M365 Change Tracker

← All changes · api-change

API changev1.0

Updated the assignedLabels property on the group resource to support assigning sensitivity labels to cloud security groups in addition to Microsoft 365 groups.

From Microsoft's description: “Requires a Microsoft Entra ID P1 license.”

1 changed 2 added
Changed assignedLabels
Added Group +1 more

Updated the assignedLabels property on the group resource to support assigning sensitivity labels to cloud security groups in addition to Microsoft 365 groups. For cloud security groups, this property is immutable once set. Requires a Microsoft Entra ID P1 license. Added the Group.Security and Group.Security.Policies setting templates to the groupSettingTemplate resource. Use these templates to configure tenant-wide or per-object settings for cloud security groups, including enabling Microsoft Information Protection (MIP) sensitivity labels ( EnableMIPLabels ) and controlling guest access ( AllowToAddGuests ). Requires a Microsoft Entra ID P1 license. Added the *Group.ManageProtection.All* delegated permission as the least privilege permission for updating the assignedLabels property on the group resource.

Source last updated 2026-07-08

Affected: Microsoft Graph, Groups

Related changes

Change history

2026-08-24 · First captured by tracker

View at Microsoft →