Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Vestíbulo de oficina con una fila de tornos de acceso de cristal alineados y vacíos
8 min read

The Conditional Access policies you never wrote are already in your tenant

Open the Conditional Access policy list in your tenant and look at the Created by column. If any row says Microsoft, nobody in your company wrote that policy: Microsoft creates it in Report-only and switches it on itself "no less than 30 days" later, with two weeks' notice and a note saying it can be sooner. They cannot be renamed or deleted; the only thing you can change is who you exclude —starting with your emergency account—. Which ten exist today, the three that actually break things (device code flow and Teams rooms, legacy authentication and the scan-to-email printer, MFA for all users and licensed service accounts), the detail almost nobody quotes —your P2 license count and MFA registration draw who the risk policy protects— and the audit query that tells you what Microsoft changed in your tenant and when.

Fila de mesas de oficina con los monitores apagados y una silla vacía
8 min read

Office 2021 does not stop working: it stops being tested against Microsoft 365

On 13 October 2026 nothing switches off: Word will open, Outlook will sync and nobody will notice. That day two clocks start at once and only one makes noise. The first is the ordinary end of support — Microsoft stops providing technical support, bug fixes and security updates. The second raises no alert: Microsoft stops checking that its own services still work with your Office, and the outage arrives months later without you touching a thing. The two different dates Microsoft itself publishes, the Office 2016/2019 precedent from 2023, and the finding that decides who is in a hurry: Windows 11 24H2 Home and Pro expires in the very same second, but the Enterprise edition holds on for another year.

Sala de reuniones vacía con mesa larga, sillas y una pizarra de cristal borrada al fondo
5 min read

Your Teams chats are not in your backup

Microsoft 365 Backup protects three workloads: OneDrive, SharePoint and Exchange Online. Teams chat is none of them. And on the limitations page of one of the most widely deployed third-party tools, individual and group chats appear in the list of what is not backed up. Where a Teams message actually lives according to Microsoft's own documentation, why a retention policy preserves but does not restore, the 21 days it takes a deleted message to reach the SubstrateHolds folder, and the six questions we ask of a company's Microsoft 365 backup before touching anything.

Hilera de buzones de correo metálicos alineados junto a un camino de tierra
5 min read

onmicrosoft.com is no longer just an ugly domain: it is the slow lane

On 28 August Microsoft warned (MC1463510) that organisations using only the default domain will face external messaging limits in Teams, with rollout from mid-September. Read on its own it looks like an anti-spam tweak. Read alongside email it is something else: the limit of 100 external recipients per rolling 24 hours for onmicrosoft.com domains finished rolling out to every size band on 1 June 2026, with its own 550 5.7.236 bounce code. The case that catches companies who think they are unaffected, and why fixing it is not buying a domain but changing what people log in with.

Pasillo de un depósito de archivo con estanterías móviles cerradas y cajas de documentación
11 min read

Project Online shuts down on 30 September: no licence, no export

Microsoft switches Project Online off on 30 September and PWA sites stop being available. But what decides whether you make it in time is not in the announcement: it is in the service description, which requires a live Plan 3 or Plan 5 subscription in the tenant for ANY interaction. Which means the licence you were going to drop to save money during the migration is the one you need in order to export. There is also a second 120-day clock written somewhere else, the PWA is a SharePoint site and not a calendar, and the destination's published limits explicitly exclude your plan.

Sala con filas de puestos de trabajo: torres bajo las mesas, monitores apagados, teclados y cables recogidos
10 min read

EDR isolates the device on its own; the rule that brings it back is written beforehand

On 3 September Microsoft added a sentence to the Defender for Endpoint documentation and by the next day it was gone: it warned that automatic isolation fires as FULL isolation and that, with a web proxy, the device might not recover. The two facts it joined are both still published, but in separate sections. What gets isolated on its own and what does not, what "containing" does and what "isolating" does, and the way back point by point.

Fila de puestos de trabajo vacíos en una oficina
10 min read

Entra ID retires memberOf on 3 November: after that date, membership stops being recalculated

Message centre post MC1448379, published on 5 August, has been read as a deadline. Read it the other way round: if you run a memberOf rule in production, you already have the problem it describes, and the preview documentation says so in a paragraph almost nobody reads. What happens on 3 November is not an outage or an error: memberships stay "in their last known state". That is where licences, Conditional Access and Teams membership hang from.

Cajas de archivo numeradas en estanterías de un depósito documental
9 min read

One checkbox will protect a whole workload in Microsoft 365 Backup. What it bills is not what you see in the usage report

Full Workload Backup reaches general availability from mid-September: one policy per workload protecting every SharePoint site, or every OneDrive account, or every mailbox, including the ones created later. List price is $0.15 per GB per month, applied to a base that adds in the second-stage recycle bin and online archives. Microsoft warns that its own usage report includes neither, "and is thus incomplete", and offers a calculator that does ask for them. The problem is that the report is what everybody looks at.

Mesa de soporte de una oficina con un teléfono fijo de sobremesa, una libreta de anillas, un cordón con llaves y un teclado apartado a un lado
9 min read

The phone number on the record was a credential: Entra ID stops accepting it

Microsoft's own documentation has said it plainly for years: if you fill in a user's mobile phone or alternate email, that user can reset their password immediately "even if they haven't registered for the service". Which means a field written by a sync or by an admin worked as proof of identity. Entra ID is about to stop accepting it. What changes, why the 86% everyone quotes does not mean what it looks like, and the four different dates Microsoft gives for the same cutoff.

Armario rack de pared en un cuarto de instalaciones de oficina, con un servidor encendido, polvo en la bandeja, una escalera plegada y un cubo de fregona al lado
7 min read

The Exchange you left running: 21,899 unpatched servers, and yours could be one

On 31 August 2026, Shadowserver scans counted 21,899 IP addresses running an Exchange Server without the CVE-2026-62911 patch released on 11 August. Many of those servers do not belong to companies that never migrated: they are the one left running after the move to Microsoft 365, published on the internet and owned by nobody. What Microsoft's advisory says and does not say next to Germany's BSI, why since April 2022 that server can be switched off, which route Microsoft recommends in 2026 to remove it for good, and the three cases where you should not touch it.

Priority Cleanup de Microsoft Purview: borrar por encima de la retención en Microsoft 365
9 min read

Deleting above retention: three approvals in Exchange, one in SharePoint

Microsoft Purview Priority Cleanup deletes Microsoft 365 content by overriding retention policies, labels and eDiscovery holds, and the documentation says what it deletes cannot be restored by users, by admins, or by Microsoft. Mailboxes always demand three approvals; SharePoint and OneDrive, one — and none from the retention owner. What stops it, what to switch off beforehand, and what it asks of your backup.

Custom controls de Acceso Condicional: el MFA de terceros que Entra no cuenta como MFA
9 min read

Custom controls: the third-party MFA that Entra does not count as MFA

The Microsoft Learn page on Conditional Access custom controls lists eight things that control cannot do, and the third is satisfying the MFA claim requirement. It is no good for PIM role elevation, device enrollment, SSPR, sign-in frequency or cross-tenant trusts either. From September 2026 they can no longer be created or edited, and "editing" means deleting and creating again. With the Graph query to find out whether you have one.

Cuadro eléctrico general abierto en un cuarto de instalaciones, con filas de magnetotérmicos colgando todos de un mismo interruptor principal
5 min read

Six Microsoft 365 services went down together. For your continuity plan they are one

On Monday 31 August, incident EX1464935 on Exchange Online ended up as MO1465074, with OneDrive, SharePoint Online, Teams, Purview and Defender XDR inside it. Six names, one shared authentication configuration underneath. We go through the hours —including the ones BleepingComputer and Computerworld disagree on, which we say rather than picking one—, why nobody has confirmed the expired-certificate story, and the dependency almost nobody will look at: the security console and the audit layer were inside the thing that had gone down.

Puesto de trabajo vacío en una oficina técnica de noche, con dos monitores apagados y un rack al fondo
5 min read

Defender switches off the investigate button: AIR can no longer be triggered by hand

Tomorrow, 1 September 2026, Microsoft Defender's automated investigation and response stops running as a separate experience and can no longer be triggered by hand. The official documentation says so in a two-paragraph box, and message MC1411577 went up on 2 July: sixty-one days of notice. We go through what actually breaks (the scripts calling startInvestigation), why "run a full scan" does not answer the same question, who this does not affect at all, and the seven-day clock in the Action center you should look at today.

Mesa de oficina con un portátil cerrado, una llave de seguridad USB en un llavero y un teléfono móvil boca abajo
5 min read

Passkeys on 1 September: the cases that do not fit

In July we went through the timeline for the retirement of SMS and voice in Microsoft Entra ID. Five days after that post Microsoft published a FAQ, and there are now forty-eight hours to go until the first date. This is the run-through of what is still unanswered: the FAQ's "No" to the lockout question and what it says three lines further down, the self-service password reset that goes with the same move, the declared gap for B2B guests, the break-glass accounts the documentation never mentions, and why the temporary opt-out switch, which lives on the Graph beta endpoint, is not the answer we would give.

Rincón de oficina con una papelera metálica desbordada de papel y una destructora con el depósito lleno
9 min read

Recoverable Items: 14 days, 30 GB and the day the mailbox can no longer delete

The folder that saves you when someone empties the deleted items does not show up in Outlook, keeps things for 14 days by default and holds 30 GB. Put the mailbox on hold and the ceiling rises to 100 GB — in exchange for never draining again: things only go in. And on the day it hits that ceiling, per Microsoft's own documentation, the user cannot delete, versions stop being kept and audit entries stop being written. How to measure your headroom with two commands, how to open the drain that ships disconnected, and why a folder deleted with Shift+Delete does not come back even under litigation hold.

Sala de archivo con estanterías metálicas llenas de cajas de cartón y una caja sacada a medias del estante
5 min read

Microsoft 365 Archive is coming to retention policies: compliance up, availability down

This autumn, a Purview retention policy will be able to move SharePoint files into the cold tier (roadmap 561208: preview in September, GA in October). Microsoft promises cost, compliance and search; its own documentation adds that archived content is "no longer directly accessible to anyone" and lists the apps that break: Word and PowerPoint online, the mobile apps, the macOS sync client and Office builds not updated since March. A reactivated file cannot be archived again for 120 days.

Fotocopiadora multifunción de oficina con la puerta de tóner abierta y la bandeja de papel a medio sacar
7 min read

August's patch broke printing in WPF apps: the three ways out, with the maths done

The 11 August .NET Framework cumulative update breaks printing and PDF export in WPF applications using Calibri, Cambria, Constantia and Corbel: <code>System.IO.FileFormatException</code> on a font Windows itself installs. Microsoft acknowledged it on the 24th, thirteen days later, and the interim workaround switches off the overflow protection that same patch had just added. We looked at what exactly it turns off, why the decision should be per application rather than per fleet, and which of the three ways out costs least in each case.

Sala de reuniones pequeña y vacía, con un altavoz de conferencia sobre la mesa, sillas desordenadas y luz natural entrando por la persiana
5 min read

Teams can now block meeting bots: it ships turned off

On 21 August Microsoft announced (MC1459141) that admins will be able to automatically block detected external bots in Teams meetings. We read the documentation for the ExternalBotAccessMode parameter: the word doing all the work is "detected", the new mode has to be assigned through policy, and it touches neither Copilot nor the assistant recording from your client's tenant. What actually decides where the transcript ends up — and when we would not switch it on.

Jaula de rejilla metálica cerrada con candado en una sala de datacenter compartida, con dos racks de servidores detrás
9 min read

The patch that isn't yours: what to do with Entra ID's CVE-2026-69836

On 20 August Microsoft published a critical remote code execution flaw in Entra ID, and the next day corrected the exploitation field to "No". There is nothing to install: the record says "customerActionRequired: false". What is yours is the ability to answer "were we affected?", and on an Entra ID Free licence that lasts seven days. How to read the record from Microsoft's own API, and the checklist we apply to the tenant.

  • 1
  • 2

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN