Issue #1: 13 October 2025
Dunetrails Secure Workspace Brief
Hello and welcome to our very first edition!
- The workplace
- The security
- The technology
- The Copilot revolution
Big milestones this month
- Windows 10 End of Life is almost here (14 October 2025). If you still have Windows 10 devices, now is the time to plan upgrades or extended security updates.
- NIS2 turns one year old. Enforcement is ramping up, and SMBs can’t afford to ignore it.
Six Signals from the Secure Workspace
Copilot Gets Deeper Windows Integration
Copilot on Windows can now connect to email and create Office docs.
Why it matters: Great for productivity, but review who can use Copilot and what data it touches.
https://blogs.windows.com/windows-insider/2025/10/09/copilot-on-windows-connectors-and-document-creation/
Exchange Online Auto-Archiving Enabled by Default
Microsoft is turning on auto-archiving to prevent overflowing mailboxes.
Why it matters: Good for storage hygiene, but check retention policies—especially for compliance.
https://techcommunity.microsoft.com/blog/exchange/auto-archiving-for-exchange-online/4459735
Microsoft Blocks More Tricks to Skip Account Setup
Windows 11 now closes loopholes that allowed bypassing Microsoft account setup.
Why it matters: This enforces identity consistency, which is good for security.
https://www.bleepingcomputer.com/news/microsoft/microsoft-blocks-more-tricks-to-skip-microsoft-account-setup-in-windows-11/
What’s New in Intune — September 2025
Highlights include improved app deployment controls, new analytics, and expanded Conditional Access integration.
Why it matters: Easier for SMBs to enforce security baselines without heavy IT overhead.
https://techcommunity.microsoft.com/blog/microsoftintuneblog/what%E2%80%99s-new-in-microsoft-intune-september-2025/4457065
Defender Detects Prompt Injection Attacks in AI Apps
Microsoft Defender now helps security teams detect prompt injection attacks targeting AI-powered apps.
Why it matters: As Copilot adoption grows, so do AI-specific threats. SMBs should monitor Defender alerts and review AI security policies.
https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/how-microsoft-defender-helps-security-teams-detect-prompt-injection-attacks-in-m/4457047
Apple iPhone 17 Adds Always-On Memory Integrity Protection
Apple introduced Memory Integrity Enforcement, a hardware/software feature that blocks memory exploits in real time, similar to Microsoft’s virtualization-based protections in Windows 11.
Why it matters: This makes iPhones much harder to compromise, even against advanced spyware like Pegasus. For SMB leaders who rely on iPhones for work, this is a big security win.
https://security.apple.com/blog/memory-integrity-enforcement/