---
title: "Microsoft 365 Upcoming \"Secure by Default\" Settings Changes"
description: Microsoft is making changes to their Secure Future Initiative (SFI) and the principle of “Secure by Default.”
image: https://www.daymarksi.com/hubfs/Microsoft_365_logo.png
---

- [MICROSOFT SERVICE OFFERINGS](https://www.daymarksi.com/microsoft-service-offerings)
- [CONTACT](https://www.daymarksi.com/location-for-our-new-england-office-massachusetts)
- [SUPPORT](https://www.daymarksi.com/support)

[![DM_LogoTag_white-20yr](https://www.daymarksi.com/hubfs/brand-assets/DM_LogoTag_white-20yr.png "DM_LogoTag_white-20yr")](https://www.daymarksi.com)

- [About](https://www.daymarksi.com/about-daymark) 
    - [Why Daymark](https://www.daymarksi.com/why-daymark)
    - [Leadership](https://www.daymarksi.com/leadership)
    - [Industry Awards](https://www.daymarksi.com/industry-awards)
    - [Daymark Solutions Charitable Trust](https://www.daymarksi.com/charitable-trust)
    - [Customers](https://www.daymarksi.com/customers)
    - [Testimonials](https://www.daymarksi.com/testimonials)
    - [Technical Certifications](https://www.daymarksi.com/technical-certifications)
    - [Careers](https://www.daymarksi.com/careers)
    - [Locations](https://www.daymarksi.com/location-for-our-new-england-office-massachusetts)
- [Solutions](https://www.daymarksi.com/solutions) 
    - [Cloud Solutions](https://www.daymarksi.com/cloud)
    - [CMMC Compliance](https://www.daymarksi.com/understanding-the-cybersecurity-maturity-model-certification)
    - [Data Center Infrastructure](https://www.daymarksi.com/solutions/data-center-infrastructure-for-storage-networking-compute-security)
    - [Data Protection](https://www.daymarksi.com/solutions/data-protection-backups-recovery-restore)
    - [Networking](https://www.daymarksi.com/solutions/networking-and-security)
    - [Security](https://www.daymarksi.com/solutions/networking-and-security)
    - [Virtualization](https://www.daymarksi.com/solutions/virtualization)
    - [All Technology Partners](https://www.daymarksi.com/partners)
- Cloud 
    - [Microsoft Azure](https://www.daymarksi.com/microsoftazure)
    - [Microsoft Azure Government](https://www.daymarksi.com/protecting-government-data-for-the-defense-industrial-base)
    - [Microsoft 365](https://www.daymarksi.com/microsoft-365)
    - [Copilot for Microsoft 365](https://www.daymarksi.com/copilot-for-microsoft-365)
    - [Microsoft 365 GCC High](https://www.daymarksi.com/microsoft-gcc-high-for-defense-contractors)
    - [Mimecast](https://www.daymarksi.com/cloud)
    - [Okta](https://www.daymarksi.com/cloud)
    - [All Cloud Partners](https://www.daymarksi.com/cloud-partners)
- [Services](https://www.daymarksi.com/services) 
    - [Microsoft Service Offerings](https://www.daymarksi.com/microsoft-service-offerings)
    - [Assessment & Health Checks](https://www.daymarksi.com/services/assessment-and-health-checks)
    - [Cloud Architecture](https://www.daymarksi.com/services/custom-cloud-computing-implementations-and-services-in-new-england)
    - [CMMC Compliance Readiness](https://www.daymarksi.com/understanding-the-cybersecurity-maturity-model-certification)
    - [Contract & Maintenance Management](https://www.daymarksi.com/services/contract-maintenance-management)
    - [Documentation & Knowledge Transfer](https://www.daymarksi.com/services/documentation)
    - [Government Community Cloud](https://www.daymarksi.com/microsoft-gcc-high-for-defense-contractors)
    - [Identity Mangement](https://www.daymarksi.com/microsoft-entra-id-workshop)
    - [Implementations](https://www.daymarksi.com/services/it-project-implementation-on-budget-on-time-on-scope)
    - [Proof of Concepts](https://www.daymarksi.com/services/proof-of-concept-for-information-technology-initiatives)
    - [Solution Architecture](https://www.daymarksi.com/services/it-solution-architecture-for-complex-storage-network-and-computer-solutions)
    - [Staging & Integration](https://www.daymarksi.com/services/staging-and-integration)
- [MyDaymark](https://www.daymarksi.com/mydaymark/) 
    - [Advanced Support](https://www.daymarksi.com/mydaymark/advanced-support)
    - [Premier Support](https://www.daymarksi.com/mydaymark/premier-support)
    - [Managed Services](https://www.daymarksi.com/mydaymark/managed-services)
    - [Management Platform](https://www.daymarksi.com/mydaymark/management-platform)
    - [Security & Compliance](https://www.daymarksi.com/mydaymark/security-compliance)
- Industries 
    - [Energy & Utilities](https://www.daymarksi.com/new-england-it-project-management-and-implementation-for-energy-and-utilities-industry)
    - [Financial Services](https://www.daymarksi.com/new-england-it-project-implementation-for-financial-services-companies)
    - [Defense Industrial Base](https://www.daymarksi.com/protecting-government-data-for-the-defense-industrial-base)
    - [Healthcare](https://www.daymarksi.com/healthcare-information-technology-development-and-implementation)
    - [Life Sciences](https://www.daymarksi.com/new-england-it-initiative-implementation-for-life-sciences-companies)
- [Resources](https://www.daymarksi.com/information-technolocy-resources) 
    - [Case Studies](https://www.daymarksi.com/information-technolocy-resources?types=casestudy)
    - [Data Sheets](https://www.daymarksi.com/information-technolocy-resources?types=datasheet)
    - [Partner Resources](https://www.daymarksi.com/information-technolocy-resources?types=partnerresources)
    - [Workshops](https://www.daymarksi.com/information-technolocy-resources?types=workshop)
- [News & Events](https://www.daymarksi.com/news-events)
- Blog 
    - [Daymark IT Insights](https://www.daymarksi.com/blog)
    - [Cole Tramp's Microsoft Insights](https://www.daymarksi.com/blog/topic/cole-tramps-microsoft-insights)

![banner-why-daymark.jpg](https://www.daymarksi.com/hs-fs/hub/30865/file-2671640025-jpg/2015_Images/Banner_Images/banner-why-daymark.jpg?width=1400&name=banner-why-daymark.jpg "banner-why-daymark.jpg")

##### **Daymark IT Insights**

Enterprise IT, cloud, security, and AI guidance from Daymark’s technology experts.

# [Microsoft 365 Upcoming "Secure by Default" Settings Changes](https://www.daymarksi.com/blog/microsoft-365-upcoming-secure-by-default-settings-changes)

Posted by [Blake Bernard](https://www.daymarksi.com/blog/author/blake-bernard)

 Wed, Jul 02, 2025

- [Tweet](https://twitter.com/share)

![Microsoft_365_logo](https://www.daymarksi.com/hs-fs/hubfs/Microsoft_365_logo.png?width=1871&height=308&name=Microsoft_365_logo.png)

Microsoft is making changes to their Secure Future Initiative (SFI) and the principle of “Secure by Default.” The updates to Microsoft 365 default settings will strengthen your tenant’s security and meet essential benchmarks. These changes focus on addressing vulnerabilities associated with outdated authentication protocols and app access permissions that could increase risks to organizations.

**When this will happen:**

These changes will begin rolling out in mid-July 2025 and are expected to be completed by **August 2025**.

**How this affects your organization**

The following settings will be updated:

| **Settings** | **Impact** |
| --- | --- |
| **Block legacy browser authentication to SharePoint and OneDrive using RPS (Relying Party Suite)** | Legacy authentication protocols like RPS (Relying Party Suite) are vulnerable to brute-force and phishing attacks due to non-modern authentication. Blocking this prevents applications that use outdated methods from accessing SharePoint and OneDrive via browser. To use PowerShell to block legacy browser authentication, see [Set-SPOTenant](https://go.microsoft.com/fwlink/p/?linkid=2324508). |
| **Block FPRPC (FrontPage Remote Procedure Call) protocol for Office file opens** | FrontPage Remote Procedure Call (FPRPC) is a legacy protocol used for remote web page authoring. While no longer widely used, legacy protocols such as FPRPC can be more susceptible to compromise, and blocking FPRPC helps reduce exposure to vulnerabilities. With this change, FPRPC will be blocked from opening files, preventing the use of this non-modern protocol in Microsoft 365 clients. To learn how to block the FPRPC protocol, see [turn on web content filtering](https://go.microsoft.com/fwlink/p/?linkid=2324509). |
| **Require admin consent for third-party app access to files and sites** | Users allowing third-party apps to access file and site content can lead to overexposure of an organization’s content. Requiring admins to consent to this access can help reduce overexposure. With this change, Microsoft-managed [App Consent Policies](https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/manage-app-consent-policies) will be enabled, and users will be unable to consent to third-party applications accessing their files and sites by default. Instead, they can request administrators to consent on their behalf. To configure admin consent, follow instructions here: [Configuring the Admin Consent Workflow](https://go.microsoft.com/fwlink/p/?linkid=2324703). Customers who have already blocked user consent, turned on our previously recommended consent settings, or applied custom user consent settings, will not be affected by this change. Admins can also configure granular app access policies, such as limiting user access to the application for specific users or groups. Learn more [here](https://aka.ms/entra-app-access). |

These changes are on by default and apply to all Microsoft 365 tenants. No additional licensing is required.

**What you can do to prepare:**

Microsoft recommends the following actions:

- **Assess current configurations:** As applicable, identify current configurations for [RPS ](https://learn.microsoft.com/en-us/powershell/module/sharepoint-online/set-spotenant?view=sharepoint-ps#-legacybrowserauthprotocolsenabled)or [FPRPC](https://learn.microsoft.com/powershell/module/sharepoint-online/set-spotenant?view=sharepoint-ps) protocols.
- **Notify stakeholders: **Inform IT admins, app owners, and security teams about the upcoming changes.
- **Update documentation: **Ensure internal guidance reflects the new defaults and admin consent process.
- **Configure Admin Consent workflow:** If third party app access is applicable for your organization, learn how to set up the workflow: [Configuring admin consent workflow.](https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/configure-admin-consent-workflow)

Additional considerations

- Does the change alter how existing customer data is processed, stored, or accessed? Yes — it blocks access to content via legacy authentication protocols.

**How Daymark Can Help**

Security settings are a top priority for all organizations. If you’d like guidance on making the right changes, please [reach out](https://www.daymarksi.com/location-for-our-new-england-office-massachusetts). Daymark Microsoft consultants are happy to help.

### Subscribe to Daymark Insights

### Latest Posts

### Browse by Tag

- [Microsoft (88)](https://www.daymarksi.com/blog/topic/microsoft)
- [Cloud (70)](https://www.daymarksi.com/blog/topic/cloud)
- [Cole Tramp's Microsoft Insights (58)](https://www.daymarksi.com/blog/topic/cole-tramps-microsoft-insights)
- [Azure (55)](https://www.daymarksi.com/blog/topic/azure)
- [Security (49)](https://www.daymarksi.com/blog/topic/security)
- [Data Protection (43)](https://www.daymarksi.com/blog/topic/data-protection)
- [Microsoft Fabric (41)](https://www.daymarksi.com/blog/topic/microsoft-fabric)
- [Data Governance (38)](https://www.daymarksi.com/blog/topic/data-governance)
- [AI (35)](https://www.daymarksi.com/blog/topic/ai)
- [Partners (33)](https://www.daymarksi.com/blog/topic/partners)
- [Compliance (31)](https://www.daymarksi.com/blog/topic/compliance)
- [Data Center (30)](https://www.daymarksi.com/blog/topic/data-center)
- [CMMC (27)](https://www.daymarksi.com/blog/topic/cmmc)
- [Backup (26)](https://www.daymarksi.com/blog/topic/backup)
- [Daymark News (23)](https://www.daymarksi.com/blog/topic/daymark-news)
- [Storage (22)](https://www.daymarksi.com/blog/topic/storage)
- [GCC High (19)](https://www.daymarksi.com/blog/topic/gcc-high)
- [Veritas (18)](https://www.daymarksi.com/blog/topic/veritas)
- [Virtualization (18)](https://www.daymarksi.com/blog/topic/virtualization)
- [Cybersecurity (17)](https://www.daymarksi.com/blog/topic/cybersecurity)
- [Azure AI Foundry (16)](https://www.daymarksi.com/blog/topic/azure-ai-foundry)
- [Featured Gov (16)](https://www.daymarksi.com/blog/topic/featured-gov)
- [Government Cloud (16)](https://www.daymarksi.com/blog/topic/government-cloud)
- [Disaster Recovery (15)](https://www.daymarksi.com/blog/topic/disaster-recovery)
- [Cloud Backup (14)](https://www.daymarksi.com/blog/topic/cloud-backup)
- [Managed Services (13)](https://www.daymarksi.com/blog/topic/managed-services)
- [Copilot (11)](https://www.daymarksi.com/blog/topic/copilot)
- [Industry Expertise (9)](https://www.daymarksi.com/blog/topic/industry-expertise)
- [NIST SP 800-171 (7)](https://www.daymarksi.com/blog/topic/nist-sp-800-171)
- [Hybrid Cloud (6)](https://www.daymarksi.com/blog/topic/hybrid-cloud)
- [Networking (6)](https://www.daymarksi.com/blog/topic/networking)
- [Power BI (6)](https://www.daymarksi.com/blog/topic/power-bi)
- [Pure Storage (4)](https://www.daymarksi.com/blog/topic/pure-storage)
- [Reporting (3)](https://www.daymarksi.com/blog/topic/reporting)
- [Services (3)](https://www.daymarksi.com/blog/topic/services)
- [AI for Defense (2)](https://www.daymarksi.com/blog/topic/ai-for-defense)
- [Cloud Security (2)](https://www.daymarksi.com/blog/topic/cloud-security)
- [Everpure (2)](https://www.daymarksi.com/blog/topic/everpure)
- [GDPR (2)](https://www.daymarksi.com/blog/topic/gdpr)
- [Microsoft Purview (2)](https://www.daymarksi.com/blog/topic/microsoft-purview)
- [Apple (1)](https://www.daymarksi.com/blog/topic/apple)
- [CMMC 2.0 Requirements (1)](https://www.daymarksi.com/blog/topic/cmmc-2-0-requirements)
- [FedRamp AI (1)](https://www.daymarksi.com/blog/topic/fedramp-ai)
- [Mobile (1)](https://www.daymarksi.com/blog/topic/mobile)
- [Power Automate (1)](https://www.daymarksi.com/blog/topic/power-automate)

[see all](https://www.daymarksi.com/blog/microsoft-365-upcoming-secure-by-default-settings-changes#)

### How Can We Help?  [![Speak With An Expert](https://no-cache.hubspot.com/cta/default/30865/5de282fd-640c-49b2-bf45-603dbee66842.png)](https://cta-redirect.hubspot.com/cta/redirect/30865/5de282fd-640c-49b2-bf45-603dbee66842)

#### About

Daymark Solutions is an experienced technology integration and solutions provider that helps organizations effectively architect, implement, and deploy customized solutions to help their customers grow and scale their IT infrastructure. Specializing in AI, cloud and modern data center solutions, Daymark’s unique combination of in-depth technical knowledge, extensive experience, and proven methodologies enable its customers to successfully address even the most difficult technology challenges.

#### Connect

<https://twitter.com/daymarksi>     <https://twitter.com/daymarksi><https://www.linkedin.com/company/daymark-solutions-inc./>

#### Links

- [About](https://www.daymarksi.com/about-daymark)
- [Industry Expertise](https://www.daymarksi.com/industry-experience-in-finance-healthcare-energy-utilities-and-life-sciences)
- [Solutions](https://www.daymarksi.com/solutions)
- [Services](https://www.daymarksi.com/services)
- [Cloud](https://www.daymarksi.com/services/custom-cloud-computing-implementations-and-services-in-new-england)
- [Resources](https://www.daymarksi.com/whitepapers-videos-analyst-reports-and-case-studies-on-information-technologies)
- [News & Events](https://www.daymarksi.com/news-events)
- [Blog](https://www.daymarksi.com/blog)

#### Contact

**Corporate Headquarters**  
Daymark Solutions  
131 Middlesex Turnpike  
Burlington, MA 01803

**Corporate:** [+1 781-359-3000](tel:17813593000)

**Email:** [info@daymarksi.com](mailto:info@daymarksi.com)

![DM_LogoTag_white.png](https://www.daymarksi.com/hs-fs/hubfs/Daymarksi-2017/Image/DM_LogoTag_white.png?width=176&name=DM_LogoTag_white.png "DM_LogoTag_white.png")

© 2026 Daymark Solutions, Inc. All rights reserved.  |  [Daymark Privacy Policy](https://www.daymarksi.com/hubfs/Daymark%20-%20Privacy%20Policy.pdf)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Blake Bernard",
    "url" : "https://www.daymarksi.com/blog/author/blake-bernard"
  },
  "dateModified" : "2025-07-02T12:54:36.186Z",
  "datePublished" : "2025-07-02T12:54:36.000Z",
  "headline" : "Microsoft 365 Upcoming \"Secure by Default\" Settings Changes",
  "image" : [ "https://www.daymarksi.com/hubfs/Microsoft_365_logo.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.daymarksi.com/blog/microsoft-365-upcoming-secure-by-default-settings-changes",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.daymarksi.com/hubfs/v2/images/daymark-logo.png"
    },
    "name" : "Daymark Solutions, Inc."
  }
}
```