Microsoft is implementing significant security enhancements for Windows 365 Cloud PCs, introducing new default settings that will take effect in the second half of 2025. These changes represent a major shift toward more secure cloud computing environments.
## Key Security Changes
Starting in late 2025, all newly provisioned and reprovisioned Windows 365 Cloud PCs will have several redirection features disabled by default:
– **Clipboard redirection** – Prevents copying files between Cloud PCs and physical devices
– **Drive redirection** – Blocks access to local drives from cloud environments
– **USB redirection** – Limits low-level device access while preserving functionality for mice, keyboards, and webcams
– **Printer redirection** – Restricts printing capabilities by default
These restrictions aim to reduce data theft risks and prevent malware attacks by limiting file transfer capabilities between cloud and local environments.
## Enhanced Security Features Already Active
Since May 2025, Microsoft has enabled advanced security features on Windows 365 Cloud PCs running Windows 11:
– **Virtualization-based Security (VBS)** – Creates secure memory enclaves
– **Credential Guard** – Protects authentication credentials
– **Hypervisor-protected Code Integrity (HVCI)** – Prevents malicious code execution at the kernel level
These features work together to provide hardware-level security protection for cloud-based workstations.
## Administrative Control and Flexibility
IT administrators will maintain full control over these new defaults through:
– **Intune Admin Center notifications** – Alerts about upcoming changes
– **Policy overrides** – Ability to modify settings using Intune device configuration policies or Group Policy Objects
– **Automatic policy synchronization** – Existing policies will override new defaults after initial provisioning
## Broader Microsoft 365 Security Updates
Microsoft is implementing additional security measures across its ecosystem:
– **Legacy authentication blocking** – SharePoint, OneDrive, and Office files will block outdated authentication protocols starting July 2025
– **ActiveX controls disabled** – Removed from Windows versions of Microsoft 365 and Office 2024
– **Teams screenshot protection** – New feature to prevent unauthorized screen captures during meetings
– **Outlook attachment restrictions** – Additional file types (.library-ms and .search-ms) added to blocked attachment list
## Impact on Organizations
These changes reflect Microsoft’s commitment to zero-trust security principles. While the new defaults may require adjustment periods for some organizations, they significantly strengthen the security posture of cloud-based work environments. IT teams should prepare by reviewing current redirection policies and planning for any necessary configuration changes to maintain business continuity while benefiting from enhanced security.
