
Microsoft 365 Expert, Author, YouTuber, Speaker & Senior Technology Instructor (MCT)
In a recent YouTube video, Andy Malone [MVP] walks viewers through three major Microsoft 365 security updates that aim to reshape how organizations protect their cloud workplace. He focuses on Baseline Security Mode (BSM), the evolving role of AI in security through Microsoft 365 Security Copilot, and expanded protections across email and collaboration tools. Moreover, he flags a noteworthy catch about the new Copilot inclusion for certain subscriptions and explains practical steps administrators should take next.
Andy frames these changes as a move toward making baseline protection more universal, while also pushing advanced controls into higher-tier plans. Consequently, organizations should expect stronger default defenses, but they also need to plan for configuration and change management. Furthermore, Andy stresses that IT teams must balance protection with user productivity so that security does not become an obstacle to everyday work.
Andy explains that Baseline Security Mode aims to set safer defaults across Microsoft 365 apps so fewer tenants start from a risky configuration. By enabling protections automatically, BSM reduces exposure to common attacks such as malicious links and unsafe file types, and it helps organizations achieve a more consistent security posture. However, he notes that automatic settings require review because they can affect workflows; therefore, administrators should pilot changes and gather user feedback before broad roll-out.
In the video, Andy highlights that Microsoft is integrating AI-driven capabilities into security workflows through Microsoft 365 Security Copilot, which can speed investigation, suggest remediation steps, and surface patterns across signals. He notes that Microsoft now includes this capability in certain subscriptions, making AI-enabled security more accessible to organizations that already invest in higher-tier Microsoft 365 plans. At the same time, he warns that inclusion is not necessarily without tradeoffs and that some organizations will face choices about data handling and feature scope.
For example, Andy points out that admins must consider privacy and compliance when enabling Copilot features because AI-driven tools often need access to telemetry and logs to be effective. Additionally, while Copilot can reduce time-to-detect and time-to-respond, teams should plan for model tuning and governance to avoid over-reliance on automated suggestions. Therefore, organizations should adopt a phased approach that pairs Copilot with clear policies and human oversight.
Andy also covers expanded protections for email and collaboration tools, emphasizing that Microsoft is broadening access to technologies once reserved for higher-priced plans. For instance, features like Safe Links and real-time URL scanning are becoming more widely available to help stop phishing and malicious content before users click. Moreover, the integration between collaboration apps and threat detection can improve incident visibility, but it also raises the need for clear processes around false positives and user reporting.
The video outlines upgrades in endpoint management, with E3 and E5 subscribers receiving more powerful tools such as Intune enhancements, remote help, and advanced analytics. These additions simplify device troubleshooting and elevate visibility into risks across distributed estates, which in turn helps reduce exposure to compromised endpoints. However, Andy emphasizes tradeoffs: richer telemetry and controls demand more administrative effort and may require additional training or staff to manage effectively.
He also discusses how enterprise features like endpoint privilege management and cloud PKI can secure AI usage and reduce lateral risk, while noting that implementing them can increase complexity. Consequently, security teams must balance cost, skills, and user impact when deciding which features to enable immediately and which to phase in. In practice, this often means prioritizing high-impact controls that protect critical assets first and then expanding protections over time.
Overall, Andy Malone’s video provides a clear-eyed look at Microsoft 365 security changes and how they influence operational choices. He encourages administrators to test new defaults, plan governance for AI-driven tools like Security Copilot, and prepare teams for added endpoint controls, while always weighing usability against risk reduction. For organizations aiming to strengthen defenses without disrupting users, Andy recommends staged deployment, strong monitoring, and continual review to strike the right balance.
Microsoft 365 security updates, M365 security features 2026, Microsoft Defender for Office 365 updates, Zero Trust Microsoft 365, Microsoft Entra ID updates, Microsoft Purview compliance updates, Intune endpoint security updates, Conditional Access improvements