Microsoft 365: Crucial Security Updates
Security
Jan 3, 2026 7:02 AM

Microsoft 365: Crucial Security Updates

by HubSite 365 about Andy Malone [MVP]

Microsoft 365 Expert, Author, YouTuber, Speaker & Senior Technology Instructor (MCT)

Microsoft expert breaks down Three Sixty Five security updates: BSM, Security Copilot and E five caveat

Key insights

  • Three major updates: Microsoft rolled out Baseline Security Mode (BSM), guidance to secure background agents, and changes to Microsoft Security Copilot.
    These updates reshape default protections across Microsoft 365 and the session warns there is an important caveat to check if you use Copilot in E5.
  • Baseline Security Mode (BSM) and Teams defaults: BSM enforces stricter, secure-by-default settings to reduce risky file types and links in Teams.
    Users can report false positives to improve detection without blocking valid collaboration.
  • Defender for Office 365 expansion: Microsoft expands core email and collaboration protections by bringing Defender for Office 365 features to more plans and adding Safe Links and URL protections to lower-tier subscribers.
    This broadens anti-phishing and link-scanning defenses across more users.
  • Endpoint and device controls for E3/E5: E3 gains tools like Intune Remote Help, Advanced Analytics, and Intune Plan 2 to improve device management and risk detection.
    E5 adds capabilities such as Endpoint Privilege Management, enterprise app governance, and Cloud PKI for stronger access control.
  • Microsoft Security Copilot: Copilot acts as an AI-powered security agent to speed threat investigation and response, and Microsoft includes it in E5 at no extra charge in this rollout.
    Admins should verify privacy settings, usage limits, and any licensing details tied to the service.
  • Practical actions for IT: Enable BSM where appropriate, update Teams and email protection policies, and test workflows to avoid business disruption.
    Review license changes, train users on reporting threats, and monitor alerts to measure impact.

Introduction

In a recent YouTube video, Andy Malone [MVP] walks viewers through three major Microsoft 365 security updates that aim to reshape how organizations protect their cloud workplace. He focuses on Baseline Security Mode (BSM), the evolving role of AI in security through Microsoft 365 Security Copilot, and expanded protections across email and collaboration tools. Moreover, he flags a noteworthy catch about the new Copilot inclusion for certain subscriptions and explains practical steps administrators should take next.

Overview of the Updates and What They Mean

Andy frames these changes as a move toward making baseline protection more universal, while also pushing advanced controls into higher-tier plans. Consequently, organizations should expect stronger default defenses, but they also need to plan for configuration and change management. Furthermore, Andy stresses that IT teams must balance protection with user productivity so that security does not become an obstacle to everyday work.

Baseline Security Mode (BSM)

Andy explains that Baseline Security Mode aims to set safer defaults across Microsoft 365 apps so fewer tenants start from a risky configuration. By enabling protections automatically, BSM reduces exposure to common attacks such as malicious links and unsafe file types, and it helps organizations achieve a more consistent security posture. However, he notes that automatic settings require review because they can affect workflows; therefore, administrators should pilot changes and gather user feedback before broad roll-out.

Microsoft 365 Security Copilot — Power and the Catch

In the video, Andy highlights that Microsoft is integrating AI-driven capabilities into security workflows through Microsoft 365 Security Copilot, which can speed investigation, suggest remediation steps, and surface patterns across signals. He notes that Microsoft now includes this capability in certain subscriptions, making AI-enabled security more accessible to organizations that already invest in higher-tier Microsoft 365 plans. At the same time, he warns that inclusion is not necessarily without tradeoffs and that some organizations will face choices about data handling and feature scope.

For example, Andy points out that admins must consider privacy and compliance when enabling Copilot features because AI-driven tools often need access to telemetry and logs to be effective. Additionally, while Copilot can reduce time-to-detect and time-to-respond, teams should plan for model tuning and governance to avoid over-reliance on automated suggestions. Therefore, organizations should adopt a phased approach that pairs Copilot with clear policies and human oversight.

Email, Teams, and Defender Enhancements

Andy also covers expanded protections for email and collaboration tools, emphasizing that Microsoft is broadening access to technologies once reserved for higher-priced plans. For instance, features like Safe Links and real-time URL scanning are becoming more widely available to help stop phishing and malicious content before users click. Moreover, the integration between collaboration apps and threat detection can improve incident visibility, but it also raises the need for clear processes around false positives and user reporting.

Endpoint Management: New Tools and Tradeoffs

The video outlines upgrades in endpoint management, with E3 and E5 subscribers receiving more powerful tools such as Intune enhancements, remote help, and advanced analytics. These additions simplify device troubleshooting and elevate visibility into risks across distributed estates, which in turn helps reduce exposure to compromised endpoints. However, Andy emphasizes tradeoffs: richer telemetry and controls demand more administrative effort and may require additional training or staff to manage effectively.

He also discusses how enterprise features like endpoint privilege management and cloud PKI can secure AI usage and reduce lateral risk, while noting that implementing them can increase complexity. Consequently, security teams must balance cost, skills, and user impact when deciding which features to enable immediately and which to phase in. In practice, this often means prioritizing high-impact controls that protect critical assets first and then expanding protections over time.

Conclusion

Overall, Andy Malone’s video provides a clear-eyed look at Microsoft 365 security changes and how they influence operational choices. He encourages administrators to test new defaults, plan governance for AI-driven tools like Security Copilot, and prepare teams for added endpoint controls, while always weighing usability against risk reduction. For organizations aiming to strengthen defenses without disrupting users, Andy recommends staged deployment, strong monitoring, and continual review to strike the right balance.

Security - Microsoft 365: Crucial Security Updates

Keywords

Microsoft 365 security updates, M365 security features 2026, Microsoft Defender for Office 365 updates, Zero Trust Microsoft 365, Microsoft Entra ID updates, Microsoft Purview compliance updates, Intune endpoint security updates, Conditional Access improvements