
M365 Roundup, July 2025: Token Protection Comes to P1
Token protection reaches Entra ID P1, Defender gains mail-bombing detection, the Conditional Access Optimization Agent hits GA, and Intune ships LAPS for macOS.
Topic

Token protection reaches Entra ID P1, Defender gains mail-bombing detection, the Conditional Access Optimization Agent hits GA, and Intune ships LAPS for macOS.

Entra flags risky users by default, but nobody gets told and nothing happens without P2. How to route risk detections to your PSA and the one policy that prevents most compromises.

Token theft via AiTM phishing hit 51% of webinar respondents in the past year. Five layered controls, from Defender tuning to attack disruption, break the kill chain at each stage.

Six Conditional Access policies can stop token theft before it starts. Each blocks a different part of the attack, and each has a gap. Here is the full comparison with exact settings.

Entra's token protection session control sounds like the end of token replay. In testing, stolen tokens still replay in the browser. Here is exactly what the preview covers, as of May 2025.

Exchange Online enforces tenant-wide outbound email limits, E5 Security arrives as a Business Premium add-on, and the Report Message add-in enters maintenance mode.

Microsoft-managed Conditional Access policies start auto-enforcing after 45 days, Skype interop in Teams dies May 1, and Hotpatch hits preview. The February 2025 changes, sorted by deadline.

Users refuse enrollment, admins refuse open access. Intune app protection policies plus one Conditional Access rule protect Microsoft 365 data on personal phones without managing the device.

External collaborators do not need download rights to do their job. Two settings force guests into authenticated, browser-only access and block local downloads in SharePoint and OneDrive.

Entra lets any user register any device by default, and attackers use that to persist after a compromise. Three policies, from MFA on registration to TAP gating, shut the door.

Microsoft 365 lets users sign in from any device in the world by default. Here are the two Conditional Access policies, exact settings included, that restrict access to devices you manage.

When customers demand BYOD access to Microsoft 365, contain it: web-only access, download blocks, session limits, TAP-gated enrollment, and MAM, with a dynamic group to segment personal devices.