Managed ISPM features continue to grow as we move towards General Availability on July 1. In this set of updates, new Security Controls and enhancements have been added to the following platforms:
SharePoint Online
  • An Idle session timeout for SharePoint and OneDrive is in place
  • Anonymous sharing links are blocked in SharePoint and OneDrive
  • User creation of SharePoint sites is blocked
  • Deleted user OneDrive content is retained for at least 90 days
Microsoft Teams
  • Communication with unmanaged Teams should be blocked
  • Ensure the Organization cannot communicate with accounts in trial Teams tenants
Continuous Enforcement Improvements
The following policies now support Continuous Enforcement with drift detection and auto-remediation:
  • Ensure access to the Azure Management portal is restricted
  • Ensure unused device types are blocked
  • Ensure Guests are restricted from using Microsoft Office clients
  • Require frequent sign-in for Admins
  • Require MFA to register or join devices