compliance
976 TopicsSecurity Review for Microsoft Edge version 152
We have reviewed the new settings in Microsoft Edge version 152 and determined that there are no additional security settings that require enforcement. The Microsoft Edge version 151 security baseline continues to be our recommended configuration which can be downloaded from the Microsoft Security Compliance Toolkit. Microsoft Edge version 152 introduced 4 new Computer and User settings; we have included a spreadsheet listing the new settings to make it easier for you to find. Starting with version 152 Microsoft Edge is moving to a more frequent release cycle. To better align with the needs of the enterprise customers, the Microsoft Edge security baseline is expected to align with the Extended Stable Channel, which provides major feature updates on an eight-week cadence while continuing to receive security and quality updates between releases. This approach provides organizations with additional time to evaluate and deploy feature changes while ensuring security protections remain current. Why the change? Security baselines are intended to provide guidance for managing security relevant configuration settings, not to track every feature introduced in a browser release. With the move to a two-week release cadence, publishing baseline updates for every release would increase operational overhead while providing limited security benefit. The Extended Stable cadence offers a more practical balance for enterprise customers by allowing additional time for testing and evaluation, while continuing to receive security and critical fixes between major feature releases. By aligning with Extended Stable, we can update the baselines less frequently and focus on publishing them earlier in the release cycle, giving IT administrators more time to review and plan for upcoming changes. Our goal is to make security baseline adoption more predictable and easier to manage while continuing to provide timely security guidance. As a friendly reminder, all available settings for Microsoft Edge are documented here, and all available settings for Microsoft Edge Update are documented here. Please continue to give us feedback through the Security Baselines Discussion site or this post.1.2KViews0likes2CommentsHow to properly redact a PDF?
I need to share a PDF that contains names, email addresses, and other confidential details that must be removed first. Simply placing black boxes over the text does not seem secure, since the original content may still be searchable, selectable, or recoverable, so I need a way to permanently redact a PDF. Because the document contains sensitive information, I would prefer not to upload it to an online tool. I’m looking for either a built-in option or professional third-party desktop software that can permanently redact both text and images while processing the file locally. It would also be useful to remove hidden information from a PDF before sharing, including comments, document metadata, and any other embedded details. What is the safest way to handle this, and how can I verify that a PDF is properly redacted before I send it?326Views0likes5CommentsSecurity baseline for Microsoft Edge version 151
We are pleased to announce the enterprise-ready release of the security baseline for Microsoft Edge version 151! We have reviewed the settings in Microsoft Edge version 151 and updated our guidance with six new recommendations. We have also identified one additional setting that organizations should consider evaluating in their environments. A new Microsoft Edge security baseline package was just released to the Download Center. You can download the new package from the Security Compliance Toolkit. Enable Process Isolation (added) We are enforcing ‘Enable Process Isolation’ to help protect Microsoft Edge from unauthorized access, modification, and tampering by other applications running on the device. This setting strengthens browser process integrity and helps safeguard sensitive data used by Microsoft Edge. Organizations that encounter compatibility issues with software that depends on browser process injection should treat such configurations as exceptions requiring explicit risk acceptance and compatibility validation. Enable renderer in app container (added) We are enforcing the default and enabling ‘Enable renderer in app container’ to strengthen Microsoft Edge’s browser isolation protections by ensuring renderer processes run within the additional restrictions provided by AppContainer. This helps reduce the impact of browser-based attacks and limits the ability of exploited renderer processes to interact with system resources. Organizations that require this setting to be disabled due to incompatible software should treat such configurations as exceptions that require explicit risk acceptance. Enable the network service sandbox (added) We are enforcing the default and enabling ‘Enable the network service sandbox’ to ensure Microsoft Edge network-facing processes operate within sandbox isolation boundaries that help reduce the impact of exploitation and limit access to system resources. Because disabling the network service sandbox weakens a core browser security protection, organizations should treat any requirement to disable this setting as an exception scenario requiring explicit risk acceptance and compatibility validation. Configure browser process code integrity guard (added) We are enabling ‘Configure browser process code integrity guard setting’ with a value of ‘Enable code integrity guard enforcement in the browser process’. The setting strengthens protections against unauthorized code injection into Microsoft Edge browser processes. Some enterprise applications, extensions, accessibility tools, or security products may still rely on legacy injection techniques and require compatibility validation. We encourage organizations to fully test this setting in their environments and work with vendors to identify or remediate incompatible software. Enable Application Bound Encryption (added) We are enabling ‘Enable Application Bound Encryption’ to strengthen protections for browser-stored credentials, authentication tokens, and other sensitive data by binding encryption more closely to the browser process. This helps reduce the risk of unauthorized access to protected browser data by malware or other untrusted software. Because disabling this setting weakens an important protection boundary, organizations should treat any requirement to disable the feature as an exception requiring explicit risk review. Enhance the security state in Microsoft Edge (added) We are enabling ‘Enhance the security state in Microsoft Edge’ and configuring the setting to Balanced to provide additional protection against modern web-based attacks while maintaining compatibility for most enterprise users. In Balanced mode, Microsoft Edge applies additional mitigations such as disabling just-in-time (JIT) JavaScript compilation and enabling added operating system protections on processes used to load sites that users do not frequently visit, helping reduce the risk of memory-related vulnerabilities. Because these protections can introduce compatibility issues for some applications or workflows, organizations should validate critical business sites and applications during their normal testing process prior to broad deployment and configure exceptions as needed. Additional details can be found here. Configure Automatic HTTPS (worth considering) We previously released a blog discussing a new feature called Automatic HTTPS. This setting can automatically switch your connections to websites from HTTP to HTTPS on sites that are highly likely to support the more secure protocol. This option helps ensure that users' network traffic is more secure and less susceptible to SSL stripping attacks. The best part, the end user doesn’t get prompted, it just works! This new feature has two configuration options: Navigations delivered over HTTP are switched to HTTPS’ (UpgradeCapableDomains) and ‘All navigation delivered over HTTP are switched to HTTPS’ (AlwaysUpgrade). There are trade-offs for each configuration: the UpgradeCapableDomains option only upgrades to HTTPS if Microsoft believes the site is likely to work over HTTPS, and this setting is unavailable if you’ve disabled the ComponentUpdatesEnabled policy. The more secure AlwaysUpgrade option unconditionally updates all HTTP requests to HTTPS, which will result in a user-visible error page if the target site does not support HTTPS. We encourage organizations to consider implementing and testing Automatic HTTPS within their environment. Collectively, these changes continue our focus on strengthening browser isolation, sandboxing, process integrity, and protection of sensitive browser data while balancing enterprise compatibility requirements. Microsoft Edge version 151 introduced 4 new computer and user settings. We have included a spreadsheet listing the new settings in the release to make it easier for you to find them. As a friendly reminder, all available settings for Microsoft Edge are documented here, and all available settings for Microsoft Edge Update are documented here. Please continue to give us feedback through the Security Baseline Community or in comments on this post.1.4KViews0likes6CommentsURGENT: Blocked from Partner Center Enrollment ("Runs on trust") - Support portals inaccessible
Hello Microsoft Partner Community Team, I am urgently seeking assistance with an automated enrollment block. We are trying to register our business, Connect In Cloud Ltd (UK Companies House: 09550508), for the Microsoft AI Cloud Partner Program, but we have triggered the "Microsoft runs on trust" security block. I am completely unable to raise a standard support ticket because my Partner Center dashboard shows no active workspaces, meaning the support form will not allow me to submit a request. Furthermore, the standard business phone support lines drop the call after instructing me to use the broken portal. I need a moderator to please escalate this directly to the Vetting and Enrollment team so I can provide my business documentation, verify my identity, and have this block cleared. Here are my exact error details from the blocked screen: Error: Microsoft runs on trust... your request was blocked. Reference Number: 715-123160 Transaction ID: 4b89b272-50fe-4f37-8f5f-15f539cbaed0 Correlation ID: f13ebdd3-5d9d-4b45-a31d-0049e3489a11 Thank you in advance for your help in getting an internal support ticket opened for us706Views1like20CommentsMAICPP identity verification stuck "In Progress" — no Resolve action, ticket unanswered 2 weeks
Our Microsoft AI Cloud Partner Program enrollment (İNFRASPRO BİLGİ TEKNOLOJİLERİ TİCARET LİMİTED ŞİRKETİ) has been stuck since 25 Aug 2026. Verification Summary shows Contact = Verified, Identity = In Progress, Business = In Progress (Microsoft Action). The "Action required" banner persists on Legal Info, and clicking "go here" only opens the Verification Summary page — no "Resolve/Start" or "Get verified here" action ever renders under Identity verification for the primary contact (mailto:email address removed for privacy reasons), who holds Global Admin + Compliance Admin. There is no self-service path to obtain or present a verified credential. Support ticket TrackingID#2609020040003471 has gone unanswered for over a week. Requesting a Community Manager to escalate this to the Partner Vetting / Trust & Safety team for manual review and re-issuance of the identity vetting request. I can share Tenant ID, Partner ID, and entity details via DM.Hardware enrollment blocked — requesting manual review
Hello Microsoft Partner Compliance / Verification team, We are a legitimate and established software development company incorporated in the Qatar Financial Centre (QFC) in September 2022. We hold a valid software development license and operate as a real business with a corporate office, an established website, and a portfolio of software products that can be reviewed on our website. Our company is fully identifiable through its corporate and registration information. We are actively developing and distributing our software products and have a genuine business need for the Microsoft Partner Center Hardware program. We are trying to enroll in the Microsoft Partner Center Hardware program because our software products require Windows driver signing. We have already obtained an EV code signing certificate in preparation for this process. As part of the Partner Center enrollment and verification process, our company was successfully identified using its D-U-N-S number, with the corresponding company information listed in the D&B database. Our enrollment request was immediately blocked with the following message: “Microsoft runs on trust. We engage in a rigorous set of evaluation and certification processes; as a result your request was blocked. If you require further information please reach out to Microsoft Support…” Given the information available about our company and its legitimate business activities, it is absolutely unclear to us why the enrollment request was blocked. In particular, we were not asked to provide any supporting documentation or clarification before the enrollment was blocked, so we were not given an opportunity to address any specific concern that may have arisen during the evaluation. As instructed in the enrollment message, we contacted Microsoft Support. We were provided with troubleshooting recommendations, which we followed, but the enrollment remained blocked with the same result. Microsoft Support subsequently confirmed that the Trust-related block remained in place and that our access could not be reactivated at that time. We then sent follow-up questions asking what specifically had caused the issue and whether there was anything we could provide or correct. We did not receive a further response or any notification confirming that the case had been closed. Following Microsoft's troubleshooting recommendations, we subsequently repeated the enrollment. Unfortunately, the same Trust-related block occurred again. We are also currently unable to obtain further assistance through Partner Center Support. When we try to submit a support request concerning the Hardware enrollment issue, the portal returns: “There is a problem submitting your request, try again!”. We tried multiple times over the course of about a week, using different browsers, but received the same error message each time. This leaves us without a clear path to understand or resolve the issue. We fully understand and respect Microsoft's need to conduct appropriate trust, compliance, and verification checks. However, as a legitimate licensed software company with an established business presence, identifiable corporate operations, a portfolio of products, and a genuine need for the Hardware program, we would very much like to understand what specifically is preventing our enrollment. Could a Microsoft Community Manager please help route this matter to the appropriate Partner Vetting / Trust & Safety or Hardware enrollment team for manual review? If there is a specific concern, requirement, or verification issue affecting our company, we are fully prepared to provide the relevant documentation and clarification. We would simply appreciate the opportunity to understand what needs to be addressed rather than having our enrollment blocked without any specific information being provided to us. We are not asking Microsoft to bypass its verification requirements. We are asking for a fair opportunity to complete the verification process and address any concerns that may have resulted in the Trust evaluation decision. Thank you for your assistance.208Views0likes2CommentsError 2100 during MAICPP enrollment – Legal info blank
Issue: I'm stuck at the Agreements step of the Microsoft AI Cloud Partner Program (MAICPP) enrollment. When I click Accept and continue, the page displays: The request could not be completed. No further details are provided (no reference number, no transaction ID). Evidence of orphaned legal entity (error 2100): After the failed submission, I navigated to Settings → Account settings → Organization profile → Legal info, and the page renders only the title and description text—no tabs, no form fields, completely blank (screenshot attached). This matches the documented symptom of error 2100 / orphaned legal entity: the backend created a legal entity record during the first submission attempt, but it was never linked to a program enrollment. Subsequent attempts to accept the agreements fail because the system tries to create a duplicate entity. Environment: Tenant ID: 70a418c9-dca7-4bf3-90b0-765294ae60aa Verified domain: http://myclaw.ai/ Publisher name: MyClaw Account type: Company Submitting user role: Global Administrator Target program: Microsoft AI Cloud Partner Program (MAICPP) Goal: Obtain Partner ID → apply for Verified Publisher in Entra ID Already tried: Clearing cache, incognito mode, different browsers – no change Checked Identifiers page – also blank (no Partner ID, no publisher table) Cannot use the standard support form (requires a workspace, which I don't have until enrollment completes) Cannot use the no-login support form (Submit button fails) Request: Please manually clear the orphaned legal entity record or link the existing entity to the MAICPP enrollment, so I can complete the registration. Attached screenshots: "The request could not be completed" error at the Agreements step Legal info page rendering no tabs Thank you.Partner Center enrollment blocked – 715-123160 – requesting manual review
Our Microsoft AI Cloud Partner Program enrollment was blocked by the automated trust filter. Reference number: 715-123160. Correlation ID: 60efdff8-0e40-4745-8d33-d7b950000571. Company: Newox Group AB (Sweden), org. no. 559318-6280, trading as Aida Labs (aidalabs.io). Tenant domain: aidalabs.io (verified). We are an ISV building a B2B analytics SaaS with a planned Microsoft Teams integration. Since no workspace was created, we cannot open a ticket in Partner Center, and the Swedish support phone numbers listed in the M365 admin center do not connect. Please route this to the Partner Center vetting team for manual review. We can provide our company registration certificate immediately.Online Archive Not Working for One User
Hi, I am experiencing an issue with the online archive for one of my users. The online archive has been working correctly for this user for years, but it has not archived any emails for the past six months. I have checked the licensing, retention tags, and retention policy, and everything appears to be correctly configured. I have also tried running the Start-ManagedFolderAssistant cmdlet multiple times, but it has not resolved the issue. Other users in my organization have the same retention policy and their online archives are working correctly. I have also tried changing the retention policy for the affected user to one that is known to work for other users, but this did not resolve the issue. I have tried running several cmdlets to gather more information about the issue, including Get-Mailbox | FL RetentionPolicy, Export-MailboxDiagnosticLogs -Identity -ExtendedProperties, Get-RetentionPolicy | FL Name, Get-RetentionPolicyTag, Get-ComplianceTag, Get-Mailbox | fl *hold*, Get-MailboxStatistics | fl ManagedFolderAssistantLastRunTime, Get-Mailbox -Archive | fl *, and Get-MailboxFolderStatistics -Archive | fl *. However, none of these cmdlets have helped me identify the cause of the issue. The output from these cmdlets appears to be normal and does not indicate any issues with the mailbox or the archive mailbox. One thing I noticed is that the Get-MailboxStatistics | fl ManagedFolderAssistantLastRunTime cmdlet does not return any output for any of my users, even though I have run the Start-ManagedFolderAssistant cmdlet multiple times. I am at a loss as to what could be causing this issue and would appreciate any suggestions or guidance on how to troubleshoot it further. Thank you29KViews0likes10CommentsSeller verification Rejected at Employment step — no email received, no appeal (ID 94611890)
Our Partner (MAICPP) verification completed successfully on 31 Aug 2026 — contact, identity (Verified ID) and business all Verified (Partner ID 7113511, DIGITAL QAZAQSTAN LTD, UK company no. 17178943). The Developer/seller verification for the same legal entity (Seller ID 94611890) is closed as "Rejected — no appeals available", stuck at "Employment Verification — Pending Partner Action" with an estimated date of 06.09.2026 still showing. No verification email or action request was ever received at the primary contact (monitored, junk folder included), and the closed page shows no Fix now / appeal / upload control. Root cause we identified: the seller profile contained an outdated registered address. It has been corrected and now matches Companies House exactly (Office 393, Unit 5, 399-405 Oxford Street, Mayfair, London W1C 2BU). Business verification documents show "Provided". A fully prepared transactable professional service offer is blocked from publication only by this verification. Could a Community Manager please escalate this to the Partner Vetting team to reopen or reinitiate the seller verification?