M365 Change Tracker Changes & security across Microsoft 365
Updated 2026-09-06 19:51 UTC RSS

Know what changed in Microsoft 365 — and what needs action.

Roadmap, security CVEs, Defender XDR, Entra ID & Graph API changes from official public sources — snapshotted every 2 hours, so you also see the edits, date slips and removals Microsoft makes later.

  • See the changes Microsoft later edits or removes
  • Prioritize exploited & high-impact issues
  • Focus on the products you manage
2,318Tracked items
146Security CVEs
0Exploited CVEs
2,000Recent changes

Act now (10)

In developmentPossibleSharePointMicrosoft Viva

SharePoint: Viva Connections multi-home site management moving to SharePoint admin center

Viva Connections multi-home site management is moving from the Microsoft 365 admin center (MAC) to the SharePoint Admin Center (SPAC). Administrators will be able to create and manage multiple Home sites, configure audience targeting, manage home site priority order, and remove Home sites directly from SPAC. Existing entry points in the Microsoft 365 admin center will direct administrators to the new SPAC experience. As part of this update, legacy Viva Connections (VC) instances and draft/enabled management concepts are being deprecated as Viva Connections administration is consolidated into SharePoint Home site management. Existing VC experiences will be upgraded to full Home sites.

LaunchedPossibleMicrosoft Purview

Microsoft Purview compliance portal: Communication Compliance - Policy insights

The Communication Compliance homepage will provide two columns that offer a quick overview of policy performance: the first column shows the number of scanned parent items in real time, giving visibility into scanning progress; the second column keeps you informed about parent items that meet policy conditions, ensuring you stay updated on potential issues requiring attention and maintaining control over communication compliance. This item is no longer accurate and is being removed from the roadmap. We apologize for the inconvenience.

In developmentPossibleMicrosoft Copilot (Microsoft 365)

Microsoft Copilot (Microsoft 365): Dynamic Tool Discovery for Declarative Agents and Federated Copilot Connectors

We're introducing dynamic tool discovery for declarative agents in Microsoft 365 Copilot. Developers can now add, update, or retire tools on their MCP servers without republishing the agent - so end users get the latest agent capabilities immediately, with no deployment cycle in between. Support for federated Copilot connectors will be a fast follow to declarative agents at a later stage. Dynamic tool discovery is backed by Microsoft's enterprise RAI and security protections, and customers retain full control over agent deployment and availability to users and groups.

Rolling outPossibleMicrosoft TeamsMicrosoft Copilot (Microsoft 365)

Microsoft Teams: Spoken language detection is now automatic

Spoken language detection is now fully automatic. Teams will automatically detect each speaker’s spoken language and update it in real time as the conversation evolves. Manual spoken language selection will no longer be available. This applies to both live captions and transcripts when Interpreter is enabled or when multilingual speech recognition is turned on in meeting options, helping deliver more accurate language recognition and a more consistent multilingual meeting experience.

Rolling outPossibleMicrosoft Teams

Microsoft Teams: Automatic removal of EXIF data from shared images

Teams will automatically remove hidden metadata (EXIF) from images shared in conversations. This privacy protection helps prevent sensitive information such as photo location and device details from being shared without your knowledge.

LaunchedPossibleMicrosoft Viva

Microsoft Viva: Focus Area simplification and enhancements

Beginning with this feature release, Focus Areas will be associated with survey cycles and goal periods will be retired. Users will be able to select the same Focus Area across multiple cycles. The Focus Area Overview report will be filterable to groups of interest (e.g. managers only). Draft/deleted Focus Areas will no longer be included in Focus Area calculations.

LaunchedPossibleMicrosoft Purview

Microsoft Purview | Communication Compliance: Integration with Power Automate

Currently in public preview, Communication Compliance integration with Power Automate allows organizations to configure Power Automate flows to automate tasks for Communication Compliance cases and users. Microsoft Purview Communication Compliance provides the tools to help organizations detect regulatory compliance violations (e.g. SEC or FINRA), such as sensitive or confidential information, harassing or threatening language, and sharing of adult content. Built with privacy by design, usernames are pseudonymized by default, role-based access controls are built in, investigators are opted in by an admin, and audit logs are in place to help ensure user-level privacy. This item is no longer accurate and is being removed from the roadmap. We apologize for any inconvenience.

Plan (42)

Rolling outMicrosoft Teams

Microsoft Teams: Town hall media optimization for VDI attendees

Act before September CY2026 · overdue

What’s new Teams now supports audio and video offloading for Town hall attendees in VDI environments that are using the new optimization. Media streams are offloaded directly to the user’s local device, improving performance and delivering a high definition viewing experience while reducing virtual desktop resource usage. Who it applies to • Windows endpoints only using the new VDI optimization • Supported VDI platforms: o Azure Virtual Desktop and Windows 365 o Citrix o Omnissa o Amazon WorkSpaces What stays the same All attendee interactivity features remain supported, including captions, DVR, reactions, streaming chat, and Q&A. Additional details First party and third party eCDNs are supported. When enabled, the attendee’s endpoint establishes a direct peer to peer connection using the local device network, avoiding virtual desktop double hop traffic. Action required No action is required if the new optimization for Microsoft Teams is already enabled.

Rolling outMicrosoft Teams

Microsoft Teams: Mandatory pre-meeting consent

Act before September CY2026 · overdue

We are providing a new configuration experience in Teams Admin Center where tenant admins can enable and customize an explicit consent message before joining any meeting hosted in their organization.

In developmentMicrosoft Edge

Microsoft Edge: Vertical Tabs update

Act before December CY2026 · ~3 mo away

Microsoft Edge is updating its vertical tab implementation and architecture. Edge is reimplementing capabilities across pane, layout, controls, tab behavior, visual treatments, & embedder customizations. No admin action is required.

In developmentOutlook

Outlook: Enhanced user interface updates for iPhone and iPad

Act before September CY2026 · overdue

People using Outlook for iOS on iPhone and iPad will see refreshed interface elements aligned with the latest Liquid Glass iOS visual experience, including modernized app chrome, navigation, and use of screen space. It will be enabled by default with no administrator action required.

betaMicrosoft GraphIdentity and access

Added the user member to the agentIdentityType enumeration. Added the displayName property to the agentRiskDetection…

Added the user member to the agentIdentityType enumeration. Added the displayName property to the agentRiskDetection resource. Added the identityId property to the agentRiskDetection resource. Deprecated the agentId property in the agentRiskDetection resource. Use identityId instead. This property will be removed after 2027-04-28. Deprecated the agentDisplayName property in the agentRiskDetection resource. Use displayName instead. This property will be removed after 2027-04-28.

betaMicrosoft GraphDevice and app management

Added the enrollmentState enumeration type. Added the updateCategoryEnrollmentInformation resource type. Removed the…

Update before removal Jul 1, 2024 · passed 797d ago

Added the enrollmentState enumeration type. Added the updateCategoryEnrollmentInformation resource type. Removed the updateCategory property from the updateManagementEnrollment resource. Added the feature property to the updateManagementEnrollment resource. Added the quality property to the updateManagementEnrollment resource. Added the driver property to the updateManagementEnrollment resource. Deprecated the updatableAssetEnrollment resource. The updatableAssetEnrollment resource is deprecated and stopped returning data on July 1, 2024. Removed the enrollments property from the azureADDevice resource. Added the enrollment property to the azureADDevice resource.

betaMicrosoft GraphIdentity and access

Added the accessReviewContextData resource. Added the calloutRequest resource. Added the data resource. Added the app…

Added the accessReviewContextData resource. Added the calloutRequest resource. Added the data resource. Added the applyDecisionContextData resource. Added the accessReviewContextDataBase resource. Removed the source property from the customDataProvidedResourceUploadSessionRequest resource. Removed the type property from the customDataProvidedResourceUploadSessionRequest resource. Added the customDataProvidedResourceAccessReviewUploadSession resource. Removed the source property from the customDataProvidedResourceUploadSession resource. Removed the type property from the customDataProvidedResourceUploadSession resource.

betaMicrosoft GraphIdentity and access

Removed the accessReviewDataUploadTriggerCallbackData resource. Removed the accessReviewResourceDataUploadSessionCont…

Removed the accessReviewDataUploadTriggerCallbackData resource. Removed the accessReviewResourceDataUploadSessionContextData resource. Removed the source property from the customDataProvidedResourceUploadSessionRequest resource. Removed the type property from the customDataProvidedResourceUploadSessionRequest resource. Removed the customExtensionData resource. Added the accessPackageAssignmentResourceRole resource. Added the customDataProvidedResourceAccessReviewUploadSession resource. Removed the source property from the customDataProvidedResourceUploadSession resource. Removed the type property from the customDataProvidedResourceUploadSession resource. Added the accessReviewContextData resource. Added the accessReviewContextDataBase resource. Added the applyDecisionContextData resource. Added the calloutRequest resource. Added the data resource.

betaMicrosoft GraphTenants

Added the migrate method to the crossTenantMigrationJob resource. Changed the behavior of the validate method on the…

Added the migrate method to the crossTenantMigrationJob resource. Changed the behavior of the validate method on the crossTenantMigrationJob resource to validate an existing job as an entity-bound action. Going forward, use the POST /solutions/migrations/crossTenantMigrationJobs/{crossTenantMigrationJobId}/validate endpoint to trigger the validation of an existing cross-tenant migration job. Removed the displayName parameter from the validate method. Removed the completeAfterDateTime parameter from the validate method. Removed the sourceTenantId parameter from the validate method. Removed the exchangeSettings parameter from the validate method. Removed the workloads parameter from the validate method. Removed the resourceType parameter from the validate method. Removed the resources parameter from the validate method.

betaMicrosoft GraphSecurity

Added the detectionRuleStatus enumeration type. Added the accountObjectIdAction resource. Added the accountSidAction…

Added the detectionRuleStatus enumeration type. Added the accountObjectIdAction resource. Added the accountSidAction resource. Added the alertCustomDetails resource. Removed the alertTemplate resource. Deprecated the allowFileResponseAction resource. Added the automatedAction resource. Added the automatedActionSet resource. Deprecated the blockFileResponseAction resource. Deprecated the collectInvestigationPackageResponseAction resource. Removed the detectionAction resource. Added the deviceAction resource. Deprecated the disableUserResponseAction resource. Added the emailAction resource. Added the fileAction resource. Deprecated the forceUserPasswordResetResponseAction resource. Deprecated the hardDeleteResponseAction resource. Deprecated the impactedAsset resource. Deprecated the impactedDeviceAsset resource. Deprecated the impactedMailboxAsset resource. Deprecated the impactedUserAsset resource. Deprecated the initiateInvestigationResponseAction resource. Added the isolateDeviceAction resource. Deprecated the isolateDeviceResponseAction resource. Deprecated the markUserAsCompromisedResponseAction resource. Added the mitreTactic resource. Added the mitreTechnique resource. Deprecated the moveToDeletedItemsResponseAction resource. Deprecated the moveToInboxResponseAction resource. Deprecated the moveToJunkResponseAction resource. Added the deviceGroups property to the organizationalScope resource. Deprecated the organizationalScope resource. Deprecated the organizationalScope resource. Deprecated the queryCondition resource. Deprecated the responseAction resource. Deprecated the restrictAppExecutionResponseAction resource. Added the frequency property to the ruleSchedule resource. Deprecated the ruleSchedule resource. Deprecated the ruleSchedule resource. Deprecated the runAntivirusScanResponseAction resource. Deprecated the runDetails resource. Deprecated the softDeleteResponseAction resource. Added the stopAndQuarantineFileAction resource. Deprecated the stopAndQuarantineFileResponseAction resource. Added the accountEntityMapping resource. Added the alertTemplate resource. Added the amazonResourceEntityMapping resource. Added the azureResourceEntityMapping resource. Added the cloudApplicationEntityMapping resource. Added the detectionAction resource. Added the createdBy property to the detectionRule resource. Added the createdDateTime property to the detectionRule resource. Added the description property to the detectionRule resource. Removed the detectionAction property from the detectionRule resource. Deprecated the detectionRule resource. Added the displayName property to the detectionRule resource. Added the id property to the detectionRule resource. Added the isEnabled property to the detectionRule resource. Added the lastModifiedBy property to the detectionRule resource. Added the lastModifiedDateTime property to the detectionRule resource. Deprecated the detectionRule resource. Added the status property to the detectionRule resource. Added the detectionAction relationship to the detectionRule resource. Added the dnsEntityMapping resource. Added the entityMapping resource. Added the entityMappingConfiguration resource. Added the fileEntityMapping resource. Added the googleCloudResourceEntityMapping resource. Added the hostEntityMapping resource. Added the ipEntityMapping resource. Added the mailboxEntityMapping resource. Added the mailClusterEntityMapping resource. Added the mailMessageEntityMapping resource. Added the oAuthApplicationEntityMapping resource. Added the processEntityMapping resource. Removed the protectionRule resource. Added the registryValueEntityMapping resource. Added the securityGroupEntityMapping resource. Added the urlEntityMapping resource.

v1.0Microsoft GraphApplications

Added the applicationDataType enumeration type. Added the csaStarLevel enumeration type. Added the dataProtection enu…

Added the applicationDataType enumeration type. Added the csaStarLevel enumeration type. Added the dataProtection enumeration type. Added the dataRetentionLevel enumeration type. Added the fedRampLevel enumeration type. Added the holdType enumeration type. Added the passwordPolicy enumeration type. Added the pciVersion enumeration type. Added the restEncryptionType enumeration type. Added the sslVersion enumeration type. Added the userOwnership enumeration type. Added the applicationLocation resource. Added the applicationRiskFactorCertificateInfo resource. Added the applicationRiskFactorGeneralInfo resource. Added the applicationRiskFactorLegalInfo resource. Added the applicationRiskFactorLegalInfoGdpr resource. Added the applicationRiskFactors resource. Added the applicationRiskFactorSecurityInfo resource. Added the applicationRiskScore resource. Added the applicationSecurityCompliance resource. Added the deprecationDate property to the applicationTemplate resource. Added the endpoints property to the applicationTemplate resource. Added the isEntraIntegrated property to the applicationTemplate resource. Added the lastModifiedDateTime property to the applicationTemplate resource. Added the riskFactors property to the applicationTemplate resource. Added the riskScore property to the applicationTemplate resource. Added the licenseRequired resource.

betaMicrosoft GraphDevice and app management

Removed the troubleshootDetailsReport member from the cloudPCTroubleshootReportType enumeration. Removed the troubles…

Removed the troubleshootDetailsReport member from the cloudPCTroubleshootReportType enumeration. Removed the troubleshootTrendCountReport member from the cloudPCTroubleshootReportType enumeration. Removed the troubleshootRegionalReport member from the cloudPCTroubleshootReportType enumeration. Removed the troubleshootIssueCountReport member from the cloudPCTroubleshootReportType enumeration. Added the troubleshootTenantGlobalFilterReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootTenantNetworkTrendReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootTenantNetworkAggregatedReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootTenantConnectionFailureRateTrendReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootTenantConnectionFailureRateAggregatedReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootTenantCloudPCHealthTrendReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootTenantCloudPCHealthAggregatedReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootTenantActiveConnectionCountTrendReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootTenantActiveConnectionCountAggregatedReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootTenantMeanTimeToFailureTrendReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootTenantMeanTimeToFailureAggregatedReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootTenantRemoteSignInTimeTrendReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootTenantRemoteSignInTimeAggregatedReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootEventsOfViewDataTableReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootTenantEnvironmentMetricsOfViewDataTableReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootCloudPCMetricsOfViewDataTableReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootConfigurationConnectionCountTrendV1Report member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootConfigurationTotalConnectionCountBarV1Report member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootConfigurationGlobalFilterV1Report member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootConnectionConfigurationOfViewDataTableV1Report member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootTenantConnectedDevicesOfViewDataTableReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootEnvironmentOverviewOfViewDataTableReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootCloudPCNetworkTrendReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootCloudPCNetworkAggregatedReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootCloudPCErrorTrendReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootCloudPCErrorAggregatedReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootCloudPCDurationTrendReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootCloudPCDurationAggregatedReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootCloudPCRemoteSignInTimeTrendReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootCloudPCRemoteSignInTimeAggregatedReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootCloudPCListReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootCloudPCHealthTrendReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootMatchedUserReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootMatchedCloudPCReport member to the cloudPCTroubleshootReportType enumeration. Added the troubleshootUserListReport member to the cloudPCTroubleshootReportType enumeration.

betaMicrosoft GraphCompliance

Added the AlertSubmission member to the auditLogRecordType enumeration. Removed the ReportSubmission member from the…

Added the AlertSubmission member to the auditLogRecordType enumeration. Removed the ReportSubmission member from the auditLogRecordType enumeration. Added the AlertSubmissionResultDetail member to the auditLogRecordType enumeration. Removed the ReportSubmissionResultDetail member from the auditLogRecordType enumeration. Added the ComplianceSitGradingSharePoint member to the auditLogRecordType enumeration. Added the CompliancePolicyGradingSharePoint member to the auditLogRecordType enumeration. Added the AzureAISearchAudit member to the auditLogRecordType enumeration. Added the P4AIRiskScoreRecord member to the auditLogRecordType enumeration. Added the DragonCopilotAdmin member to the auditLogRecordType enumeration. Added the AISpanOutputs member to the auditLogRecordType enumeration. Added the EopSubmissionFeedEntity member to the auditLogRecordType enumeration. Added the SonarFileDetonationEntity member to the auditLogRecordType enumeration. Added the SonarSubmissionEntity member to the auditLogRecordType enumeration. Added the SonarUrlDetonationEntity member to the auditLogRecordType enumeration. Added the SubmissionEntity member to the auditLogRecordType enumeration. Added the SonarDetonationEntity member to the auditLogRecordType enumeration. Added the MicrosoftTeamsUserConcern member to the auditLogRecordType enumeration. Added the VivaGlintAgenticCampaign member to the auditLogRecordType enumeration. Added the MSPVectorSearchContentMetadata member to the auditLogRecordType enumeration. Added the FabricPolicy member to the auditLogRecordType enumeration. Added the SecurityCopilotAgentIdentityManagement member to the auditLogRecordType enumeration. Added the CopilotSessionSharing member to the auditLogRecordType enumeration. Added the DragonCopilotAccess member to the auditLogRecordType enumeration. Added the DragonCopilotClinicalData member to the auditLogRecordType enumeration. Added the DragonCopilotSession member to the auditLogRecordType enumeration. Added the aISpanOutputsAuditRecord resource. Added the alertSubmissionAuditRecord resource. Added the alertSubmissionResultDetailAuditRecord resource. Added the dynamicProperties property to the auditData resource. Added the auditRecordTypeDictionary resource. Added the azureAISearchAuditRecord resource. Added the compliancePolicyGradingSharePointAuditRecord resource. Added the complianceSitGradingSharePointAuditRecord resource. Added the copilotSessionSharingAuditRecord resource. Added the eopSubmissionFeedEntityAuditRecord resource. Added the fabricPolicyRecord resource. Added the microsoftTeamsUserConcernAuditRecord resource. Added the mspVectorSearchContentMetadataAuditRecord resource. Added the p4AIRiskScoreRecord resource. Removed the reportSubmission resource. Removed the reportSubmissionResultDetail resource. Added the securityCopilotIdentityManagementAuditRecord resource. Added the sonarDetonationEntityAuditRecord resource. Added the sonarFileDetonationEntityAuditRecord resource. Added the sonarSubmissionEntityAuditRecord resource. Added the sonarUrlDetonationEntityAuditRecord resource. Added the submissionEntityAuditRecord resource. Added the vivaGlintAgenticCampaignAuditRecord resource. Added the MosAgentInfoRecordV2 member to the auditLogRecordType enumeration. Added the SecurityDevelopmentLifecycleAILog member to the auditLogRecordType enumeration. Added the MDASH member to the auditLogRecordType enumeration. Added the DefenderSecurityForAIConfiguration member to the auditLogRecordType enumeration. Added the SparkCoreCustomLivePool member to the auditLogRecordType enumeration. Added the mosAgentInfoRecordV2 resource type. Added the securityDevelopmentLifecycleAILogAuditRecord resource type. Added the mDASHAuditRecord resource type. Added the defenderSecurityForAIConfigurationAuditRecord resource type. Added the sparkCoreCustomLivePoolRecord resource type. Added the dragonCopilotAccessRecord resource type. Added the dragonCopilotAdminRecord resource type. Added the dragonCopilotClinicalDataRecord resource type. Added the dragonCopilotSessionRecord resource type.

UpcomingMicrosoft Entra IDEntra Connect

Enhanced admin authorization for Microsoft Entra Connect Sync configuration changes

We're enhancing the security posture of Microsoft Entra Connect Sync by introducing interactive admin authorization for configuration changes. With this update, an authorized administrator will need to sign in and explicitly approve changes to sync settings, ensuring that configuration updates are intentional and made by the right person.

betaMicrosoft GraphAgents

Added a deprecation notice to the agentRegistry resource and related APIs indicating that these Agent Registry APIs w…

Update before removal May 1, 2026 · passed 128d ago

Added a deprecation notice to the agentRegistry resource and related APIs indicating that these Agent Registry APIs will be replaced by Agent 365-based APIs starting May 1, 2026. Added a deprecation notice to the agentCardManifest resource indicating that these Agent Registry APIs will be replaced by Agent 365-based APIs starting May 1, 2026. Added a deprecation notice to the agentCollection resource indicating that these Agent Registry APIs will be replaced by Agent 365-based APIs starting May 1, 2026. Added a deprecation notice to the agentInstance resource indicating that these Agent Registry APIs will be replaced by Agent 365-based APIs starting May 1, 2026.

v1.0×2 recordsMicrosoft GraphTeamwork and communications

Deleted the model query parameter from the update operation of the chatMessage resource. Deleted the model query para…

Deleted the model query parameter from the update operation of the chatMessage resource. Deleted the model query parameter from the chats: getAllMessages method. Deleted the model query parameter from the chat: getAllRetainedMessages method. Deleted the model query parameter from the channel: getAllMessages method. Deleted the model query parameter from the channel: getAllRetainedMessages method. Deleted the model query parameter from the deletedTeam: getAllMessages method. Deleted the model query parameter from the create operation of the subscription resource.

betaMicrosoft GraphIdentity and access

Added the keyCredentials property to the appManagementConfiguration resource. Added the passwordCredentials property…

Added the keyCredentials property to the appManagementConfiguration resource. Added the passwordCredentials property to the appManagementConfiguration resource. Removed the keyCredentials relationship from the appManagementConfiguration resource. Removed the passwordCredentials relationship from the appManagementConfiguration resource. Added the customSecurityAttributes property to the appManagementPolicyActorExemptions resource. Removed the customSecurityAttributes relationship from the appManagementPolicyActorExemptions resource. Changed the customSecurityAttributeExemption resource from an entity type to a complex type. Changed the customSecurityAttributeStringValueExemption resource from an entity type to a complex type. Changed the keyCredentialConfiguration resource from an entity type to a complex type. Changed the passwordCredentialConfiguration resource from an entity type to a complex type.

UpcomingMicrosoft Entra IDEntra Connect

Migrate from Microsoft Entra Connect Sync to Microsoft Entra Cloud Sync

As organizations look to strengthen identity security and advance their Zero Trust strategies, many are looking for simpler, more reliable ways to manage hybrid identity. To support these needs, we’re beginning the transition from Microsoft Entra Connect Sync to the cloud‑native Microsoft Entra Cloud Sync - helping reduce on‑premises complexity while improving security, reliability, and day‑to‑day manageability.

betaMicrosoft GraphMicrosoft.Intune.AndroidFOTA

Added the samsungEFotaFirmwareVersion resource. Added the samsungEFotaFirmwareVersionTarget resource. Added the samsu…

Added the samsungEFotaFirmwareVersion resource. Added the samsungEFotaFirmwareVersionTarget resource. Added the samsungEFotaFirmwareVersions property to the deviceManagement resource. Removed the samsungEFotaFirmwareVersions relationship from the deviceManagement resource. Removed the samsungEFotaFirmwareVersion resource. Removed the samsungEFotaFirmwareVersionTarget resource. Added the androidAppCredentialProviderRoleState enumeration type. Added the credentialProviderRoleState property to the androidForWorkMobileAppConfiguration resource. Added the credentialProviderRoleState property to the androidManagedStoreAppConfiguration resource. Added the wpa3Personal member to the wiFiSecurityType enumeration. Added the isKioskModeExitCodeSet property to the androidDeviceOwnerGeneralDeviceConfiguration resource. Added the controlledConfigurationEnabled property to the windowsProtectionState resource. Added the windowsZtdnsExemptionRule resource. Added the deviceConfiguration resource. Added the windowsZtdnsConfiguration resource. Added the releaseAppleDevices method to the depOnboardingSetting resource. Added the deviceAndAppManagementAssignmentFilterType enumeration type. Added the deviceAndAppManagementAssignmentSource enumeration type. Added the deviceAndAppManagementPayloadType enumeration type. Added the devicePlatformType enumeration type. Added the allDevicesAssignmentTarget resource. Added the allLicensedUsersAssignmentTarget resource. Added the configurationManagerCollectionAssignmentTarget resource. Added the deviceAndAppManagementAssignmentTarget resource. Added the exclusionGroupAssignmentTarget resource. Added the groupAssignmentTarget resource. Added the deviceManagement resource.

Latest changes

LaunchedMicrosoft 365 admin centerMicrosoft Copilot (Microsoft 365)

Microsoft 365 admin center: Capacity Pack Support for SharePoint Agent and Copilot Tuning in MAC

To help organizations manage metered consumption costs for SharePoint Agents and Copilot Tuning, we are introducing support for Capacity Packs in the Microsoft 365 Admin Center (MAC). This feature allows global administrators to use prepaid message subscriptions before incurring pay-as-you-go (PAYG) charges. Each Capacity Pack provides 25,000 Copilot messages per month, which can be allocated to Copilot Chat environments via the Power Platform Admin Center (PPAC). Once enabled, MAC will prioritize consumption from these prepaid packs and automatically switch to PAYG when the pack is exhausted. Admins can monitor usage in PPAC, including: • Total messages consumed • Remaining prepaid capacity • Message allocation per environment Key Benefits: • Streamlined billing setup in MAC • Reduced risk of overage charges • Automated environment provisioning for Copilot Chat • Improved cost visibility and governance

CriticalCloud + on-premSharePoint ServerMicrosoft OfficeMicrosoft 365 Apps

Microsoft Office Remote Code Execution Vulnerability

Remote Code Execution · Critical · CVSS 8.4. Affects: SharePoint Server, Microsoft Office, Microsoft 365 Apps, Microsoft Office LTSC for Mac, Microsoft Office LTSC, Microsoft Office 365 for Mac.

CriticalCloud + on-premSharePoint ServerMicrosoft OfficeMicrosoft 365 Apps

Microsoft Word Remote Code Execution Vulnerability

Remote Code Execution · Critical · CVSS 7.8. Affects: SharePoint Server, Microsoft Office, Microsoft 365 Apps, Microsoft Office LTSC for Mac, Microsoft Office LTSC, Microsoft Word.

CriticalCloud + on-premSharePoint ServerMicrosoft OfficeMicrosoft 365 Apps

Microsoft Word Remote Code Execution Vulnerability

Remote Code Execution · Critical · CVSS 7.8. Affects: SharePoint Server, Microsoft Office, Microsoft 365 Apps, Microsoft Office LTSC for Mac, Microsoft Office LTSC, Microsoft Word.

CriticalCloud + on-premMicrosoft Office 365 for MacSharePoint ServerMicrosoft Office

Microsoft Word Remote Code Execution Vulnerability

Remote Code Execution · Critical · CVSS 7.8. Affects: Microsoft Office 365 for Mac, SharePoint Server, Microsoft Office, Microsoft 365 Apps, Microsoft Office LTSC for Mac, Microsoft Office LTSC.

CriticalCloud + on-premMicrosoft Office 365 for MacMicrosoft OfficeMicrosoft 365 Apps

Microsoft Office Remote Code Execution Vulnerability

Remote Code Execution · Critical · CVSS 7.8. Affects: Microsoft Office 365 for Mac, Microsoft Office, Microsoft 365 Apps, Microsoft Office LTSC for Mac, Microsoft Office LTSC.

CriticalCloud + on-premMicrosoft OfficeMicrosoft 365 AppsMicrosoft Office LTSC for Mac

Microsoft Office Remote Code Execution Vulnerability

Remote Code Execution · Critical · CVSS 7.8. Affects: Microsoft Office, Microsoft 365 Apps, Microsoft Office LTSC for Mac, Microsoft Office LTSC, Microsoft Office 365 for Mac.

CriticalCloud + on-premMicrosoft Office 365 for MacMicrosoft OfficeMicrosoft 365 Apps

Microsoft Office Remote Code Execution Vulnerability

Remote Code Execution · Critical · CVSS 7.8. Affects: Microsoft Office 365 for Mac, Microsoft Office, Microsoft 365 Apps, Microsoft Office LTSC for Mac, Microsoft Office LTSC.

CriticalCloud + on-premMicrosoft Office 365 for MacMicrosoft OfficeMicrosoft 365 Apps

Microsoft Office Remote Code Execution Vulnerability

Remote Code Execution · Critical · CVSS 7.8. Affects: Microsoft Office 365 for Mac, Microsoft Office, Microsoft 365 Apps, Microsoft Office LTSC for Mac, Microsoft Office LTSC.

CriticalCloud + on-premMicrosoft Office 365 for MacMicrosoft OfficeMicrosoft 365 Apps

Microsoft PowerPoint Remote Code Execution Vulnerability

Remote Code Execution · Critical · CVSS 7.8. Affects: Microsoft Office 365 for Mac, Microsoft Office, Microsoft 365 Apps, Microsoft Office LTSC for Mac, Microsoft Office LTSC, Microsoft PowerPoint.

CriticalCloud + on-premMicrosoft OfficeMicrosoft 365 AppsMicrosoft Office LTSC for Mac

Microsoft Office Remote Code Execution Vulnerability

Remote Code Execution · Critical · CVSS 7.8. Affects: Microsoft Office, Microsoft 365 Apps, Microsoft Office LTSC for Mac, Microsoft Office LTSC, Microsoft Office 365 for Mac.

CriticalCloud + on-premMicrosoft OfficeMicrosoft 365 AppsMicrosoft Office LTSC for Mac

Microsoft Office Remote Code Execution Vulnerability

Remote Code Execution · Critical · CVSS 7.8. Affects: Microsoft Office, Microsoft 365 Apps, Microsoft Office LTSC for Mac, Microsoft Office LTSC, Microsoft Office 365 for Mac.

CriticalCloud + on-premMicrosoft OfficeMicrosoft 365 AppsMicrosoft Office LTSC for Mac

Microsoft PowerPoint Remote Code Execution Vulnerability

Remote Code Execution · Critical · CVSS 7.8. Affects: Microsoft Office, Microsoft 365 Apps, Microsoft Office LTSC for Mac, Microsoft Office LTSC, Microsoft PowerPoint, Microsoft Office 365 for Mac.

CriticalCloud + on-premMicrosoft Office 365 for MacMicrosoft OfficeMicrosoft 365 Apps

Microsoft PowerPoint Remote Code Execution Vulnerability

Remote Code Execution · Critical · CVSS 7.8. Affects: Microsoft Office 365 for Mac, Microsoft Office, Microsoft 365 Apps, Microsoft Office LTSC for Mac, Microsoft Office LTSC, Microsoft PowerPoint.