Stop Wasting Money on IBKR: 12 Essential Default Settings to Fix Today (Step-by-Step Guide)

Optimizing your Interactive Brokers (IBKR) account defaults is one of the highest-leverage actions you can take as an investor. Left on default settings, IBKR can quietly siphon off returns through unfavorable commission tiers, unnecessary exchange markups, lost tax-efficiency opportunities, and idle cash drag.

Here is a complete, step-by-step master guide to 12 essential IBKR configurations that will save you money, unlock tax-advantaged assets, secure your account, and put your wealth building on autopilot.

First if you havent got a IBKR account yet,open an account: Use my IBKR Referral Link to claim up to $1,000 in welcome stock bonus.

1. Switch to IBKR Pro (Tiered Pricing)

When setting up your account, IBKR defaults to fixed commission rates (or IBKR Lite for US users). However, IBKR Pro with Tiered Pricing is significantly cheaper for most global investors.

Why It Matters

  • IBKR Lite vs. Pro: While Lite offers $0 commissions on US stocks, it charges higher currency conversion markups, lower interest on cash balances, higher margin rates, and disables IB SmartRouting (IBKR’s algorithm that hunts across exchanges for the best execution price).
  • Fixed vs. Tiered: Fixed charges a high minimum per order (e.g., $1.00 USD / £6.00 GBP). Tiered drops the minimum per order down to $0.35 USD, charging fractions of a cent per share plus exchange pass-through fees.

Step-by-Step Setup

  1. Open the IBKR Mobile App.
  2. Tap Menu (top-left) ➡️ Settings ➡️ Account Settings.
  3. Scroll down and tap IBKR Pricing Plan.
  4. Select IBKR Pro.
  5. Change the pricing model from Fixed to Tiered.
  6. Tap Continue to apply (changes take effect on the next trading day).

2. Unlock UK Trading Permissions & Global Fractional Shares

By default, IBKR restricts access to international exchanges and whole-share execution only. Unlocking these permissions expands your investment menu and reduces tax drag.

Why It Matters

  • UK Access (Ireland-Domiciled ETFs): Gaining access to the London Stock Exchange (LSE) allows non-US investors to purchase UCITS ETFs (e.g., CSPX, VWRA). These Ireland-domiciled funds cut US dividend withholding tax from 30% down to 15% and completely shield you from US Estate Tax risks.
  • Fractional Shares: Allows you to invest exact dollar amounts (e.g., $10 or $50) rather than waiting until you can afford a single full share.

Step-by-Step Setup

  1. Tap Menu ➡️ Settings ➡️ Trading Settings ➡️ Trading Permissions.
  2. Tap Edit under the Stocks section.
  3. Scroll down, locate United Kingdom, and check the box.
  4. Scroll to the bottom of the list and check Global Trade in Fractions.
  5. Tap Continue and confirm your updated agreement.

3. Verify Account Type (Cash vs. Margin)

Understanding whether you are on a Cash or Margin account dictates your risk exposure and how foreign currency transactions behave.

Why It Matters

  • Cash Account: You can only trade with money you have deposited. You can never lose more than your total balance, making it ideal for standard buy-and-hold ETF investors.
  • Margin Account: Allows you to borrow capital against existing positions and is required for trading multi-leg options strategies. Crucial note: On a margin account, if you buy a foreign stock without converting currency first, IBKR won’t auto-convert; it will automatically start charging you margin interest on that foreign currency balance.

Step-by-Step Setup

  1. Go to Menu ➡️ Settings ➡️ Account Settings.
  2. Locate Account Type (under Account Configuration).
  3. Review or switch your status between Cash and Margin based on your target trading strategy.

4. Master Currency Conversion (Manual vs. Auto-Convert)

Foreign exchange fees can quietly eat into your portfolio returns if you use the wrong conversion mechanism for your trade size.

How It Works

  • Manual Spot FX Conversion: Charges a flat fee of ~$2.00 USD, but gives you direct access to the spot interbank market with virtually no spread markup.
  • Auto-Conversion: Occurs automatically on Cash accounts or recurring investment plans. IBKR waives the flat $2.00 fee, but applies a slightly wider FX spread.
       Trade Amount < $6,700 USD   ===>   Use AUTO-CONVERT (Saves the $2 flat fee)
Trade Amount > $6,700 USD ===> Use MANUAL SPOT FX (Lower spread beats the $2 fee)

Step-by-Step Setup (Manual Conversion)

  1. On the app home screen, tap Trade ➡️ Convert Currency.
  2. Select your source currency (e.g., SGD, GBP, EUR) and destination currency (e.g., USD).
  3. Enter the amount, review the live interbank exchange rate, and slide to execute.

5. Set Your Correct Base Currency

Your Base Currency determines how IBKR calculates overall portfolio returns, Margin metrics, and tax reporting summaries.

Why It Matters

If your base currency is set incorrectly, your portfolio performance graphs will constantly fluctuate due to daily FX shifts against an arbitrary currency rather than your actual spending or reporting currency.

Step-by-Step Setup

  1. Go to Menu ➡️ Settings ➡️ Account Settings.
  2. Locate Base Currency under Configuration.
  3. Select your local or primary currency (e.g., USD, GBP, EUR, SGD) and confirm.

6. Optimize Yield on Idle Cash Balances

IBKR offers competitive interest on uninvested cash (up to 3.10%+ on USD balances), but key thresholds determine how much you actually earn.

Key Rules

  • $10,000 USD Threshold: IBKR pays 0% interest on the first $10,000 USD of cash. Interest is calculated strictly on cash balances exceeding $10,000.
  • Account Value Scaling: To earn the full advertised benchmark interest rate, your account Net Asset Value (NAV) must be $100,000 USD or higher. For accounts under $100k, the rate scales down proportionally.
  • Currency Selection: USD cash generally yields higher interest rates; holding idle balances in low-yielding currencies yields minimal to no return.

7. Connect AI Portfolio Tools via Open Financial Connectors

You can connect external AI engines (such as Claude or ChatGPT) directly to your IBKR account via read-only financial API connectors to perform instant portfolio audits.

Why It Matters

  • Run instant risk audits (e.g., detecting over-concentration or overlapping holdings across ETFs).
  • Generate automated morning portfolio briefs and earnings updates tailored to your specific holdings.
  • Safety First: The connector is strictly read-only. AI can analyze your metrics, but it cannot place trades, withdraw funds, or alter settings without your explicit manual approval.

Step-by-Step Setup

  1. Tap your User Profile icon ➡️ Connectors (or via Web Portal ➡️ Customize Connectors).
  2. Search for Interactive Brokers.
  3. Authorize the read-only credentials via secure OAuth.
  4. Use targeted prompts like:“Analyze my current IBKR holdings for sector over-concentration and list top 3 risk factors.”

8. Enable the Dividend Reinvestment Plan (DRIP)

Instead of leaving dividend payouts sitting idle as non-earning cash balances, set them to compound automatically back into your assets.

Why It Matters

DRIP automatically purchases whole and fractional shares of the underlying stock/ETF as soon as dividends settle, putting compounding returns on complete autopilot.

Step-by-Step Setup

  1. Navigate to Menu ➡️ Settings ➡️ Account Settings.
  2. Scroll to Account Configuration and select Dividend Election.
  3. Toggle the selection to Reinvest in shares (or specify individual stock rules).
  4. Save your changes. (Note: DRIP is supported for US, Canadian, and European exchange-listed stocks).

9. Build an Automated Recurring Savings Plan (RSP)

Automating deposits and recurring purchases takes emotion out of investing and enforces continuous Dollar-Cost Averaging (DCA).

Step-by-Step Setup

  1. Automate Bank Deposit:
    • Go to Menu $\rightarrow$ Transfers $\rightarrow$ Deposit Funds.
    • Select your linked transfer mechanism (e.g., e-GIRO, ACH, or Direct Debit).
    • Check Make this a recurring transaction, pick a monthly frequency and set the transfer date.
  2. Automate Order Execution:
    • Search for your target asset (e.g., CSPX or VWRA).
    • Tap the Three Dots (…) in the top-right corner $\rightarrow$ select Create Recurring Investment.
    • Set the purchase start date 2–3 days after your recurring bank deposit date to allow funds to clear.
    • Input your recurring dollar amount and leave the end date blank to run indefinitely.

10. Optimize Your Tax-Lot Matching Method

When you eventually sell a portion of a position, IBKR needs to know which specific shares you are disposing of.

Why It Matters

By default, IBKR uses FIFO (First-In, First-Out), which sells your oldest shares first. If those shares have appreciated the most over time, FIFO triggers the largest possible taxable capital gain. By switching your default method to Tax-Efficient Loss Harvesting or LIFO (Last-In, First-Out), you can defer capital gains taxes or realize capital losses first to offset other gains.

Step-by-Step Setup

  1. Go to Menu ➡️ Settings ➡️ Account Settings.
  2. Scroll to Tax Configuration and select Tax-Lot Matching Method.
  3. Change your default from FIFO to your preferred strategy (e.g., Maximized Tax Loss or LIFO).

11. Enroll in the Stock Yield Enhancement Program (SYEP)

SYEP allows you to generate passive income from shares you already own by lending them to other market participants.

How It Works

IBKR lends your fully-paid shares to short sellers, charges them a borrow fee, and splits the interest revenue 50/50 with you.

Key Trade-offs

  • What you keep: You retain 100% economic ownership of the stock. You can sell your shares at any time without restriction, and you receive cash payments in lieu of dividends.
  • What changes: Shares on loan temporarily surrender voting rights and are backed by IBKR cash collateral equal to 102%+ of the share value rather than standard SIPC coverage.

Step-by-Step Setup

  1. Go to Menu ➡️ Settings ➡️ Account Settings.
  2. Scroll down to Stock Yield Enhancement Program.
  3. Read the program disclosures and toggle to Enroll.

12. Enable IB Key (Biometric 2FA Security)

Securing your investment platform goes beyond basic passwords or SMS verification code steps.

Why It Matters

SMS 2FA is vulnerable to SIM-swapping attacks. Enabling IB Key (biometric authentication built directly into the IBKR Mobile app) secures your portfolio with FaceID/TouchID. Beyond security, having IB Key active increases daily withdrawal limits and reduces settlement friction.

Step-by-Step Setup

  1. Open the IBKR Mobile App.
  2. Go to Menu ➡️ Settings ➡️ User Profile ➡️ Two-Factor Authentication.
  3. Follow the prompt to activate IB Key and link it to your phone’s biometrics.

Summary Checklist

#SettingRecommended SelectionPrimary Benefit
1Pricing PlanIBKR Pro + TieredLower minimum fees ($0.35) & SmartRouting execution
2PermissionsUK + Fractional SharesTax-efficient UCITS ETFs & partial share purchasing
3Account TypeCash AccountAvoids accidental margin interest / borrowing drag
4FX StrategyManual >$6,700 / Auto <$6,700Minimizes total currency spreads and conversion fees
5Base CurrencyHome / Reporting CurrencyAccurate performance metrics and tax reporting
6Cash YieldHold idle cash in USDEarns up to 3.10%+ on balances over $10k USD
7AI ConnectorsRead-Only API IntegrationInstant risk audits and automated portfolio briefs
8DividendsEnable DRIPAutomatically compounds payouts into shares
9Automated DCARecurring Savings Plan (RSP)Hands-off bank deposits & recurring purchases
10Tax LotsMaximized Tax Loss / LIFOMinimizes immediate capital gains tax drag
11Share LendingEnable SYEPEarns passive yield on long-term holdings
12SecurityEnable IB Key 2FAPrevents SIM-swap risk via app biometrics
Ready to set up your IBKR account?

If you haven’t opened an Interactive Brokers account yet, sign up using my IBKR Referral Link to earn up to $1,000 in free IBKR stock ($1 in IBKR stock for every $100 deposited).*

*Disclosure: This is an official affiliate/referral link. If you sign up using this link, I may receive a referral reward at no extra cost to you.

Disclaimer: This post is for educational and informational purposes only and does not constitute financial or investment advice.

Comparing the Free Forever Tiers in Azure, GCP, AWS, and OCI…and the winner is OCI!

Understanding the perpetual free offerings of major cloud providers

The cloud computing landscape is dominated by a few key players, each offering a range of services to cater to diverse needs. Among these giants, Microsoft Azure, Google Cloud Platform (GCP), Amazon Web Services (AWS), and Oracle Cloud Infrastructure (OCI) stand out. One of the most compelling reasons for individuals and businesses to explore these platforms is the availability of free forever tiers. These free tiers provide an opportunity to experiment, develop, and even deploy applications without incurring significant costs. In this blog, we will delve into and compare the free forever tier offerings of Azure, GCP, AWS, and OCI.

Microsoft Azure

Microsoft Azure offers several services that remain free forever. These always free services include:

  • Azure Functions: 1 million requests per month
  • File Storage: 5 GB of LRS (Locally Redundant Storage)
  • SQL Database: 250 GB of storage

Google Cloud Platform (GCP)

Google Cloud Platform provides a variety of services that are always free, which include:

  • Compute Engine: 1 f1-micro instance per month in select regions
  • Cloud Storage: 5 GB of Regional Storage
  • Network Egress: 1 GB from North America to all regions

Amazon Web Services (AWS)

Amazon Web Services offers an extensive array of services that are perpetually free. These always free services include:

  • AWS Lambda: 1 million requests per month
  • DynamoDB: 1 GB of storage
  • Glacier: 25 GB of data retrievals

Oracle Cloud Infrastructure (OCI)

Oracle Cloud Infrastructure provides several services that are free forever, including:

  • Autonomous Database: 2 instances with Oracle APEX
  • Compute VMs: 2 AMD-based virtual machines
  • Data Transfer: 10 TB outbound per month

Comparison and Conclusion

When comparing the free forever tiers of Azure, GCP, AWS, and OCI, several key points stand out:

  • Service variety: Each provider offers a range of services under their always free tier, from computing instances to storage and databases. AWS tends to have one of the most extensive always free offerings, while OCI provides substantial data transfer and compute options.
  • Use case suitability: Depending on your needs—whether it’s running virtual machines, exploring database options, or experimenting with cloud functions—you might find one provider’s free tier more suitable than the others. For instance, AWS is excellent for those needing a broad range of services, while OCI provides substantial data transfer and compute options.

In conclusion, the choice of a cloud provider’s free forever tier should align with your specific requirements and future scalability plans. Each provider—Azure, GCP, AWS, and OCI—brings unique strengths to the table, making it essential to analyze which free tier best fits your project needs.

Whether you’re a developer, a small business, or a large enterprise, leveraging these free forever tiers can provide a cost-effective way to innovate and grow in the cloud.

The final verdict with a lead of 2 free VMs for life on its free forever tier, OCI takes the crown.

Set Microsoft Edge as the default browser via GPO

You can set Microsoft Edge as the default browser on domain-joined devices by configuring the Set a default associations configuration file via group policy.

Turning this group policy on requires you to create and store a default associations configuration file in XML format. This file is stored locally or on a network share. Copy below XML content to a file name Edge.xml and store in a central share accessible by all domain joined resources.

XML
<?xml version="1.0" encoding="UTF-8"?>
<DefaultAssociations> 
  <Association ApplicationName="Microsoft Edge" ProgId="MSEdgeHTM" Identifier=".html"/>
  <Association ApplicationName="Microsoft Edge" ProgId="MSEdgeHTM" Identifier=".htm"/>
  <Association ApplicationName="Microsoft Edge" ProgId="MSEdgeHTM" Identifier="http"/>
  <Association ApplicationName="Microsoft Edge" ProgId="MSEdgeHTM" Identifier="https"/>  
  <Association ApplicationName="Microsoft Edge" ProgId="MSEdgePDF" Identifier=".pdf"/>
</DefaultAssociations>

note: If you dont want to associate Edge to open PDF files, edit this xml file and remove the line “<Association ApplicationName=”Microsoft Edge” ProgId=”MSEdgePDF” Identifier=”.pdf”/>”

Configure the GPO  for a default file type and protocol associations configuration file:
  1. Open the Group Policy editor and go to the Computer Configuration\Administrative Templates\Windows Components\File Explorer.
  2. Select Set a default associations configuration file.
  3. Click policy setting, and then click Enabled.
  4. Under Options:, type the location to your default associations configuration file.
  5. Click OK to save the policy settings.
  6. Ensure this GPO is linked to the OU where all devices are
  7. The GPO will be processed the next time the user logs in

The example in the next screenshot shows an associations file named Edge.xml on a network share that is accessible from the target device on \\APP1\Users\testadmin\Documents\Edge.xml

Restrict Users From Creating New Teams in Microsoft Teams

If you have recently adopted the usage for Microsoft Teams, managing Teams within Teams becomes a toungue twister in itself, If you’re concerned about users creating teams or groups that don’t comply with your business standards, perhaps you want this to be delegated to set of mindful power users group.

  1. Create a Group – This could be a Active Directory Synced group or M365 group
  2. Install AzureAD Public Preview – AzureAD PowerShell Module.
  3. Run the below script, replace the value of “<GroupName>” with the name of the group you have created, enter the administrator credentials when prompted
$GroupName = "<GroupName>"
$AllowGroupCreation = $False

Connect-AzureAD

$settingsObjectID = (Get-AzureADDirectorySetting | Where-object -Property Displayname -Value "Group.Unified" -EQ).id
if(!$settingsObjectID)
{
    $template = Get-AzureADDirectorySettingTemplate | Where-object {$_.displayname -eq "group.unified"}
    $settingsCopy = $template.CreateDirectorySetting()
    New-AzureADDirectorySetting -DirectorySetting $settingsCopy
    $settingsObjectID = (Get-AzureADDirectorySetting | Where-object -Property Displayname -Value "Group.Unified" -EQ).id
}

$settingsCopy = Get-AzureADDirectorySetting -Id $settingsObjectID
$settingsCopy["EnableGroupCreation"] = $AllowGroupCreation

if($GroupName)
{
  $settingsCopy["GroupCreationAllowedGroupId"] = (Get-AzureADGroup -SearchString $GroupName).objectid
} else {
$settingsCopy["GroupCreationAllowedGroupId"] = $GroupName
}
Set-AzureADDirectorySetting -Id $settingsObjectID -DirectorySetting $settingsCopy

(Get-AzureADDirectorySetting -Id $settingsObjectID).Values

reference: https://docs.microsoft.com/en-us/microsoft-365/solutions/manage-creation-of-groups?view=o365-worldwide

Microsoft Admin Portals

Microsoft 365 Admin Portals

Portal NameURL
Microsoft 365 Admin Portalhttps://admin.microsoft.com/ 
Microsoft 365 Compliancehttps://compliance.microsoft.com/
Microsoft Endpoint Manager Admin Consolehttps://endpoint.microsoft.com/
Microsoft Endpoint Manager Admin Console (old)https://devicemanagement.portal.azure.com/
Exchange Admin Center (new)https://admin.exchange.microsoft.com/
Exchange Admin Center (old)https://outlook.office365.com/ecp/
Microsoft Teams Admin Centerhttps://admin.teams.microsoft.com/ 
SharePoint Admin Centerhttps://admin.microsoft.com/sharepoint
OneDrive Admin Centerhttps://admin.onedrive.com/
Apps Admin Centerhttps://config.office.com/officeSettings#
Power BI Admin Portalhttps://app.powerbi.com/admin-portal/usageMetrics?noSignUpCheck=1
Power Platform admin centerhttps://admin.powerplatform.microsoft.com/
Microsoft Stream Admin Centerhttps://web.microsoftstream.com/admin
Skype for Business admin center (deprecated)https://webdir2a.online.lync.com/LSCP
Kaizala Management Portalhttps://manage.kaiza.la/
Yammer Adminhttps://www.yammer.com/office365/admin
Microsoft Store for Businesshttps://businessstore.microsoft.com/
Microsoft Store for Educationhttps://educationstore.microsoft.com/
Microsoft Partner Centerhttps://partner.microsoft.com/dashboard
Microsoft Remote Connectivity Analyzerhttps://testconnectivity.microsoft.com
Microsoft 365 network connectivity testhttps://connectivity.office.com/
Microsoft Call Quality Dashboardhttps://cqd.teams.microsoft.com/

Azure IT Admin Portals

Portal NameURL
Microsoft Azure Portalhttps://portal.azure.com/ 
Microsoft Azure (Release Candidate)https://rc.portal.azure.com/
Microsoft Azure (Preview)https://preview.portal.azure.com/
Azure Resource Explorerhttps://resources.azure.com/
Azure Cloud Shellhttps://shell.azure.com/
Azure Active Directory admin centerhttps://aad.portal.azure.com/
Azure Cosmos DBhttps://cosmos.azure.com/
Azure Data Factoryhttps://adf.azure.com/
Azure Cognitive Services Custom Translatorhttps://portal.customtranslator.azure.ai/
Azure Non-profit Portalhttps://nonprofit.microsoft.com/#/ngoportal
Portal NameURL
Azure Security Centerhttps://portal.azure.com…

Microsoft Licensing/Support Portals

Portal NameURL
Volume Licensing Service Centerhttps://www.microsoft.com/Licensing/servicecenter/
Next Generation Volume Licensinghttps://businessaccount.microsoft.com/
Microsoft Azure Enterprise Portalhttps://ea.azure.com/
Microsoft Services Hubhttps://serviceshub.microsoft.com/
Microsoft License Advisorhttps://mla.microsoft.com/
Microsoft Partner Centerhttps://partner.microsoft.com/
Azure Subscriptionshttps://account.azure.com/Subscriptions

Security / Defender IT Admin Portals

Portal NameURL
Microsoft Cloud App Securityhttps://portal.cloudappsecurity.com/
Microsoft Defender for Endpoints
(Previously Defender ATP)
https://securitycenter.windows.com/
Microsoft 365 Defenderhttps://security.microsoft.com/
Office 365 Security & Compliancehttps://protection.office.com/
Microsoft Defender for Identity
(Previously Azure ATP)
https://portal.atp.azure.com/
Multi-factor authenticationhttps://account.activedirectory.windowsazure.com…

Developer Portals

Portal NameURL
Graph Explorerhttps://developer.microsoft.com/en-us/graph/graph-explorer 
Azure DevOpshttps://dev.azure.com/
Visual Studio Subscriptionshttps://my.visualstudio.com/
Visual Studio Subscriptions Managementhttps://manage.visualstudio.com/
Adaptive Cardshttps://adaptivecards.io/

Other Useful Microsoft Portals

Portal NameURL
Office 365 Anti-Spam IP Delist Portalhttps://sender.office.com/
Azure Statushttps://status.azure.com/
Azure DevOps Statushttps://status.dev.azure.com/
Windows Virtual Desktop Consent Pagehttps://rdweb.wvd.microsoft.com/
Customer Digital Experienceshttp://demos.microsoft.com/
Group Policy Searchhttps://gpsearch.azurewebsites.net/
Microsoft Startupshttps://portal.startups.microsoft.com/
Office UI Fabric Iconshttps://uifabricicons.azurewebsites.net/ 
Become Microsoft Certifiedhttps://query.prod.cms.rt.microsoft.com… 
Tech Community Video Hubhttps://techcommunity.microsoft.com/t5/video-hub/ct-p/VideoHub 
Microsoft Azure Sponsorshipshttps://www.microsoftazuresponsorships.com/
Microsoft Dynamics Lifecycle Serviceshttps://lcs.dynamics.com/
Microsoft MVPhttps://mvp.microsoft.com/
Portal NameURL
What is my Microsoft Azure and Office 365 tenant ID?https://www.whatismytenantid.com/
Office 365 ATP Safe Links Decoderhttps://o365atp.com/
Message Header Analyzerhttps://mha.azurewebsites.net/
Tenant Availability Checkhttps://o365.rocks/

Reference: https://msportals.xyz/

Block File Sharing in Teams

COVID-19 has led many IT Departments scrambling to roll out some form of conference/ collaboration tool as many had to work remotely. This has affected organizations that where were not agile or cloud agnostic by not adopting to modern workplace earlier on.

Microsoft Teams runs on SharePoint Online, OneDrive in its core, organizations running on-premises compliance/DLP solutions will find it hard to put in controls for data in the cloud, not being an early adopter, and having to enable collaboration tools such as Microsoft Teams is a daunting task when you want to protect the organizational data from going walkabouts. If your organization is one of those, which is like a cat on the wall – how do we do it?

Block File sharing in Teams by:

1. Not assigning a SharePoint Online license for End-users

2. Not creating a Teams or Channels, if you do….

3. Create Teams for your organization but remove the Teams members from having EDIT permission on the Teams SharePoint Site.

4. Additionally if the tenant has Microsoft Cloud App Security enabled – create a session based conditional policy, which blocks upload and download of files in Teams and SharePoint Online.

SharePoint Online License – by not assigning this you deprive the end users from accessing OneDrive for business, which is primary storage for file sharing when it comes to 1-1 and group chats.

Creating a Team – when a team is created with members, this creates a SharePoint online site, which by default allows members to have edit permission on the site. By removing the EDIT permission from the Team site leaves members with only read permission leaving only the owner of the Team/SharePoint site full permission, no just do not assign or delegate the owner permission to a regular user.

Microsoft Cloud App Security – is a Microsoft CASB solution (Cloud Access Security Broker) acts as a reverse proxy. A session based conditional policy can be configured to prevent file uploads/downloads in Teams/Sharepoint site, caveat this only works when accessing them via Web but not through desktop client, hence the above point – remove EDIT permission for Team members. MCAS gives you an insight and alert when someone does indeed try to upload a file as it will block and alert the admin.

Now that you have control of filesharing and enabled Microsoft Teams, start strategic roll out of cloud solutions for DLP, Information protection and governance, classification – all of this is available via Microsoft 365 through Azure Information Protection, DLP, Azure and Defender ATP which can scan and classify your organization data automatically based on data sensitivity you can control.

Licenses could not be assigned or removed due to an error -Azure AD group based licenses

Scenario: Group based licensing is enabled in Azure AD. Exchange online is not assigned through the group based licensed. Newly added users to the group fail to get licenses assigned via the group. Reprocessing the group based license throws error:

Licenses could not be assigned or removed due to an error

Solution: A recent service plan backfilled by the O365 Commerce Team into the Office and Microsoft SKUs Microsoft Bookings a has been added as Enabled on all the licenses. This service plan has a dependency on Exchange Online (Plan 1) or Exchange Online (Plan2).

Disabling the Microsoft Bookings service plan in the affected groups should resolve the licensing error.

Kill all active user sessions in any Azure AD/ Office 365 application

If you are are ever in a situation where you have to deal with a compromised O365 account or situation similar to mine where users were assigned Onedrive/SPO license and you want to revoke them and stop users from using them immediately, the below cmdlet is much helpful.

If you are dealing with a large group of users, you may tire your fingers clicking on “initiate sign-out” or better get all members of the group and use cmdlet Revoke-AzureADUserAllRefreshToken which invalidates the refresh tokens issued to applications for a user. The cmdlet also invalidates tokens issued to session cookies in a browser for the user. The cmdlet operates by resetting the refreshTokensValidFromDateTime user property to the current date and time.

Get the group objectid

Get-MsolGroup [groupname] | fl ObjectId

Next, export the users of the group to a csv

Get-MsolGroupMember -GroupObjectId xxxxx-xxxxx-xxxxx-xxxxx | Select-Object EmailAddress | Export-Csv -Path c:\temp\users.csv

Import the csv and revoke th refresh token for these users.

Import-CSV “c:\temp\users.csv” | % {Get-AzureADUser -SearchString $_.emailaddress | Revoke-AzureADUserAllRefreshToken}

Add Fullmailbox Permission in PowerShell using a CSV file

Create a CSV with following fields and save it in a temp folder

UserMailbox and User

copy the below and save as .ps1 file in the same temp folder e.g C:\temp

$csv = Import-csv -path “C:\temp\fullaccess.csv”
foreach($User in $csv)
{
Add-MailboxPermission -Identity $user.UserMailbox -User $user.User -AccessRights FullAccess -InheritanceType All
}

 

Run the script to apply permissions