#WeekITtip

dmstorkdmstork
2025-08-29

The biggest gain is achieved by changing your default domain and checking existing objects. In addition, the default DKIM signing domain is often the MOERA domain. Take a moment to properly configure each custom domain as well, enhancing .

Read more here for a more detailed explanation and how to monitor the use of MOERA domains: techcommunity.microsoft.com/bl

dmstorkdmstork
2025-08-29

Last week announced an important change throttling Online outbound mail using *.onmicrosoft.com, or MOERA (Microsoft Online Exchange Routing Address). This is done to limit malicious\unsolicited mails from trail tenants, which is indeed a problem.

The impact for organizations using custom domains is limited. However, orgs might not be aware that some non-user objects use MOERA domains per default (i.e. Booking app, notifications etc.).

dmstorkdmstork
2025-08-13

In any case, if you still have or use Lens: time to look for alternatives that suit your needs. I think there are better options than the M365 Copilot, for me native iPhone is adequate. Especially with OCR built-in.

Read more here: mc.merill.net/message/MC1131064
Admin M365 MC: admin.microsoft.com/ref=Messag

dmstorkdmstork
2025-08-13

It makes me sad as a was a avid user during conferences to get photos of projected slides unskewed and suitable for social media. To be fair, I haven't used Lens probably since 2019, the last year I went to a lot of conferences. After that a lot of hybrid conferences and (pre-)shared slidedecks limited the need for photos or live tweeting for that matter.

dmstorkdmstork
2025-08-13

This Message Center hurt a little: Microsoft Lens app will retire. Starting this September in phases and concluding on 15 December 2025. The replacement app is the Microsoft365 Copilot app, although it certainly does not have feature parity with Lens.

Screenshot of Message Center ID MC1123830. Title: Microsoft Lens app will retire
Summary:
Microsoft Lens mobile app will retire starting September 15, 2025, with new installs disabled by mid-October and removal by mid-November. After December 15, 2025, new scans can't be created. Users should switch to Microsoft 365 Copilot app for scanning; no admin action is required.
dmstorkdmstork
2025-08-08

If you are responsible for your orgs mail infrastructure, definitely read this post and evaluate the impact of disabling Direct Send: techcommunity.microsoft.com/bl

dmstorkdmstork
2025-08-08

Direct Send is defined as your organization sending mail to Online using a sender domain that is an accepted domain AND which is not send via any authentication (user or via Connectors). In some cases you might require this functionality, however this obviously can open your organization up to receive spoofed mails. Those should be filtered, but depending on the complexity the ability to disable Direct Send is a welcome option.

dmstorkdmstork
2025-08-08

Recently the product group posted an article on disabling Direct Send and after feedback reposted it with some additional clarifications because there were some misconceptions on the definition. I have had similar discussions with organizations. It depends on your configuration what the impact might be, but IMHO it is a welcome option to reduce your attack surface but you obviously need to understand it correctly.

dmstorkdmstork
2025-07-28

Spent some useful time digging into an IETF regarding Certificate Authority Authorization or (RFC6844 rfc-editor.org/rfc/rfc6844 ) *and* checking security guidelines on the use of specific cipher suites because the Dutch National Cyber Security Center () recently released new TLS guidelines. ncsc.nl/wat-kun-je-zelf-doen/d

is never dull 😀

Logo of the Dutch Government (Rijksoverheid), depicting a small crown in the middle above a shield with a lion holding a sword and two bigger lions facing the shield. White on a blue background, surrounded by a maroon color.
dmstorkdmstork
2025-01-17

Reading for the weekend. I am currently involved in a case in which mail (auto)forwarding is used but that is causing the forwarded mail to be rejected. When , and are implemented properly, this can break legitimate mail forwarding.

dmstorkdmstork
2024-08-23

So, I've started a new blog site. Consider this a soft launch, I still need to quite a lot of customizations. But I wanted to get this out in the world. I'll probably post a lot about and related topics. Bookmark davestork.nl !

Bing Image Creator with prompt: create me an image of me writing blog posts behind a computer. Make it a cartoon style
dmstorkdmstork
2024-07-30

PSA: There seem to be networking issues in the in North & West-Europe region. It's affecting and services. See for status:
azure.microsoft.com/en-us/stat and MO842351 in the M365 Admin portal.

dmstorkdmstork
2024-05-22

And with every big event such as , there is a Book of News or that summarizes the biggest announcements which aren't only for developers. Ideal if you don't have the time to attend any sessions. You can find it here: news.microsoft.com/build-2024-

dmstorkdmstork
2024-05-16

In this week's I share my thoughts about why I am excited about and its Public Preview. Read more on my profile page linkedin.com/in/dmstork/

Created with Bing Image Creator with the prompt: "create an cartoon image where you see a lot of meeting rooms and business people running around, angry, frustrated in and out of those rooms". Alas, no separate rooms, but generally what I wanted
dmstorkdmstork
2024-05-08

Well, I can now finally talk about the near future of as just published their product roadmap for Server! And Exchange Server "vNext" now has a name: Exchange Server Subscription Edition or SE.
Read more details here: techcommunity.microsoft.com/t5

I talk a bit more in-depth about Subscription Edition on my profile page: linkedin.com/in/dmstork/

Cartoon generated by Bing Image Creator with the prompt: "depict a very happy and outrageously celebrating exchange administrator carrying a new Exchange Server surrounded by several subscriptions"
dmstorkdmstork
2024-03-06

Sending a mail you shouldn't have sent or used the Reply-All button by mistake.. It happens to the best of us. Yes, that includes me 🤫. Read my post on on a feature you might have missed! Check linkedin.com/in/dmstork/ and tags

Screenshot of the Exchange Online Message Recall Status Report webpage with relevant information on the recall: sender, recipients, subject, recall submitter, recall state including if it was read.
dmstorkdmstork
2024-01-26

New year, new (with a bit of a delay)!

Did you know Google and Yahoo are going to be stricter with unauthenticated mails from 1 februari?

Google: blog.google/products/gmail/gma
Yahoo: senders.yahooinc.com/best-prac

Especially tend to 3rd-party services you might use. In recent days I've seen a lot of requests to implement DNS changes. Sadly, often the bare minimum.

So, again a little help on the fundamentals of mail authentication: youtube.com/watch?v=gc58wubizx

dmstorkdmstork
2023-12-06

Hey, instead of doing a weekly I'm currently doing an tip every day until Christmass! I'm posting those on . Today's tip is about Outlook COM going away in favor of web add-ins. Check out: linkedin.com/in/dmstork/recent

Created via Bing Image Creator: Cartoon of middle aged glasses wearing white male in blue business casual playing with Christmass ornaments in front of a cabin sized Advent Calender

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst