The Latest In Microsoft Security: November Updates And Insights

24 October 2023by Abdallah Alhajeid

Major operating system and platform vendors, including Microsoft, regularly release updates that typically incorporate new security features and patches for identified vulnerabilities. Microsoft issues security updates for its suite of products, which encompasses Windows, Office 365, Azure, and more.

On September 26th, Microsoft launched a significant update for Windows 11 and Office, which also introduced several security features. Additionally, Microsoft has issued various security updates for its other products throughout the year. In today’s article, we will delve into the latest information about the security updates that Microsoft has announced or introduced for its various products in the last couple of months. Let’s get started!

 

Windows 11 Security updates

As stated earlier, Microsoft released a feature update for Windows 11 on the 26th of September, which included several major security updates. These updates include the following;

 

Passkeys

One of the standout security features in this Windows 11 update is the introduction of passkeys. Passkeys serve as a modern and highly secure alternative to traditional passwords. They leverage your device’s built-in authentication methods, such as biometrics like Face ID on iPhones, fingerprint sensors on Android phones, or Windows Hello on PCs.

By creating a passkey, two keys are generated: one is stored securely by the website or service you’re using, and the other is a private key stored on your device. Whenever you want to access that site, your device and the website will communicate by double-checking on both sides to ensure the private and public passkeys match.

This technology not only enhances security but also simplifies the sign-in process, making it possible to access websites and applications with a simple scan of your face or fingerprint. Additionally, you can use your mobile device for authentication, offering an extra layer of convenience and security.

 

Deleting Passkeys

This Windows 11 update also provides a user-friendly way to manage your passkeys. In the system’s settings, you can view and delete passkeys associated with your favorite apps and websites. This feature can be accessed through Settings > Accounts > Passkeys. In this section, you’ll find a list of passkeys connected to your account. It allows you to search for and remove any passkey from your device.

This feature is particularly valuable for maintaining your security credentials efficiently, ensuring you have control over the keys used for authentication. Users of Microsoft Edge or Google Chrome will also find this feature integrated into their browser’s passkey user interface, where they can opt for “Windows Hello or external security key” for authentication.

 

Enhanced Phishing Protection

The security update in Windows 11 also extends its protection against phishing attacks by incorporating Enhanced Phishing Protection into Microsoft Defender SmartScreen. This added layer of security is designed to safeguard your work-related passwords from phishing threats and the unsafe use of credentials on websites and within apps. To enable this feature, users must activate the warning options within Windows Security, found in the App & Browser control settings.

Once activated, if the system detects any unsafe password practices, like password reuse, it triggers a warning dialog, effectively alerting you to potential security risks. Enhanced Phishing Protection will help users stay safe from the ever-evolving landscape of phishing attacks and promote best practices in password management.

 

Microsoft Office security updates

Fixes to the Remote Code Execution (RCE) vulnerability

An RCE vulnerability is a serious security flaw within Office software that, if exploited, allows an attacker to execute arbitrary code on a victim’s computer from a remote location. This means that an attacker can take control of your system without physical access or direct interaction. The way this works is through the exploitation of the vulnerability present in specially crafted Office documents, such as Word files, Excel spreadsheets, or PowerPoint presentations.

When a victim unwittingly opens one of these malicious documents, the vulnerability is triggered, and the attacker’s code is executed. Once this code is executed, the attacker gains a significant degree of control over the victim’s computer. The consequences of such an attack can be severe. The attacker could use this control to steal sensitive data, install malware, or manipulate the victim’s computer for their own purposes. So, ensure to update to the latest Office version to avoid being a victim of this vulnerability.

 

Defender for cloud updates

Data Security Dashboard

As of September 27, 2023, the Data Security Dashboard is available in public preview as part of the Defender Cloud Security Posture Management (CSPM) plan. This interactive dashboard focuses on data security and highlights significant risks related to sensitive data. It provides valuable insights into alerts and potential attack paths for data across hybrid cloud workloads. This dashboard is a crucial tool for organizations looking to enhance their data protection and threat detection capabilities.

 

Auto-Provisioning Process for SQL Server (MMA Replacement)

This feature was implemented starting from September 21, 2023. With this feature, Microsoft is deprecating the Microsoft Monitoring Agent (MMA) and introducing a new auto-provisioning process for SQL Server in Defender for Cloud. This change is part of a broader strategy, with the release of a SQL Server-targeted Azure Monitoring Agent auto-provisioning process.

During the preview phase, customers using the MMA auto-provisioning process with the Azure Monitor Agent (Preview) are encouraged to migrate to the new Azure Monitoring Agent for SQL Server on machines (Preview) auto-provisioning process. This transition offers a seamless experience and ensures continuous protection for all machines.

 

GitHub Advanced Security Integration

As of September 20, 2023, Defender for Cloud now allows users to view GitHub Advanced Security for Azure DevOps (GHAzDO) alerts related to CodeQL, secrets, and dependencies. These alerts can be accessed in the DevOps blade and Recommendations within Defender for Cloud.

To access these alerts, organizations need to onboard their GHAzDO-enabled repositories to Defender for Cloud. This integration facilitates better security management and provides insights into the security of code and dependencies in DevOps environments.

 

Containers Vulnerability Assessment Enhancement

This feature was implemented on September 6, 2023. With this new security feature, the Containers Vulnerability Assessment, powered by Microsoft Defender Vulnerability Management (MDVM), now supports an additional trigger for scanning images pulled from an Azure Container Registry (ACR).

This new trigger adds to the existing capabilities of scanning images pushed to an ACR in the last 90 days and images currently running in Azure Kubernetes Service (AKS). This enhancement increases the coverage and ensures that vulnerabilities in actively used container images are detected promptly.

 

Microsoft Power Platform updates

The major update for power platforms is the deprecating support for unregistered MSA and External Azure Active Directory users in Dataverse. Dataverse is a platform used for data management and application development. The decision to deprecate support for unregistered MSA and external AAD users is part of Microsoft’s ongoing efforts to enhance the security and performance of the Dataverse platform. Unregistered MSA and external AAD users refer to individuals who do not have formal registration or accounts within the Microsoft ecosystem.

These accounts are relatively obscure and add complexity to the authorization scenarios within Dataverse. By deprecating support for these types of users, Microsoft aims to simplify the platform’s security and authentication processes, thereby improving overall performance and ensuring that only registered and authorized users have access to Dataverse resources.

 

Final thoughts

Those are some of the major security updates coming or already available to various Microsoft products. Depending on the products you use, be sure to take advantage of these updates to ensure the security of you and your team. Updates such as Passkeys introduce new security features to Microsoft platforms, while others like the vulnerability fixes in Office are intended to address potential weaknesses that could be exploited by hackers.

To further enhance the security in your Microsoft ecosystem, consider exploring the managed services provided by WizardCyber, such as Managed Microsoft Azure Sentinel and Office 365 Review. These services are managed by cybersecurity experts with years of experience, further enhancing the protection of your digital environment.

 

CYBERSECURITY READINESS

Strengthen Your Cyber Defences Today

As cyber threats grow more complex, proactive detection is no longer optional.

With Wizard Cyber’s Microsoft expertise, organizations can transform their security posture and gain real-time visibility across all endpoints.

Start your journey to smarter, faster cybersecurity today.

EXPLORE MORE

Related Blogs & Insights

Discover blogs that deepen your knowledge and accelerate your security strategy.

Abdallah Alhajeid

WordPress Developer

WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-27001-scaled.png
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-9001-scaled.png
WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry

Copyright by Wizard Cyber. All rights reserved.

Copyright by Wizard Cyber. All rights reserved.

Contact Us
×
Contact Us
Need Cybersecurity Guidance? Get in touch with us!

Our experts are ready to help with your cybersecurity questions—book a conversation with us by clicking the button.

Book a Meeting
Funded Workshops
×
Funded Workshops
Explore Our Funded Microsoft Security Workshops

Click to learn more about each Microsoft-supported engagement

Book a Consultation