Microsoft Rolls Out Baseline Security Mode for Office, SharePoint, Exchange, Teams, and Entra
## Cybersecurity: Microsoft Baseline Security Mode Deployment
Cybersecurity: Microsoft Baseline Security Mode Deployment
Microsoft has initiated the deployment of Baseline Security Mode across Microsoft 365 tenants. This new feature, available in the M365 Admin Center, centralizes recommended security configurations for Office, SharePoint, Exchange, Teams, and Entra.
Announced at Ignite 2025, the Baseline Security Mode is an opt-in feature designed to assist administrators in assessing vulnerabilities, running impact reports, and applying risk-based hardening with minimal disruption to users. As of December 2025, it is available in select tenants under Org Settings > Security & Privacy, with a full rollout expected by late January 2026 worldwide.
Baseline Security Mode enforces 18 to 20 policies across three core areas. These policies are informed by Microsoft's threat intelligence and extensive response center data.
Microsoft has initiated the deployment of Baseline Security Mode across Microsoft 365 tenants.
Authentication Policies: A total of 12 policies block legacy protocols like basic auth and Exchange Web Services (EWS), while requiring phishing-resistant multi-factor authentication (MFA) for administrators using FIDO2 or passkeys. File Protections: These limit risky behaviors such as opening documents via insecure protocols like HTTP/FTP, ActiveX, DDE, or legacy formats outside Protected View. Vulnerable tools like Microsoft Publisher will be disabled ahead of its 2026 retirement.
The public preview and general availability began in mid-November 2025, with a phased deployment expected to conclude by March 2026 for GCC, DoD, and GCCH clouds. Administrators with Security or Global roles can enable the feature directly, choosing to "Automatically apply default policies" for low-impact controls or "Generate report" for simulation on the remaining controls. Audit-based impact data is available within 24 hours, with no tenant disruptions until changes are approved.
This secure-by-default model addresses common misconfigurations, mitigating risks from credential stuffing, phishing, and supply chain attacks. By streamlining enforcement across services, it prepares organizations for AI-driven threats under the Secure Future Initiative, with future expansions planned for Purview, Intune, and Azure. Current tenants benefit from enhanced proactive defense amid increasing ransomware and APT campaigns.
Based on reporting by Cyber Security News.
