Event details
Have a question about Windows 11, device management, security, updates, or modern endpoint operations? This hour is dedicated entirely to your questions. Bring what's top of mind—from Windows 11 adoption and application compatibility to update management, cloud-native administration, Zero Trust, Intune, Windows 365, and hybrid environments.
Drop your questions in the comments and hear directly from Microsoft experts. Whether you're planning your next rollout, troubleshooting a management challenge, evaluating new capabilities, or looking for best practices, this is your opportunity to get answers and learn from the questions other IT admins are asking right now.
This is part of our continuing series of live Q&A for IT professionals here on Tech Community. Follow the Windows Office Hours to add future dates to your calendar.
How does it work?
We will have a broad group of product experts, servicing experts, and engineers representing Windows, Microsoft Intune, Configuration Manager, Windows 365, Windows Autopilot, security, and more. They will be standing by here -- in chat -- to provide guidance, discuss strategies and tactics, and, of course, answer any specific questions you may have.
Post your questions in the Comments early and throughout the one-hour event.
Note: This is a chat-based event. There is no video or live meeting component. Questions and answers will appear in the Comments section below.
1 Comment
- stdcsbBrass Contributor
Unanswered question from September 17th:
We are seeing an increasing number of vulnerability findings in Microsoft applications where the application itself appears current, but a bundled third-party security library remains vulnerable.
As a specific example, Microsoft Defender Vulnerability Management is reporting that Microsoft OneDrive version 26.153.0809.0004 contains OpenSSL 3.4.5. At the time of assessment, OpenSSL 3.4.6 had been available since 9 June 2026 and OpenSSL 3.4.7 since 25 August 2026, meaning OneDrive appears to have missed at least one complete OpenSSL security release cycle and remained on a vulnerable OpenSSL version for more than three months after a fixed upstream release became available.
From an enterprise vulnerability management perspective, this raises several questions:
- What is Microsoft's expected servicing timeframe for critical third-party components embedded within Microsoft applications such as OneDrive?
- When a current Microsoft application is flagged by Microsoft Defender Vulnerability Management due to a vulnerable bundled library, should customers treat that vulnerability as a remediation requirement, or as a risk that must be accepted until Microsoft republishes the application?
- Is there a documented service level objective, target timeframe, or best-practice guidance for how quickly Microsoft applications should incorporate upstream security fixes for bundled libraries such as OpenSSL?
- What is Microsoft's recommended course of action when no newer Microsoft-published version is available but vulnerability scanners continue to report critical or high-severity findings within Microsoft-managed software?
We are looking for guidance on how enterprise security teams should assess, report, and respond to these findings, particularly when the vulnerable component is embedded within a Microsoft application and remediation is wholly dependent on Microsoft's release process.