Skip to content

Commit 1f50bd0

Browse files
committed
Merge branch 'main' into kwekua-freshness-feb-25
2 parents e5342d9 + d50af56 commit 1f50bd0

10 files changed

Lines changed: 2767 additions & 68 deletions

copilot/release-notes.md

Lines changed: 2660 additions & 7 deletions
Large diffs are not rendered by default.

microsoft-365/commerce/billing-and-payments/manage-payment-methods.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ f1.keywords:
55
author: cmcatee-MSFT
66
ms.author: cmcatee
77
manager: scotv
8-
ms.reviewer: lishepar, ramagane
8+
ms.reviewer: lishepar, jobailey
99
audience: Admin
1010
ms.topic: how-to
1111
ms.service: microsoft-365-business

microsoft-365/commerce/use-cost-mgmt.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ title: "Use Cost management in the Microsoft 365 admin center"
33
author: cmcatee-MSFT
44
ms.author: cmcatee
55
manager: scotv
6-
ms.reviewer: jkinma, ramagane
6+
ms.reviewer: shrshett, vikdesai
77
audience: Admin
88
ms.topic: article
99
ms.service: microsoft-365-business

microsoft-365/enterprise/microsoft-365-non-compliant-shared-mailboxes-exo-service-advisory.md

Lines changed: 27 additions & 27 deletions
Original file line numberDiff line numberDiff line change
@@ -28,13 +28,13 @@ description: "Learn about service advisories for non-compliant shared mailboxes
2828

2929
An Exchange Online service advisory informs you about shared mailboxes which are out of compliance. These service advisories provide visibility to the number of shared mailboxes in your organization that might require admin intervention.
3030

31-
These service advisories are displayed in the Microsoft 365 admin center. To view these service advisories, you can go to **Health > Service health > Overview** and then look for **Shared mailbox(es) have exceeded the 50 GB storage limit in your tenant**, or you can go **Health > Service health > Exchange Online** and select the **Active issues** tab. Here's an example of a non-compliant shared mailbox service advisory under Service Health.
31+
These service advisories are displayed in the Microsoft 365 admin center. To view these service advisories, you can go to **Health > Service health > Overview** and then look for **Shared mailbox(es) have exceeded the 50 GB storage limit in your tenant**, or you can go to **Health > Service health > Exchange Online** and select the **Active issues** tab. Here's an example of a non-compliant shared mailbox service advisory under Service Health.
3232

3333
:::image type="content" source="../media/m365-non-compliant-shared-mailboxes-exo-service-advisory-1.png" alt-text="Service health - issues for your organization to act on":::
3434

3535
## What does this service advisory indicate?
3636

37-
The service advisories for non-compliant shared mailboxes inform admins about their tenants having shared mailboxes that exceed 50 GB storage and don't have a required license. These advisories provide awareness so that you can take these limits into consideration when managing and troubleshooting shared mailboxes.
37+
The service advisories for non-compliant shared mailboxes inform admins about their tenants having shared mailboxes that exceed 50 GB storage without having the required licenses. These advisories provide awareness so that you can take these limits into consideration when managing and troubleshooting shared mailboxes.
3838

3939
Here’s an example of the advisory:
4040

@@ -46,43 +46,43 @@ You can expect to see this type of advisory until the time when shared mailbox s
4646

4747
## More information
4848

49-
Identifying Non-compliant Shared Mailboxes is a two-step process:
49+
Identifying non-compliant shared mailboxes is a two-step process:
5050

51-
1. Identify Shared Mailboxes with > 50 GB storage
52-
2. Check licensing for those Shared Mailboxes
51+
1. Identify shared mailboxes with > 50 GB storage.
52+
2. Check licensing for those shared mailboxes.
5353

54-
## Identifying Non-Compliant Shared Mailboxes in Exchange Online via Exchange Admin Center
54+
## Identifying non-compliant shared mailboxes in Exchange Online via Exchange Admin Center
5555

56-
To ensure your shared mailboxes comply with Exchange storage limits, follow these steps to identify those exceeding 50 GB and check their licensing status.
56+
To ensure your shared mailboxes comply with Exchange storage limits, follow these steps to identify those exceeding 50 GB and to check their licensing status.
5757

58-
### Retrieve Shared Mailboxes Exceeding 50 GB
58+
### Retrieve shared mailboxes exceeding 50 GB
5959

60-
1. Access the Exchange Admin Center Portal.
60+
1. Access the Microsoft 365 admin center portal.
6161
2. Generate Usage Reports:
62-
- Go to **Reports -> Usage -> Exchange**.
63-
- Select **Mailbox Usage**.
62+
1. Go to **Reports -> Usage -> Exchange**.
63+
1. Select **Mailbox Usage**.
6464
3. Export Mailbox Data:
65-
- Ensure the **Recipient type** column is checked.
66-
- Select **Export** to download the report.
65+
1. Ensure the **Recipient type** column is checked.
66+
1. Select **Export** to download the report.
6767
4. Filter Shared Mailboxes:
68-
- Open the downloaded CSV file.
69-
- Filter the **Recipient type** column to show only "**Shared**" mailboxes.
68+
1. Open the downloaded CSV file.
69+
1. Filter the **Recipient type** column to show only "**Shared**" mailboxes.
7070
5. Convert Storage Data:
71-
- The Storage Used (Byte) column displays data in Bytes. Convert this to Gigabytes (GB) by dividing the values by 1,073,741,824 (1024^3).
72-
6. Identify Mailboxes with Storage > 50 GB:
73-
- Filter the converted storage data to identify mailboxes with sizes greater than 50 GB.
71+
1. The **Storage Used (Byte)** column displays data in "Bytes". Convert this to Gigabytes (GB) by dividing the values by 1,073,741,824 (1024^3).
72+
6. Identify mailboxes with Storage > 50 GB:
73+
1. Filter the converted storage data to identify mailboxes with sizes greater than 50 GB.
7474

75-
### Check Licensing for Shared Mailboxes exceeding 50 GB
75+
### Check licensing for shared mailboxes exceeding 50 GB
7676

77-
1. Access Active Users:
78-
- Go to **Home -> Active Users**.
79-
2. Locate Mailboxes with Storage > 50 GB:
80-
- Select the mailboxes identified in the previous step 6 that have more than 50 GB of storage.
81-
3. Verify Licensing:
82-
- Go to **License and Apps** for the selected user.
83-
- If the mailbox is assigned Exchange Online (Plan 1), it isn't in compliance. You need to either assign Exchange Online (Plan 2) or reduce the storage to less than 50 GB.
77+
1. Access active users:
78+
1. Go to **Home -> Active Users**.
79+
2. Locate mailboxes with storage > 50 GB:
80+
1. Select the mailboxes identified in the earlier step that have more than 50 GB of storage.
81+
3. Verify licensing:
82+
1. Go to **License and Apps** for the selected user.
83+
1. If the mailbox is assigned Exchange Online (Plan 1), it isn't in compliance. You need to either assign Exchange Online (Plan 2) or reduce the storage to less than 50 GB.
8484

85-
## Identifying Non-Compliant Shared Mailboxes in Exchange Online through PowerShell
85+
## Identifying non-compliant shared mailboxes in Exchange Online through PowerShell
8686

8787
You can use PowerShell to identify non-compliant shared mailboxes. Save the following script to your local hard drive and run it in PowerShell:
8888

microsoft-365/enterprise/microsoft-365-u-s-government-dod-endpoints.md

Lines changed: 21 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ title: Microsoft 365 US Government DOD endpoints
33
ms.author: kvice
44
author: kelleyvice-msft
55
manager: scotv
6-
ms.date: 02/28/2025
6+
ms.date: 03/31/2025
77
audience: ITPro
88
ms.topic: article
99
ms.service: microsoft-365-enterprise
@@ -21,7 +21,7 @@ search.appverid:
2121
ms.assetid: 5d7dce60-4892-4b58-b45e-ee42fe8a907f
2222
f1.keywords:
2323
- NOCSH
24-
description: Microsoft 365 requires connectivity to the Internet. The endpoints below should be reachable for customers using Microsoft 365 U.S. Government DoD plans only.
24+
description: Microsoft 365 requires connectivity to the Internet. The following endpoints should be reachable for customers using Microsoft 365 U.S. Government DoD plans only.
2525
hideEdit: true
2626
ms.custom: seo-marvel-mar2020
2727
---
@@ -30,7 +30,7 @@ ms.custom: seo-marvel-mar2020
3030

3131
*Applies To: Microsoft 365 Admin*
3232

33-
Microsoft 365 requires connectivity to the Internet. The endpoints below should be reachable for customers using Microsoft 365 U.S. Government DoD plans only.
33+
Microsoft 365 requires connectivity to the Internet. The following endpoints should be reachable for customers using Microsoft 365 U.S. Government DoD plans only.
3434

3535
**Microsoft 365 endpoints:** [Worldwide (including GCC)](urls-and-ip-address-ranges.md) \| [Microsoft 365 operated by 21 Vianet](urls-and-ip-address-ranges-21vianet.md) \| *Microsoft 365 U.S. Government DoD* \| [Microsoft 365 U.S. Government GCC High](microsoft-365-u-s-government-gcc-high-endpoints.md)
3636

@@ -42,11 +42,11 @@ Microsoft 365 requires connectivity to the Internet. The endpoints below should
4242
|**Last updated:** 02/28/2025 - ![RSS.](../media/5dc6bb29-25db-4f44-9580-77c735492c4b.png) [Change Log subscription](https://endpoints.office.com/version/USGOVDoD?allversions=true&format=rss&clientrequestid=b10c5ed1-bad1-445f-b386-b919946339a7)|**Download:** the full list in [JSON format](https://endpoints.office.com/endpoints/USGOVDoD?clientrequestid=b10c5ed1-bad1-445f-b386-b919946339a7)|
4343
|
4444

45-
Start with [Managing Microsoft 365 endpoints](managing-office-365-endpoints.md) to understand our recommendations for managing network connectivity using this data. Endpoints data is updated as needed at the beginning of each month with new IP Addresses and URLs published 30 days in advance of being active. This lets customers who don't yet have automated updates to complete their processes before new connectivity is required. Endpoints may also be updated during the month if needed to address support escalations, security incidents, or other immediate operational requirements. The data shown on this page below is all generated from the REST-based web services. If you're using a script or a network device to access this data, you should go to the [Web service](microsoft-365-ip-web-service.md) directly.
45+
Start with [Managing Microsoft 365 endpoints](managing-office-365-endpoints.md) to understand our recommendations for managing network connectivity using this data. Endpoints data is updated as needed at the beginning of each month with new IP Addresses and URLs published 30 days in advance of being active. This lets customers who don't yet have automated updates to complete their processes before new connectivity is required. Endpoints might also be updated during the month if needed to address support escalations, security incidents, or other immediate operational requirements. The data shown on this page is all generated from the REST-based web services. If you're using a script or a network device to access this data, you should go to the [Web service](microsoft-365-ip-web-service.md) directly.
4646

4747
Endpoint data below lists requirements for connectivity from a user's machine to Microsoft 365. It doesn't include network connections from Microsoft into a customer network, sometimes called hybrid or inbound network connections. For more information, see [Additional endpoints not included in the web service](additional-office365-ip-addresses-and-urls.md).
4848

49-
The Microsoft 365 suite is broken down into four major service areas representing the three primary workloads and a set of common resources. These service areas may be used to associate traffic flows with a particular application, however given that features often consume endpoints across multiple workloads, these service areas can't effectively be used to restrict access.
49+
The Microsoft 365 suite is broken down into four major service areas representing the three primary workloads and a set of common resources. These service areas might be used to associate traffic flows with a particular application, however given that features often consume endpoints across multiple workloads, these service areas can't effectively be used to restrict access.
5050

5151
Data columns shown are:
5252

@@ -56,14 +56,27 @@ Data columns shown are:
5656

5757
- **ER**: This is **Yes** if the endpoint set is supported over Azure ExpressRoute with Microsoft 365 route prefixes. The BGP community that includes the route prefixes shown aligns with the service area listed. When ER is **No**, this means that ExpressRoute isn't supported for this endpoint set. However, it shouldn't be assumed that no routes are advertised for an endpoint set where ER is **No**. If you plan to use Microsoft Entra Connect, read the [special considerations section](/azure/active-directory/hybrid/reference-connect-instances#microsoft-azure-government) to ensure you have the appropriate Microsoft Entra Connect configuration.
5858

59-
- **Addresses**: Lists the FQDNs or wildcard domain names and IP Address ranges for the endpoint set. Note that an IP Address range is in CIDR format and may include many individual IP Addresses in the specified network.
59+
- **Addresses**: Lists the FQDNs or wildcard domain names and IP Address ranges for the endpoint set. An IP Address range is in CIDR format and might include many individual IP Addresses in the specified network.
6060

61-
- **Ports**: Lists the TCP or UDP ports that are combined with the Addresses to form the network endpoint. You may notice some duplication in IP Address ranges where there are different ports listed.
61+
- **Ports**: Lists the TCP or UDP ports that are combined with the Addresses to form the network endpoint. You might notice some duplication in IP Address ranges where there are different ports listed.
62+
63+
## Microsoft 365 Unified Domains
64+
65+
> [!NOTE]
66+
> In response to customer feedback and to streamline endpoint management, Microsoft has initiated the process of consolidating Microsoft 365 apps and services into a select group of dedicated, secured, and purpose-managed domains within the **.microsoft** top level domain (TLD).
67+
>
68+
> To avoid connectivity issues for users, ensure that the following essential domains are included in your allowlist and that connectivity to these domains isn't blocked.
69+
70+
| ID | Category | Domain name| Purpose | Ports |
71+
|---|---|---|---|---|
72+
|12|Required|`*.usgovcloud.microsoft`|Dedicated to authenticated user facing Microsoft SaaS product experiences.|**TCP:** 443,80<br>**UDP:** 443|
73+
|12|Required|`*.usgovcloud-static.microsoft`|Dedicated to static (not customer generated) content hosted on CDNs.|**TCP:** 443,80<br>**UDP:** 443|
74+
|12|Required|`*.usgovcloud-usercontent.microsoft`|Content used in Microsoft 365 experiences that requires domain isolation from applications.|**TCP:** 443,80<br>**UDP:** 443|
6275

6376
[!INCLUDE [Microsoft 365 U.S. Government DoD endpoints](../includes/office-365-u.s.-government-dod-endpoints.md)]
6477

6578
Notes for this table:
6679

6780
- The Security and Compliance Center (SCC) provides support for Azure ExpressRoute for Microsoft 365. The same applies for many features exposed through the SCC such as Reporting, Auditing, eDiscovery (Premium), Unified DLP, and Data Governance. Two specific features, PST Import and eDiscovery Export, currently don't support Azure ExpressRoute with only Microsoft 365 route filters due to their dependency on Azure Blob Storage. To consume those features, you need separate connectivity to Azure Blob Storage using any supportable Azure connectivity options, which include Internet connectivity or Azure ExpressRoute with Azure Public route filters. You have to evaluate establishing such connectivity for both of those features. The Microsoft 365 Information Protection team is aware of this limitation and is actively working to bring support for Azure ExpressRoute for Microsoft 365 as limited to Microsoft 365 route filters for both of those features.
6881

69-
- There are additional optional endpoints for Microsoft 365 Apps for enterprise that aren't listed and aren't required for users to launch Microsoft 365 Apps for enterprise applications and edit documents. Optional endpoints are hosted in Microsoft datacenters and don't process, transmit, or store customer data. We recommend that user connections to these endpoints be directed to the default Internet egress perimeter.
82+
- There are other optional endpoints for Microsoft 365 Apps for enterprise that aren't listed and aren't required for users to launch Microsoft 365 Apps for enterprise applications and edit documents. Optional endpoints are hosted in Microsoft datacenters and don't process, transmit, or store customer data. We recommend that user connections to these endpoints be directed to the default Internet egress perimeter.

0 commit comments

Comments
 (0)