Lars Lohmann

External mail settings

As demonstrated previously, numerous technical configurations are available to support effective Microsoft 365 Governance. In this post, we will examine several minor adjustments that have the potential to significantly influence our user’s behavior. When receiving mail from external partners, by default our users must know that the mail is received

Continue to read »

Microsoft Teams and external members Pt. 1

Many customers using Microsoft Teams request teams restricted to internal members, without guest account access. Teams’ behavior is very often controlled by SharePoint or Microsoft 365 Group settings and a typical team user may not know anything about these settings. We recommend building your own app or automation to ensure

Continue to read »

Inactive Teams and governance

During our Microsoft 365 Governance workshops with customers, a common question is how to handle inactive teams. Our primary recommendation is to implement automated processes for archiving inactive teams, team owners can also archive a team themselves. The team’s conversations and files will be set to read-only and remain searchable.

Continue to read »

Send an email to a channel in Microsoft Teams

You can email a Teams channel using its email address. Once set up, anyone in the team can reply. To see a channel email, you must select use the option Get email address on the channel itself. You may use this email address as the recipient address in Outlook. Any

Continue to read »

Default selected options when sharing files in Teams

When you select Share on a file in Teams, it is actually shared in SharePoint. The default options selected can be changed, and when we run our Microsoft 365 Governance workshops this is often a required action for a lot of customers. By default SharePoint will show these option when

Continue to read »

Delete chats in Microsoft Teams based on a retention policy

A frequently discussed topic during our Microsoft 365 governance workshops is the appropriate retention period for chat messages within Teams. Some customers prefer that chat messages are deleted after a predefined period rather than being retained for an extended time. In this post, we will examine how to efficiently delete

Continue to read »

Teams and file sync to OneDrive Pt. 2

As explained in Part one, a common Microsoft 365 Governance workshop question is how to use the Sync to OneDrive and Add shortcut to OneDrive features, both found under the Files tab in Teams channels. We recommend using only Add shortcut to OneDrive and disabling Sync. However, here we’ll also

Continue to read »

Teams and file sync to OneDrive Pt. 1

A common inquiry that arises during our Microsoft 365 Governance workshop concerns the use of the Sync to OneDrive feature in Teams and the Add shortcut to OneDrive option. Both functionalities are accessible from the Files tab within a Teams channel. We normally recommend using Add shortcut to OneDrive instead

Continue to read »

Unlock Teams Premium prompt

We are starting to see the Unlock Teams Premium prompt, on more tenants, and at the same time we are now also starting to get the question on our Microsoft 365 Governance workshops. Teams Premium is not the only license that users can do self-service/trials set up and purchase on.

Continue to read »

Restrict save in Office apps to Cloud locations

A new policy setting has been introduced in Microsoft 365 Apps for Enterprise that governs the ability of Word, Excel, and PowerPoint to create new files using non-Cloud locations, such as local or network drives. When this policy is enabled, users will be restricted to Cloud Locations for the Save

Continue to read »

Per-user Entra ID multifactor authentication

Today we secure our tenants using conditional access or security defaults, but in the old days many tenants were configured to use Legacy per-user Multi-Factor Authentication (MFA). It is recommended that per-user Microsoft Entra multifactor authentication should not be enabled or enforced when Conditional Access policies are in use. Convert

Continue to read »

SharePoint integration with Entra B2B (2025)

In 2022 we wrote a post about SharePoint and OneDrive integration with Microsoft Entra B2B. As of 2025, the information in this post remains relevant for tenants created before June 2023; tenants provisioned after that date have Entra B2B integration enabled by default. Now, only one command is needed instead

Continue to read »

OneDrive Sync

A common question in our Microsoft 365 governance workshops is whether to allow the OneDrive client to sync with other organizations. If needed, modern managed Windows computers can restrict OneDrive syncing to specific Entra ID tenants only. Previously, we used a Group Policy Object (GPO) to restrict OneDrive access to

Continue to read »

Non-Destructive PIN reset

When we use Windows Hello for Business and a user forgets the PIN, it can be reset directly from the sign-in page. By default, this will be a destructive PIN reset, the existing PIN, and underlying credentials, including any keys or certificates added to their Windows Hello container, will be

Continue to read »

Windows Hello for Business Cloud Trust

We have a lot of customers who use Windows Hello for Business Azure AD joined Key trust. But now that Windows Hello for Business cloud trust is available (preview), we expect to see a move towards Cloud Trust, maybe this could also be interesting for your setup? Key trust is

Continue to read »

SharePoint integration with Azure AD B2B

When we share data In SharePoint with a user outside our directory, SharePoint will by default use a one-time code sent to the user so the user can verify their identity. This is also the case with OneDrive and if you do it from teams using open in SharePoint. But

Continue to read »

Group writeback in Azure AD

This time we will take a closer look at the new group writeback functionality in Azure AD. I really think this will open a lot of possibilities also on-premises. Prerequisites Azure AD Premium license Azure AD Connect version 2021 December release or later. Enable Azure AD Connect group writeback But

Continue to read »

Welcome to MEM tips and tricks

  This is the first video on the brand new MEM tips and tricks YouTube site created by Mindcore’s Mattias Melkersen. The place to see and learn practical endpoint management skills in the real world.    

Continue to read »

Identity Protection and guests

This time we will have a closer look at Identity Protection and possible impact for guest users (B2B collaboration users).   So in order to test this out we will create a Identity protection user risk policy requiring all users to change password if there risk is calculated to medium

Continue to read »

Creating a Simple No Code Custom Apps in Microsoft Teams

  With the massive growth of Microsoft Teams since the start of the global COVID19 pandemic and Microsoft’s focus on pushing Teams as its primary collaboration interface. Organisations are now looking at how Teams can be used to optimise their End User experience by customising the solution to meet their

Continue to read »

Microsoft Endpoint Manager tenant attach

Now that we have tenant attach available let’s have a closer look. Microsoft is now bringing Configuration Manager and Intune closer together in a the console Microsoft Endpoint Manager admin center (https://endpoint.microsoft.com/). Starting in Configuration Manager version 2002, we can upload Configuration Manager devices to the admin center and start

Continue to read »
Search blog posts
Search
Authors
Modern Workplace consultant and a Microsoft MVP in Enterprise Mobility.

Modern Workplace consultant and a Microsoft MVP in Windows and Devices.

Infrastructure architect with focus on Modern Workplace and Microsoft 365 security.

Cloud & security specialist with focus on Microsoft backend products and cloud technologies.

Cloud & security specialist with focus on Microsoft 365.

Cloud & Security Specialist, with a passion for all things Cybersecurity

Cloud and infrastructure security specialist with background in networking.

Infrastructure architect with focus on design, implementation, migration and consolidation.

Infrastructure consultant with focus on cloud solutions in Office365 and Azure.

Modern workplace and infrastructure architect with a focus on Microsoft 365 and security.

follow us in feedly
Categories
  • Follow on SoMe