365 Multi-Tenant Manager Release on October 20th, 2025

Enhancements

The following new predefined policies have been introduced in the predefined policies library:

  • HS-P0051 – Block Adobe Flash activation in Microsoft Office Applications
    • Blocks any Adobe Flash content from running inside Microsoft Office apps on Windows devices.
  • HS-P0052 – Ensure data execution prevention for Windows Explorer is disabled
    • Disables Data Execution Prevention for Windows Explorer which allows certain legacy plugins to function without causing Explorer to terminate on Windows devices.
  • HS-P0053 – Ensure that sending unencrypted password to third-party SMB servers is disabled
    • Disables Windows clients from transmitting plaintext passwords to third-party Server Message Block (SMB) servers.
  • HS-P0054 – Disable anonymous enumeration of shares
    • Blocks unauthenticated users from enumerating Security Account Manager (SAM) accounts and shared folders.
  • HS-P0055 – Ensure macOS Firewall is enabled
    • Enables the firewall in macOS, which filters inbound network traffic and prevents unwanted incoming connections.
  • HS-P0056 – Disable IP source routing
    • Disables IP source routing for IPv4 and IPv6 on Windows devices, which helps prevent packet spoofing
  • HS-P0057 – Disable running or installing downloaded software with invalid signature on Windows devices
    • Prevents the installation or execution of software in Internet Explorer with an invalid digital signature, applying to both device and user scopes.
  • HS-P0058 – Ensure additional authentication is enforced on startup for Windows devices
    • Enforces BitLocker to require additional authentication at startup (using TPM, PIN, or key). This setting applies only if BitLocker drive encryption is enabled on the device
  • HS-P0059 – macOS Antivirus Policy
    • Configures Microsoft Defender Antivirus for macOS to enable real-time protection, automatic sample submission, tamper protection, and strict enforcement settings, ensuring continuous antivirus protection on managed Mac devices.
  • HS-P0060 – macOS Password Security Policy
    • Enforces secure access to macOS devices by requiring a strong password with a minimum of 15 characters, a maximum password age of 90 days, prevention of reuse of the last 24 passwords, and account lockout after 5 failed attempts.

Check other releases