This page outlines the latest updates to your Microsoft 365 tenant, delivered as a managed service by OneOffice
Please reach out to your designated consultant at OneOffice for inquiries related to the updates.
All updates have been tested and verified by trained personnel.
Profiles, apps, groups or settings in Microsoft 365 bearing the [OO Baseline] and [OO Baseline SS] identifiers are exclusively maintained and managed by OneOffice. They must not be altered under any circumstances.
Identifiers containing [OO Baseline SS] indirectly or directly affect your Secure Score and denote elements specifically related to security enhancements.
Updates to our baseline are implemented on a quarterly basis by the end of March, June, September and December, allowing for consistent improvement and adherence to evolving security best practices.
Date for implementation: 2026 Q3
<aside> ✅ This profile has been added to baseline
</aside>
| What does this do? | Forces the Windows device to sign outbound LDAP traffic, so directory authentication to a domain controller can't be tampered with in transit |
|---|---|
| Why should you use this? | To protect LDAP authentication sessions from man-in-the-middle tampering, where an attacker alters directory traffic between the device and the DC |
| What is the end-user impact? | Applications or services relying on unsigned or simple (plaintext) LDAP binds from the device will fail until moved to a signed bind (SASL Kerberos/NTLM) or LDAPS |
| Learn more | This setting is a Settings Catalog. These LDAP and the previous NTLM settings can be safely applied in pure cloud native environments where devices are Entra ID joined and managed by Intune. This policy should not be applied in environments with Active Directory without first assessing LDAP dependencies |
| Release date | - |
<aside> ✅ This profile has been added to baseline
</aside>
| What does this do? | Forces the Windows device to encrypt outbound LDAP bind traffic, so directory lookups to a domain controller can't be read on the wire |
|---|---|
| Why should you use this? | To protect credentials, usernames, and group data exchanged over LDAP from being intercepted in plaintext on the network |
| What is the end-user impact? | Applications or services that rely on unencrypted LDAP binds from the device will fail until reconfigured to use secure LDAP |
| Learn more | This setting is a Powershell platform script. These LDAP and the previous NTLM settings can be safely applied in pure cloud native environments where devices are Entra ID joined and managed by Intune. This policy should not be applied in environments with Active Directory without first assessing LDAP dependencies |
| Release date | - |
<aside> ✅ This profile has been added to baseline
</aside>
| What does this do? | Blocks Windows devices from accepting incoming NTLM authentication requests from other systems |
|---|---|
| Why should you use this? | To reduce the attack surface by preventing NTLM based authentication attempts against the device |
| What is the end-user impact? | Systems or applications attempting to authenticate to the device using NTLM will fail, which may affect legacy services or integrations relying on NTLM |
| Learn more | This settings is a Settings Catalog. [Network security Restrict NTLM Incoming NTLM traffic - Windows 10 |
| Release date | - |
<aside> ✅ This profile has been added to baseline
</aside>
| What does this do? | Prevents Windows devices from sending NTLM authentication requests to remote servers |
|---|---|
| Why should you use this? | To eliminate NTLM usage and enforce stronger authentication protocols like Kerberos, reducing risk of credential relay and reuse |
| What is the end-user impact? | Applications, services, or connections that rely on NTLM for authentication to remote systems will fail, potentially impacting legacy systems or external integrations |
| Learn more | This setting is a Settings Catalog. [Network security Restrict NTLM Incoming NTLM traffic - Windows 10 |
| Release date | - |
Date for implementation: before April 1st 2026.
| --- | --- |
| --- | --- |
| --- | --- |
| --- | --- |
| --- | --- |
| --- | --- |