Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Microsoft to Launch New Secure Default Settings for Exchange and Teams APIs

Microsoft has announced updates to its security policies, introducing a requirement for administrator consent for new third-party applications seeking access to Exchange and Teams content. These "Secure by Default" changes are scheduled to be implemented…

Microsoft has announced updates to its security policies, introducing a requirement for administrator consent for new third-party applications seeking access to Exchange and Teams content. These "Secure by Default" changes are scheduled to be implemented between late October and late November 2025. The goal is to enhance tenant security by providing administrators with increased control over data access.

This update is a significant part of the Microsoft Secure Future Initiative (SFI), which focuses on prioritizing security across Microsoft’s product ecosystem. The changes are designed to align with industry best practices by strengthening the security posture of Microsoft 365 tenants.

This initiative follows a similar security enhancement previously applied to SharePoint and OneDrive, which involved blocking legacy protocols and requiring admin consent for third-party apps accessing files. By extending this approach to Exchange and Teams, Microsoft aims to systematically evaluate and improve default security settings, thereby ensuring customer data is protected from unauthorized access. These changes will be applied without the need for additional licensing.

The core of this update involves changes to the Microsoft-managed default consent policy. For organizations utilizing this policy, any new third-party application requesting permissions to access Exchange and Teams data via Microsoft Graph, Exchange Web Services (EWS), Exchange ActiveSync (EAS), POP3, and IMAP4 will require explicit approval from an administrator.

These "Secure by Default" changes are scheduled to be implemented between late October and late November 2025.
Noah Kensington · Thehackingpost

Applications that have already been granted consent by users will continue to function without interruption for those existing users. However, if a new user attempts to authorize an app or an existing app requests new permissions, it will trigger the admin consent requirement. Organizations with custom user consent policies already in place will not be impacted by this update.

To facilitate a smooth transition, Microsoft recommends several preparatory steps for administrators. These include assessing the current environment, reviewing permissions of existing third-party applications accessing Exchange mail, calendars, contacts, and Teams chat or meeting data.

It is advisable to configure the admin consent workflow, allowing users to formally request application approval. Without this workflow, users will lack the means to request access. For critical applications that are already trusted, administrators can establish granular app access policies in advance to prevent service interruptions.

Advertisement

Finally, communicating these changes to IT teams, app owners, and security personnel, as well as updating internal onboarding documentation, will be crucial for effectively managing the new process.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories