M365 Weekly Newsletter
Issue #219
☁️Productivity & Modern Workplace
Have you maybe noticed that OneDrive can suddenly go into read-only mode?
There was a loophole Microsoft fixed recently.
A partner called me recently, panicked. He had a user’s OneDrive stuck in read-only, obviously over quota, on a Business Standard license.
I asked how much storage the guy had. 2 TB, he said.
It didn’t compute. Business Standard tops out at 1 TB unless you’re shelling out extra for more space, and that extra costs a small fortune.
I pushed back. Told him straight up it wasn’t possible.
Turns out I was wrong about one thing. It was possible.
It just wasn’t supposed to be.
The culprit? Microsoft’s Universe of Inconsistencies.
Some admin, years back, manually cranked that user’s OneDrive quota past what the license allowed. The system let it ride. Nothing flagged the mismatch. The extra room just sat there, working fine, for years.
And now Microsoft has closed this loophole in their MC1310684.
Microsoft published MC1310684 in the admin Message Center to fix all this. Applied OneDrive quotas that drift above their license entitlement are now pulled back in line.
Lesson 1 learned: chasing workarounds bites you later. I’ve done this myself. Found a setting nobody’s supposed to touch, used it because it worked, told myself it was fine since nothing broke. Early in my career, I leaned on more than one of these. They held for years, long enough that I half forgot they weren’t supposed to work in the first place. The client just inherited a workaround some admin left behind long before he ever showed up.
Lesson 2 learned: Read the Message Center. MC1310684 didn’t drop out of nowhere. It sat in the Message Center from May 16, well before it hit anyone’s tenant. But who am I kidding? It’s the torrent of those messages that makes reading them all nearly impossible.
Workarounds aren’t free. Somewhere down the line, Microsoft closes the gap you were leaning on, and you get hit from a direction you never saw coming.
Have a nice rest of the week,
Matic
☁️Security & Data Governance
3 steps to take before Microsoft kills SMS and voice MFA.
On July 13, 2026, Microsoft announced Entra ID is retiring SMS and voice authentication, with passkeys becoming the default. After February 1, 2027, Entra ID stops providing SMS codes or voice calls for MFA entirely. You can still get them, but only by paying a telecom provider directly.
The clock starts earlier than that. Starting September 1, 2026, Microsoft auto-enables passkeys for every user still on SMS or voice, and nudges them to register one. Nobody gets locked out that day. But do nothing before February, and any user whose only MFA method is SMS or voice hits a blocking prompt they can’t skip.
Here’s what to do, in order.
1. Find out who’s still on SMS or voice.
Entra admin center → Authentication methods → Monitoring → User registration details. That report shows your real exposure. Do this first, everything else depends on it.
2. Decide if you want Microsoft auto-enrolling those users on September 1.
By default, you don’t get a say. If you need more time, a temporary opt-out covers September 1, 2026 through February 1, 2027. It buys you some time, but not past February.
3. Move everyone off SMS and voice before February 1, 2027.
After that date, SMS and voice from Microsoft stop working. Organizations wishing to continue SMS or voice MFA must configure a customer-managed telecom provider.
Run the inventory this week. You’ll either find you’re clear, or find out exactly how much runway you have before September.
☁️Copilot & AI
How I’d Roll Out AI in Any Business (Exact 4-Stage Framework). Most AI rollouts stall because companies chase a massive project before proving anything works. Nick’s four-stage framework – land, ground, build, connect – fixes shadow AI and unclear ROI by starting small: govern individual tools first, then connect data, automate departments, and scale across the business.
☁️Sysadmin Stuff
Configuring Remote Help – A New Feature Of Your M365 E3 & E5 Licence. Setting up Remote Help in Intune takes seconds, but a few things catch people off guard. Watch for a phantom trial licence warning even on fully licensed tenants, get RBAC roles right for your helpdesk, and register the RemoteAssistantService if you want a dedicated Conditional Access rule.
☁️Security & Data Governance
Unified RBAC becomes the default in Microsoft Defender. Unified RBAC replaces four separate permission systems with one role model covering Endpoint, Microsoft 365, Identity, Sentinel and more. If your tenant still runs legacy RBAC, this switches automatically between late September and December 2026, with a 30-day warning banner first. Check role assignments before it lands on you.
How I Clean Up Years of SharePoint Sprawl. Old SharePoint sites don’t just sit there quietly. They eat storage, keep outdated permissions alive, and can feed stale content straight into Copilot’s answers. This walks through using Site Lifecycle Management to flag, confirm, and archive dead sites, plus why read-only alone won’t keep them out of AI search results.
☁️Noteworthy (long)reads
Is Microsoft preparing license enforcement for Entra ID? Microsoft just added a licensing overage warning to your Conditional Access overview page, comparing P1 and P2 entitlements against actual usage. It’s not enforcement yet, but the visibility signals where things are heading. Check your license usage now, before a warning becomes something more forceful.
☁️On a Less Serious Note

☁️ We value your feedback!
How much are you enjoying this issue? Please give us your feedback so we can improve.
If you have any suggestions, just reply and leave us your message.
☁️ Last but not least …
Here are a few things you can do if you enjoyed reading this newsletter:
- Become a subscriber: m365 Weekly Newsletter Subscribe
- Explore past issues: m365 Weekly Newsletter Archive.
- Get in touch / Share cool M365 or other stuff: matic@m365weekly.com

