Cyber Security News

Microsoft Rolls Out Baseline Security Mode for Office, SharePoint, Exchange, Teams, and Entra

Microsoft has begun deploying Baseline Security Mode across Microsoft 365 tenants, a new dashboard in the M365 Admin Center that centralizes recommended security configurations for Office, SharePoint, Exchange, Teams, and Entra.

Announced at Ignite 2025, this opt-in feature helps administrators quickly assess vulnerabilities, run impact reports, and apply risk-based hardening without immediate user disruptions.

As of December 2025, it’s appearing in select tenants under Org Settings > Security & Privacy, with full rollout targeted for late January 2026 worldwide.​

Baseline Security Mode enforces 18 to 20 policies across three core areas, drawing from Microsoft’s threat intelligence and two decades of response center data.

Authentication policies 12 in total block legacy protocols like basic auth, Exchange Web Services (EWS), and IDCRL, while mandating phishing-resistant MFA for admins using FIDO2 or passkeys.

File protections limit risky behaviors, such as opening documents via insecure HTTP/FTP protocols, ActiveX, DDE, or legacy formats outside Protected View, and disable vulnerable tools like Microsoft Publisher ahead of its 2026 retirement.​

Public preview and general availability started mid-November 2025, with phased deployment completing by March 2026 for GCC, DoD, and GCCH clouds.

Admins with Security or Global roles can enable it directly: select “Automatically apply default policies” for seven low-impact controls or “Generate report” for simulation on the rest, reviewing audit-based impact data within 24 hours. No tenant disruptions occur until changes are approved, and progress tracking shows “At risk” or “Meets standards” statuses.​

This secure-by-default model addresses common misconfigurations, closing gaps exploited in credential stuffing, phishing, and supply chain attacks.

By simplifying enforcement across services, it prepares organizations for AI-driven threats under the Secure Future Initiative, with future expansions to Purview, Intune, and Azure planned. Tenants seeing it now, like the users, gain an edge in proactive defense amid rising ransomware and APT campaigns.​

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

16 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago