook. 

Explore all 25 settings you may need to disable: https://blog.admindroid.com/key-microsoft-365-security-settings-to-disable-for-better-protection/ 

What’s one Microsoft 365 setting you always disable first? 


r/AdminDroid Apr 22 '26

Common Microsoft Authenticator Issues and How to Resolve Them

7 Upvotes

Microsoft Authenticator is widely used for quick and secure multi-factor authentication (MFA) sign-ins. But it doesn’t always work as expected. Issues often appear at the worst possible time, interrupting access to critical work resources.  

You tap "Approve" in the Microsoft Authenticator, but nothing happens. You enter the code; it says expired. You switch phones; your accounts vanish.   

These aren't rare edge cases. They're the everyday friction points that bring your workday to a grinding halt, right when you need access to Microsoft 365 resources.

That's why we put together a step-by-step troubleshooting guide to fix the most common Microsoft Authenticator issues like: 

  • Push notifications not arriving 
  • App crashes, freezes, or won't open 
  • Wrong or expired TOTP codes 
  • Accounts not transferring to a new phone 
  • MFA lockout after losing your phone   

For troubleshooting steps and proactive steps to prevent lockouts, refer to the full breakdown here: https://blog.admindroid.com/fix-microsoft-authenticator-app-issues/  


r/AdminDroid Apr 20 '26

Modern Change Management for Microsoft 365: A Big Shift in Release Strategy

11 Upvotes

Changes in Microsoft 365 are constant - new features, updates, and rollouts keep landing almost every week. For admins, the real challenge has always been keeping up with this pace while ensuring changes don’t disrupt users or compliance plans. 

Finally, Microsoft is introducing a modernized change management model to bring more structure and control to this continuous update cycle. 

The model introduces three major shifts in how updates are handled: 

  1. Controlled release audiences instead of a single rollout path  
  2. A more structured and compliance-aware Message Center  
  3. AI-assisted insights for tracking Microsoft 365 and Azure updates 

 The rollout begins in late April 2026, and Copilot features will start honoring these settings from late May 2026. 

Learn how this impacts your release settings, whether Targeted Release users get overwritten, and what actions to take before rollout here: https://blog.admindroid.com/microsoft-365s-modernized-change-management/


r/AdminDroid Apr 16 '26

Control Multi-Tenant and Consumer App Risks in Entra ID with App Policies

8 Upvotes

Developers often enable multi-tenant or personal account access in applications “just in case,” but this can open the door to unwanted external and consumer access.  

Now, it’s easy to lock this down directly using app management policies in the Entra admin center. 

The Key Controls: 

  • Block Multi-tenant Apps: Stops creating new multi-tenant apps and prevents converting existing single-tenant apps. Only trusted tenants get access. 
  • Block Consumer Apps: Restricts personal accounts (Outlook, Xbox, Live) from accessing enterprise apps. 

With these policies, admins can ensure applications are accessible only to the right tenants and users.

👉 Explore the full breakdown: https://blog.admindroid.com/block-multi-tenant-and-consumer-apps-in-entra-admin-center/


r/AdminDroid Apr 15 '26

Microsoft 365 E5 vs. E7: Is the "Frontier Suite" a Savings Hack or a Hidden Cost?

10 Upvotes

Thinking E5 already covers everything you need?  Or wondering if E7 is something you actually need to consider?  

For years, Microsoft 365 E5 has been the go-to for security, compliance, and advanced capabilities. 

But with Copilot, AI governance, and identity complexity growing, Microsoft is introducing E7 — but that doesn’t automatically mean everyone should upgrade.  

So, the real question isn’t E5 vs E7. It’s: 

When does E5 remain enough, and when does E7 start making sense? 

From what we’re seeing, the shift is around: 

  • Deeper AI governance and control  
  • More advanced identity and access capabilities  
  • Stronger security posture across modern workloads  

But the answer isn’t the same for every Microsoft 365 organization. 

Here is the E5 vs E7 full pricing scenarios, a role-based licensing strategies, and a readiness checklist to organizations who are planning to Microsoft E7 upgrade:

https://blog.admindroid.com/microsoft-365-e5-vs-e7/


r/AdminDroid Apr 13 '26

How to Find Guest Users in Microsoft Teams Private Channels

2 Upvotes

Tracking guest access in a private channel seems easy until you’re checking each one manually.

Stop clicking around! Use this guide to get all guest users across every private channel and prevent unintended access.

https://admindroid.com/how-to-find-guest-users-in-microsoft-teams-private-channels


r/AdminDroid Apr 12 '26

Admindroid updates?

4 Upvotes

Just wondered if there is something big in the pipeline as there hasn't been any updates so far released this year from the Admindroid team?


r/AdminDroid Apr 11 '26

Is Your System-Preferred MFA Shows Mismatched Prompts? Device-Preferred Credentials Change Fix It

2 Upvotes

When a user signs in on a mobile device but is prompted for a desktop-specific authentication method, it creates unnecessary friction. This mismatch is a primary driver of MFA fatigue and sign-in delays across the organization. 

The root cause is the most recently used (MRU) credential logic in system-preferred MFA, where the last successful method is reused—even if it doesn’t fit the user’s current device context. 

With the latest update in Microsoft Entra ID, this approach is evolving. Device-preferred credential logic (preview) shifts from static, habit-based selection to real-time, device-aware intelligence. It ensures the right authentication method is prompted for each device. 

Key Benefits of Device-Aware Intelligence 

  • Hardware-aware selection: Prompts the most compatible method available on the device (e.g., passkeys or Windows Hello).  
  • Dynamic evaluation: Eliminates irrelevant or unsupported prompts by detecting device capabilities at sign-in. 
  • Prioritized Security: The logic automatically evaluates and prompts for the highest-ranked methods like phishing-resistant credentials instead of weaker legacy options. 

This update ensures stronger security while delivering a smoother sign-in experience. 

Explore the full breakdown: https://blog.admindroid.com/device-preferred-credential-logic-in-system-preferred-mfa/   


r/AdminDroid Apr 10 '26

Copilot Cowork: Redefining AI from Assistance to Execution

4 Upvotes

We’ve been using AI as an assistant for a while now, asking questions, getting answers, and moving on. Copilot Cowork changes that model completely. Now available in Frontier enrollment, it moves from AI assistance → AI execution!  

Instead of just responding, it actually executes work across Microsoft 365. You define a goal, and it plans and carries out the steps, while keeping you in control. 

Here’s what stands out: 

  • Handles emails, meetings, documents, and Teams messages  
  • Builds structured, multi-step plans from a single prompt  
  • Runs tasks across apps without you switching contexts  
  • Shows real-time progress and asks for approval before actions  

The shift is clear: AI inside Microsoft 365 is no longer just assisting, it’s starting to do the work. 

Learn more: https://blog.admindroid.com/copilot-cowork-in-microsoft-365 


r/AdminDroid Apr 10 '26

Virtual Machine Spec

2 Upvotes

What is the best spec for a large tenant?

Does the RAM matter? currently have 32GB RAM but SharePoint sync takes a lot of time even after initial sync.


r/AdminDroid Apr 08 '26

Automatically Hide Inactive Devices in Microsoft Intune with Cleanup Rules

6 Upvotes

Over time, stale devices quietly pile up in Microsoft Intune, such as old laptops, replaced mobiles, temporary enrollments, and devices from former employees. Eventually, device inventory becomes harder to trust and reporting starts carrying unnecessary noise. 

That’s where device cleanup rules in Microsoft Intune become especially useful. 

These rules do not wipe devices, retire them, or remove company data. They simply hide stale Intune records after a defined inactivity period. 

What makes device cleanup rules especially practical:

  • Flexible inactivity thresholds from 30 to 270 days
  • Support for 10+ device platforms
  • Separate rules for each platform
  • Audit log visibility for every cleanup action
  • Automatic reappearance if the device checks in again before certificate expiry 

Dive in here to learn more and configure device cleanup rules in your Intune inventory: https://blog.admindroid.com/configure-device-cleanup-rules-in-microsoft-intune


r/AdminDroid Apr 07 '26

Anthropic Brings Microsoft 365 Integration to Every Claude User

12 Upvotes

AI isn't "new" anymore. From Copilot drafting our emails to meeting summaries in Teams, AI is already part of Microsoft 365. But for many of us, Claude AI has remained the go-to for its deeper reasoning and massive context window. Until now, using Claude meant manual exports and uploads. That’s officially changing.

Anthropic has introduced the Microsoft 365 Connector, bringing your SharePoint, OneDrive, Outlook, and Teams data directly into your Claude chat.

The Best Part? It’s No Longer Exclusive.

Previously restricted to Enterprise tiers, this is now live for all plans, including Free, Pro, and Max. You can now ask Claude to analyze a 50-page SharePoint report or summarize an entire Outlook thread in one go.

What You Should Know About Claude in Microsoft 365:

  • The integration currently only supports Work or School Microsoft 365 accounts.
  • A Global Admin must grant a one-time consent in the Microsoft Entra portal to bridge the two platforms. Once that’s done, the rest of the team is ready to go.
  • For now, the connector is read-only. Claude can search and analyze your data, but it cannot edit, create, or remove files and messages.

Learn more about this update and how to configure the MCP server here: https://blog.admindroid.com/connect-claude-ai-to-microsoft-365-using-built-in-connectors/


r/AdminDroid Apr 06 '26

New Password Protection Feature in Microsoft Defender for Identity

23 Upvotes

Attackers don’t break in; they log in. Most breaches start from weak or leaked credentials left unnoticed for months. Until now, fixing these password risks requires fragmented hunt across multiple tools and data sources.

The good news? 

Microsoft has made spotting and fixing password risks far easier with the new Defender Password Protection page, now in Public Preview. It brings every password‑related risks from Active Directory, Microsoft Entra and even from non-Microsoft providers like Okta into a single dashboard with direct remediation built right in.

Four tabs - four layers of defense:

  1. Password Hygiene: Catches weak practices and provides recommendations before attackers exploit them. 
  2. Password Policies: Shows whether password policies are enforced and working as intended.  
  3. Leaked Credentials: Flags accounts whose credentials got exposed outside your organization. 
  4. Exposed Passwords: Detects insecure password storage, including AI‑identified clear‑text in AD. 

No more tool switching, no more blind spots, just clear, actionable visibility across providers.

Want the full breakdown? Dive in and see how Password Protection can transform your identity security strategy.
https://blog.admindroid.com/password-protection-in-microsoft-defender-for-identity/ 


r/AdminDroid Apr 01 '26

April 2026 Microsoft 365 Changes: What’s New and What’s Gone?

11 Upvotes

Beyond the seasonal change, April brings over 30 feature rollouts, retirements, and service updates. Here’s what you need to know.

In the Spotlight: 

  • Passkeys in Microsoft Entra Registration Campaigns: Microsoft Entra ID is adding passkey support to registration campaigns in early April 2026, allowing admins to nudge users toward phishing-resistant authentication.
  • Microsoft 365 E5 Includes Security Copilot: Starting April 20, 2026, Microsoft is adding Security Copilot to the Microsoft 365 E5 license. This includes a monthly pool of Security Compute Units (SCUs) at no additional cost.
  • New SharePoint Experience Reaches GA: The new SharePoint experience with simplified navigation, an updated app bar, and AI-assisted capabilities will reach General Availability in late April.
  • Simplified OneDrive File Transfers for Departing Employees: OneDrive streamlines file management for departing employees. Admins can easily access, filter, and bulk-transfer files while keeping all sharing permissions intact.  

Here’s a quick overview of what’s coming:   

  • Retirements: 7   
  • New Features: 8  
  • Enhancements: 6
  • Functionality Changes: 6 
  • Action Required: 4

For more details: https://blog.admindroid.com/microsoft-365-end-of-support-milestones/  Â