The three built-in quarantine policies differ on exactly two settings, and one of them is a silent ticket generator sitting in every tenant by default. Here’s the decision map, the override that ignores your permissions, and the PowerShell to audit it.
On September 1, 2026, Microsoft auto-enables passkeys and flips your registration campaign to Microsoft-managed. There is a tenant-level opt-out — passkeyDynamicMigration — that delays it. Here’s what it actually buys you, why setting it safely needed a script rather than a one-line PATCH, and why February 1, 2027 is the date that can’t be postponed.
Microsoft is making passkeys the default sign-in and retiring native SMS and voice MFA. MC1426371 sets the clock: passkeys auto-enable September 1, 2026, and Microsoft-provided telecom delivery ends February 1, 2027. Here’s what changes on its own, what quietly changes underneath you, and the two decisions every MSP has to make before the dates arrive.
Most MSPs patch Windows through their RMM — detect, push, force a reboot. Intune’s hotpatch does the same monthly security work in-memory, no reboot, honoring your rings. Here’s the case for moving Windows quality updates off the RMM and onto the platform built for them.
Disabling Chrome’s built-in password manager through Intune’s settings catalog takes about a minute. Understanding what it actually does — and the two ways it quietly doesn’t do what people assume — is the part that saves you a ticket later.
Zeno’s Paradox says you should never cross the room. Defenders have always felt that way. A new class of AI might finally change the math.
I went into the SC-900 confident. Working at an MSP, I use Entra and Defender every day. What I didn’t expect was how much the exam would reveal about the edges of what I actually knew.
A walkthrough of configuring a Conditional Access Policy in Microsoft Entra to require compliant devices when accessing sensitive data via Authentication Context.