diff --git a/.github/workflows/Publish.yml b/.github/workflows/AutoPublish.yml similarity index 80% rename from .github/workflows/Publish.yml rename to .github/workflows/AutoPublish.yml index e1d6aa38502..a7e46e4f165 100644 --- a/.github/workflows/Publish.yml +++ b/.github/workflows/AutoPublish.yml @@ -14,7 +14,7 @@ jobs: auto-publish: if: github.repository_owner == 'MicrosoftDocs' && contains(github.event.repository.topics, 'build') - uses: MicrosoftDocs/max-cpub-test/.github/workflows/Shared-Publish.yml@main + uses: MicrosoftDocs/microsoft-365-docs/.github/workflows/Shared-AutoPublish.yml@workflows-prod with: PayloadJson: ${{ toJSON(github) }} EnableAutoPublish: true @@ -22,4 +22,4 @@ jobs: secrets: AccessToken: ${{ secrets.GITHUB_TOKEN }} PrivateKey: ${{ secrets.M365_APP_PRIVATE_KEY }} - ClientId: ${{ secrets.M365_APP_CLIENT_ID }} + ClientId: ${{ secrets.M365_APP_CLIENT_ID }} \ No newline at end of file diff --git a/.github/workflows/Shared-StaleBranch.yml b/.github/workflows/Shared-StaleBranch.yml index 63b03d17dab..bf9349036cf 100644 --- a/.github/workflows/Shared-StaleBranch.yml +++ b/.github/workflows/Shared-StaleBranch.yml @@ -355,7 +355,7 @@ jobs: # If the workflow is in reporting mode, don't delete the branch. If it isn't, delete it. If (!$ReportOnly) { - #Invoke-RestMethod -Headers $GitHubHeaders -Uri $BranchDeleteUrl -Method DELETE -ResponseHeadersVariable ResponseHeaders | Out-Null + Invoke-RestMethod -Headers $GitHubHeaders -Uri $BranchDeleteUrl -Method DELETE -ResponseHeadersVariable ResponseHeaders | Out-Null } @@ -387,7 +387,7 @@ jobs: # If the workflow is in reporting mode, don't delete the branch. If it isn't, delete it. If (!$ReportOnly) { - #Invoke-RestMethod -Headers $GitHubHeaders -Uri $BranchDeleteUrl -Method DELETE -ResponseHeadersVariable ResponseHeaders | Out-Null + Invoke-RestMethod -Headers $GitHubHeaders -Uri $BranchDeleteUrl -Method DELETE -ResponseHeadersVariable ResponseHeaders | Out-Null } diff --git a/.github/workflows/StaleBranch.yml b/.github/workflows/StaleBranch.yml index eb6b63edb0d..bc93e4d9e07 100644 --- a/.github/workflows/StaleBranch.yml +++ b/.github/workflows/StaleBranch.yml @@ -2,12 +2,17 @@ name: (Scheduled) Stale branch removal permissions: contents: write - + +# This workflow is designed to be run in the days up to, and including, a "deletion day", specified by 'DeleteOnDayOfMonth' in env: in https://github.com/MicrosoftDocs/microsoft-365-docs/blob/workflows-prod/.github/workflows/Shared-StaleBranch.yml. +# On the days leading up to "deletion day", the workflow will report the branches to be deleted. This lets users see which branches will be deleted. On "deletion day", those branches are deleted. +# The workflow should not be configured to run after "deletion day" so that users can review the branches were deleted. +# Recommendation: configure cron to run on days 1,15-31 where 1 is what's configured in 'DeleteOnDayOfMonth'. If 'DeleteOnDayOfMonth' is set to something else, update cron to run the two weeks leading up to it. + on: schedule: - - cron: "0 9 1 * *" + - cron: "0 9 1,15-31 * *" - # workflow_dispatch: + workflow_dispatch: jobs: diff --git a/.openpublishing.redirection.admin.json b/.openpublishing.redirection.admin.json index d5f2b44afb5..f3664d13395 100644 --- a/.openpublishing.redirection.admin.json +++ b/.openpublishing.redirection.admin.json @@ -1,2224 +1,2244 @@ { - "redirections": [ - { - "source_path": "microsoft-365/admin/manage/manage-plugins-for-copilot-in-integrated-apps.md", - "redirect_url": "/microsoft-365/admin/manage/manage-copilot-agents-integrated-apps", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/manage/servicenow-aad-oauth-token.md", - "redirect_url": "/microsoft-365/admin/manage/servicenow-authentication", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/manage/servicenow-basic-authentication.md", - "redirect_url": "/microsoft-365/admin/manage/servicenow-authentication", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/manage/servicenow-support-integration.md", - "redirect_url": "/microsoft-365/admin/manage/servicenow-virtual-agent-integration", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/admin-overview/index.md", - "redirect_url": "admin-overview", - "redirect_document_id": true - }, - { - "source_path": "microsoft-365/admin/security-and-compliance/multi-factor-authentication-plan.md", - "redirect_url": "/microsoft-365/admin/security-and-compliance/multi-factor-authentication-microsoft-365", - "redirect_document_id": true - }, - { - "source_path": "microsoft-365/admin/services-in-china/index.md", - "redirect_url": "services-in-china", - "redirect_document_id": true - }, - { - "source_path": "microsoft-365/admin/usage-analytics/index.md", - "redirect_url": "usage-analytics", - "redirect_document_id": true - }, - { - "source_path": "microsoft-365/admin/support/afghanistan.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/aland-islands.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/albania.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/misc/integrated-apps.md", - "redirect_url": "/microsoft-365/admin/misc/user-consent", - "redirect_document_id": true - }, - { - "source_path": "microsoft-365/admin/support/algeria.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/american-samoa.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/create-groups/index.md", - "redirect_url": "create-groups", - "redirect_document_id": true - }, - { - "source_path": "microsoft-365/admin/support/andorra.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/admin-home.md", - "redirect_url": "index", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/angola.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/anguilla.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/antigua-and-barbuda.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/argentina.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/misc/index.md", - "redirect_url": "misc", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/armenia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/dns/index.md", - "redirect_url": "../setup/add-domain", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/aruba.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/manage/manage.md", - "redirect_url": "index", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/activity-reports/index.md", - "redirect_url": "activity-reports", - "redirect_document_id": true - }, - { - "source_path": "microsoft-365/admin/support/ascension.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/email/email.md", - "redirect_url": "index", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/email/email-collaboration.md", - "redirect_url": "/microsoft-365/admin/index", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/australia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/austria.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/azerbaijan.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/bahamas.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/bahrain.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/bangladesh.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/barbados.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/belarus.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/belgium.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/belize.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/benin.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/bermuda.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/bhutan.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/bolivia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/bonaire.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/bosnia-and-herzegovina.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/botswana.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/bouvet-island.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/brazil.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/british-virgin-islands.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/brunei.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/bulgaria.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/burkina-faso.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/burundi.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/cambodia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/cameroon.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/canada.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/cape-verde.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/cayman-islands.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/central-african-republic.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/chad.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/chile.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/china-prc.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/christmas-island.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/cocos-keeling-islands.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/colombia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/comoros.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/congo-drc.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/congo.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/cook-islands.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/costa-rica.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/cote-divoire.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/croatia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/curacao.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/cyprus.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/czech-republic.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/denmark.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/djibouti.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/dominica.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/dominican-republic.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/ecuador.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/egypt.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/el-salvador.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/equatorial-guinea.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/eritrea.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/estonia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/ethiopia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/falkland-islands.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/faroe-islands.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/fiji.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/finland.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/france.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/french-guiana.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/french-polynesia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/french-southern-territories.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/gabon.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/gambia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/georgia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/germany.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/ghana.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/gibraltar.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/greece.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/greenland.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/grenada.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/guadeloupe.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/guam.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/guatemala.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/guernsey.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/guinea-bissau.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/guinea.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/guyana.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/haiti.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/heard-island-and-mcdonald-islands.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/honduras.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/hong-kong-sar.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/hungary.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/iceland.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/india.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/indonesia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/iraq.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/ireland.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/isle-of-man.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/israel.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/italy.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/jamaica.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/jan-mayen.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/japan.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/jersey.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/jordan.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/kazakhstan.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/kenya.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/kiribati.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/korea.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/kosovo.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/kuwait.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/kyrgyzstan.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/laos.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/latvia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/lebanon.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/lesotho.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/liberia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/libya.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/liechtenstein.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/lithuania.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/luxembourg.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/macau-sar.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/macedonia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/madagascar.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/malawi.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/malaysia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/maldives.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/mali.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/malta.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/marshall-islands.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/martinique.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/mauritania.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/mauritius.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/mayotte.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/mexico.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/micronesia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/moldova.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/monaco.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/mongolia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/montenegro.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/montserrat.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/morocco.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/mozambique.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/myanmar.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/namibia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/nauru.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/nepal.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/netherlands.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/new-caledonia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/new-zealand.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/nicaragua.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/niger.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/nigeria.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/niue.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/norfolk-island.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/northern-mariana-islands.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/norway.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/oman.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/pakistan.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/palau.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/palestinian-authority.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/panama.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/papua-new-guinea.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/paraguay.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/peru.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/philippines.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/pitcairn-islands.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/poland.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/portugal.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/puerto-rico.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/qatar.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/reunion.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/romania.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/russia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/rwanda.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/saba.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/saint-barthelemy.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/saint-lucia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/saint-martin.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/saint-pierre-and-miquelon.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/saint-vincent-and-the-grenadines.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/samoa.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/san-marino.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/sao-tome-and-principe.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/saudi-arabia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/senegal.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/serbia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/seychelles.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/sierra-leone.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/singapore.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/sint-eustatius.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/sint-maarten.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/slovakia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/slovenia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/solomon-islands.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/somalia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/south-africa.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/south-georgia-and-south-sandwich-islands.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/south-sudan.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/spain.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/sri-lanka.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/st-helena.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/st-kitts-nevis.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/suriname.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/svalbard.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/swaziland.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/sweden.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/switzerland.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/taiwan.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/tajikistan.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/tanzania.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/thailand.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/timor-leste.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/togo.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/tokelau.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/tonga.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/trinidad-and-tobago.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/tristan-da-cunha.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/tunisia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/turkey.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/turkmenistan.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/turks-and-caicos-islands.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/tuvalu.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/uganda.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/ukraine.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/united-arab-emirates.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/united-kingdom.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/united-states.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/uruguay.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/uzbekistan.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/vanuatu.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/vatican-city.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/venezuela.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/vietnam.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/virgin-islands.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/wallis-and-futuna.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/yemen.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/zambia.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/support/zimbabwe.md", - "redirect_url": "/microsoft-365/admin/support-contact-info", - "redirect_document_id": false - }, - { + "redirections": [ + { + "source_path": "microsoft-365/admin/manage/manage-plugins-for-copilot-in-integrated-apps.md", + "redirect_url": "/microsoft-365/admin/manage/manage-copilot-agents-integrated-apps", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/manage/servicenow-aad-oauth-token.md", + "redirect_url": "/microsoft-365/admin/manage/servicenow-authentication", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/manage/servicenow-basic-authentication.md", + "redirect_url": "/microsoft-365/admin/manage/servicenow-authentication", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/manage/servicenow-support-integration.md", + "redirect_url": "/microsoft-365/admin/manage/servicenow-virtual-agent-integration", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/admin-overview/index.md", + "redirect_url": "admin-overview", + "redirect_document_id": true + }, + { + "source_path": "microsoft-365/admin/security-and-compliance/multi-factor-authentication-plan.md", + "redirect_url": "/microsoft-365/admin/security-and-compliance/multi-factor-authentication-microsoft-365", + "redirect_document_id": true + }, + { + "source_path": "microsoft-365/admin/services-in-china/index.md", + "redirect_url": "services-in-china", + "redirect_document_id": true + }, + { + "source_path": "microsoft-365/admin/usage-analytics/index.md", + "redirect_url": "usage-analytics", + "redirect_document_id": true + }, + { + "source_path": "microsoft-365/admin/support/afghanistan.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/aland-islands.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/albania.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/misc/integrated-apps.md", + "redirect_url": "/microsoft-365/admin/misc/user-consent", + "redirect_document_id": true + }, + { + "source_path": "microsoft-365/admin/support/algeria.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/american-samoa.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/create-groups/index.md", + "redirect_url": "create-groups", + "redirect_document_id": true + }, + { + "source_path": "microsoft-365/admin/support/andorra.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/admin-home.md", + "redirect_url": "index", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/angola.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/anguilla.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/antigua-and-barbuda.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/argentina.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/misc/index.md", + "redirect_url": "misc", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/armenia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/dns/index.md", + "redirect_url": "../setup/add-domain", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/aruba.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/manage/manage.md", + "redirect_url": "index", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/activity-reports/index.md", + "redirect_url": "activity-reports", + "redirect_document_id": true + }, + { + "source_path": "microsoft-365/admin/support/ascension.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/email/email.md", + "redirect_url": "index", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/email/email-collaboration.md", + "redirect_url": "/microsoft-365/admin/index", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/australia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/austria.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/azerbaijan.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/bahamas.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/bahrain.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/bangladesh.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/barbados.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/belarus.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/belgium.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/belize.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/benin.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/bermuda.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/bhutan.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/bolivia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/bonaire.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/bosnia-and-herzegovina.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/botswana.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/bouvet-island.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/brazil.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/british-virgin-islands.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/brunei.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/bulgaria.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/burkina-faso.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/burundi.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/cambodia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/cameroon.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/canada.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/cape-verde.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/cayman-islands.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/central-african-republic.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/chad.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/chile.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/china-prc.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/christmas-island.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/cocos-keeling-islands.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/colombia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/comoros.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/congo-drc.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/congo.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/cook-islands.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/costa-rica.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/cote-divoire.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/croatia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/curacao.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/cyprus.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/czech-republic.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/denmark.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/djibouti.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/dominica.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/dominican-republic.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/ecuador.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/egypt.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/el-salvador.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/equatorial-guinea.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/eritrea.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/estonia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/ethiopia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/falkland-islands.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/faroe-islands.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/fiji.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/finland.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/france.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/french-guiana.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/french-polynesia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/french-southern-territories.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/gabon.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/gambia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/georgia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/germany.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/ghana.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/gibraltar.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/greece.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/greenland.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/grenada.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/guadeloupe.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/guam.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/guatemala.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/guernsey.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/guinea-bissau.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/guinea.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/guyana.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/haiti.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/heard-island-and-mcdonald-islands.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/honduras.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/hong-kong-sar.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/hungary.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/iceland.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/india.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/indonesia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/iraq.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/ireland.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/isle-of-man.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/israel.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/italy.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/jamaica.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/jan-mayen.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/japan.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/jersey.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/jordan.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/kazakhstan.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/kenya.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/kiribati.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/korea.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/kosovo.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/kuwait.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/kyrgyzstan.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/laos.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/latvia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/lebanon.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/lesotho.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/liberia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/libya.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/liechtenstein.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/lithuania.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/luxembourg.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/macau-sar.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/macedonia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/madagascar.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/malawi.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/malaysia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/maldives.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/mali.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/malta.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/marshall-islands.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/martinique.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/mauritania.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/mauritius.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/mayotte.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/mexico.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/micronesia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/moldova.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/monaco.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/mongolia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/montenegro.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/montserrat.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/morocco.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/mozambique.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/myanmar.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/namibia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/nauru.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/nepal.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/netherlands.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/new-caledonia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/new-zealand.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/nicaragua.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/niger.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/nigeria.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/niue.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/norfolk-island.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/northern-mariana-islands.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/norway.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/oman.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/pakistan.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/palau.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/palestinian-authority.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/panama.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/papua-new-guinea.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/paraguay.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/peru.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/philippines.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/pitcairn-islands.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/poland.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/portugal.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/puerto-rico.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/qatar.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/reunion.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/romania.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/russia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/rwanda.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/saba.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/saint-barthelemy.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/saint-lucia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/saint-martin.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/saint-pierre-and-miquelon.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/saint-vincent-and-the-grenadines.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/samoa.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/san-marino.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/sao-tome-and-principe.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/saudi-arabia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/senegal.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/serbia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/seychelles.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/sierra-leone.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/singapore.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/sint-eustatius.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/sint-maarten.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/slovakia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/slovenia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/solomon-islands.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/somalia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/south-africa.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/south-georgia-and-south-sandwich-islands.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/south-sudan.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/spain.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/sri-lanka.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/st-helena.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/st-kitts-nevis.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/suriname.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/svalbard.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/swaziland.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/sweden.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/switzerland.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/taiwan.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/tajikistan.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/tanzania.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/thailand.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/timor-leste.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/togo.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/tokelau.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/tonga.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/trinidad-and-tobago.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/tristan-da-cunha.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/tunisia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/turkey.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/turkmenistan.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/turks-and-caicos-islands.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/tuvalu.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/uganda.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/ukraine.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/united-arab-emirates.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/united-kingdom.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/united-states.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/uruguay.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/uzbekistan.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/vanuatu.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/vatican-city.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/venezuela.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/vietnam.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/virgin-islands.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/wallis-and-futuna.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/yemen.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/zambia.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/support/zimbabwe.md", + "redirect_url": "/microsoft-365/admin/support-contact-info", + "redirect_document_id": false + }, + { "source_path": "microsoft-365/admin/support-contact-info.md", "redirect_url": "https://support.microsoft.com/topic/customer-service-phone-numbers-c0389ade-5640-e588-8b0e-28de8afeb3f2#ID0EBBD=signinorgid", "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/misc/sign-up-for-online-services.md", - "redirect_url": "/microsoft-365/admin/misc/remove-a-domain-from-another-account", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/misc/move-a-domain.md", - "redirect_url": "/microsoft-365/admin/misc/remove-a-domain-from-another-account", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/get-help-with-domains/domain-connect.md", - "redirect_url": "/microsoft-365/admin/setup/add-domain", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/setup/o365-setup-wizard-and-setup-page.md", - "redirect_url": "/microsoft-365/admin/setup/setup-business-standard", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/misc/sign-up-with-a-personal-email-address.md", - "redirect_url": "/microsoft-365/admin/simplified-signup/signup-business-standard", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/add-users/resend-user-password.md", - "redirect_url": "/microsoft-365/admin/add-users/reset-passwords", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/misc/empower-your-small-business-with-remote-work.md", - "redirect_url": "/microsoft-365/admin/toc.yml", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/add-users/strong-password.md", - "redirect_url": "/microsoft-365/admin/add-users/reset-passwords", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/basic-mobility-security/troubleshoot.md", - "redirect_url": "/microsoft-365/admin/basic-mobility-security/frequently-asked-questions", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/add-users/create-edit-or-delete-a-custom-user-view.md", - "redirect_url": "/microsoft-365/admin/add-users/add-users", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/basic-mobility-security/get-details-about-managed-devices.md", - "redirect_url": "/microsoft-365/admin/basic-mobility-security/manage-device-access-settings", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/admin-overview/what-is-help.md", - "redirect_url": "/microsoft-365/admin/get-help-support", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/misc/power-bi-in-your-organization.md", - "redirect_url": "/power-bi/enterprise/service-admin-org-subscription", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/misc/set-up-outlook-to-read-email.md", - "redirect_url": "/microsoft-365/admin/setup/setup-outlook", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/manage/show-hide-new-features.md", - "redirect_url": "/microsoft-365/admin/whats-new-in-preview", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/security-guide.md", - "redirect_url": "/microsoft-365/business-premium/m365bp-secure-users#download-the-digital-threats-guide", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/devices/choose-device-security.md", - "redirect_url": "/microsoft-365/admin/basic-mobility-security/choose-between-basic-mobility-and-security-and-intune", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/manage/manage-microsoft-rewards.md", - "redirect_url": "https://www.microsoft.com/rewards?rtc=1", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/manage/servicenow-service-health-incidents-solutions-only.md", - "redirect_url": "/microsoft-365/admin/manage/servicenow-overview", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/admin-overview/learn-about-office-365-germany.md", - "redirect_url": "https://aka.ms/germanymigrateassist", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/work-with-customers/index.yml", - "redirect_url": "/microsoft-365/admin", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/devices/index.yml", - "redirect_url": "/microsoft-365/admin", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/manage/index.yml", - "redirect_url": "/microsoft-365/admin", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/get-help-with-domains/index.yml", - "redirect_url": "/microsoft-365/admin", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/email/index.yml", - "redirect_url": "/microsoft-365/admin", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/setup/index.yml", - "redirect_url": "/microsoft-365/admin", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/add-users/index.yml", - "redirect_url": "/microsoft-365/admin", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/get-help-with-domains/set-up-your-domain-host-specific-instructions.md", - "redirect_url": "/microsoft-365/admin/setup/add-domain", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/contact-support-for-business-products.md", - "redirect_url": "/microsoft-365/admin/get-help-support", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/activity-reports/yammer-groups-activity-report.md", - "redirect_url": "/microsoft-365/admin/activity-reports/yammer-groups-activity-report-ww", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/activity-reports/yammer-device-usage-report.md", - "redirect_url": "/microsoft-365/admin/activity-reports/yammer-device-usage-report-ww", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/activity-reports/yammer-activity-report.md", - "redirect_url": "/microsoft-365/admin/activity-reports/yammer-activity-report-ww", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/activity-reports/sharepoint-site-usage.md", - "redirect_url": "/microsoft-365/admin/activity-reports/sharepoint-site-usage-ww", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/activity-reports/sharepoint-activity.md", - "redirect_url": "/microsoft-365/admin/activity-reports/sharepoint-activity-ww", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/activity-reports/onedrive-for-business-usage.md", - "redirect_url": "/microsoft-365/admin/activity-reports/onedrive-for-business-usage-ww", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/activity-reports/onedrive-for-business-activity.md", - "redirect_url": "/microsoft-365/admin/activity-reports/onedrive-for-business-activity-ww", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/activity-reports/office-365-groups.md", - "redirect_url": "/microsoft-365/admin/activity-reports/office-365-groups-ww", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/activity-reports/microsoft365-apps-usage.md", - "redirect_url": "/microsoft-365/admin/activity-reports/microsoft365-apps-usage-ww", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/activity-reports/microsoft-office-activations.md", - "redirect_url": "/microsoft-365/admin/activity-reports/microsoft-office-activations-ww", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/activity-reports/forms-pro-activity.md", - "redirect_url": "/microsoft-365/admin/activity-reports/forms-pro-activity-ww", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/activity-reports/forms-activity.md", - "redirect_url": "/microsoft-365/admin/activity-reports/forms-activity-ww", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/activity-reports/email-apps-usage.md", - "redirect_url": "/microsoft-365/admin/activity-reports/email-apps-usage-ww", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/activity-reports/email-activity.md", - "redirect_url": "/microsoft-365/admin/activity-reports/email-activity-ww", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/activity-reports/active-users.md", - "redirect_url": "/microsoft-365/admin/activity-reports/active-users-ww", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/manage/manage-messages.md", - "redirect_url": "/microsoft-365/admin/manage/message-center", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/admin-overview/get-started-with-office-365.md", - "redirect_url": "/microsoft-365/business/microsoft-365-business-start", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/misc/types-of-users.md", - "redirect_url": "/microsoft-365/admin/add-users/assign-admin-roles", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/manage/share-sites-with-external-users.md", - "redirect_url": "/sharepoint/change-external-sharing-site?WT.mc_id=365AdminCSH_globalsearch", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/misc/customize-help-desk.md", - "redirect_url": "/microsoft-365/admin/manage/change-address-contact-and-more", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/misc/contacts.md", - "redirect_url": "https://docs.microsoft.com/", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/misc/ways-to-manage-contacts.md", - "redirect_url": "https://docs.microsoft.com/", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/add-users/azure-ad-roles-in-the-mac.md", - "redirect_url": "/azure/active-directory/roles/permissions-reference#available-roles", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/services-in-china/view-your-bill-or-get-a-fapiao.md", - "redirect_url": "/microsoft-365/commerce/billing-and-payments/view-your-bill-or-invoice", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/services-in-china/buy-or-try-subscriptions.md", - "redirect_url": "/microsoft-365/commerce/try-or-buy-microsoft-365", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/dns/create-dns-records-at-crazy-domains.md", - "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/dns/create-dns-records-at-dnsmadeeasy.md", - "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/dns/create-dns-records-at-dreamhost.md", - "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/dns/create-dns-records-at-dyn-com.md", - "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/dns/create-dns-records-at-enomcentral.md", - "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/dns/create-dns-records-at-freenom.md", - "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/dns/create-dns-records-at-google-domains.md", - "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/dns/create-dns-records-at-hostgator.md", - "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/dns/create-dns-records-at-mydomain.md", - "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/dns/create-dns-records-at-name-com.md", - "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/dns/create-dns-records-at-names-co-uk.md", - "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/dns/create-dns-records-at-netregistry.md", - "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/dns/create-dns-records-at-register365.md", - "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/dns/create-dns-records-at-register-com.md", - "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/dns/create-dns-records-at-yahoo-small-business.md", - "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/dns/create-dns-records-for-azure-dns-zones.md", - "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/dns/create-dns-records-for-domain-managed-by-google-enom.md", - "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/dns/set-up-dns-records-at-easydns.md", - "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/dns/change-nameservers-at-1-1-internet.md", - "redirect_url": "/microsoft-365/admin/get-help-with-domains/change-nameservers-at-any-domain-registrar", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/dns/create-dns-records-at-1-1-internet.md", - "redirect_url": "/microsoft-365/admin/dns/create-dns-records-at-ionos-com", - "redirect_document_id": true - }, - { - "source_path": "microsoft-365/admin/dns/change-nameservers-at-aws.md", - "redirect_url": "/microsoft-365/admin/get-help-with-domains/change-nameservers-at-any-domain-registrar", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/dns/change-nameservers-at-bluehost.md", - "redirect_url": "/microsoft-365/admin/get-help-with-domains/change-nameservers-at-any-domain-registrar", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/dns/change-nameservers-at-google-domains.md", - "redirect_url": "/microsoft-365/admin/get-help-with-domains/change-nameservers-at-any-domain-registrar", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/dns/change-nameservers-at-hostgator.md", - "redirect_url": "/microsoft-365/admin/get-help-with-domains/change-nameservers-at-any-domain-registrar", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/dns/change-nameservers-at-mydomain.md", - "redirect_url": "/microsoft-365/admin/get-help-with-domains/change-nameservers-at-any-domain-registrar", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/dns/change-nameservers-at-namecheap.md", - "redirect_url": "/microsoft-365/admin/get-help-with-domains/change-nameservers-at-any-domain-registrar", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/dns/change-nameservers-at-network-solutions.md", - "redirect_url": "/microsoft-365/admin/get-help-with-domains/change-nameservers-at-any-domain-registrar", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/admin-overview/admin-overview.md", - "redirect_url": "/microsoft-365/admin/admin-overview/admin-center-overview", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/microsoft-365-admin-center-preview.md", - "redirect_url": "/microsoft-365/admin/admin-overview/admin-center-overview", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/manage/resolve-license-conflicts.md", - "redirect_url": "/microsoft-365/commerce/licenses/buy-licenses", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/manage/remove-licenses-from-users.md", - "redirect_url": "/microsoft-365/admin/manage/assign-licenses-to-users", - "redirect_document_id": true - }, - { - "source_path": "microsoft-365/admin/dns/create-dns-records-at-bluehost.md", - "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/dns/create-dns-records-at-hover.md", - "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/misc/become-admin-and-make-purchases.md", - "redirect_url": "/microsoft-365/admin/misc/become-the-admin", - "redirect_document_id": true - }, - { - "source_path": "microsoft-365/admin/dns/add-or-edit-custom-dns-records.md", - "redirect_url": "/microsoft-365/admin/setup/add-domain", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/create-groups/manage-creation-of-groups.md", - "redirect_url": "/microsoft-365/solutions/manage-creation-of-groups", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/create-groups/choose-domain-to-create-groups.md", - "redirect_url": "/microsoft-365/solutions/choose-domain-to-create-groups", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/create-groups/groups-naming-policy.md", - "redirect_url": "/microsoft-365/solutions/groups-naming-policy", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/create-groups/office-365-groups-expiration-policy.md", - "redirect_url": "/microsoft-365/solutions/microsoft-365-groups-expiration-policy", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/create-groups/allow-members-to-send-as-or-send-on-behalf-of-group.md", - "redirect_url": "/microsoft-365/solutions/allow-members-to-send-as-or-send-on-behalf-of-group", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/create-groups/plan-for-groups-governance.md", - "redirect_url": "/microsoft-365/solutions/collaboration-governance-overview", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/setup/employee-quick-setup.md", - "redirect_url": "https://support.microsoft.com/office/7f34c318-e772-46a5-8c0a-ab86661542d1", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/add-users/get-access-to-and-back-up-a-former-user-s-data.md", - "redirect_url": "/microsoft-365/admin/add-users/remove-former-employee-step-4", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/admin-video-library.yml", - "redirect_url": "https://go.microsoft.com/fwlink/?linkid=2197659", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/setup/get-started-windows-365-business.md", - "redirect_url": "/windows-365/business/get-started-windows-365-business", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/setup/troubleshoot-windows-365-business.md", - "redirect_url": "/windows-365/business/troubleshoot-windows-365-business", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/setup/windows-365-business-sizing.md", - "redirect_url": "/windows-365/business/windows-365-business-sizing", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/misc/business-assist.md", - "redirect_url": "https://support.microsoft.com/office/37deb8fe-61cc-4cf9-9ad1-1c8d93475070", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/admin-overview/about-the-admin-center.md", - "redirect_url": "/microsoft-365/admin/admin-overview/admin-center-overview", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/setup/access-resources.md", - "redirect_url": "/azure/active-directory/devices/azuread-join-sso", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/misc/secure-windows-10-devices.md", - "redirect_url": "/microsoft-365/business-premium/m365bp-secure-windows-devices", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/devices/app-protection-settings-for-android-and-ios.md", - "redirect_url": "/microsoft-365/business-premium/m365bp-app-protection-settings-for-android-and-ios", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/devices/add-autopilot-devices-and-profile.md", - "redirect_url": "/mem/autopilot/windows-autopilot", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/devices/autopilot-profile-settings.md", - "redirect_url": "/microsoft-365/business-premium/m365bp-autopilot-profile-settings", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/devices/create-and-edit-autopilot-devices.md", - "redirect_url": "/microsoft-365/business-premium/m365bp-create-and-edit-autopilot-devices", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/devices/device-states.md", - "redirect_url": "/microsoft-365/business-premium/m365bp-device-states", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/devices/map-protection-features-to-intune-settings.md", - "redirect_url": "/microsoft-365/business-premium/m365bp-map-protection-features-to-intune-settings", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/devices/protection-settings-for-windows-10-devices.md", - "redirect_url": "/microsoft-365/business-premium/m365bp-protection-settings-for-windows-10-devices", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/devices/remove-company-data.md", - "redirect_url": "/microsoft-365/business-premium/m365bp-remove-company-data", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/devices/reset-devices-to-factory-settings.md", - "redirect_url": "/microsoft-365/business-premium/m365bp-reset-devices-to-factory-settings", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/devices/view-policies-and-devices.md", - "redirect_url": "/microsoft-365/business-premium/m365bp-view-policies-and-devices", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/misc/prepare-for-office-client-deployment.md", - "redirect_url": "/microsoft-365/admin/setup/upgrade-users-to-latest-office-client", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/security-and-compliance/pre-requisites-for-data-protection.md", - "redirect_url": "/microsoft-365/business-premium/index", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/setup/manage-windows-devices.md", - "redirect_url": "/microsoft-365/business-premium/m365bp-manage-windows-devices", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/devices/protection-settings-for-windows-10-pcs.md", - "redirect_url": "/microsoft-365/business-premium/m365bp-protection-settings-for-windows-10-devices", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/security-and-compliance/set-up-compliance.md", - "redirect_url": "/microsoft-365/business-premium/m365bp-set-up-compliance", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/devices/create-and-edit-autopilot-profiles.md", - "redirect_url": "/microsoft-365/business-premium/create-and-edit-autopilot-profiles", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/misc/microsoft-365-business-faqs.yml", - "redirect_url": "/microsoft-365/business-premium/microsoft-365-business-faqs", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/setup/business-set-up.md", - "redirect_url": "/microsoft-365/business-premium/m365bp-setup", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/security-and-compliance/threats-detected-defender-av.md", - "redirect_url": "/microsoft-365/business-premium/m365bp-review-threats-take-action", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/security-and-compliance/review-threats-take-action.md", - "redirect_url": "/microsoft-365/business-premium/m365bp-review-threats-take-action", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/devices/validate-settings-on-android-or-ios.md", - "redirect_url": "/microsoft-365/business-premium/m365bp-validate-settings-on-android-or-ios", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/validate-settings-on-windows-10-pcs.md", - "redirect_url": "/microsoft-365/business-premium/m365bp-validate-settings-on-windows-10-pcs", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/setup/secure-win-10-pcs.md", - "redirect_url": "/microsoft-365/business-premium/m365bp-secure-windows-devices", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/productivity/apps-health.md", - "redirect_url": "/microsoft-365/admin/adoption/apps-health", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/productivity/communication.md", - "redirect_url": "/microsoft-365/admin/adoption/communication", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/productivity/content-collaboration.md", - "redirect_url": "/microsoft-365/admin/adoption/content-collaboration", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/productivity/meetings.md", - "redirect_url": "/microsoft-365/admin/adoption/meetings", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/productivity/mobility.md", - "redirect_url": "/microsoft-365/admin/adoption/mobility", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/productivity/privacy.md", - "redirect_url": "/microsoft-365/admin/adoption/privacy", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/productivity/productivity-score.md", - "redirect_url": "/microsoft-365/admin/adoption/adoption-score", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/productivity/teamwork.md", - "redirect_url": "/microsoft-365/admin/adoption/teamwork", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/adoption/organizational-message.md", - "redirect_url": "/microsoft-365/admin/adoption/organizational-messages", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/manage/upgrade-distribution-lists.md", - "redirect_url": "/microsoft-365/admin/create-groups/office-365-groups", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/security-and-compliance/secure-your-business-data.md", - "redirect_url": "/microsoft-365/business-premium/secure-your-business-data", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/security-and-compliance/enable-modern-authentication.md", - "redirect_url": "/microsoft-365/admin", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/basic-mobility-security/privacy-and-security.md", - "redirect_url": "/microsoft-365/admin/basic-mobility-security/overview", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/misc/deleted-users-checklist.md", - "redirect_url": "/microsoft-365/admin/add-users/remove-former-employee", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/misc/message-center-conformance.md", - "redirect_url": "/microsoft-365/admin/manage/message-center", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/manage/language-translation-for-message-center-posts.md", - "redirect_url": "/microsoft-365/enterprise/view-service-health", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/email/resolve-issues-with-shared-mailboxes.md", - "redirect_url": "/microsoft-365/admin/email/about-shared-mailboxes", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/new-subscription-names.md", - "redirect_url": "https://go.microsoft.com/fwlink/p/?linkid=2120533", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/misc/deleted-user.md", - "redirect_url": "/microsoft-365/admin/add-users/delete-a-user", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/setup/migrate-email-and-contacts-admin.md", - "redirect_url": "https://support.microsoft.com/office/365-2c37f0b7-2915-423c-b35e-9e03267f23dc", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/services-in-china/services-in-china.md", - "redirect_url": "/office365/servicedescriptions/office-365-platform-service-description/microsoft-365-operated-by-21vianet", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/services-in-china/download-office-app-for-android.md", - "redirect_url": "https://support.microsoft.com/office/0383d031-a1c6-46c9-b734-53cd1d22765b", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/services-in-china/download-office-app-for-ios.md", - "redirect_url": "https://support.microsoft.com/office/c8880c05-883a-46b6-ad32-9bffa31228d0", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/services-in-china/apply-for-a-fapiao.md", - "redirect_url": "/office365/servicedescriptions/office-365-platform-service-description/microsoft-365-operated-by-21vianet", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/misc/device-list.md", - "redirect_url": "/autopilot/add-devices", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/copilot/m365-copilot-setup.md", - "redirect_url": "/microsoft-365-copilot/microsoft-365-copilot-setup", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/copilot/m365-early-access-program.yml", - "redirect_url": "/microsoft-365-copilot/microsoft-365-early-access-program", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/top-m365-admin-articles.md", - "redirect_url": "https://support.microsoft.com/smallbusiness", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/misc/cortana-integration.md", - "redirect_url": "https://support.microsoft.com/topic/d025b39f-ee5b-4836-a954-0ab646ee1efa", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/activity-reports/yammer-activity-report-ww.md", - "redirect_url": "/microsoft-365/admin/activity-reports/viva-engage-activity-report-ww", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/activity-reports/yammer-device-usage-report-ww.md", - "redirect_url": "/microsoft-365/admin/activity-reports/viva-engage-device-usage-report-ww", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/activity-reports/yammer-groups-activity-report-ww.md", - "redirect_url": "/microsoft-365/admin/activity-reports/viva-engage-groups-activity-report-ww", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/email/manage-email-app-access.md", - "redirect_url": "/exchange/clients-and-mobile-in-exchange-online/exchange-activesync/mobile-device-mailbox-policies", - "redirect_document_id": false - }, - { + }, + { + "source_path": "microsoft-365/admin/misc/sign-up-for-online-services.md", + "redirect_url": "/microsoft-365/admin/misc/remove-a-domain-from-another-account", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/misc/move-a-domain.md", + "redirect_url": "/microsoft-365/admin/misc/remove-a-domain-from-another-account", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/get-help-with-domains/domain-connect.md", + "redirect_url": "/microsoft-365/admin/setup/add-domain", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/setup/o365-setup-wizard-and-setup-page.md", + "redirect_url": "/microsoft-365/admin/setup/setup-business-standard", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/misc/sign-up-with-a-personal-email-address.md", + "redirect_url": "/microsoft-365/admin/simplified-signup/signup-business-standard", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/add-users/resend-user-password.md", + "redirect_url": "/microsoft-365/admin/add-users/reset-passwords", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/misc/empower-your-small-business-with-remote-work.md", + "redirect_url": "/microsoft-365/admin/toc.yml", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/add-users/strong-password.md", + "redirect_url": "/microsoft-365/admin/add-users/reset-passwords", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/basic-mobility-security/troubleshoot.md", + "redirect_url": "/microsoft-365/admin/basic-mobility-security/frequently-asked-questions", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/add-users/create-edit-or-delete-a-custom-user-view.md", + "redirect_url": "/microsoft-365/admin/add-users/add-users", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/basic-mobility-security/get-details-about-managed-devices.md", + "redirect_url": "/microsoft-365/admin/basic-mobility-security/manage-device-access-settings", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/admin-overview/what-is-help.md", + "redirect_url": "/microsoft-365/admin/get-help-support", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/misc/power-bi-in-your-organization.md", + "redirect_url": "/power-bi/enterprise/service-admin-org-subscription", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/misc/set-up-outlook-to-read-email.md", + "redirect_url": "/microsoft-365/admin/setup/setup-outlook", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/manage/show-hide-new-features.md", + "redirect_url": "/microsoft-365/admin/whats-new-in-preview", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/security-guide.md", + "redirect_url": "/microsoft-365/business-premium/m365bp-secure-users#download-the-digital-threats-guide", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/devices/choose-device-security.md", + "redirect_url": "/microsoft-365/admin/basic-mobility-security/choose-between-basic-mobility-and-security-and-intune", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/manage/manage-microsoft-rewards.md", + "redirect_url": "https://www.microsoft.com/rewards?rtc=1", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/manage/servicenow-service-health-incidents-solutions-only.md", + "redirect_url": "/microsoft-365/admin/manage/servicenow-overview", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/admin-overview/learn-about-office-365-germany.md", + "redirect_url": "https://aka.ms/germanymigrateassist", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/work-with-customers/index.yml", + "redirect_url": "/microsoft-365/admin", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/devices/index.yml", + "redirect_url": "/microsoft-365/admin", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/manage/index.yml", + "redirect_url": "/microsoft-365/admin", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/get-help-with-domains/index.yml", + "redirect_url": "/microsoft-365/admin", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/email/index.yml", + "redirect_url": "/microsoft-365/admin", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/setup/index.yml", + "redirect_url": "/microsoft-365/admin", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/add-users/index.yml", + "redirect_url": "/microsoft-365/admin", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/get-help-with-domains/set-up-your-domain-host-specific-instructions.md", + "redirect_url": "/microsoft-365/admin/setup/add-domain", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/contact-support-for-business-products.md", + "redirect_url": "/microsoft-365/admin/get-help-support", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/activity-reports/yammer-groups-activity-report.md", + "redirect_url": "/microsoft-365/admin/activity-reports/yammer-groups-activity-report-ww", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/activity-reports/yammer-device-usage-report.md", + "redirect_url": "/microsoft-365/admin/activity-reports/yammer-device-usage-report-ww", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/activity-reports/yammer-activity-report.md", + "redirect_url": "/microsoft-365/admin/activity-reports/yammer-activity-report-ww", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/activity-reports/sharepoint-site-usage.md", + "redirect_url": "/microsoft-365/admin/activity-reports/sharepoint-site-usage-ww", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/activity-reports/sharepoint-activity.md", + "redirect_url": "/microsoft-365/admin/activity-reports/sharepoint-activity-ww", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/activity-reports/onedrive-for-business-usage.md", + "redirect_url": "/microsoft-365/admin/activity-reports/onedrive-for-business-usage-ww", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/activity-reports/onedrive-for-business-activity.md", + "redirect_url": "/microsoft-365/admin/activity-reports/onedrive-for-business-activity-ww", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/activity-reports/office-365-groups.md", + "redirect_url": "/microsoft-365/admin/activity-reports/office-365-groups-ww", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/activity-reports/microsoft365-apps-usage.md", + "redirect_url": "/microsoft-365/admin/activity-reports/microsoft365-apps-usage-ww", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/activity-reports/microsoft-office-activations.md", + "redirect_url": "/microsoft-365/admin/activity-reports/microsoft-office-activations-ww", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/activity-reports/forms-pro-activity.md", + "redirect_url": "/microsoft-365/admin/activity-reports/forms-pro-activity-ww", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/activity-reports/forms-activity.md", + "redirect_url": "/microsoft-365/admin/activity-reports/forms-activity-ww", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/activity-reports/email-apps-usage.md", + "redirect_url": "/microsoft-365/admin/activity-reports/email-apps-usage-ww", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/activity-reports/email-activity.md", + "redirect_url": "/microsoft-365/admin/activity-reports/email-activity-ww", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/activity-reports/active-users.md", + "redirect_url": "/microsoft-365/admin/activity-reports/active-users-ww", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/manage/manage-messages.md", + "redirect_url": "/microsoft-365/admin/manage/message-center", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/admin-overview/get-started-with-office-365.md", + "redirect_url": "/microsoft-365/business/microsoft-365-business-start", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/misc/types-of-users.md", + "redirect_url": "/microsoft-365/admin/add-users/assign-admin-roles", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/manage/share-sites-with-external-users.md", + "redirect_url": "/sharepoint/change-external-sharing-site?WT.mc_id=365AdminCSH_globalsearch", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/misc/customize-help-desk.md", + "redirect_url": "/microsoft-365/admin/manage/change-address-contact-and-more", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/misc/contacts.md", + "redirect_url": "https://docs.microsoft.com/", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/misc/ways-to-manage-contacts.md", + "redirect_url": "https://docs.microsoft.com/", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/add-users/azure-ad-roles-in-the-mac.md", + "redirect_url": "/azure/active-directory/roles/permissions-reference#available-roles", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/services-in-china/view-your-bill-or-get-a-fapiao.md", + "redirect_url": "/microsoft-365/commerce/billing-and-payments/view-your-bill-or-invoice", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/services-in-china/buy-or-try-subscriptions.md", + "redirect_url": "/microsoft-365/commerce/try-or-buy-microsoft-365", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/dns/create-dns-records-at-crazy-domains.md", + "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/dns/create-dns-records-at-dnsmadeeasy.md", + "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/dns/create-dns-records-at-dreamhost.md", + "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/dns/create-dns-records-at-dyn-com.md", + "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/dns/create-dns-records-at-enomcentral.md", + "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/dns/create-dns-records-at-freenom.md", + "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/dns/create-dns-records-at-google-domains.md", + "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/dns/create-dns-records-at-hostgator.md", + "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/dns/create-dns-records-at-mydomain.md", + "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/dns/create-dns-records-at-name-com.md", + "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/dns/create-dns-records-at-names-co-uk.md", + "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/dns/create-dns-records-at-netregistry.md", + "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/dns/create-dns-records-at-register365.md", + "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/dns/create-dns-records-at-register-com.md", + "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/dns/create-dns-records-at-yahoo-small-business.md", + "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/dns/create-dns-records-for-azure-dns-zones.md", + "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/dns/create-dns-records-for-domain-managed-by-google-enom.md", + "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/dns/set-up-dns-records-at-easydns.md", + "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/dns/change-nameservers-at-1-1-internet.md", + "redirect_url": "/microsoft-365/admin/get-help-with-domains/change-nameservers-at-any-domain-registrar", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/dns/create-dns-records-at-1-1-internet.md", + "redirect_url": "/microsoft-365/admin/dns/create-dns-records-at-ionos-com", + "redirect_document_id": true + }, + { + "source_path": "microsoft-365/admin/dns/change-nameservers-at-aws.md", + "redirect_url": "/microsoft-365/admin/get-help-with-domains/change-nameservers-at-any-domain-registrar", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/dns/change-nameservers-at-bluehost.md", + "redirect_url": "/microsoft-365/admin/get-help-with-domains/change-nameservers-at-any-domain-registrar", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/dns/change-nameservers-at-google-domains.md", + "redirect_url": "/microsoft-365/admin/get-help-with-domains/change-nameservers-at-any-domain-registrar", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/dns/change-nameservers-at-hostgator.md", + "redirect_url": "/microsoft-365/admin/get-help-with-domains/change-nameservers-at-any-domain-registrar", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/dns/change-nameservers-at-mydomain.md", + "redirect_url": "/microsoft-365/admin/get-help-with-domains/change-nameservers-at-any-domain-registrar", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/dns/change-nameservers-at-namecheap.md", + "redirect_url": "/microsoft-365/admin/get-help-with-domains/change-nameservers-at-any-domain-registrar", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/dns/change-nameservers-at-network-solutions.md", + "redirect_url": "/microsoft-365/admin/get-help-with-domains/change-nameservers-at-any-domain-registrar", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/admin-overview/admin-overview.md", + "redirect_url": "/microsoft-365/admin/admin-overview/admin-center-overview", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/microsoft-365-admin-center-preview.md", + "redirect_url": "/microsoft-365/admin/admin-overview/admin-center-overview", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/manage/resolve-license-conflicts.md", + "redirect_url": "/microsoft-365/commerce/licenses/buy-licenses", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/manage/remove-licenses-from-users.md", + "redirect_url": "/microsoft-365/admin/manage/assign-licenses-to-users", + "redirect_document_id": true + }, + { + "source_path": "microsoft-365/admin/dns/create-dns-records-at-bluehost.md", + "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/dns/create-dns-records-at-hover.md", + "redirect_url": "/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/misc/become-admin-and-make-purchases.md", + "redirect_url": "/microsoft-365/admin/misc/become-the-admin", + "redirect_document_id": true + }, + { + "source_path": "microsoft-365/admin/dns/add-or-edit-custom-dns-records.md", + "redirect_url": "/microsoft-365/admin/setup/add-domain", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/create-groups/manage-creation-of-groups.md", + "redirect_url": "/microsoft-365/solutions/manage-creation-of-groups", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/create-groups/choose-domain-to-create-groups.md", + "redirect_url": "/microsoft-365/solutions/choose-domain-to-create-groups", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/create-groups/groups-naming-policy.md", + "redirect_url": "/microsoft-365/solutions/groups-naming-policy", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/create-groups/office-365-groups-expiration-policy.md", + "redirect_url": "/microsoft-365/solutions/microsoft-365-groups-expiration-policy", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/create-groups/allow-members-to-send-as-or-send-on-behalf-of-group.md", + "redirect_url": "/microsoft-365/solutions/allow-members-to-send-as-or-send-on-behalf-of-group", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/create-groups/plan-for-groups-governance.md", + "redirect_url": "/microsoft-365/solutions/collaboration-governance-overview", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/setup/employee-quick-setup.md", + "redirect_url": "https://support.microsoft.com/office/7f34c318-e772-46a5-8c0a-ab86661542d1", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/add-users/get-access-to-and-back-up-a-former-user-s-data.md", + "redirect_url": "/microsoft-365/admin/add-users/remove-former-employee-step-4", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/admin-video-library.yml", + "redirect_url": "https://go.microsoft.com/fwlink/?linkid=2197659", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/setup/get-started-windows-365-business.md", + "redirect_url": "/windows-365/business/get-started-windows-365-business", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/setup/troubleshoot-windows-365-business.md", + "redirect_url": "/windows-365/business/troubleshoot-windows-365-business", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/setup/windows-365-business-sizing.md", + "redirect_url": "/windows-365/business/windows-365-business-sizing", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/misc/business-assist.md", + "redirect_url": "https://support.microsoft.com/office/37deb8fe-61cc-4cf9-9ad1-1c8d93475070", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/admin-overview/about-the-admin-center.md", + "redirect_url": "/microsoft-365/admin/admin-overview/admin-center-overview", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/setup/access-resources.md", + "redirect_url": "/azure/active-directory/devices/azuread-join-sso", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/misc/secure-windows-10-devices.md", + "redirect_url": "/microsoft-365/business-premium/m365bp-secure-windows-devices", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/devices/app-protection-settings-for-android-and-ios.md", + "redirect_url": "/microsoft-365/business-premium/m365bp-app-protection-settings-for-android-and-ios", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/devices/add-autopilot-devices-and-profile.md", + "redirect_url": "/mem/autopilot/windows-autopilot", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/devices/autopilot-profile-settings.md", + "redirect_url": "/microsoft-365/business-premium/m365bp-autopilot-profile-settings", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/devices/create-and-edit-autopilot-devices.md", + "redirect_url": "/microsoft-365/business-premium/m365bp-create-and-edit-autopilot-devices", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/devices/device-states.md", + "redirect_url": "/microsoft-365/business-premium/m365bp-device-states", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/devices/map-protection-features-to-intune-settings.md", + "redirect_url": "/microsoft-365/business-premium/m365bp-map-protection-features-to-intune-settings", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/devices/protection-settings-for-windows-10-devices.md", + "redirect_url": "/microsoft-365/business-premium/m365bp-protection-settings-for-windows-10-devices", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/devices/remove-company-data.md", + "redirect_url": "/microsoft-365/business-premium/m365bp-remove-company-data", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/devices/reset-devices-to-factory-settings.md", + "redirect_url": "/microsoft-365/business-premium/m365bp-reset-devices-to-factory-settings", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/devices/view-policies-and-devices.md", + "redirect_url": "/microsoft-365/business-premium/m365bp-view-policies-and-devices", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/misc/prepare-for-office-client-deployment.md", + "redirect_url": "/microsoft-365/admin/setup/upgrade-users-to-latest-office-client", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/security-and-compliance/pre-requisites-for-data-protection.md", + "redirect_url": "/microsoft-365/business-premium/index", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/setup/manage-windows-devices.md", + "redirect_url": "/microsoft-365/business-premium/m365bp-manage-windows-devices", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/devices/protection-settings-for-windows-10-pcs.md", + "redirect_url": "/microsoft-365/business-premium/m365bp-protection-settings-for-windows-10-devices", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/security-and-compliance/set-up-compliance.md", + "redirect_url": "/microsoft-365/business-premium/m365bp-set-up-compliance", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/devices/create-and-edit-autopilot-profiles.md", + "redirect_url": "/microsoft-365/business-premium/create-and-edit-autopilot-profiles", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/misc/microsoft-365-business-faqs.yml", + "redirect_url": "/microsoft-365/business-premium/microsoft-365-business-faqs", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/setup/business-set-up.md", + "redirect_url": "/microsoft-365/business-premium/m365bp-setup", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/security-and-compliance/threats-detected-defender-av.md", + "redirect_url": "/microsoft-365/business-premium/m365bp-review-threats-take-action", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/security-and-compliance/review-threats-take-action.md", + "redirect_url": "/microsoft-365/business-premium/m365bp-review-threats-take-action", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/devices/validate-settings-on-android-or-ios.md", + "redirect_url": "/microsoft-365/business-premium/m365bp-validate-settings-on-android-or-ios", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/validate-settings-on-windows-10-pcs.md", + "redirect_url": "/microsoft-365/business-premium/m365bp-validate-settings-on-windows-10-pcs", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/setup/secure-win-10-pcs.md", + "redirect_url": "/microsoft-365/business-premium/m365bp-secure-windows-devices", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/productivity/apps-health.md", + "redirect_url": "/microsoft-365/admin/adoption/apps-health", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/productivity/communication.md", + "redirect_url": "/microsoft-365/admin/adoption/communication", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/productivity/content-collaboration.md", + "redirect_url": "/microsoft-365/admin/adoption/content-collaboration", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/productivity/meetings.md", + "redirect_url": "/microsoft-365/admin/adoption/meetings", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/productivity/mobility.md", + "redirect_url": "/microsoft-365/admin/adoption/mobility", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/productivity/privacy.md", + "redirect_url": "/microsoft-365/admin/adoption/privacy", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/productivity/productivity-score.md", + "redirect_url": "/microsoft-365/admin/adoption/adoption-score", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/productivity/teamwork.md", + "redirect_url": "/microsoft-365/admin/adoption/teamwork", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/adoption/organizational-message.md", + "redirect_url": "/microsoft-365/admin/adoption/organizational-messages", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/manage/upgrade-distribution-lists.md", + "redirect_url": "/microsoft-365/admin/create-groups/office-365-groups", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/security-and-compliance/secure-your-business-data.md", + "redirect_url": "/microsoft-365/business-premium/secure-your-business-data", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/security-and-compliance/enable-modern-authentication.md", + "redirect_url": "/microsoft-365/admin", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/basic-mobility-security/privacy-and-security.md", + "redirect_url": "/microsoft-365/admin/basic-mobility-security/overview", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/misc/deleted-users-checklist.md", + "redirect_url": "/microsoft-365/admin/add-users/remove-former-employee", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/misc/message-center-conformance.md", + "redirect_url": "/microsoft-365/admin/manage/message-center", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/manage/language-translation-for-message-center-posts.md", + "redirect_url": "/microsoft-365/enterprise/view-service-health", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/email/resolve-issues-with-shared-mailboxes.md", + "redirect_url": "/microsoft-365/admin/email/about-shared-mailboxes", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/new-subscription-names.md", + "redirect_url": "https://go.microsoft.com/fwlink/p/?linkid=2120533", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/misc/deleted-user.md", + "redirect_url": "/microsoft-365/admin/add-users/delete-a-user", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/setup/migrate-email-and-contacts-admin.md", + "redirect_url": "https://support.microsoft.com/office/365-2c37f0b7-2915-423c-b35e-9e03267f23dc", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/services-in-china/services-in-china.md", + "redirect_url": "/office365/servicedescriptions/office-365-platform-service-description/microsoft-365-operated-by-21vianet", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/services-in-china/download-office-app-for-android.md", + "redirect_url": "https://support.microsoft.com/office/0383d031-a1c6-46c9-b734-53cd1d22765b", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/services-in-china/download-office-app-for-ios.md", + "redirect_url": "https://support.microsoft.com/office/c8880c05-883a-46b6-ad32-9bffa31228d0", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/services-in-china/apply-for-a-fapiao.md", + "redirect_url": "/office365/servicedescriptions/office-365-platform-service-description/microsoft-365-operated-by-21vianet", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/misc/device-list.md", + "redirect_url": "/autopilot/add-devices", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/copilot/m365-copilot-setup.md", + "redirect_url": "/microsoft-365-copilot/microsoft-365-copilot-setup", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/copilot/m365-early-access-program.yml", + "redirect_url": "/microsoft-365-copilot/microsoft-365-early-access-program", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/top-m365-admin-articles.md", + "redirect_url": "https://support.microsoft.com/smallbusiness", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/misc/cortana-integration.md", + "redirect_url": "https://support.microsoft.com/topic/d025b39f-ee5b-4836-a954-0ab646ee1efa", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/activity-reports/yammer-activity-report-ww.md", + "redirect_url": "/microsoft-365/admin/activity-reports/viva-engage-activity-report-ww", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/activity-reports/yammer-device-usage-report-ww.md", + "redirect_url": "/microsoft-365/admin/activity-reports/viva-engage-device-usage-report-ww", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/activity-reports/yammer-groups-activity-report-ww.md", + "redirect_url": "/microsoft-365/admin/activity-reports/viva-engage-groups-activity-report-ww", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/email/manage-email-app-access.md", + "redirect_url": "/exchange/clients-and-mobile-in-exchange-online/exchange-activesync/mobile-device-mailbox-policies", + "redirect_document_id": false + }, + { "source_path": "microsoft-365/admin/misc/move-email-and-data-to-office-365-business-premium.md", "redirect_url": "https://support.microsoft.com/office/move-your-old-email-calendars-and-contacts-to-microsoft-365-2c37f0b7-2915-423c-b35e-9e03267f23dc", "redirect_document_id": false - }, - { + }, + { "source_path": "microsoft-365/admin/manage/servicenow-testing-the-configuration-v1.md", "redirect_url": "/microsoft-365/manage/servicenow-testing-the-configuration", "redirect_document_id": false - }, - { + }, + { "source_path": "microsoft-365/admin/manage/servicenow-troubleshooting-v1.md", "redirect_url": "/microsoft-365/admin/manage/servicenow-troubleshooting", "redirect_document_id": false - }, - { + }, + { "source_path": "microsoft-365/admin/manage/servicenow-basic-authentication-v1.md", "redirect_url": "/microsoft-365/admin/manage/servicenow-authentication", "redirect_document_id": false - }, - { + }, + { "source_path": "microsoft-365/admin/manage/servicenow-overview-v1.md", "redirect_url": "/microsoft-365/admin/manage/servicenow-overview", "redirect_document_id": false - }, - { + }, + { "source_path": "microsoft-365/admin/services-in-china/parity-between-azure-information-protection.md", "redirect_url": "/azure/information-protection/parity-between-azure-information-protection", "redirect_document_id": false - }, - { + }, + { "source_path": "microsoft-365/admin/email/access-email-from-a-mobile-device.md", "redirect_url": "/microsoft-365/admin/setup/set-up-mobile-devices", "redirect_document_id": false - }, - { + }, + { "source_path": "microsoft-365/admin/add-users/admin-roles-page.md", "redirect_url": "/microsoft-365/admin/add-users/assign-admin-roles", "redirect_document_id": false - }, - { + }, + { "source_path": "microsoft-365/admin/misc/account-disabled-error.md", "redirect_url": "/exchange/recipients-in-exchange-online/manage-user-mailboxes/enable-or-disable-outlook-web-app", "redirect_document_id": false - }, - { + }, + { "source_path": "microsoft-365/enterprise/identity-sync.md", "redirect_url": "/microsoft-365/enterprise/deploy-identity-solution-identity-model", "redirect_document_id": false - }, - { + }, + { "source_path": "microsoft-365/enterprise/google-groups-migration.md", "redirect_url": "/microsoft-365/enterprise/deploy-identity-solution-identity-model", "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/misc/experience-insights-help-articles.md", - "redirect_url": "/microsoft-365/admin/misc/experience-insights-dashboard", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/email/remove-license-from-shared-mailbox.md", - "redirect_url": "/microsoft-365/admin/email/create-a-shared-mailbox", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/admin-overview/what-is-microsoft-365.md", - "redirect_url": "/microsoft-365/business-premium/m365bp-overview", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/activity-reports/agent-usage.md", - "redirect_url": "/microsoft-365/admin/activity-reports/microsoft-365-copilot-agents", - "redirect_document_id": true - }, - { - "source_path": "microsoft-365/admin/misc/places-ios-mobile.md", - "redirect_url": "/microsoft-365/admin/", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/misc/admin-controls-profile-videos.md", - "redirect_url": "/microsoft-365/admin/add-users/change-user-profile-photos", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/manage/change-contact-preferences.md", - "redirect_url": "/microsoft-365/admin/manage/change-address-contact-and-more", - "redirect_document_id": false - }, - { - "source_path": "microsoft-365/admin/manage/use-qr-code-download-outlook.md", - "redirect_url": "https://go.microsoft.com/fwlink/?linkid=2309759", - "redirect_document_id": false - } - ] - } \ No newline at end of file + }, + { + "source_path": "microsoft-365/admin/misc/experience-insights-help-articles.md", + "redirect_url": "/microsoft-365/admin/misc/experience-insights-dashboard", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/email/remove-license-from-shared-mailbox.md", + "redirect_url": "/microsoft-365/admin/email/create-a-shared-mailbox", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/admin-overview/what-is-microsoft-365.md", + "redirect_url": "/microsoft-365/business-premium/m365bp-overview", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/activity-reports/agent-usage.md", + "redirect_url": "/microsoft-365/admin/activity-reports/microsoft-365-copilot-agents", + "redirect_document_id": true + }, + { + "source_path": "microsoft-365/admin/misc/places-ios-mobile.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/misc/admin-controls-profile-videos.md", + "redirect_url": "/microsoft-365/admin/add-users/change-user-profile-photos.md", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/manage/change-contact-preferences.md", + "redirect_url": "/microsoft-365/admin/manage/change-address-contact-and-more", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/manage/use-qr-code-download-outlook.md", + "redirect_url": "https://go.microsoft.com/fwlink/?linkid=2309759", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/admin/adoption/ai-assistance.md", + "redirect_url": "/microsoft-365/admin/adoption/ai-adoption-score", + "redirect_document_id": true + }, + { + "source_path": "microsoft-365/admin/add-users/add-new-employee.md", + "redirect_url": "https://support.microsoft.com/office/7f34c318-e772-46a5-8c0a-ab86661542d1", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/bookings/hide-service-on-booking-page.md", + "redirect_url": "/microsoft-365/bookings/define-service-offerings.md", + "redirect_document_id": false + }, + { + "source_path": "microsoft-365/bookings/set-buffer-time.md", + "redirect_url": "/microsoft-365/bookings/set-buffer-time.md", + "redirect_document_id": false + } + ] +} \ No newline at end of file diff --git a/.openpublishing.redirection.commerce.json b/.openpublishing.redirection.commerce.json index 4cffdc27750..9911ce4bd54 100644 --- a/.openpublishing.redirection.commerce.json +++ b/.openpublishing.redirection.commerce.json @@ -969,6 +969,11 @@ "source_path": "microsoft-365/commerce/licenses/user-roles-faq.yml", "redirect_url": "/microsoft-365/commerce/licenses/manage-user-roles-vl", "redirect_document_id": false + }, + { + "source_path": "microsoft-365/commerce/licenses/contracts-faq.yml", + "redirect_url": "/microsoft-365/commerce/licenses/manage-contracts-vl", + "redirect_document_id": false } ] } diff --git a/.openpublishing.redirection.frontline.json b/.openpublishing.redirection.frontline.json index 9878ab1ed41..e54893db887 100644 --- a/.openpublishing.redirection.frontline.json +++ b/.openpublishing.redirection.frontline.json @@ -64,6 +64,11 @@ "source_path":"microsoft-365/frontline/manage-shift-based-access-flw.md", "redirect_url":"/microsoft-365/frontline/shifts-for-teams-landing-page", "redirect_document_id":false + }, + { + "source_path":"microsoft-365/frontline/deploy-dynamic-teams-at-scale.md", + "redirect_url":"/microsoft-365/frontline/deploy-flexible-membership-teams-at-scale", + "redirect_document_id":true } ] } diff --git a/copilot/TOC.yml b/copilot/TOC.yml index 26b7fe33123..503f7e8f14b 100644 --- a/copilot/TOC.yml +++ b/copilot/TOC.yml @@ -40,19 +40,17 @@ items: href: microsoft-365-copilot-licensing.md - name: Enable users and welcome email href: microsoft-365-copilot-enable-users.md - - name: Copilot Prompt Gallery - href: copilot-prompt-gallery.md - name: Adoption resources href: microsoft-365-copilot-enablement-resources.md - name: Pay-as-you-go for Microsoft 365 Copilot items: - - name: Microsoft 365 Copilot pay-as-you-go overview + - name: Pay-as-you-go overview href: pay-as-you-go/overview.md - - name: Set up pay-as-you-go for Microsoft 365 Copilot Chat + - name: Set up pay-as-you-go href: pay-as-you-go/setup.md - - name: Meters for Microsoft 365 Copilot Chat pay-as-you-go + - name: Meters for pay-as-you-go href: pay-as-you-go/meters.md - - name: View costs and billing for Microsoft 365 Copilot Chat pay-as-you-go + - name: View costs and billing for pay-as-you-go href: pay-as-you-go/view-cost.md - name: Manage Microsoft 365 Copilot items: @@ -60,6 +58,8 @@ items: href: microsoft-365-copilot-page.md - name: Pin Copilot Chat to the navigation bar href: pin-copilot.md + - name: Manage scheduled prompts + href: scheduled-prompts.md - name: Enable Facilitator in Microsoft Teams href: /microsoftteams/facilitator-teams?toc=%2Fcopilot%2Fmicrosoft-365%2Ftoc.json&bc=%2Fcopilot%2Fmicrosoft-365%2Fbreadcrumb%2Ftoc.json - name: Manage Copilot for Microsoft Teams meetings and events @@ -72,14 +72,12 @@ items: href: /viva/copilot/viva-copilot-overview?toc=%2Fcopilot%2Fmicrosoft-365%2Ftoc.json&bc=%2Fcopilot%2Fmicrosoft-365%2Fbreadcrumb%2Ftoc.json - name: Manage access to Microsoft 365 Copilot in Viva href: /viva/copilot/copilot-access-management?toc=%2Fcopilot%2Fmicrosoft-365%2Ftoc.json&bc=%2Fcopilot%2Fmicrosoft-365%2Fbreadcrumb%2Ftoc.json -- name: Maximize the value of Microsoft 365 Copilot for your organization +- name: Maximize the value of Microsoft 365 Copilot items: - - name: Use the Microsoft Copilot Dashboard - href: /viva/insights/org-team-insights/copilot-dashboard?toc=%2Fcopilot%2Fmicrosoft-365%2Ftoc.json&bc=%2Fcopilot%2Fmicrosoft-365%2Fbreadcrumb%2Ftoc.json - - name: View the Microsoft 365 Copilot readiness report - href: /microsoft-365/admin/activity-reports/microsoft-365-copilot-readiness?toc=%2Fcopilot%2Fmicrosoft-365%2Ftoc.json&bc=%2Fcopilot%2Fmicrosoft-365%2Fbreadcrumb%2Ftoc.json - - name: View the Microsoft 365 Copilot usage report - href: /microsoft-365/admin/activity-reports/microsoft-365-copilot-usage?toc=%2Fcopilot%2Fmicrosoft-365%2Ftoc.json&bc=%2Fcopilot%2Fmicrosoft-365%2Fbreadcrumb%2Ftoc.json + - name: Reports and insights + href: microsoft-365-copilot-reports-for-admins.md + - name: Copilot Prompt Gallery + href: copilot-prompt-gallery.md - name: "Trust: Data, Privacy, and Security" items: - name: Data, privacy, and security for Microsoft 365 Copilot diff --git a/copilot/copilot-prompt-gallery-export-prompts.md b/copilot/copilot-prompt-gallery-export-prompts.md index a3b17785a0c..223c4eae2da 100644 --- a/copilot/copilot-prompt-gallery-export-prompts.md +++ b/copilot/copilot-prompt-gallery-export-prompts.md @@ -1,6 +1,6 @@ --- -title: "Export prompts that users saved or shared in Copilot Prompt Gallery" -description: "Provides admins the steps to take to export prompts that users saved or shared in Copilot Prompt Gallery" +title: "Export prompts that users saved, liked, or shared in Copilot Prompt Gallery" +description: "Provides admins the steps to take to export prompts that users saved, liked, or shared in Copilot Prompt Gallery" ms.author: danbrown author: DHB-MSFT manager: laurawi @@ -12,14 +12,14 @@ ms.collection: - m365copilot - magic-ai-copilot hideEdit: true -ms.date: 11/19/2024 +ms.date: 04/16/2025 --- -# Export prompts that users saved or shared in Copilot Prompt Gallery +# Export prompts that users saved, liked, or shared in Copilot Prompt Gallery -In [Copilot Prompt Gallery](https://copilot.cloud.microsoft/prompts), users can save or share prompts they created, including sharing prompts with a specific team (in Microsoft Teams) that they're a member of. As an admin, you can use Windows PowerShell to export data to a file about either of the following types of prompts in Copilot Prompt Gallery: +In [Copilot Prompt Gallery](https://copilot.cloud.microsoft/prompts), users can save or share prompts they created, including sharing prompts with a specific team (in Microsoft Teams) that they're a member of. Users can also like prompts created by others. As an admin, you can use Windows PowerShell to export data to a file about either of the following types of prompts in Copilot Prompt Gallery: -- The saved and shared prompts of a specific user. +- The saved, liked, and shared prompts of a specific user. - The prompts shared with a specific team. > [!NOTE] @@ -27,7 +27,7 @@ In [Copilot Prompt Gallery](https://copilot.cloud.microsoft/prompts), users can ## Configure your Windows PowerShell environment -Before you can export prompts that users saved or shared in Copilot Prompt Gallery, you need to configure your PowerShell environment by doing the following steps: +Before you can export prompts that users saved, liked, or shared in Copilot Prompt Gallery, you need to configure your PowerShell environment by doing the following steps: 1. [Download the CopilotLabDSR PowerShell script](#download-the-copilotlabdsr-powershell-script) 2. [Install the MSAL.PS module](#install-the-msalps-module) @@ -35,11 +35,10 @@ Before you can export prompts that users saved or shared in Copilot Prompt Galle ### Download the CopilotLabDSR PowerShell script -1. To get started, you need to [download the CopilotLabDSR PowerShell script](https://download.microsoft.com/download/b/a/b/babff430-cc1f-46e0-b98b-2997d79af5ae/tenant-admin-scripts.zip). -2. Extract the CopilotLabDSR.psm1 file from the tenant-admin-scripts.zip file to a location you can access from PowerShell. -3. In File Explorer, go to the location where you saved the CopilotLabDSR.psm1 file that you extracted. -4. Right-click on the CopilotLabDSR.psm1 file and select **Properties**. -5. On the **General** tab, select **Unblock** checkbox, and then select **Ok**. +1. To get started, you need to [download the CopilotLabDSR PowerShell script](https://download.microsoft.com/download/a541f114-f315-4b2f-bc2c-e7e89bb3022f/CopilotLabDSR.psm1). +2. In File Explorer, go to the location where you saved the CopilotLabDSR.psm1 file. +3. Right-click on the CopilotLabDSR.psm1 file and select **Properties**. +4. On the **General** tab, select **Unblock** checkbox, and then select **Ok**. You need to unblock the file because, by default, executing scripts downloaded from the internet isn't allowed. @@ -64,7 +63,7 @@ Before you can export prompts that users saved or shared in Copilot Prompt Galle 2. Run the following command to import the module with all available cmdlets. ```PowerShell - Import-module "" + Import-module "" ``` For example, if your file is saved in C:\AdminScripts, you would type: @@ -73,9 +72,9 @@ Before you can export prompts that users saved or shared in Copilot Prompt Galle Import-module "C:\AdminScripts\CopilotLabDSR.psm1" -## Export the saved and shared prompts of a specific user +## Export the saved, liked, and shared prompts of a specific user -1. From Windows PowerShell, use the `Export- PromptsUserContent` cmdlet to export the saved or shared prompts of a specific user from Copilot Prompt Gallery. +1. From Windows PowerShell, use the `Export- PromptsUserContent` cmdlet to export the saved, liked, or shared prompts of a specific user from Copilot Prompt Gallery. ```powershell Export-PromptsUserContent -UserAadIdOrPrincipalName -ExportDirectory -PromptType @@ -85,7 +84,7 @@ Export-PromptsUserContent -UserAadIdOrPrincipalName -E |--------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------| | UserAadIdOrPrincipalName | Use either the Microsoft Entra ID or the User Principal Name (UPN) of the user for which you want to export content. | | ExportDirectory | Location to store your output files. The folder should already exist. If not specified, the export files are saved to the current folder. | -| PromptType | Specify "saved" to export the prompts saved by the user. Specify "shared" to export the prompts for which a shareable link to the prompt was generated. | +| PromptType | Specify "saved" to export the prompts saved by the user. Specify "shared" to export the prompts for which a shareable link to the prompt was generated. Specify "liked" to export prompts liked by the user. | For example, the following exports Reed Smiths's saved prompts in Copilot Prompt Gallery using his UPN and downloads the export files to the location C:\PromptsExportReedSmith. @@ -125,36 +124,39 @@ Export- PromptsGroupContent -M365TeamsGroupId d0efcad2-6744-0de6-0624-ea467d4293 After running the PowerShell cmdlet to export your user's data from Copilot Prompt Gallery, you'll receive one file in your download location folder. You can use the information in the following sections to help you understand the properties you see in the file you received. -### Export file for the saved and shared prompts of a specific user +### Export file for the saved, liked, and shared prompts of a specific user The file name is prefixed with "User" and the Microsoft Entra ID of the user followed by the prompts type used for export. The file has the properties listed in the following table. -| Property | Description | -|-----------------------------------------------------|-------------------------------------------------------------------------| -| Prompts | An array of users saved or shared prompts information. | -| Prompt.Title | Title of the prompt given by user while saving or sharing the prompt. | -| Prompt.PromptText | Prompt text | -| Prompt.Products | A list containing the product in which user saved or shared the prompt. | -| Prompt.CreatedTime | Time when the user saved the prompt. | -| Prompt.SharedTime | Time when the user shared the prompt | -| Prompt.HydratedEntities | List of entities with type and entity information. | -| Prompt.HydratedEntities.Type | Currently People, File, and Meeting entity types are supported. | -| Prompt.HydratedEntities.Entity | Entity information based on entity type. | -| Prompt.HydratedEntities.Entity.Id | Unique entity ID. | -| Prompt.HydratedEntities.Entity.DisplayName | Person entity display name. | -| Prompt.HydratedEntities.Entity.EmailAddresses | List of email addresses for person entity. | -| Prompt.HydratedEntities.Entity.ReferenceId | Unique ID for instrumentation mapping. | -| Prompt.HydratedEntities.Entity.FileName | Name of the file entity. | -| Prompt.HydratedEntities.Entity.AccessUrl | Access URL of file entity. | -| Prompt.HydratedEntities.Entity.SpoId | SharePoint Document Identifier for File entity. | -| Prompt.HydratedEntities.Entity.OriginalId | Meeting ID of event entity. | -| Prompt.HydratedEntities.Entity.Subject | Subject of event entity. | -| Prompt.HydratedEntities.Entity.SkypeTeamsMeetingUrl | URL of event entity. | -| Prompt.HydratedEntities.Entity.Start | Start time of event entity. | -| Prompt.HydratedEntities.Entity.End | End time of event entity. | -| Prompt.HydratedEntities.Entity.OrganizerName | Organizer Name of event entity. | -| Prompt.HydratedEntities.Entity.OrganizerAddress | Organizer Address of event entity. | -| Prompt.HydratedEntities.Entity.Attendees | Attendees list of event entity. | +| Property | Description | +|-----------------------------------------------------|------------------------------------------------------------------------------| +| Prompts | An array of users saved or shared prompts information. | +| Prompt.Title | Title of the prompt given by user while saving or sharing the prompt. | +| Prompt.PromptText | Prompt text | +| Prompt.Products | A list containing the product in which user saved or shared the prompt. | +| Prompt.IsFavorite | Boolean (true or false) indicating that a user has saved or liked the prompt.| +| Prompt.UserActivity.Favorite.IsFavorite | Boolean (true or false) indicating that a user has saved or liked the prompt.| +| Prompt.UserActivity.Favorite.ActivityDateTimeInUtc | Time when user saved or liked the prompt. | +| Prompt.CreatedTime | Time when the user saved the prompt. | +| Prompt.SharedTime | Time when the user shared the prompt | +| Prompt.HydratedEntities | List of entities with type and entity information. | +| Prompt.HydratedEntities.Type | Currently People, File, and Meeting entity types are supported. | +| Prompt.HydratedEntities.Entity | Entity information based on entity type. | +| Prompt.HydratedEntities.Entity.Id | Unique entity ID. | +| Prompt.HydratedEntities.Entity.DisplayName | Person entity display name. | +| Prompt.HydratedEntities.Entity.EmailAddresses | List of email addresses for person entity. | +| Prompt.HydratedEntities.Entity.ReferenceId | Unique ID for instrumentation mapping. | +| Prompt.HydratedEntities.Entity.FileName | Name of the file entity. | +| Prompt.HydratedEntities.Entity.AccessUrl | Access URL of file entity. | +| Prompt.HydratedEntities.Entity.SpoId | SharePoint Document Identifier for File entity. | +| Prompt.HydratedEntities.Entity.OriginalId | Meeting ID of event entity. | +| Prompt.HydratedEntities.Entity.Subject | Subject of event entity. | +| Prompt.HydratedEntities.Entity.SkypeTeamsMeetingUrl | URL of event entity. | +| Prompt.HydratedEntities.Entity.Start | Start time of event entity. | +| Prompt.HydratedEntities.Entity.End | End time of event entity. | +| Prompt.HydratedEntities.Entity.OrganizerName | Organizer Name of event entity. | +| Prompt.HydratedEntities.Entity.OrganizerAddress | Organizer Address of event entity. | +| Prompt.HydratedEntities.Entity.Attendees | Attendees list of event entity. | ### Export file for the prompts shared with a specific team diff --git a/copilot/media/copilot-pay-azure.png b/copilot/media/copilot-pay-azure.png new file mode 100644 index 00000000000..a96045e1726 Binary files /dev/null and b/copilot/media/copilot-pay-azure.png differ diff --git a/copilot/media/microsoft-365-copilot-reports-for-admins/microsoft-365-admin-center-reports.png b/copilot/media/microsoft-365-copilot-reports-for-admins/microsoft-365-admin-center-reports.png new file mode 100644 index 00000000000..45a787ce42a Binary files /dev/null and b/copilot/media/microsoft-365-copilot-reports-for-admins/microsoft-365-admin-center-reports.png differ diff --git a/copilot/media/microsoft-365-copilot-reports-for-admins/microsoft-365-admin-center-usage.png b/copilot/media/microsoft-365-copilot-reports-for-admins/microsoft-365-admin-center-usage.png new file mode 100644 index 00000000000..5d14f54bd7b Binary files /dev/null and b/copilot/media/microsoft-365-copilot-reports-for-admins/microsoft-365-admin-center-usage.png differ diff --git a/copilot/media/microsoft-365-copilot-reports-for-admins/microsoft-purview-portal-audit-search.png b/copilot/media/microsoft-365-copilot-reports-for-admins/microsoft-purview-portal-audit-search.png new file mode 100644 index 00000000000..68c5046d1f5 Binary files /dev/null and b/copilot/media/microsoft-365-copilot-reports-for-admins/microsoft-purview-portal-audit-search.png differ diff --git a/copilot/media/microsoft-365-copilot-reports-for-admins/microsoft-purview-portal-solutions-audit.png b/copilot/media/microsoft-365-copilot-reports-for-admins/microsoft-purview-portal-solutions-audit.png new file mode 100644 index 00000000000..80f97481bfc Binary files /dev/null and b/copilot/media/microsoft-365-copilot-reports-for-admins/microsoft-purview-portal-solutions-audit.png differ diff --git a/copilot/microsoft-365-copilot-enablement-resources.md b/copilot/microsoft-365-copilot-enablement-resources.md index f5940e9c86d..112d20d691e 100644 --- a/copilot/microsoft-365-copilot-enablement-resources.md +++ b/copilot/microsoft-365-copilot-enablement-resources.md @@ -35,5 +35,5 @@ To get started, go to [Microsoft 365 Copilot adoption](https://adoption.microsof ## Related content - [Copilot Prompt Gallery](copilot-prompt-gallery.md) -- [Microsoft 365 Copilot E3 implementation guide](microsoft-365-copilot-e3-guide.md) -- [Microsoft 365 Copilot E5 implementation guide](microsoft-365-copilot-e5-guide.md) +- Microsoft 365 Copilot [E3](microsoft-365-copilot-e3-guide.md) and [E5](microsoft-365-copilot-e5-guide.md) implementation guides +- [Microsoft 365 Copilot reports](microsoft-365-copilot-reports-for-admins.md) diff --git a/copilot/microsoft-365-copilot-page.md b/copilot/microsoft-365-copilot-page.md index 0469c790381..7010999e5c8 100644 --- a/copilot/microsoft-365-copilot-page.md +++ b/copilot/microsoft-365-copilot-page.md @@ -1,12 +1,12 @@ --- title: Microsoft 365 admin center scenarios that configure Copilot -description: Learn about some of the Microsoft 365 Copilot scenarios and some settings that IT admins can configure in the Microsoft 365 admin center. M365 Copilot scenarios in the admin center. +description: Learn about some of the Microsoft 365 Copilot scenarios and some settings that IT admins can configure using the Copilot Control System in the Microsoft 365 admin center. f1.keywords: - NOCSH ms.author: camillepack author: camillepack manager: scotv -ms.date: 02/11/2025 +ms.date: 04/09/2025 ms.reviewer: elvaf audience: Admin ms.topic: how-to @@ -22,7 +22,7 @@ appliesto: # Manage Microsoft 365 Copilot scenarios in the Microsoft 365 admin center -When [Microsoft 365 Copilot](microsoft-365-copilot-overview.md) is available in a tenant, there are some Copilot scenarios that admins can configure in the Microsoft 365 admin center. +When [Microsoft 365 Copilot](microsoft-365-copilot-overview.md) is available in a tenant, there are some Copilot scenarios that admins can configure using the Copilot Control System in the Microsoft 365 admin center. The admin center also gives shortcuts to other services that can affect how Copilot is used in your organization. @@ -54,6 +54,7 @@ This article applies to: To view and make changes to the Copilot scenarios in the Microsoft 365 admin center, sign in with the following account: - Global Administrator + - AI Administrator To view the Copilot scenarios in the Microsoft 365 admin center, sign in with the following account: @@ -76,9 +77,9 @@ This article applies to: - The Microsoft 365 admin center changes frequently. So the scenarios in this article can be different than what you see in the Microsoft 365 admin center. -## Open the Copilot page +## Open the Copilot Control System -This section lists the steps to open the Copilot page in the Microsoft 365 admin center. +This section lists the steps to open the Copilot Control System in the Microsoft 365 admin center. Make sure you sign in with the appropriate role needed for your task. In our example, we want to change the settings. So, we sign in with the Global Administrator role. diff --git a/copilot/microsoft-365-copilot-reports-for-admins.md b/copilot/microsoft-365-copilot-reports-for-admins.md new file mode 100644 index 00000000000..b1f57bfd80c --- /dev/null +++ b/copilot/microsoft-365-copilot-reports-for-admins.md @@ -0,0 +1,274 @@ +--- +title: Microsoft 365 Copilot reports for IT admins +description: Learn about the different Microsoft 365 Copilot reporting options available for enterprise admins. Get an overview of the Copilot readiness and usage reports, enable the Copilot Dashboard in Viva Insights, get advanced insights and Power BI templates with Microsoft Viva, view agent reports in Power Platform and Copilot Studio, and access the Microsoft Purview audit logs. +author: MandiOhlinger +ms.author: mandia +manager: laurawi +ms.date: 04/16/2025 +ms.topic: overview +ms.service: microsoft-365-copilot +ms.subservice: +ms.localizationpriority: medium +ms.collection: +- scotvorg +- m365copilot +- magic-ai-copilot +ms.custom: +ms.reviewer: alejanl, camillepack +search.appverid: MET150 +f1.keywords: Copilot reporting options, Copilot usage reports, Microsoft 365 Copilot reports, Power BI templates, Purview audit logs +audience: Admin +ai-usage: ai-assisted +appliesto: + - ✅ Microsoft 365 Copilot +--- + +# Microsoft 365 Copilot reporting options for admins + +[Microsoft 365 Copilot](microsoft-365-copilot-overview.md) provides several reporting options that help administrators monitor usage, performance, and compliance. These reports provide insights into how Copilot is being used within your organization. + +Microsoft 365 Copilot offers four main sources for usage reports. Use these reports to make informed decisions about your Copilot adoption, deployment, and governance: + +- **Microsoft 365 admin center**: Provides readiness and usage reports focused on license eligibility, adoption, and basic usage metrics. +- **Viva Insights Copilot Analytics**: Offers comprehensive Copilot analytics through the Copilot Dashboard and Advanced Insights Analyst workbench for detailed metrics and custom reporting. +- **Microsoft Purview audit logs**: Delivers detailed audit logs of all Copilot activities for compliance tracking and security auditing. +- **Power Platform & Copilot Studio Analytics**: Provides consumption metrics for Copilot agents and detailed analytics on agent performance. + +This article provides an overview of the different Microsoft 365 Copilot reporting options available to IT administrators, including access requirements and the insights each report provides. + +This article applies to: + +- Microsoft 365 Copilot + +## Access requirements + +To use the reporting features described in this article, you need to sign into different portals with the appropriate permissions. + +| Reporting option | Required roles & access | +|------------------|-------------------------| +| **[Microsoft 365 admin center](https://admin.microsoft.com)** | - **Microsoft 365 Global Administrator**: Assigns the **AI Administrator** role.
- **AI Administrator**: Accesses the Copilot reports. | +| **Copilot Analytics, powered by Viva Insights** | - **Microsoft 365 Global Administrator**: Enables the Copilot Dashboard and delegates access to the dashboard and organizational insights. Senior leaders [might automatically get access](/viva/insights/org-team-insights/copilot-dashboard#how-automatic-access-to-the-copilot-dashboard-is-determined).
- **Microsoft 365 Global Administrator**: Sets up Viva Insights and assigns the **Insights Analyst** and **Insights Administrator** roles.
- **Insights Analyst**: Uses the Advanced Insights Analyst Workbench to build Copilot Power BI Templates.
- **Insights Administrator**: Manages settings in the Advanced Insights Analyst Workbench, like security, privacy, and uploading organization data files. | +| **[Microsoft Purview portal](https://purview.microsoft.com)** | - **Audit Reader**: Searches the audit logs. | +| **[Power Platform admin center](https://admin.powerplatform.microsoft.com)** | - **System Administrator**: Assigns the **Copilot Studio authors** role.
- **License admin** in [Microsoft 365 admin center](https://admin.microsoft.com): Assigns Copilot Studio licenses. | +| **[Copilot Studio](https://copilotstudio.microsoft.com)** | - **Copilot Studio Author**: Accesses analytics for agents they create. | + +## Microsoft 365 admin center reports + +The Microsoft 365 admin center provides Copilot readiness and usage reports: + +- **[Readiness report](/microsoft-365/admin/activity-reports/microsoft-365-copilot-readiness)** - This report shows how ready your organization is to adopt Microsoft 365 Copilot, including: + + - **License eligibility**: Shows the users that meet the prerequisites for Copilot licensing + - **App readiness**: Indicates usage levels of Microsoft 365 apps that Copilot integrates with + - **Technical requirements**: Highlights potential technical blockers for deployment + +- **[Usage report](/microsoft-365/admin/activity-reports/microsoft-365-copilot-usage)** - This report shows how Microsoft 365 Copilot is used in your organization, including: + + - **Adoption metrics**: Shows the number of users who accessed Copilot + - **User activity**: Displays active usage trends over time + - **App integration**: Reveals the Microsoft 365 applications that are being used with Copilot + - **Top agents**: Identifies the most frequently used Copilot agents + +### View the reports + +1. Sign in to the [Microsoft 365 admin center](https://admin.microsoft.com/) as the **Microsoft 365 Global Administrator** and assign the **AI Administrator** role to the users who need to access these reports. +1. The AI Admins can start using the reports: + + 1. Sign in to the [Microsoft 365 admin center](https://admin.microsoft.com/) as the **AI Administrator**. + 1. Select **Reports** > **Usage**. + + :::image type="content" source="media/microsoft-365-copilot-reports-for-admins/microsoft-365-admin-center-reports.png" alt-text="In Microsoft 365 admin center, select reports and then select usage."::: + + 1. Select **Microsoft 365 Copilot** > **Readiness** or **Usage**: + + :::image type="content" source="media/microsoft-365-copilot-reports-for-admins/microsoft-365-admin-center-usage.png" alt-text="In Microsoft 365 admin center reports, select Microsoft 365 Copilot and then readiness or usage." lightbox="media/microsoft-365-copilot-reports-for-admins/microsoft-365-admin-center-usage.png"::: + +To learn more about these reports, see: + +- [Microsoft 365 Copilot readiness report](/microsoft-365/admin/activity-reports/microsoft-365-copilot-readiness) +- [Microsoft 365 Copilot usage report](/microsoft-365/admin/activity-reports/microsoft-365-copilot-usage) + +## Viva Insights Copilot Analytics + +Microsoft Viva Insights provides deeper analytical capabilities for Microsoft 365 Copilot through two main features - **Copilot Dashboard** and **Advanced Insights Analyst tools**. + +### Copilot Dashboard + +The **Copilot Dashboard** offers a comprehensive view of Copilot's usage metrics and actionable insights, including: + +- **Adoption metrics**: Tracks user adoption rates and growth trends +- **Usage patterns**: Analyzes when and how users interact with Copilot +- **Productivity impact**: Measures the effect of Copilot on productivity metrics +- **ROI indicators**: Provides data points to help assess return on investment +- **Actionable insights**: Suggests ways to improve Copilot adoption and effectiveness + +#### Open the Copilot Dashboard + +1. Sign into the [Microsoft 365 admin center](https://admin.microsoft.com) as the **Microsoft 365 Global Administrator** and: + + 1. [Enable the Copilot Dashboard](/viva/insights/advanced/admin/manage-settings-copilot-dashboard). + 1. [Delegate access](/viva/insights/org-team-insights/delegate-access) to the users who need it. + +1. The users can start using the Copilot Dashboard: + + 1. In Microsoft Teams, users search for and open the **Viva Insights** app. + 1. In **Viva Insights**, select **Copilot Dashboard**. + +To learn more, see: + +- [Manage settings for the Microsoft Copilot Dashboard](/viva/insights/advanced/admin/manage-settings-copilot-dashboard) +- [Delegate access to organizational insights and Copilot Dashboard](/viva/insights/org-team-insights/delegate-access) +- [Connect the Microsoft Copilot Dashboard to Microsoft 365 customers](/viva/insights/org-team-insights/copilot-dashboard) + +### Advanced Insights Analyst tools + +For organizations requiring deeper analysis, Viva Insights provides advanced analytical capabilities, including: + +- **Custom Copilot queries**: Create specialized queries focused on Copilot usage +- **Power BI templates**: Use prebuilt templates to visualize Copilot data +- **Cross-data analysis**: Combine Copilot metrics with other workplace analytics +- **Detailed reporting**: Generate comprehensive reports for executives and stakeholders + +#### Open the Insights Analyst tools + +1. Sign into the [Microsoft 365 admin center](https://admin.microsoft.com/) as the **Microsoft 365 Global Administrator** and: + + 1. [Set up Viva Insights](/viva/insights/advanced/setup-maint/setup-overview). + 1. Add users to the **Insights Analyst** role. + 1. Add users to the **Insights Administrator** role. + + For the complete steps, see [Viva Insights setup checklist](/viva/insights/advanced/setup-maint/setup-overview). + +1. The **Insights Analyst** can go to **Viva Insights** > **Analysis**. Then, use the templates and [set up Copilot queries](/viva/insights/advanced/analyst/copilot-query). + + To learn more about some of the reports and view any prerequisites, see: + + - [Microsoft 365 Copilot adoption report](/viva/insights/advanced/analyst/templates/microsoft-365-copilot-adoption) + - [Microsoft 365 Copilot impact report](/viva/insights/advanced/analyst/templates/microsoft-365-copilot-impact) + +1. The **Insights Administrator** can sign into the [Analyst Workbench](https://analysis.insights.cloud.microsoft) > select **Copilot** to filter reports > select the report. + +To learn more, see: + +- [Advanced insights introduction](/viva/insights/advanced/introduction-to-advanced-insights) +- [Power BI report templates](/viva/insights/advanced/analyst/templates/introduction-to-templates) +- [Set up your queries using Microsoft 365 Copilot in Viva Insights](/viva/insights/advanced/analyst/copilot-query) + +## Microsoft Purview audit logs + +Microsoft Purview provides detailed audit logs of all Copilot activities, including: + +- **Complete activity tracking**: Logs all user interactions with Copilot +- **Prompt auditing**: Records the actual prompts entered by users +- **Compliance monitoring**: Helps ensure adherence to organizational policies +- **Security analysis**: Identifies potential security concerns in Copilot usage +- **Detailed filtering**: Allows filtering by user, date, action type, and more + +### Open the audit logs + +1. Sign in to the [Microsoft Purview portal](https://purview.microsoft.com) with a role that can search audit logs, like **Audit Reader**. + + There are other roles that can also search the audit logs. For a list of roles and what they can do, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview](/defender-office-365/scc-permissions). + +1. Select **Solutions** > **Audit**. + + :::image type="content" source="media/microsoft-365-copilot-reports-for-admins/microsoft-purview-portal-solutions-audit.png" alt-text="In the Microsoft Purview portal, select solutions and then select audit."::: + +1. In **Search** > **Workloads**, select **AIApp** and **Copilot**. Select **Search**. This step searches the audit log search results to only show activities related to Microsoft 365 Copilot. You can also get granular and set a date range and more. + + :::image type="content" source="media/microsoft-365-copilot-reports-for-admins/microsoft-purview-portal-audit-search.png" alt-text="In the Microsoft Purview portal audit feature, go to workloads and select some search options."lightbox="media/microsoft-365-copilot-reports-for-admins/microsoft-purview-portal-audit-search.png"::: + +To learn more, see: + +- [Microsoft Purview auditing solutions](/purview/audit-get-started) +- [Microsoft Purview audit logs for Copilot and AI activities](/purview/audit-copilot). +- [Considerations for Data Security Posture Management (DSPM) for AI & data security and compliance protections for Copilot](/purview/ai-microsoft-purview-considerations) + +## Power Platform reports and Copilot Studio Analytics + +For organizations using Copilot agents, there are some options for specialized analytics: + +- Power Platform admin center for consumption-based agents +- Copilot Studio Analytics for individual agents +- Copilot Studio Kit for testing and tracking custom agents + +To learn more, see: + +- [Key concepts – Analytics in Copilot Studio](/microsoft-copilot-studio/analytics-overview) +- [Set up your development environment for Microsoft 365 Copilot](/microsoft-365-copilot/extensibility/ecosystem) + +### Power Platform admin center + +The **Power Platform admin center** is for consumption-based agents, like [pay-as-you-go](./pay-as-you-go/overview.md) or pre-purchased message packs. + +The Power Platform admin center includes the following analytics: + +- **Message consumption**: Tracks the number of messages processed by agents +- **Session metrics**: Monitors agent session counts and durations +- **Capacity management**: Helps manage consumption-based billing +- **Tenant-wide visibility**: Provides an overview of all agents across the tenant + +#### Open the Power Platform reports + +To view the analytics for consumption-based agents, use the Power Platform admin center. + +1. Sign into the [Power Platform admin center](https://admin.powerplatform.microsoft.com) as the **System Administrator** and: + + 1. Select **Manage** > **Tenant settings**. + 1. Add users to the **Copilot Studio authors** role. Users with this role can create agents in Copilot Studio and view the analytics for the agents they create. + + To learn more, see [Assign a security role to a user](/power-platform/admin/assign-security-roles). + + > [!TIP] + > Users with the **Power Platform Administrators** role can view the analytics for all agents in the tenant. To add users to this role, use the [Microsoft Azure portal](https://portal.azure.com) > **Microsoft Entra ID** > **Manage** > **Roles and administrators**. + +2. The **Copilot Studio authors** can start using the reports: + + 1. Sign into the [Power Platform admin center](https://admin.powerplatform.microsoft.com) as the **Copilot Studio author**. + 1. Select **Licensing** > **Copilot Studio** > **Summary**. + 1. View the reports. + +### Copilot Studio Analytics + +**Copilot Studio Analytics** is for individual agents that are included in your Microsoft 365 Copilot license. + +Copilot Studio includes the following analytics: + +- **Agent performance**: Measures how effectively agents respond to queries +- **User satisfaction**: Tracks satisfaction ratings from users +- **Session metrics**: Analyzes session duration, completion rates, and abandonment +- **Topic effectiveness**: Identifies which topics are handled well or need improvement +- **Trace data**: Offers detailed logs for troubleshooting + +#### Open Copilot Studio Analytics + +To assign Copilot Studio licenses, use the Microsoft 365 admin center. To view the analytics for the agents, use Copilot Studio. + +1. Sign into the [Microsoft 365 admin center](https://admin.microsoft.com/) as the **License admin**. Assign Copilot Studio licenses to the users who need to create agents. + + To learn more, see: + + - [About admin roles in the Microsoft 365 admin center](/microsoft-365/admin/add-users/about-admin-roles) + - [Assign licenses and manage access to Copilot Studio](/microsoft-copilot-studio/requirements-licensing) + +1. The Copilot Studio users can start using the reports: + + 1. Sign into [Copilot Studio](https://copilotstudio.microsoft.com) as a licensed Copilot Studio user. + 1. Select **Agents** > select your agent > **Analytics** tab. + + To learn more, see [Review and improve agent effectiveness in Copilot Studio](/microsoft-copilot-studio/analytics-improve-agent-effectiveness). + +### Copilot Studio Kit + +The **Copilot Studio Kit** is a set of tools and resources that helps you test custom agents, track key performance indicators of your custom agents, and more. + +To learn more, see: + +- [Copilot Studio Kit - AppSource](https://appsource.microsoft.com/product/dynamics-365/microsoftpowercatarch.copilotstudiokit2) +- [Power CAT Copilot Studio Kit - GitHub](https://github.com/microsoft/Power-CAT-Copilot-Studio-Kit/blob/main/README.md) + +## Related articles + +- [Microsoft 365 Copilot license plans](microsoft-365-copilot-licensing.md) +- [Microsoft 365 Copilot setup](microsoft-365-copilot-setup.md) +- [Activity Reports in Microsoft 365](/microsoft-365/admin/activity-reports/activity-reports) diff --git a/copilot/microsoft-365-copilot-setup.md b/copilot/microsoft-365-copilot-setup.md index 64f1579eae9..c8ecdc31922 100644 --- a/copilot/microsoft-365-copilot-setup.md +++ b/copilot/microsoft-365-copilot-setup.md @@ -84,7 +84,7 @@ Audit logging is essential for tracking and monitoring activities within your Mi #### Steps to implement audit logging -- **Enable unified audit logging** Turn on unified audit logging in the Microsoft Purview compliance portal to capture all user and admin activities. +- **Enable unified audit logging** Turn on unified audit logging in the Microsoft Purview portal to capture all user and admin activities. - **Configure audit log retention** Set up retention policies to ensure that audit logs are retained for the required period based on your organization's compliance needs. - **Monitor and review logs** Regularly monitor and review audit logs to identify any suspicious activities or potential security threats. diff --git a/copilot/multiple-account-access.md b/copilot/multiple-account-access.md index d031bc7d9bc..f1266f332b0 100644 --- a/copilot/multiple-account-access.md +++ b/copilot/multiple-account-access.md @@ -13,7 +13,7 @@ ms.collection: - m365copilot - magic-ai-copilot hideEdit: true -ms.date: 03/20/2025 +ms.date: 04/24/2025 --- # Multiple account access to Copilot for work and school documents @@ -72,7 +72,7 @@ The end-user experience for blocked users viewing work and school documents is a ## Apps where multiple account access to Copilot is available -As of April 8, 2025, multiple account access is rolling out gradually in the following apps, starting with the version listed. +As of April 24, 2025, multiple account access is rolling out gradually in the following apps, starting with the version listed. ### On Android devices @@ -80,9 +80,23 @@ As of April 8, 2025, multiple account access is rolling out gradually in the fol ### On iOS devices +- OneNote: Version 16.96 (25040710) - PowerPoint: Version 2.95.25030623 - Word: Version 2.95.305.0 +### On iPad devices + +- Excel: Version 2.95.224.0 +- PowerPoint: Version 2.95.224.0 + +### On Mac devices + +- OneNote: Version 16.96 +- PowerPoint: Version 16.95 +- Word: Version 16.95.3 + ### On Windows devices -- Word: Version 16.0.18623.20018 +- Excel: Version 2503 +- PowerPoint: Version 2503 +- Word: Version 2503 diff --git a/copilot/pay-as-you-go/meters.md b/copilot/pay-as-you-go/meters.md index 0b5f111fc52..86c34a0148f 100644 --- a/copilot/pay-as-you-go/meters.md +++ b/copilot/pay-as-you-go/meters.md @@ -1,11 +1,11 @@ --- -title: Meters for Microsoft 365 Copilot Chat pay-as-you-go -description: Learn about the meters for the pay-as-you-go service for Microsoft 365 Copilot Chat. +title: Meters for Microsoft 365 Copilot pay-as-you-go for IT admins +description: Enterprise and company IT administrators can learn about the meters for the pay-as-you-go service for Microsoft 365 Copilot, including Copilot Chat. ms.author: camillepack author: camillepack manager: scotv -ms.date: 03/12/2025 -ms.reviewer: +ms.date: 04/22/2025 +ms.reviewer: nishanair audience: Admin ms.topic: get-started ms.service: microsoft-365-copilot @@ -16,20 +16,32 @@ ms.collection: - magic-ai-copilot - essentials-overview ms.custom: [copilot-learning-hub] +appliesto: + - ✅ Microsoft 365 Copilot --- -# Meters for Microsoft 365 Copilot Chat pay-as-you-go +# Meters for Microsoft 365 Copilot pay-as-you-go for IT admins -When you choose to use pay-as-you-go, usage of M365 Copilot Chat agents is billed to your Azure subscription using Azure meters. The following table describes the meter that is used for measuring usage. +The Microsoft 365 Copilot pay-as-you-go service offers a consumption-based option for organizations to access Copilot services, like Microsoft 365 Copilot Chat. To learn more about the pay-as-you-go service, see [Microsoft 365 Copilot pay-as-you-go overview](overview.md). + +When you choose to use pay-as-you-go, usage of Microsoft 365 Copilot Chat agents is billed to your Azure subscription using Azure meters. This article provides information about the meters used for billing Microsoft 365 Copilot pay-as-you-go services. + +This article applies to: + +- Microsoft 365 Copilot ## Meter details table -| Meter | What is counted? | What is billed? | -|------------------|----------------------------------------------------------------------------------------------------------------------------|-----------------------| -| Copilot Studio | A billable Copilot Studio message is a request or message sent to the Copilot triggering an action or response. Any agent or custom Copilot usage is billed through Copilot Studio message meter. | $0.01 per message | +The following table describes the meter that is used for measuring usage. + +| Meter | What is counted? | What is billed? | +|---|---|---| +| Copilot Studio | A billable Copilot Studio message is a request or message sent to the Copilot triggering an action or response. Any agent or custom Copilot usage is billed through Copilot Studio message meter. | $0.01 per message | To learn more about meters, see [Pay-as-you-go-meters](/power-platform/admin/pay-as-you-go-meters). -## Next step +## Related articles -[Set up pay-as-you-go](setup.md) (article) +- [Microsoft 365 Copilot pay-as-you-go service overview](overview.md) (article) +- [Set up pay-as-you-go for Microsoft 365 Copilot](setup.md) (article) +- [View costs and billing for Microsoft 365 Copilot pay-as-you-go](view-cost.md) (article) diff --git a/copilot/pay-as-you-go/overview.md b/copilot/pay-as-you-go/overview.md index fdcaae2621a..ae6f5f8bc76 100644 --- a/copilot/pay-as-you-go/overview.md +++ b/copilot/pay-as-you-go/overview.md @@ -1,11 +1,11 @@ --- title: Microsoft 365 Copilot pay-as-you-go overview -description: Learn about the pay-as-you-go service for Microsoft 365 Copilot Chat and how you can enable consumption-based billing for Copilot. +description: Enterprise and company IT admins can learn about the pay-as-you-go service for Microsoft 365 Copilot services, including Copilot Chat. Get an overview of the consumption-based billing process, connecting the billing to a Copilot service, and monitoring costs. ms.author: camillepack author: camillepack manager: scotv -ms.date: 03/12/2025 -ms.reviewer: +ms.date: 04/22/2025 +ms.reviewer: nishanair audience: Admin ms.topic: get-started ms.service: microsoft-365-copilot @@ -20,51 +20,92 @@ appliesto: - ✅ Microsoft 365 Copilot --- -# Microsoft 365 Copilot pay-as-you-go overview +# Microsoft 365 Copilot pay-as-you-go overview for IT admins -The Microsoft 365 Copilot pay-as-you-go plan offers a flexible and cost-effective way for organizations to access Copilot services. This plan allows administrators to enable consumption-based billing for specific Copilot scenarios, providing users with the ability to use Copilot features without committing to a full license. This article provides an overview of the pay-as-you-go plan, its benefits, and pricing details. +The Microsoft 365 Copilot pay-as-you-go plan offers a flexible and cost-effective way for organizations to access Copilot services. This plan allows administrators to enable consumption-based billing for specific Copilot scenarios, providing users with the ability to use Copilot features without committing to a full license. + +This article provides an overview of the pay-as-you-go plan, its benefits, and pricing details. ## Why pay-as-you-go? -The Microsoft 365 Copilot pay-as-you-go plan offers a flexible and scalable solution for organizations looking to leverage AI capabilities without the commitment of a full license. By enabling consumption-based billing, administrators can better manage costs and provide users with access to powerful Copilot features as needed. +The Microsoft 365 Copilot pay-as-you-go plan offers a flexible and scalable solution for organizations looking to use AI capabilities without the commitment of a full license. When you enable consumption-based billing, administrators can better manage costs and provide users with access to Copilot features as needed. + +The following services are available for pay-as-you-go billing: + +- Microsoft 365 Copilot Chat + +More services will be added in the future. No ETA. ### Common use cases -- **Establish usage patterns** Understand adoption patterns for new apps to determine whether prepaid licenses make financial sense for your business. -- **Scalability** Organizations can scale their usage based on demand, paying only for the consumption. +- **Establish usage patterns** - Understand adoption patterns for new apps to determine if prepaid licenses make financial sense for your business. +- **Scalability** - Organizations can scale their usage based on demand, paying only for the consumption. ## How does it work? -The pay-as-you-go plan allows administrators to set up billing for Microsoft 365 Copilot Chat, enabling users to access declarative agents on a consumption basis. You can manage billing, view costs, and turn off services as needed. +The pay-as-you-go plan allows administrators to set up billing and enable users to access declarative agents on a consumption basis. You can manage billing, view costs, and turn off services as needed. -The following administrator roles in the Microsoft 365 admin center can view and manage pay-as-you-go: +The following administrator roles in the [Microsoft 365 admin center](https://admin.microsoft.com) can view and manage pay-as-you-go: - Global administrator - AI administrator - Global reader (read-only access) -### Billing process +## Billing process + +The billing process requires two steps: + +1. Add a billing policy +2. Connect billing policy to Copilot services + +### Add a billing policy + +The billing policy acts as a distinct billing identifier that can be associated with a group responsible for the incurred cost. The main objectives of a pay-as-you-go billing policy are: + +- To allocate billing responsibilities across departments +- To facilitate the reuse of billing configurations across various pay-as-you-go scenarios +- To enable administrators to enforce governance +- To link users to a policy, establishing billing rules for a group of users -When you link your Azure subscription to a service for pay-as-you-go billing in the Microsoft 365 admin center, you're billed on a pay-as-you-go basis for the service you set up. +For the steps to add or update a billing policy, see [Set up pay-as-you-go for Microsoft 365 Copilot](setup.md). -You can cancel or delete your subscription at any time to stop processing and billing. +#### What you need to know + +- **Creating a billing policy** defines the billing infrastructure for pay-as-you-go that consists of an Azure subscription and a set of users. Creating a billing policy doesn't complete the billing setup. The billing policy must be connected to the Copilot service to complete the setup. + +- **Deleting a billing policy** removes the billing infrastructure. Any connected services are disconnected from pay-as-you-go billing. + +### Connect billing policy to Copilot services + +After you create a billing policy, the admin must link it to a Copilot service, such as Microsoft 365 Copilot Chat. This connection enables all users covered by the billing policy to access the Copilot service. + +Admins can disconnect a billing policy when it's no longer needed for the service. Upon disconnection, users linked to that billing policy lose access to the metered agents in the Copilot service. + +The following conditions apply when managing billing policies: + +- Admins can connect or disconnect a billing policy one at a time. +- Disconnect an existing "all users" billing policy before connecting to a user-specific billing policy. ### Process for new feature releases -In the future, new features using pay-as-you-go billing will be announced via a message center post. When the features become available, users in your organization will be able to take advantage of those capabilities. Pay-as-you-go billing is disabled by default. A global admin or owner to the subscription can enable or disable Microsoft 365 pay-as-you-go features in the Microsoft 365 admin center. +In the future, new features using pay-as-you-go billing are announced in a [message center](/microsoft-365/admin/manage/message-center) post. When the features become available, users in your organization can take advantage of those capabilities. Pay-as-you-go billing is disabled by default. A global admin or owner to the subscription can enable or disable Microsoft 365 pay-as-you-go features in the [Microsoft 365 admin center](https://admin.microsoft.com). ## Pricing details -When you use a Microsoft Pay-as-you-go service linked to an Azure subscription, the service gets billed using the Azure subscription that you specified when you set up Pay-as-you-go billing. The Azure subscription uses the Azure meter set up for the service. +When you use a Microsoft pay-as-you-go service linked to an Azure subscription, the service gets billed using the Azure subscription that you specified when you set up pay-as-you-go billing. The Azure subscription uses the Azure meter set up for the service. -To learn more about meters, see [Meters for Microsoft 365 Copilot Chat pay-as-you-go](meters.md). +To learn more about meters, see [Meters for Microsoft 365 pay-as-you-go](meters.md). ## Monitoring and billing -The organization's consumption of the pay-as-you-go service can be monitored on the [Cost Management](/microsoft-365/commerce/use-cost-mgmt) page in the Microsoft 365 admin center for each of the Microsoft 365 pay-as-you-go services that you use. +The organization's consumption of the pay-as-you-go service can be monitored in the [Microsoft 365 admin center](https://admin.microsoft.com) > [Cost Management](/microsoft-365/commerce/use-cost-mgmt) page for each Microsoft 365 pay-as-you-go service that you use. + +Administrators can also view the cost breakdown and analysis in [Microsoft Cost Management](/azure/cost-management-billing/costs/overview-cost-management). -Billing for services is done through the Azure subscription that you associate to the service. +To learn more, see [View costs and billing for Microsoft 365 Copilot pay-as-you-go](view-cost.md). -## Next step +## Related articles -[Meters](meters.md) (article) +- [Set up pay-as-you-go for Microsoft 365 Copilot](setup.md) (article) +- [Meters for Microsoft 365 Copilot pay-as-you-go](meters.md) (article) +- [View costs and billing for Microsoft 365 Copilot pay-as-you-go](view-cost.md) (article) diff --git a/copilot/pay-as-you-go/setup.md b/copilot/pay-as-you-go/setup.md index ee7881f6bac..3ebae1d12c3 100644 --- a/copilot/pay-as-you-go/setup.md +++ b/copilot/pay-as-you-go/setup.md @@ -1,11 +1,11 @@ --- -title: Set up Microsoft 365 Copilot Chat pay-as-you-go -description: Learn how to set up pay-as-you-go billing for Microsoft 365 Copilot Chat. +title: Set up Microsoft 365 Copilot pay-as-you-go for IT admins +description: Enterprise and company IT administrators can use the Microsoft 365 admin center to set up the Microsoft 365 Copilot pay-as-you-go feature. Get step-by-step instructions on setting up a billing policy, connecting the billing policy to the pay-as-you-go Copilot service, and removing pay-as-you-go. ms.author: camillepack author: camillepack manager: scotv -ms.date: 03/12/2025 -ms.reviewer: +ms.date: 04/22/2025 +ms.reviewer: nishanair audience: Admin ms.topic: get-started ms.service: microsoft-365-copilot @@ -16,50 +16,81 @@ ms.collection: - magic-ai-copilot - essentials-overview ms.custom: [copilot-learning-hub] +appliesto: + - ✅ Microsoft 365 Copilot --- -# Set up pay-as-you-go for Microsoft 365 Copilot Chat +# Set up pay-as-you-go for Microsoft 365 Copilot services for IT admins -Setting up the pay-as-you-go plan for Microsoft 365 Copilot Chat can be done directly from the Microsoft 365 admin center. This article provides step-by-step instructions on how to set up and manage pay-as-you-go billing. +The Microsoft 365 Copilot pay-as-you-go service offers a consumption-based option for organizations to access Copilot services, like Microsoft 365 Copilot Chat. To learn more about the pay-as-you-go service, see [Microsoft 365 Copilot pay-as-you-go overview](overview.md). + +You can set up the pay-as-you-go plan directly in the Microsoft 365 admin center. This article provides step-by-step instructions on how to set up and manage pay-as-you-go billing. + +This article applies to: + +- Microsoft 365 Copilot ## Prerequisites To set up pay-as-you-go, you must have the following prerequisites: -- Azure subscription and resource group +- Azure subscription and resource group: - You must have an owner or contributor Azure role to an Azure subscription to set up the pay-as-you-go service. - You must have an owner or contributor Azure role to an Azure resource group linked to the same Azure subscription to set up the pay-as-you-go service. - - To learn more, see [Use the Azure portal and Azure Resource Manager to Manage Resource Groups](/azure/azure-resource-manager/management/manage-resource-groups-portal). -- One of the following administrator roles: + + To learn more, see [Use the Azure portal and Azure Resource Manager to Manage Resource Groups](/azure/azure-resource-manager/management/manage-resource-groups-portal). + +- One of the following Microsoft 365 administrator roles: - Global administrator - Billing administrator - AI administrator -## Steps to set up pay-as-you-go billing + To learn more about these roles, see [Microsoft 365 admin roles](/microsoft-365/admin/add-users/about-admin-roles). + +## Step 1 - Add a billing policy + +The first step is to add a billing policy. + +1. In the [Microsoft 365 admin center](https://admin.microsoft.com), go to **Copilot** > **Billing & usage**. +2. On the **Billing policies** tab, select **Add a billing policy**. +3. Select the Azure subscription, resource group, and region for the pay-as-you-go setup. +4. Select the user scope for the billing policy: + - **All Users**: All users in the tenant are included in the billing policy + - **Specific group**: Assign a specific security group to be included in the billing policy +5. Review the details and select **Create policy** to complete the creation on billing policy. + +## Step 2 - Connect a billing policy + +After the billing policy is created, the next step is to connect the policy to the Copilot pay-as-you-go service. + +1. In the admin center, go to the **Pay-as-you-go services** tab. +2. Select **Microsoft 365 Copilot Chat** and select the billing policy you created. + +## Disable pay-as-you-go -1. In the Microsoft 365 admin center, go to **Copilot** > **Settings**. -1. If not already set up, create an Azure subscription and resource group. -1. Select the Azure subscription, resource group, and region for the pay-as-you-go setup. -1. Enable consumption-based billing for the desired Copilot scenarios. +Disabling pay-as-you-go for a Copilot service involves disconnecting the billing policies associated with the service, like Microsoft 365 Copilot Chat. -### What if pay-as-you-go is already set up in the Power Platform admin center? +1. In the admin center, go to the **Pay-as-you-go services** tab, and select the Copilot service, like Microsoft 365 Copilot Chat. +2. Unselect the billing policy, one at a time to disconnect the billing policy. +3. Read and accept the confirmation. This step completes the disconnection. -If you already set up pay-as-you-go in the Power Platform admin center, the two setups can coexist. You can also create another setup in the Microsoft 365 admin center without being double billed. The billing system ensures that you're only billed once for your user's usage, regardless of the setup location. +When you turn off pay-as-you-go, it can take up to two hours for users to stop being able to use the agents. If the agent hasn't been used, then it stops being available when pay-as-you-go is turned off. -> [!NOTE] -> Although the setups can coexist, it's recommended to turn off pay-as-you-go in the Power Platform admin center before enabling it in the Microsoft 365 admin center. +## Delete a billing policy -## Managing pay-as-you-go billing +After you disable pay-as-you-go, you can also delete the billing policy. -As an admin, you can do the following to manage pay-as-you-billing for your organization: +1. In the admin center, select a billing policy, and select the **Delete billing policy** button. +2. Accept the confirmation dialogue. Any services connected to the billing policy are disconnected. + +## What if pay-as-you-go is already set up in the Power Platform admin center? -- **View usage and costs** You can view detailed reports on Copilot usage and the associated costs. -- **Edit billing** Modify an unhealthy Azure subscription, resource group, and billing region. -- **Turn off billing** You can turn off pay-as-you-go billing for any of the Copilot services, removing the service from the agent's view. Once the service has been turned off, users without a Copilot license won't be able to use the service. +If you already set up pay-as-you-go in the Power Platform admin center, the two setups can coexist. You can create another setup in the Microsoft 365 admin center without being double billed. The billing system ensures that you're only billed once for your user's usage, regardless of the setup location. -> [!NOTE] -> When turning off pay-as-you-go, it may take up to two hours for users to stop being able to use the agents. Additionally, if the agent hasn't been used, it will no longer be accessible once pay-as-you-go is turned off. +Although the setups can coexist, we recommend you turn off pay-as-you-go in the Power Platform admin center before you enable it in the Microsoft 365 admin center. -## Next step +## Related articles -[View costs](view-cost.md) (article) +- [Microsoft 365 Copilot pay-as-you-go service overview](overview.md) (article) +- [Meters for Microsoft 365 Copilot pay-as-you-go](meters.md) (article) +- [View costs and billing for Microsoft 365 Copilot pay-as-you-go](view-cost.md) (article) diff --git a/copilot/pay-as-you-go/view-cost.md b/copilot/pay-as-you-go/view-cost.md index a85c32dbc65..2dfa2cacdda 100644 --- a/copilot/pay-as-you-go/view-cost.md +++ b/copilot/pay-as-you-go/view-cost.md @@ -1,11 +1,11 @@ --- -title: View costs for Microsoft 365 Copilot Chat pay-as-you-go -description: Learn about how to view billing and costs for pay-as-you-go for Microsoft 365 Copilot Chat. +title: View costs for Microsoft 365 Copilot pay-as-you-go +description: Enterprise and company IT administrators can learn how to view billing and costs for pay-as-you-go for Microsoft 365 Copilot services in the Microsoft 365 admin center, including Microsoft 365 Copilot Chat. ms.author: camillepack author: camillepack manager: scotv -ms.date: 03/12/2025 -ms.reviewer: +ms.date: 04/22/2025 +ms.reviewer: nishanair audience: Admin ms.topic: get-started ms.service: microsoft-365-copilot @@ -16,21 +16,42 @@ ms.collection: - magic-ai-copilot - essentials-overview ms.custom: [copilot-learning-hub] +appliesto: + - ✅ Microsoft 365 Copilot --- -# View costs and billing for Microsoft 365 Copilot Chat pay-as-you-go +# View costs and billing for Microsoft 365 Copilot pay-as-you-go -The Microsoft 365 Copilot Chat pay-as-you-go service offers a flexible and cost-effective way for organizations to access Copilot services. This article explains how administrators can view cost and billing details for pay-as-you-go. +The [Microsoft 365 Copilot pay-as-you-go service](overview.md) offers a flexible and cost-effective way for organizations to access Copilot services. + +Your organization's consumption of the pay-as-you-go service can be monitored in the [Microsoft 365 admin center](https://admin.microsoft.com) > [Cost Management](/microsoft-365/commerce/use-cost-mgmt) page for each Microsoft 365 pay-as-you-go service that you use, including Microsoft 365 Copilot Chat. + +This article explains how administrators can view cost and billing details for pay-as-you-go. + +This article applies to: + +- Microsoft 365 Copilot ## Access usage and billing information -To view detailed reports on Copilot usage and the associated costs, follow these steps: +To view detailed reports on Copilot usage and the associated costs, use the following steps: -1. Sign in to the Microsoft 365 admin center with one of the following administrator roles: +1. Sign in to the [Microsoft 365 admin center](https://admin.microsoft.com) with one of the following administrator roles: - Global administrator - Billing administrator -2. In the admin center, go to **Billing** > **Cost Management**. +2. Go to **Billing** > **Cost Management**. 3. On the **Cost Management** page, under **Service family**, you can see a service-level view of costs based on Copilot usage. -4. Alternatively, you can view costs in the Azure portal using Azure Cost Management. Billed amounts are updated daily (and sometimes more frequently), but it can take up to 24 hours after usage of a service to show up in Azure Cost Management. + +You can also view costs in the Azure portal using [Microsoft Cost Management](/azure/cost-management-billing/costs/overview-cost-management). You can filter the accumulated costs using tags, like `m365copilotchat`: + +:::image type="content" source="../media/copilot-pay-azure.png" alt-text="Screenshot of the Azure portal that shows the Cost Management page filtered on the Microsoft 365 Copilot Chat cost."::: + +Billed amounts are updated daily and sometimes more frequently. It can take 24 hours after usage of a service to show in Microsoft Cost Management. + +## Related articles + +- [Microsoft 365 Copilot pay-as-you-go service](overview.md) (article) +- [Set up pay-as-you-go for Microsoft 365 Copilot](setup.md) (article) +- [Meters for Microsoft 365 Copilot pay-as-you-go](meters.md) (article) diff --git a/copilot/pin-copilot.md b/copilot/pin-copilot.md index 636f7ed2a95..24fa1ba0223 100644 --- a/copilot/pin-copilot.md +++ b/copilot/pin-copilot.md @@ -62,7 +62,7 @@ Administrators can change this behavior by selecting an option for pinning Micro :::image type="content" source="media/do-not-pin-copilot-setting.png" alt-text="Screenshot showing the option to Do not pin Copilot for users."::: -When you uncheck the 'Allow users to be asked whether they want to pin it' option, Microsoft 365 Copilot Chat no longer appears in the App Launcher. +When you uncheck the 'Allow users to be asked whether they want to pin it' option, Copilot Chat no longer appears in the app launcher. In addition to removing the app from the launcher in the Microsoft 365 Copilot web and Windows app, it blocks users from acquiring or installing it from the metaOS app store. This behavior is specific to the Microsoft 365 Copilot app only and does not apply to Teams or Outlook. Global Admins and AI Admins can make changes to Microsoft 365 Copilot Chat pinning settings at any time. Changes take up to 48 hours to go into effect. diff --git a/copilot/release-notes.md b/copilot/release-notes.md index f5b8b094224..4ed14535f18 100644 --- a/copilot/release-notes.md +++ b/copilot/release-notes.md @@ -6,7 +6,7 @@ f1.keywords: ms.author: mandia author: MandiOhlinger manager: laurawi -ms.date: 04/02/2025 +ms.date: 04/16/2025 audience: Admin ms.reviewer: briandesouza ms.topic: get-started @@ -28,6 +28,64 @@ This page lists the latest features and improvements for Microsoft 365 Copilot. ## [All features](#tab/all) + +## April 16, 2025 +Updates released between April 2, 2025, and April 16, 2025. +### Excel +- **Access Copilot on-grid in Windows** [Windows] + + A Copilot icon appears right within your spreadsheet on Windows, giving you quick AI assistance as you work to keep your flow uninterrupted. + +- **Graph-grounded chat** [Windows, Mac, Web] + + Ask Copilot in Excel for insights drawn from your chats, documents, meetings, and emails via Microsoft Graph—enhancing your workbook analysis with contextual organizational data. + Learn more. +- **Use Copilot to search for answers from the web** [Windows, Mac, Web] + + In Excel, simply ask Copilot to search the web for answers and integrate the insights directly into your workbook, making data analysis even smoother. + Learn more. +### Microsoft 365 Admin Center +- **AI Admin role has permissions to manage agents** [Web] + + As an AI Admin, you manage agents with various capabilities including creating and overseeing Copilot connections that index data in Graph and perform actions, controlling which makers can build these connections and regulating the data sources used, maintaining observability over all connections, approving or denying agents, pre-installing them without requiring consent, and viewing them in Microsoft 365 admin center integrated apps page. + +### Microsoft 365 Copilot Chat +- **Get contextual suggestions during Copilot agent conversations** [Windows, Web] + + Speed up tasks with AI-driven prompts for next steps in Copilot Chat. See real-time suggestions to refine queries, dive deeper into topics, or resolve issues faster during agent interactions. + +- **Support for longer prompts** [Windows, Web] + + Copilot Chat now supports larger inputs for smoother handling of extensive documents and data. + +### Microsoft 365 Copilot extensibility +- **Discover agents for unlicensed and metered users** [Windows, Web] + + Empower more users with easy access to agents tailored to their needs—even if they are unlicensed or metered—broadening Copilot’s reach across your organization. + Learn more. + +- **Enable developer mode in Copilot Chat** [Developer] + + Leverage Microsoft 365 Copilot Chat developer mode directly within your development tools, simplifying the process to build and test custom integrations. + Learn more. + +### OneNote +- **Copilot-powered organization in OneNote** [Windows] + + Transform a flat list of pages within a section to have an intuitive hierarchy. Ask Copilot in chat to organize your section and apply the update for a streamlined Notebook organization experience. + Learn more. +### PowerPoint +- **Copilot in PowerPoint has improved performance when summarizing your presentation** [Web] + + PowerPoint Copilot now updates its language models regularly to deliver faster summaries, helping you quickly review your presentation content. + +### SharePoint +- **Author engaging web pages with Authoring** [Web] + + Combine the power of Large Language Models, your data in the Microsoft Graph, built-in or custom templates, and existing documents to create high-quality SharePoint pages while ensuring enterprise-level data security and privacy. + Learn more. + + ## April 2, 2025 Updates released between March 20, 2025, and April 2, 2025. ### Copilot Studio @@ -112,6 +170,10 @@ Updates released between March 5, 2025, and March 19, 2025. Replace manual topic triggers with AI-powered orchestration. You can now configure an agent to use generative AI to dynamically select relevant topics or plugin actions, creating more fluid conversations while reducing manual topic configuration. Learn more. +- **Create automated copilots triggered by events** [Web] + + Automates routine tasks by triggering copilots on events like table updates, new documents, or incoming emails—minimizing manual effort and keeping processes running smoothly. Learn more. + ### Microsoft 365 Admin Center - **Enhanced transparency for declarative agent metadata** @@ -186,6 +248,14 @@ Updates released between February 20, 2025, and March 4, 2025. Leverage Copilot Chat to search emails across both primary and archived mailboxes by appending 'from my archives' or 'also look for emails in my archives' in your prompts to quickly locate key messages. +- **Support lockbox for GenAI** [Web] + + Lets you review and approve data access requests in real time—ensuring sensitive information is safeguarded during critical support interactions. + +- **Enrichment of Messages in Copilot Chat** [Web] + + This feature enhances your communication experience by making it easier to understand and interact with your chat messages in Copilot Chat. With this feature, you will see cards and hoverable experiences that provide additional details of the chat without leaving your current view. This means you can quickly grasp the context of your conversations and find the information you need more efficiently. + ### Copilot Studio - **Add enterprise data with new graph connections** [Web] @@ -294,6 +364,13 @@ Updates released between February 5, 2025, and February 19, 2025. Updates released between January 24, 2025, and February 4, 2025. +### Microsoft 365 Clipchamp + +- **Video creation in Copilot Visual Creator powered by Clipchamp** [Web] + + Type your prompt and Clipchamp writes a bespoke script, sources high-quality footage, and assembles a video project with music, voiceover, text overlays, and transitions. Open your draft in the Clipchamp app to continue editing, exporting, and sharing your video. Learn more. + ### Microsoft 365 Copilot App - **Updates to the Microsoft 365 (Office) app** [Windows, Web, Android, iOS] @@ -318,6 +395,16 @@ Updates released between January 24, 2025, and February 4, 2025. Easily add full Copilot Chat capabilities including grounding conversations in work data and accessing Copilot in your favorite Microsoft 365 apps by purchasing or requesting a Microsoft 365 Copilot license directly in Copilot Chat. Learn more. +- **Automatic session titles for easier organization** [Web] + + Let Copilot Chat generate smart, descriptive titles for your chat sessions, making it simpler to find and revisit important conversations. + +### Excel + +- **Entry point from the column header** [Web] + + Offers an intuitive option to access column tools directly from the header, speeding up your workflow in Excel. + ### Microsoft Teams - **Speaker recognition and attribution in BYOD rooms with Copilot** [Windows, Mac] @@ -387,6 +474,10 @@ Updates released between January 8, 2025, and January 23, 2025. Check meeting details like RSVP status, date, and attachments without switching contexts in Copilot Chat. +- **Copilot agents available in Copilot Chat web mode** [Web] + + In Copilot Chat web mode, discover and use Copilot agents available for your organization. Agents are custom grounded chats that include specific knowledge sources from work and web. + ### Microsoft 365 Copilot App - **Control auto-start behavior on windows** [Windows] @@ -407,6 +498,12 @@ Updates released between January 8, 2025, and January 23, 2025. You can now access agents in the web-grounded Copilot Chat, enabling you to get access to additional sources of knowledge across both the work and web grounded experiences of Copilot Chat. Learn more. +### Microsoft 365 Copilot Studio + +- **Enable makers to configure SharePoint as a knowledge source for agents** [Web] + + Empowers makers to connect SharePoint, giving agents a richer context for delivering accurate and relevant responses. Learn more. + ### PowerPoint - **Generate summaries for longer presentations** [Windows, Web, Mac] @@ -1378,7 +1475,8 @@ Updates released between December 18, 2024, and January 7, 2025. - **Customize your draft message when you compose with Copilot** [Windows, Android, iOS, Mac] - You can now instruct Copilot to adjust your draft message however you'd like. Adjust the message with a custom prompt, like "add a call to action" or "make it persuasive". Learn more. + You can now instruct Copilot to adjust your draft message however you'd like. Adjust the message with a custom prompt, like "add a call to action" or "/make it persuasive". Learn more. + - **Enhanced Copilot UI with new date dividers** [Windows, Android, iOS, Mac] @@ -1671,6 +1769,44 @@ Updates released between December 18, 2024, and January 7, 2025. ## [Windows](#tab/win) + +## April 16, 2025 +Updates released between April 2, 2025, and April 16, 2025. +### Excel +- **Access Copilot on-grid in Windows** [Windows] + + A Copilot icon appears right within your spreadsheet on Windows, giving you quick AI assistance as you work to keep your flow uninterrupted. + +- **Graph grounded chat** [Windows, Mac, Web] + + Ask Copilot in Excel for insights drawn from your chats, documents, meetings, and emails via Microsoft Graph—enhancing your workbook analysis with contextual organizational data. + Learn more. +- **Use Copilot to search for answers from the web** [Windows, Mac, Web] + + In Excel, simply ask Copilot to search the web for answers and integrate the insights directly into your workbook, making data analysis even smoother. + Learn more. +### Microsoft 365 Copilot Chat +- **Get contextual suggestions during Copilot agent conversations** [Windows, Web] + + Speed up tasks with AI-driven prompts for next steps in Copilot Chat. See real-time suggestions to refine queries, dive deeper into topics, or resolve issues faster during agent interactions. + +- **Support  for longer prompts** [Windows, Web] + + Copilot Chat now supports larger inputs for smoother handling of extensive documents and data. + +### Microsoft 365 Copilot extensibility +- **Discover agents for unlicensed and metered users** [Windows, Web] + + Empower more users with easy access to agents tailored to their needs—even if they are unlicensed or metered—broadening Copilot’s reach across your organization. + Learn more. + +### OneNote +- **Copilot-powered organization in OneNote** [Windows] + + Transform a flat list of pages within a section to have an intuitive hierarchy. Ask Copilot in chat to organize your section and apply the update for a streamlined Notebook organization experience. + Learn more. + + ## April 2, 2025 Updates released between March 20, 2025, and April 2, 2025. @@ -2400,7 +2536,8 @@ Updates released between December 18, 2024, and January 7, 2025. - **Customize your draft message when you compose with Copilot** [Windows, Android, iOS, Mac] - You can now instruct Copilot to adjust your draft message however you'd like. Adjust the message with a custom prompt, like "add a call to action" or "make it persuasive". Learn more. + You can now instruct Copilot to adjust your draft message however you'd like. Adjust the message with a custom prompt, like "add a call to action" or "/make it persuasive". Learn more. + - **Enhanced Copilot UI with new date dividers** [Windows, Android, iOS, Mac] @@ -2584,6 +2721,50 @@ Updates released between December 18, 2024, and January 7, 2025. ## [Web](#tab/web) + +## April 16, 2025 +Updates released between April 2, 2025, and April 16, 2025. +### Excel +- **Graph grounded chat** [Windows, Mac, Web] + + Ask Copilot in Excel for insights drawn from your chats, documents, meetings, and emails via Microsoft Graph—enhancing your workbook analysis with contextual organizational data. + Learn more. +- **Use Copilot to search for answers from the web** [Windows, Mac, Web] + + In Excel, simply ask Copilot to search the web for answers and integrate the insights directly into your workbook, making data analysis even smoother. + Learn more. +### Microsoft 365 Admin Center +- **AI Admin role has permissions to manage agents** [Web] + + As an AI Admin, you manage agents with various capabilities including creating and overseeing Copilot connections that index data in Graph and perform actions, controlling which makers can build these connections and regulating the data sources used, maintaining observability over all connections, approving or denying agents, pre-installing them without requiring consent, and viewing them in Microsoft 365 admin center integrated apps page. + +### Microsoft 365 Copilot Chat +- **Get contextual suggestions during Copilot agent conversations** [Windows, Web] + + Speed up tasks with AI-driven prompts for next steps in Copilot Chat. See real-time suggestions to refine queries, dive deeper into topics, or resolve issues faster during agent interactions. + +- **Support  for longer prompts** [Windows, Web] + + Copilot Chat now supports larger inputs for smoother handling of extensive documents and data. + +### Microsoft 365 Copilot extensibility +- **Discover agents for unlicensed and metered users** [Windows, Web] + + Empower more users with easy access to agents tailored to their needs—even if they are unlicensed or metered—broadening Copilot’s reach across your organization. + Learn more. + +### PowerPoint +- **Copilot in PowerPoint has improved performance when summarizing your presentation** [Web] + + PowerPoint Copilot now updates its language models regularly to deliver faster summaries, helping you quickly review your presentation content. + +### SharePoint +- **Author engaging web pages with Authoring** [Web] + + Combine the power of Large Language Models, your data in the Microsoft Graph, built-in or custom templates, and existing documents to create high-quality SharePoint pages while ensuring enterprise-level data security and privacy. + Learn more. + + ## April 2, 2025 Updates released between March 20, 2025, and April 2, 2025. @@ -2646,6 +2827,10 @@ Updates released between March 5, 2025, and March 19, 2025. ### Copilot Studio +- **Create automated copilots triggered by events** [Web] + + Automates routine tasks by triggering copilots on events like table updates, new documents, or incoming emails—minimizing manual effort and keeping processes running smoothly. Learn more. + - **Use generative actions** [Web] Replace manual topic triggers with AI-powered orchestration. You can now configure an agent to use generative AI to dynamically select relevant topics or plugin actions, creating more fluid conversations while reducing manual topic configuration. Learn more. @@ -2704,6 +2889,14 @@ Updates released between February 20, 2025, and March 4, 2025. Leverage Copilot to search emails across both primary and archived mailboxes by appending 'from my archives' or 'also look for emails in my archives' in your prompts to quickly locate key messages. +- **Support lockbox for GenAI** [Web] + + Lets you review and approve data access requests in real time—ensuring sensitive information is safeguarded during critical support interactions. + +- **Enrichment of Messages in Copilot Chat** [Web] + + This feature enhances your communication experience by making it easier to understand and interact with your chat messages in Copilot Chat. With this feature, you will see cards and hoverable experiences that provide additional details of the chat without leaving your current view. This means you can quickly grasp the context of your conversations and find the information you need more efficiently. + ### Copilot Studio - **Add enterprise data with new graph connections** [Web] @@ -2761,6 +2954,14 @@ Updates released between February 5, 2025, and February 19, 2025. ## February 4, 2025 Updates released between January 24, 2025, and February 4, 2025. + +### Microsoft 365 Clipchamp + +- **Video creation in Copilot Visual Creator powered by Clipchamp** [Web] + + Type your prompt and Clipchamp writes a bespoke script, sources high-quality footage, and assembles a video project with music, voiceover, text overlays, and transitions. Open your draft in the Clipchamp app to continue editing, exporting, and sharing your video. Learn more. + ### Microsoft 365 Copilot App - **Updates to the Microsoft 365 (Office) app** [Windows, Web, Android, iOS] @@ -2785,6 +2986,16 @@ Updates released between January 24, 2025, and February 4, 2025. Easily add full Copilot Chat capabilities including grounding conversations in work data and accessing Copilot in your favorite Microsoft 365 apps by purchasing or requesting a Microsoft 365 Copilot license directly in Copilot Chat. Learn more. +- **Automatic session titles for easier organization** [Web] + + Let Copilot Chat generate smart, descriptive titles for your chat sessions, making it simpler to find and revisit important conversations. + +### Excel + +- **Entry point from the column header** [Web] + + Offers an intuitive option to access column tools directly from the header, speeding up your workflow in Excel. + ### PowerPoint - **Use Copilot to rewrite, trim, or formalize text** [Web, Mac] @@ -2832,6 +3043,16 @@ Updates released between January 8, 2025, and January 23, 2025. Check meeting details like RSVP status, date, and attachments without switching contexts in Copilot Chat. +- **Copilot agents available in Copilot Chat web mode** [Web] + + In Copilot Chat web mode, discover and use Copilot agents available for your organization. Agents are custom grounded chats that include specific knowledge sources from work and web. + +### Microsoft 365 Copilot Studio + +- **Enable makers to configure SharePoint as a knowledge source for agents** [Web] + + Empowers makers to connect SharePoint, giving agents a richer context for delivering accurate and relevant responses. Learn more. + ### PowerPoint - **Generate summaries for longer presentations** [Windows, Web, Mac] @@ -3430,7 +3651,6 @@ Updates released between December 18, 2024, and January 7, 2025. We have added an entry point on the right side of the page to make Loop Copilot's Draft and Rewrite capabilities more accessible. - ### Microsoft Stream - **Quickly summarize videos with Copilot in Stream** [Web] @@ -3731,7 +3951,6 @@ Updates released between December 18, 2024, and January 7, 2025. Easily turn plain text or lists into clear, organized tables for better readability and effortless data handling. Learn more. ## [Android](#tab/androidos) - ## April 2, 2025 Updates released between March 20, 2025, and April 2, 2025. ### Microsoft 365 Copilot Chat @@ -3982,7 +4201,8 @@ Updates released between December 18, 2024, and January 7, 2025. - **Customize your draft message when you compose with Copilot** [Windows, Android, iOS, Mac] - You can now instruct Copilot to adjust your draft message however you'd like. Adjust the message with a custom prompt, like "add a call to action" or "make it persuasive". Learn more. + You can now instruct Copilot to adjust your draft message however you'd like. Adjust the message with a custom prompt, like "add a call to action" or "/make it persuasive". Learn more. + - **Enhanced Copilot UI with new date dividers** [Windows, Android, iOS, Mac] @@ -4035,7 +4255,6 @@ Updates released between December 18, 2024, and January 7, 2025. Create summaries of your Whiteboard content, capturing key points from your collaborative work. ## [iOS](#tab/appleios) - ## April 2, 2025 Updates released between March 20, 2025, and April 2, 2025. ### Microsoft 365 Copilot Chat @@ -4467,7 +4686,8 @@ Updates released between December 18, 2024, and January 7, 2025. - **Customize your draft message when you compose with Copilot** [Windows, Android, iOS, Mac] - You can now instruct Copilot to adjust your draft message however you'd like. Adjust the message with a custom prompt, like "add a call to action" or "make it persuasive". Learn more. + You can now instruct Copilot to adjust your draft message however you'd like. Adjust the message with a custom prompt, like "add a call to action" or "/make it persuasive". Learn more. + - **Enhanced Copilot UI with new date dividers** [Windows, Android, iOS, Mac] @@ -4604,6 +4824,19 @@ Updates released between December 18, 2024, and January 7, 2025. ## [Mac](#tab/mac) + +## April 16, 2025 +Updates released between April 2, 2025, and April 16, 2025. +### Excel +- **Graph grounded chat** [Windows, Mac, Web] + + Ask Copilot in Excel for insights drawn from your chats, documents, meetings, and emails via Microsoft Graph—enhancing your workbook analysis with contextual organizational data. + Learn more. +- **Use Copilot to search for answers from the web** [Windows, Mac, Web] + + In Excel, simply ask Copilot to search the web for answers and integrate the insights directly into your workbook, making data analysis even smoother. + Learn more. + ## April 2, 2025 Updates released between March 20, 2025, and April 2, 2025. ### PowerPoint @@ -5092,7 +5325,8 @@ Updates released between December 18, 2024, and January 7, 2025. - **Customize your draft message when you compose with Copilot** [Windows, Android, iOS, Mac] - You can now instruct Copilot to adjust your draft message however you'd like. Adjust the message with a custom prompt, like "add a call to action" or "make it persuasive". Learn more. + You can now instruct Copilot to adjust your draft message however you'd like. Adjust the message with a custom prompt, like "add a call to action" or "/make it persuasive". Learn more. + - **Enhanced Copilot UI with new date dividers** [Windows, Android, iOS, Mac] diff --git a/copilot/scheduled-prompts.md b/copilot/scheduled-prompts.md index 192688d91a0..bb2cc53724c 100644 --- a/copilot/scheduled-prompts.md +++ b/copilot/scheduled-prompts.md @@ -5,7 +5,7 @@ f1.keywords: ms.author: camillepack author: camillepack manager: scotv -ms.date: 12/06/2024 +ms.date: 04/17/2025 audience: Admin ms.topic: how-to ms.service: microsoft-365-copilot @@ -17,21 +17,18 @@ ms.collection: description: "Learn about managing Scheduled prompts for Microsoft 365 Copilot, admin controls, data policies, and user management steps." --- -# Manage Scheduled prompts for Microsoft 365 Copilot +# Manage scheduled prompts for Microsoft 365 Copilot Scheduled prompts in Microsoft 365 Copilot allow users to automate Copilot prompts to run at set times and frequencies in Microsoft Teams, Office.com/chat, and Microsoft Outlook for the web and Desktop. As an admin, you can manage this feature for your organization. ->[!NOTE] -> This feature is in preview. As an admin, you can opt-in to making this feature available to your organization. To learn more, see [Opt in or out of preview](#opt-in-or-out-of-preview). - ## Before you begin -You must have both of the following licenses to manage Scheduled prompts: +You must have both of the following licenses to manage scheduled prompts: - Microsoft 365 Copilot license (in the Copilot subscription) - Standard Microsoft Power Automate license -Before you start using the Scheduled prompts feature, ensure that the Optional connected experiences setting is on in your tenant admin portal. This setting should be on by default, but you can double-check by accessing the Optional connected experiences setting at [config.office.com](https://config.office.com/). +Before you start using the scheduled prompts feature, ensure that the Optional connected experiences setting is on in your tenant admin portal. This setting should be on by default, but you can double-check by accessing the Optional connected experiences setting at [config.office.com](https://config.office.com/). Additionally, if you block all new connectors by default using Power Platform Data Loss Prevention (DLP) policies, you need to run the following command to explicitly reclassify the connector: @@ -48,17 +45,17 @@ To learn more about adding connectors to policies, see [Add-ConnectorsToPolicy]( ## Admin controls -To use the Scheduled prompts feature as an admin, no action is required if no DLP policies are in place and if the Optional connected experiences setting is already enabled. This feature is automatically included as part of the Optional Connected Experiences admin setting. However, if you have DLP policies in place that block new connectors, you might need to run the command script mentioned previously. You can check if you have such policies in the [Power Platform admin center](https://admin.powerplatform.microsoft.com). +To use the scheduled prompts feature as an admin, no action is required if no DLP policies are in place and if the Optional connected experiences setting is already enabled. This feature is automatically included as part of the Optional Connected Experiences admin setting. However, if you have DLP policies in place that block new connectors, you might need to run the command script mentioned previously. You can check if you have such policies in the [Power Platform admin center](https://admin.powerplatform.microsoft.com). If you prefer to not have this feature available to your organization, you can disable the Optional connected experiences setting at [config.office.com](https://config.office.com/). For more information, see [Admin controls for optional connected experiences](/microsoft-365-apps/privacy/optional-connected-experiences). -If you turn off the Optional connected experiences setting, this action prevents anyone in your organization from seeing Scheduled prompts in Copilot. +If you turn off the Optional connected experiences setting, this action prevents anyone in your organization from seeing scheduled prompts in Copilot. ### Data policies To prevent exposing organizational data, you should also create a data policy in the [Power Platform admin center](https://admin.powerplatform.microsoft.com). Creating a data policy in the center allows you to control access to these connectors in various ways to help reduce risk in your organization. To learn more, see [Data policies - Power Platform](/microsoft-365-apps/privacy/optional-connected-experiences). -## Disabling Scheduled prompts +## Disabling scheduled prompts :::image type="content" source="media/prompts-org-policy.png" alt-text="Screenshot showing the pop-up that informs users of their organization's data policy." lightbox="media/prompts-org-policy.png"::: @@ -74,9 +71,9 @@ Users will still see the feature if the Optional Connected Experiences setting i :::image type="content" source="media/prompt-set-up.png" alt-text="Screenshot showing the setup text for a new scheduled prompt in Copilot." lightbox="media/prompt-set-up.png"::: -Your users can find the Scheduled prompts feature by hovering over a prompt they have submitted to Copilot. When a user selects the Save and activate button to confirm the scheduled prompt, a user's prompt information will be sent to the Power Automate and Power Platform system, and the [Power Automate terms of service and privacy policy](/power-platform/admin/wp-compliance-data-privacy) apply. +Your users can find the scheduled prompts feature by hovering over a prompt they have submitted to Copilot. When a user selects the Save and activate button to confirm the scheduled prompt, a user's prompt information will be sent to the Power Automate and Power Platform system, and the [Power Automate terms of service and privacy policy](/power-platform/admin/wp-compliance-data-privacy) apply. -To manage their Scheduled prompts, users can follow these steps: +To manage their scheduled prompts, users can follow these steps: 1. Hover over the prompt they have submitted to Copilot. 2. Select the prompt management pane. @@ -85,15 +82,3 @@ To manage their Scheduled prompts, users can follow these steps: Users can schedule up to 10 prompts to run at specific times, with responses delivered to the right rail of their Microsoft 365 Copilot Chat experience. These prompts can be set to run on a recurring basis, ensuring users receive necessary information aligned with their workflow. Responses from scheduled prompts are bolded and have a recurring icon to help users identify them easily. To learn more about prompts for your users, see [Learn about Copilot prompts](https://support.microsoft.com/topic/learn-about-copilot-prompts-f6c3b467-f07c-4db1-ae54-ffac96184dd5). - -## Opt in or out of preview - -If you’re interested in joining the preview, you must opt in. To be eligible, you must have: - -- Copilot license -- Optional connected experiences admin toggle enabled -- DLP policies configured to allow the Microsoft 365 Copilot connector in your default Power Platform environment - -You can start the opt-in process by submitting a support ticket and stating that you would like to join the Scheduled Prompts preview. Our engineers can help validate eligibility criteria and enroll you into the preview program. - -To opt out of the preview, you can similarly submit a customer support ticket requesting to opt out. To learn more about how to do this, see [Get support for Microsoft 365 for business](/microsoft-365/admin/get-help-support). diff --git a/microsoft-365/admin/TOC.yml b/microsoft-365/admin/TOC.yml index 9ac59215fdb..28e971c039e 100644 --- a/microsoft-365/admin/TOC.yml +++ b/microsoft-365/admin/TOC.yml @@ -104,8 +104,6 @@ items: items: - name: Add users href: add-users/add-users.md - - name: Add a new employee - href: add-users/add-new-employee.md - name: Assign or unassign licenses for users href: manage/assign-licenses-to-users.md - name: Assign admin roles @@ -300,6 +298,8 @@ items: href: activity-reports/email-activity-ww.md - name: Email apps usage href: activity-reports/email-apps-usage-ww.md + - name: Enable app analytics in the Developer Portal + href: manage/enable-dev-analytics.md - name: Exchange Web Services usage href: activity-reports/ews-usage.md - name: Forms activity @@ -358,8 +358,8 @@ items: href: adoption/teamwork.md - name: Meetings href: adoption/meetings-new.md - - name: AI assistance - href: adoption/ai-assistance.md + - name: AI adoption score + href: adoption/ai-adoption-score.md - name: Organizational Messages href: adoption/organizational-messages.md - name: Group Level Aggregates @@ -557,7 +557,11 @@ items: - name: Troubleshoot href: /office/troubleshoot/ - name: Contact support - href: get-help-support.md + items: + - name: Get support for Microsoft 365 for business + href: get-help-support.md + - name: Case creation and diagnostic data + href: support-diagnostic-information-collection.md - name: Find support phone numbers href: https://support.microsoft.com/topic/customer-service-phone-numbers-c0389ade-5640-e588-8b0e-28de8afeb3f2#ID0EBBD=signinorgid - name: Navigation guide diff --git a/microsoft-365/admin/activity-reports/activity-reports.md b/microsoft-365/admin/activity-reports/activity-reports.md index 4735cfd791a..dec603ede44 100644 --- a/microsoft-365/admin/activity-reports/activity-reports.md +++ b/microsoft-365/admin/activity-reports/activity-reports.md @@ -203,7 +203,7 @@ Two methods have been approved for this API: The report will only contain a Privacy Setting property. For more information on Graph API, see [Use the Microsoft Graph API](/graph/use-the-api). You can use the Software Development Kit (SDK) or directly call the API using any program language with network ability. We recommend using [Graph Explorer](/graph/graph-explorer/graph-explorer-overview). -It will take a few minutes for these changes to take effect on the reports in the reports dashboard. This setting also applies to the Microsoft 365 usage reports in [Microsoft Graph](/graph/api/resources/report) and [Power BI](/microsoft-365/admin/usage-analytics/usage-analytics) and [the usage reports in Microsoft Teams Admin center](/microsoftteams/teams-analytics-and-reports/teams-reporting-reference). Showing identifiable user information is a logged event in the Microsoft Purview compliance portal audit log. +It will take a few minutes for these changes to take effect on the reports in the reports dashboard. This setting also applies to the Microsoft 365 usage reports in [Microsoft Graph](/graph/api/resources/report) and [Power BI](/microsoft-365/admin/usage-analytics/usage-analytics) and [the usage reports in Microsoft Teams Admin center](/microsoftteams/teams-analytics-and-reports/teams-reporting-reference). Showing identifiable user information is a logged event in the Microsoft Purview portal audit log. ## What happens to usage data when a user account is deleted? diff --git a/microsoft-365/admin/add-users/about-exchange-online-admin-role.md b/microsoft-365/admin/add-users/about-exchange-online-admin-role.md index fd008c2a4fd..5b541fa836c 100644 --- a/microsoft-365/admin/add-users/about-exchange-online-admin-role.md +++ b/microsoft-365/admin/add-users/about-exchange-online-admin-role.md @@ -2,8 +2,8 @@ title: "About the Exchange Administrator role" f1.keywords: - NOCSH -ms.author: efrene -author: efrene +ms.author: kwekua +author: kwekuako manager: scotv ms.date: 06/03/2024 audience: Admin diff --git a/microsoft-365/admin/add-users/add-new-employee.md b/microsoft-365/admin/add-users/add-new-employee.md deleted file mode 100644 index 615fdd20022..00000000000 --- a/microsoft-365/admin/add-users/add-new-employee.md +++ /dev/null @@ -1,88 +0,0 @@ ---- -title: "Add a new employee to Microsoft 365" -f1.keywords: -- NOCSH -ms.author: efrene -author: efrene -manager: scotv -ms.date: 06/03/2024 -audience: Admin -ms.topic: how-to -ms.service: microsoft-365-business -ms.localizationpriority: medium -ms.collection: -- Tier2 -- scotvorg -- M365-subscription-management -- Adm_O365 -- Adm_TOC -- must-keep -ms.custom: -- MSStore_Link -- AdminSurgePortfolio -- okr_smb -- AdminTemplateSet -search.appverid: -- MET150 -- MOE150 -ms.assetid: 9cdfa29d-7681-4af2-a79d-3e72e7ab9778 -description: "Admins can learn how to add new employees to Microsoft 365 for business and give them access to email, Skype, and apps in Microsoft 365." ---- - -# Add a new employee to Microsoft 365 - -This article helps you onboard a new employee to Microsoft 365 for business. We assume you're an Admin and you've already [completed Microsoft 365 set up](../setup/setup.md), and now you have someone new joining your company. - -You're in the right place if your new employee needs Microsoft 365, and you're using a [Microsoft 365 plan]( https://www.microsoft.com/microsoft-365/buy/compare-all-microsoft-365-products?rtc=1) that lets you install apps in Microsoft 365, like Word and Excel, on a computer. - - **Not an admin?** [Learn your way around Microsoft 365](https://support.microsoft.com/office/396b8d9e-e118-42d0-8a0d-87d1f2f055fb) helps business and home users with setup. - - **No Microsoft 365 productivity apps in your plan?** Follow these steps, but skip the sections for installing apps. Instead, use the [Get started at Microsoft365.com](https://support.microsoft.com/office/91a4ec74-67fe-4a84-a268-f6bdf3da1804). - -Here's a quick overview: - -|**Step**|**Why do this?**| -|:-----|:-----| -|[Step 1: Create a Microsoft 365 account for the employee](#step-1-create-a-microsoft-365-account-for-the-employee)
|Each time a new employee joins your business, create an account for them so they can start using Microsoft 365.
| -|[Step 2: Give the employee their user ID and password](#step-2-give-the-employee-their-user-id-and-password)
|When you create an account, you get an ID and password that you can pass to your employee so they can sign in.
| -|[Step 3: Explain where to sign in](#step-3-explain-where-to-sign-in)
|The sign in location is [https://www.office.com](https://www.office.com)
| -|[Step 4: Help your employee get started](#step-4-help-your-employee-get-started)
|Let your employee know how to use OneDrive or any team sites in your organization.
| - -## Step 1: Create a Microsoft 365 account for the employee - -For instructions, see [Add users and assign licenses at the same time](add-users.md). When you set up your new employee, you can choose to send sign-in details to the employee's personal account. This way, they receive an email from Microsoft Online Service Team that tells them how to sign in to Microsoft 365. - -## Step 2: Give the employee their user ID and password - -Unless you sent it to their personal email address, print the employee's sign in name and password, and hand it to them. Or tell them the information over the phone. - -Because they won't yet have access to their email, don't send the information to that email address. - -## Step 3: Explain where to sign in - -Just like Facebook, Amazon, or Gmail, your employee signs in to use Microsoft 365. Give them the following sign in information: - -- Sign in at [https://www.office.com](https://www.office.com). - -- Select **Sign in**, then type the user ID and password. - -## Step 4: Help your employee get started - -Share with them the [Employee quick setup for Microsoft 365](https://support.microsoft.com/office/7f34c318-e772-46a5-8c0a-ab86661542d1) to sign in, install software, set up email, and more. - -And here's a quick reference to help get them started: - -|**Task**|**Find the details**| -|:-----|:-----| -|Sign in to Microsoft 365
|Go to [https://www.microsoft365.com](https://www.microsoft365.com), select **Sign in**, and then enter your user ID and password.
| -|Install Microsoft 365 productivity apps onto your computer.

|When you sign in, the home page has a link to download and install apps like Word and Outlook. Select **Install Microsoft 365**. For instructions, see [Download and install or reinstall Microsoft 365 or Office 2021 on a PC or Mac](https://support.microsoft.com/office/4414eaaf-0478-48be-9c42-23adc4716658).
| -|Set up your email in Outlook 2016 .
|Once Microsoft 365 productivity apps are installed on your computer, set up your email. For instructions, see [How to set up Outlook](https://support.microsoft.com/office/6e27792a-9267-4aa4-8bb6-c84ef146101b).
| -|Set up Skype for Business so you can connect with coworkers or business partners in your company or around the world. You can start conversations with IM, voice, or video calls.
|[Install Skype for Business on your computer](https://support.microsoft.com/office/8a0d4da8-9d58-44f9-9759-5c8f340cb3fb).

To learn how to use Skype for Business, [watch a video.](https://support.microsoft.com/office/3a21eca4-434d-41f1-ab06-3d4a268573b7)

Have you set up Skype for Business so your employees can contact people external to your business who are using the free Skype app? If not, tell your new employee so they know what to expect when using Skype for Business.
| -|Install apps on your mobile device if you want to get email or use Skype for Business on your phone.
|If you want to set up the Outlook mobile app so you can get email via your phone. For instructions, see [iOS](https://support.microsoft.com/office/b2de2161-cc1d-49ef-9ef9-81acd1c8e234), [Android](https://support.microsoft.com/office/886db551-8dfa-4fd5-b835-f8e532091872), [Windows Phone](https://support.microsoft.com/office/181a112a-be92-49ca-ade5-399264b3d417)

If you want to use Skype for Business on your mobile device, download and install the mobile app. For instructions, see [iOS](https://support.microsoft.com/office/3239c8a3-cf55-4ff0-a967-5de51911c049#OS_Type=iOS), [Android](https://support.microsoft.com/office/4d1b7dfa-5b0b-4868-bae5-25947fb99e6e#OS_Type=Android), [Windows Phone](https://support.microsoft.com/office/4d1b7dfa-5b0b-4868-bae5-25947fb99e6e#OS_Type=Windows_Phone)
| -|Complete the OneDrive training to help you learn how to store and organize your documents, presentations, and spreadsheets in the cloud.
|Keep your business-related documents in the cloud by using OneDrive. You can always get to your content, even if you're signed in to Microsoft 365 on a different computer. [Watch a video to learn how to use your OneDrive](https://support.microsoft.com/office/b30da4eb-ddd2-44b6-943b-e6fbfc6b8dde)

**Training:** [OneDrive training](https://support.microsoft.com/office/1f608184-b7e6-43ca-8753-2ff679203132) (Select OneDrive).
| -|Complete the SharePoint training to help you collaborate with coworkers and share content.
|The best place to keep documents that your coworkers will also access is in SharePoint.

**Training:** [Video: Collaborate with team content using SharePoint](https://support.microsoft.com/office/c17b6824-cc22-478f-8757-497cc6b57121)

**Find out:** How is your organization using SharePoint, and what type of documents get stored there. Also, which documents are stored in OneDrive.
| - -## Related content - -[Remove a former employee from Microsoft 365](remove-former-employee.md) (article)\ -[Add users and assign licenses at the same time65](add-users.md) (article) diff --git a/microsoft-365/admin/add-users/add-users.md b/microsoft-365/admin/add-users/add-users.md index a27f97efb15..ac1c8d9627b 100644 --- a/microsoft-365/admin/add-users/add-users.md +++ b/microsoft-365/admin/add-users/add-users.md @@ -2,8 +2,8 @@ title: "Add users and assign licenses in Microsoft 365" f1.keywords: - NOCSH -ms.author: efrene -author: efrene +ms.author: kwekua +author: kwekuako manager: scotv audience: Admin ms.topic: how-to @@ -26,7 +26,7 @@ ms.custom: search.appverid: - MET150 description: "Learn how to give each team member a user account so they can have Microsoft 365 licenses, sign-in credentials, and Microsoft 365 mailboxes." -ms.date: 03/14/2025 +ms.date: 04/10/2025 --- # Add users and assign licenses at the same time @@ -67,7 +67,7 @@ Check out this video and others on our [YouTube channel](https://go.microsoft.co 1. Go to the admin center at https://portal.partner.microsoftonline.cn. -::: moniker-end +::: moniker-end 2. Go to **Users** > **Active users**, and select **Add a user**. 3. In the **Set up the basics** pane, fill in the basic user information, and then select **Next**. @@ -76,8 +76,13 @@ Check out this video and others on our [YouTube channel](https://go.microsoft.co - **Password settings** - Choose to use the autogenerated password or to create your own strong password for the user. - The user must change their password after 90 days. Or you can choose to **Require this user to change their password when they first sign in**. 4. In the **Assign product licenses** pane, select the location and the appropriate license for the user. If you don't have any licenses available, you can still add a user and buy additional licenses. Expand **Apps** and select or deselect apps to limit the apps the user has a license for. Select **Next**. -5. In the **Optional settings** pane, expand **Roles** if you want to make this user an admin. Expand **Profile info** to add additional information about the user. -6. Select **Next**, review your new user's settings, make any changes you like, then select **Finish adding**, then **Close**. +5. In the **Optional settings** pane, expand **Roles** if you want to make this user an admin. Expand **Profile info** to add additional information about the user. **Select Next**. +6. In the Review and finish page, review your new user's settings, make any changes you like, then select **Finish adding**. +7. On the ...**added to active users** page: + - To get the user their password, select Print to create a hard copy or a pdf of their credentials that you can securely share with them. + - Send them an email that contains useful information to help them get started with Microsoft 365. + - Select whether you want to save these user settings as a template and choose whether you want to add another user. + - Select **Close**. ## Add a user in the admin simplified view @@ -95,7 +100,7 @@ If you're seeing this page in the admin center, you're on the **admin simplified 1. Go to the admin center at https://portal.partner.microsoftonline.cn. -::: moniker-end +::: moniker-end 2. Select **Add user**. You can select either the **Add user** button at the top of the page or in the **Users** tab under **Your organization**. 3. In the **Set up the basics** pane, fill in the basic user information, and then select **Next**. @@ -105,8 +110,13 @@ If you're seeing this page in the admin center, you're on the **admin simplified - The user must change their password after 90 days. Or you can choose to **Require this user to change their password when they first sign in**. - Choose whether you want to send the password in email when the user is added. 4. In the **Assign product licenses** pane, select the location and the appropriate license for the user. If you don't have any licenses available, you can still add a user and buy additional licenses. Expand **Apps** and select or deselect apps to limit the apps the user has a license for. Select **Next**. -5. In the **Optional settings** pane, expand **Roles** to make this user an admin. Expand **Profile info** to add additional information about the user. -6. Select **Next**, review your new user's settings, make any changes you like, then select **Finish adding**, then **Close**. +5. In the **Optional settings** pane, expand **Roles** if you want to make this user an admin. Expand **Profile info** to add additional information about the user. Select **Next**. +6. In the Review and finish page, review your new user's settings, make any changes you like, then select **Finish adding**. +7. On the ...**added to active users** page: + - To get the user their password, select Print to create a hard copy or a pdf of their credentials that you can securely share with them. + - Send them an email that contains useful information to help them get started with Microsoft 365. + - Select whether you want to save these user settings as a template and choose whether you want to add another user. + - Select **Close**. ## Watch: Add multiple user @@ -144,7 +154,7 @@ When you create, edit, or delete a custom user view, the changes are shown in th A few things to note about standard views: -- Some standard views display an unsorted list if there are more than 2,000 users in the list. To locate specific users in this list, use the search box. +- Some standard views display an unsorted list if there are more than 2,000 users in the list. To locate specific users in this list, use the search box. - If you didn't purchase Microsoft 365 from Microsoft, **Billing admins** don't appear in the standard views list. For more information, see [Assigning admin roles](assign-admin-roles.md). ### Choose the filters for your custom user view @@ -210,14 +220,14 @@ You can also filter by additional user profile details used in your organization ::: moniker range="o365-21vianet" -1. In the admin center, go to **Users** \> Active users. +1. In the admin center, go to **Users** \> Active users. ::: moniker-end -2. On the **Active users** page, select **Filter**, select the filter you want to change, and then select **Edit filter**. +2. On the **Active users** page, select **Filter**, select the filter you want to change, and then select **Edit filter**. > [!TIP] - > You can edit only custom views. + > You can edit only custom views. 3. On the **Custom filter** page, edit the information as needed, and then select **Save**. Or, to delete the filter, at the bottom of the page select **Delete**. @@ -227,7 +237,6 @@ After you add a user, you get an email notification from Microsoft. The email co ## Related content -[Add a new employee to Microsoft 365](add-new-employee.md) (article)\ [Add several users at the same time to Microsoft 365](../../enterprise/add-several-users-at-the-same-time.md) (article)\ [Restore a user in Microsoft 365](restore-user.md) (article)\ [Assign licenses to users](../manage/assign-licenses-to-users.md) (article)\ diff --git a/microsoft-365/admin/add-users/change-a-user-name-and-email-address.md b/microsoft-365/admin/add-users/change-a-user-name-and-email-address.md index 794c79b8832..a835b003640 100644 --- a/microsoft-365/admin/add-users/change-a-user-name-and-email-address.md +++ b/microsoft-365/admin/add-users/change-a-user-name-and-email-address.md @@ -31,7 +31,7 @@ description: "Learn how you can change a user's email address and display name." Check out [Microsoft 365 small business help](https://go.microsoft.com/fwlink/?linkid=2197659) on YouTube. -You might need to change someone's email address and display name if, for example, they get married and their family name changes. +As the admin of a Microsoft 365 organization, you might need to change someone's email address and display name if, for example, they get married and their family name changes. > [!TIP] > If you need help with the steps in this topic, consider [working with a Microsoft small business specialist](https://go.microsoft.com/fwlink/?linkid=2186871). With Business Assist, you and your employees get around-the-clock access to small business specialists as you grow your business, from onboarding to everyday use. diff --git a/microsoft-365/admin/add-users/delete-a-user.md b/microsoft-365/admin/add-users/delete-a-user.md index bd4042b766a..9d731870b39 100644 --- a/microsoft-365/admin/add-users/delete-a-user.md +++ b/microsoft-365/admin/add-users/delete-a-user.md @@ -137,5 +137,4 @@ Here are the most common issues people encounter when deleting a user: [Restore a user](restore-user.md) (article)\ [Permanently delete a mailbox](/exchange/permanently-delete-a-mailbox-exchange-2013-help) (article)\ [Remove a former employee from Microsoft 365](remove-former-employee.md) (article)\ -[Add a new employee to Microsoft 365](add-new-employee.md) (article)\ [Delete a User Account](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc753730(v=ws.11)) (article): Use these instructions if your business uses **Active Directory** that is synchronizing with Microsoft Entra ID. You can't do it through Microsoft 365. diff --git a/microsoft-365/admin/add-users/remove-former-employee.md b/microsoft-365/admin/add-users/remove-former-employee.md index 6b5687ff7a7..bc226ea0e29 100644 --- a/microsoft-365/admin/add-users/remove-former-employee.md +++ b/microsoft-365/admin/add-users/remove-former-employee.md @@ -88,6 +88,5 @@ If you're using Microsoft Entra ID, see the [Remove-MgUser](/powershell/module/m ## Related content [Restore a user](restore-user.md) (article)\ -[Add a new employee to Microsoft 365](add-new-employee.md) (article)\ [Assign or unassign licenses for users in the Microsoft 365 admin center](../manage/assign-licenses-to-users.md) (article)\ [Remove-CalendarEvents](/powershell/module/exchange/remove-calendarevents) diff --git a/microsoft-365/admin/admin-overview/admin-center-overview.md b/microsoft-365/admin/admin-overview/admin-center-overview.md index e5817ade65e..cc439578f36 100644 --- a/microsoft-365/admin/admin-overview/admin-center-overview.md +++ b/microsoft-365/admin/admin-overview/admin-center-overview.md @@ -34,7 +34,7 @@ description: "Use either simplified view in the Microsoft 365 admin center to ma Check out all of our small business content on [Small business help & learning](https://go.microsoft.com/fwlink/?linkid=2224585). -The Microsoft 365 admin center gives users a central location to take care of common admin tasks, such as: +The Microsoft 365 admin center gives users a central location to take care of common admin tasks, such as: - Manage users: [Add users and assign licenses at the same time](../add-users/add-users.md), [Delete or restore users](../add-users/delete-a-user.md), or [Reset a user's password](../add-users/reset-passwords.md). @@ -99,7 +99,7 @@ On the **Upcoming changes** tab, view relevant announcements about new and updat On the **Learn** tab, browse videos and articles about the admin center and other Microsoft 365 features. To explore more advanced features of the admin center, open the navigation menu and expand the headings to see more. Select **Show all** to see everything in the navigation menu or use the search bar to quickly find what you're looking for. -If you need assistance, select **Help & support** (the headphones icon). Search for topic you want help with and view the recommended solution or select the headset to contact support, and then enter your question and contact information. +If you need assistance, select **Help & support** (the headphones icon). Search for topic you want help with and view the recommended solution or select the headset to contact support, and then enter your question and contact information. ## Watch: The admin center in dashboard view diff --git a/microsoft-365/admin/adoption/ai-adoption-score.md b/microsoft-365/admin/adoption/ai-adoption-score.md new file mode 100644 index 00000000000..479d0f7295d --- /dev/null +++ b/microsoft-365/admin/adoption/ai-adoption-score.md @@ -0,0 +1,169 @@ +--- +title: "AI adoption category in Adoption Score" +ms.author: camillepack +author: camillepack +manager: scotv +ms.date: 04/16/2025 +audience: Admin +ms.topic: concept-article +ms.service: microsoft-365-business +ms.localizationpriority: medium +monikerRange: 'o365-worldwide' +ms.collection: +- Tier2 +- scotvorg +- M365-subscription-management +- Adm_O365 +- Adm_TOC +- m365copilot +- magic-ai-copilot +search.appverid: +- MET150 +- MOE150 +description: "Learn about the AI adoption category in Adoption Score in the Microsoft 365 admin center." +--- + +# AI adoption category in Adoption Score + +With AI rapidly entering the day-to-day experience of people in your organization, we introduced a new People Experiences category called AI adoption. + +The AI adoption score represents the extent to which users in your organization have made Microsoft 365 Copilot a daily habit. A score of 100 means that all licensed Microsoft 365 Copilot users in your organization are using Copilot features for an average of at least three days per week (or 12 out of the past 28 days). Users that reach this three-day threshold in a given month are highly likely to become long-term engaged users of Microsoft 365 Copilot. If users fall short of that three-day threshold, the score still gives credit for making progress to it. You can use the other insights on the page to understand what behaviors and features contribute to your score, and to identify actions to take to boost your score. + +:::image type="content" source="../../media/ai-assistance.png" alt-text="Screenshot showing the Adoption Sore dashboard with AI adoption category." lightbox="../../media/ai-assistance.png"::: + +## AI adoption score calculation methodology + +The AI adoption score is calculated based on a target of getting each licensed user to use Microsoft 365 Copilot for an average of three days per week. The three-day threshold is used because individuals that achieve it have a high likelihood of becoming a consistent long-term user of Microsoft 365 Copilot. The score is computed in a way that your organization still gets credit if users fall short of the three-day threshold. For example, a score of 66 out of 100 indicates that, on average, licensed users are active in Copilot for two days per week (two-thirds of the way towards the three-day target). + +>[!NOTE] +> For organizations that have enabled at least one user for Microsoft 365 Copilot, AI adoption score is now added to your total Adoption Score, causing the denominator for the overall score to increase by 100. If your organization doesn’t have any Microsoft 365 Copilot licenses, then the maximum total score is unchanged (700 or 800) and the peer benchmark is unchanged (sum of all categories reports except AI adoption score). + +How the score is calculated: + +- For each user licensed for Microsoft 365 Copilot, Microsoft calculates the number of days out of the prior 28 days on which the user actively used Microsoft 365 Copilot. + - The score accounts for Copilot usage in the following Microsoft 365 applications: Outlook, Teams, Copilot Chat, Word, PowerPoint, Excel, OneNote, and Loop. Only intentional user actions in these apps are considered; the set of actions is consistent with those used for the [Microsoft 365 Copilot usage report](/microsoft-365/admin/activity-reports/microsoft-365-copilot-usage). + - The use of agents in any of the applications listed previously is included in addition to non-agentic features, like summarizing a Word document or drafting an email in Outlook. +- An individual-level score is produced for each user by dividing the count of active days by 12. For example, eight days of usage results in (8/12) × 100 = 66.67. 12 days over a 28 day period is equivalent to an average of three days per week. +- The tenant-level score is produced by taking the average score across all licensed users in the organization. If the score is 50 out of 100, this means that, on average, licensed users in your organization used Microsoft 365 Copilot on six days out of the past 28 days (which means an average of 1.5 days per week). + +## Peer benchmark for AI adoption score + +The AI adoption score peer benchmark allows you to compare your organization's score with organizations like yours. Consistent with other scores in Adoption Score, the benchmark is calculated by taking the average AI adoption score across organizations similar to yours (based on your region, industry, and number of users licensed for Microsoft 365). To learn more, see [Interpreting your organization's Adoption Score](adoption-score.md#interpreting-your-organizations-adoption-score) + +:::image type="content" source="../../media/ai-current-chart.png" alt-text="Screenshot showing the chart for the AI adoption score." lightbox="../../media/ai-current-chart.png"::: + +To learn more, see [Interpreting your organization's Adoption Score](adoption-score.md#interpreting-your-organizations-adoption-score). + +## Time trends + +Time trend data is provided for each category score to track progress. This allows visibility of Copilot usage across various Microsoft 365 applications over different time ranges, similar to other categories. Alongside the current 28-day rolling period (RL28), insights are available for: + +- 30 days (RL30) +- 90 days (RL90) +- 180 days (RL180) + +:::image type="content" source="../../media/ai-time-trend.png" alt-text="Screenshot showing the dropdown of time trend options to select."::: + +## View AI adoption resources + +Resources are available for administrators to facilitate adoption, including: + +- Copilot Prompt Gallery +- Success Kit (v2.0) +- User Enablement +- Copilot Dashboard in Viva Insights +- Microsoft Copilot Scenario + +:::image type="content" source="../../media/ai-as-resources.png" alt-text="Screenshot showing the list of resources you can select for Copilot adoption."::: + +## Organizational messages in AI adoption score + +Organizational messages in AI adoption score enable you to drive awareness of Microsoft 365 Copilot features for licensed users that haven’t tried certain key Copilot capabilities yet. You can use organizational messages to quickly deliver actionable notifications directly in Microsoft products (including Teams and Windows), targeted to users based on their Microsoft 365 Copilot activity, all while maintaining user-level privacy. + +:::image type="content" source="../../media/ai-as-org-message.png" alt-text="Screenshot showing the recommendation cards for Copilot organizational messages." lightbox="../../media/ai-as-org-message.png"::: + +To use organizational messages in AI adoption score, you must be assigned one of the following admin roles: + +- Global administrator +- Organizational message writer + +After selecting **Take action**, the following message configuration panel appears: + +:::image type="content" source="../../media/ai-as-org-message-create.png" alt-text="Screenshot the pane to create an organizational message for Copilot." lightbox="../../media/ai-as-org-message-create.png"::: + +Administrators can select one of three message options. Messages will be sent to users who have a Copilot license assigned to them but haven’t actively used relevant Copilot features over the prior 28 days. Admins can further filter down this list by excluding certain groups. Admins can also configure the start date and end date for the message. + +To edit a message after it has already been scheduled, admins can cancel and reschedule it. + +Currently, organizational messages will show up on either new Teams or Windows 11 notification center. The languages of the messages will adjust based on end-users’ preferred languages. + +## How are people using Microsoft 365 Copilot? + +Microsoft 365 Copilot usage insights are organized into six key areas: + +- Microsoft Copilot usage frequency +- Teams meetings and chats +- Documents (Word, Excel, PowerPoint, OneNote) +- Emails +- Microsoft 365 Copilot Chat +- Agents for Copilot + +These insights show how many users are engaging with various Copilot features compared to the total number of users enabled over a 28-day period. + +You can use these insights to: + +- Identify which Copilot features are most popular among your users +- Spot underutilized features that might benefit from more user training +- Track adoption trends across different Microsoft 365 applications over 7, 30, 90, 180 days’ time ranges + +:::image type="content" source="../../media/ai-using-copilot.png" alt-text="Screenshot showing the charts for how people are using Copilot." lightbox="../../media/ai-using-copilot.png"::: + +>[!NOTE] +> When you select the settings to opt out specific user groups from calculating People experience insights in Adoption Score, the AI adoption category would not respect that opt out for the current release. + +## Sentiment survey upload experience + +In this section, you can upload Copilot survey results to have them displayed in the Microsoft Copilot Dashboard. + +>[!NOTE] +> You won't be able to view the results on this page; they're only available in the Microsoft Copilot Dashboard. + +Use this feature to provide your organizational leaders with a centralized location for insights on how users feel about the AI adoption they receive from Copilot. + +This feature is only available for Global administrators. Users without this role can't see it in the Microsoft 365 admin center. + +### Upload survey data + +To access the Sentiment survey upload feature in the Microsoft 365 admin center, follow these steps: + +1. In the Microsoft 365 admin center, go to **Reports** > **Adoption Score**. +1. Navigate to **AI adoption score** and select **View details**. +1. On the AI adoption score page, navigate to **Assess Copilot sentiment for your org** and select **Record survey results**. + +:::image type="content" source="../../media/as-upload-survey.png" alt-text="Screenshot showing the dashboard to upload survey data for Copilot sentiment" lightbox="../../media/as-upload-survey.png"::: + +### Update results over time + +:::image type="content" source="../../media/as-update-results.png" alt-text="Screenshot showing the screen for updating survey results for Copilot sentiment" lightbox="../../media/as-update-results.png"::: + +You can upload new survey data as often as you want to keep the Copilot Dashboard updated with the latest feedback from your users. + +:::image type="content" source="../../media/as-delete-survey.png" alt-text="Screenshot showing the screen for deleting survey results for Copilot sentiment"::: + +If you want to delete or overwrite the existing survey data, select the Delete or Overwrite buttons at the bottom of the page. Note, these actions can't be undone. + +### Suggested Copilot survey questions + +To measure Copilot user sentiment in your organization, we recommend delivering a survey to users that asks them to indicate their level of agreement with the following four statements: + +- *Using Copilot helps improve the quality of my work or output* + +- *Using Copilot helps me spend less mental effort on mundane or repetitive tasks* + +- *Using Copilot allows me to complete tasks faster* + +- *When using Copilot, I am more productive* + +For each of these, we recommend allowing users to indicate whether or not they Strongly Disagree, Disagree, Neither Agree Nor Disagree, Agree, or Strongly Agree with the statement. You can then combine the Agree and Strongly Agree responses to compute the % of users who agreed with each statement and compare results with the Microsoft benchmarks shown in this tab. + +Your user survey doesn't need to be limited to these four statements, but we recommend including them at a minimum for easy comparison with Microsoft’s benchmark results. diff --git a/microsoft-365/admin/adoption/ai-assistance.md b/microsoft-365/admin/adoption/ai-assistance.md deleted file mode 100644 index 7e1c04eed11..00000000000 --- a/microsoft-365/admin/adoption/ai-assistance.md +++ /dev/null @@ -1,134 +0,0 @@ ---- -title: "AI assistance category in Adoption Score" -f1.keywords: -- NOCSH -ms.author: camillepack -author: camillepack -manager: scotv -ms.date: 01/22/2025 -audience: Admin -ms.topic: concept-article -ms.service: microsoft-365-business -ms.localizationpriority: medium -monikerRange: 'o365-worldwide' -ms.collection: -- Tier2 -- scotvorg -- M365-subscription-management -- Adm_O365 -- Adm_TOC -- m365copilot -- magic-ai-copilot -search.appverid: -- MET150 -- MOE150 -description: "Learn about the AI assistance category in Adoption Score." ---- - -# AI assistance category in Adoption Score - -With AI rapidly entering the day-to-day experience of people in your organization, we introduced a new People Experiences category called AI assistance. - -The AI assistance score represents the extent to which users in your organization have made Microsoft 365 Copilot a daily habit. A score of 100 means that all licensed Microsoft 365 Copilot users in your organization used Copilot features for more than half of working days over the prior month. You can use the other insights on the page to understand what behaviors and features contribute to your score, and to identify actions to take to boost your score. - -:::image type="content" source="../../media/ai-assistance.png" alt-text="Screenshot showing the Adoption Sore dashboard with AI assistance category." lightbox="../../media/ai-assistance.png"::: - ->[!NOTE] -> AI assistance score is in preview. The scoring logic and insights displayed on the page might change over time. As of January 2025, the score now includes more Microsoft 365 Copilot actions, such as sending prompts in Microsoft 365 Copilot Chat and using Intelligent Recap in Microsoft Teams. This update causes the score value to increase as compared with the original score delivered in Fall 2023. - -## AI assistance score calculation methodology - -The AI assistance score is calculated based on a target of getting each licensed user to use Microsoft 365 Copilot on at least 12 out of the past 28 days. The 12-day threshold is used because individuals that achieve it have a high likelihood of becoming a consistent long-term user of Microsoft 365 Copilot. - -How the score is calculated: - -- For each user licensed for Microsoft 365 Copilot, Microsoft calculates the number of days out of the prior 28 days on which the user actively used Microsoft 365 Copilot. - - Note: The score accounts for Copilot usage in the following Microsoft 365 applications: Outlook, Teams, Copilot Chat, Word, PowerPoint, Excel, OneNote, and Loop. Only intentional user actions in these apps are considered; the set of actions is consistent with those used for the Microsoft 365 Copilot usage report. -- An individual-level score is produced for each user by dividing the count of active days by 12. For example, eight days of usage results in (8/12) × 100 = 66.67 -- The tenant-level score is produced by taking the average score across all licensed users in the organization. If the score is 50 out of 100, this means that, on average, licensed users in your organization used Microsoft 365 Copilot on six days out of the past 28 days. - -## Peer benchmark for AI assistance score - -The AI assistance score peer benchmark allows you to compare your organization's score with organizations like yours. Consistent with other scores in Adoption Score, the benchmark is calculated by taking the average AI assistance score across organizations similar to yours (based on your region, industry, and number of users licensed for Microsoft 365). - -:::image type="content" source="../../media/ai-current-chart.png" alt-text="Screenshot showing the chart for the AI assistance score." lightbox="../../media/ai-current-chart.png"::: - -To learn more, see [Interpreting your organization's Adoption Score](adoption-score.md#interpreting-your-organizations-adoption-score). - -## Time trend - -Time trend data is provided for each category score to track progress. This allows visibility of Copilot usage across various Microsoft 365 applications over different time ranges, similar to other categories. Alongside the current 28-day rolling period (RL28), insights are available for: - -- 30 days (RL30) -- 90 days (RL90) -- 180 days (RL180) - -## How can I improve my score? - -Resource cards are available for administrators to facilitate adoption, including Copilot Lab, Success Kit (v2.0), User Enablement, Copilot Dashboard in Viva Insights, and Microsoft Copilot Scenario. For more details, refer to the resource cards. - -:::image type="content" source="../../media/ai-improve-score.png" alt-text="Screenshot showing the resource card for improving Copilot." lightbox="../../media/ai-improve-score.png"::: - -## How are people using Microsoft 365 Copilot? - -Microsoft 365 Copilot usage insights are organized into five key areas: Teams meetings & chats, documents, emails, Copilot Chat, and Microsoft Copilot usage frequency. These insights show how many users are engaging with various Copilot features compared to the total number of enabled users over a 28-day period. - -You can use these insights to: - -- Identify which Copilot features are most popular among your users. -- Spot underutilized features that might benefit from more user training. -- Track adoption trends across different Microsoft 365 applications over 7, 30, 90, 180 days’ time ranges. - -:::image type="content" source="../../media/ai-using-copilot.png" alt-text="Screenshot showing the charts for how people are using Copilot." lightbox="../../media/ai-using-copilot.png"::: - ->[!NOTE] -> When you select the settings to opt out specific user groups from calculating People experience insights in Adoption Score, the AI assistance category wouldn't be respecting that opt out for the current release. This will be changed in future releases. - -## Sentiment survey upload experience - -In this section, you can upload Copilot survey results to have them displayed in the Microsoft Copilot Dashboard. - ->[!NOTE] -> You won't be able to view the results on this page; they're only available in the Microsoft Copilot Dashboard. - -Use this feature to provide your organizational leaders with a centralized location for insights on how users feel about the AI assistance they receive from Copilot. - -This feature is only available for Global administrators. Users without this role can't see it in the Microsoft 365 admin center. - -### Upload survey data - -To access the Sentiment survey upload feature in the Microsoft 365 admin center, follow these steps: - -1. In the Microsoft 365 admin center, go to **Reports** > **Adoption Score**. -1. Navigate to **AI assistance** and select **View details**. -1. On the AI assistance page, navigate to **Assess Copilot sentiment for your org** and select **Record survey results**. - -:::image type="content" source="../../media/as-upload-survey.png" alt-text="Screenshot showing the dashboard to upload survey data for Copilot sentiment" lightbox="../../media/as-upload-survey.png"::: - -:::image type="content" source="../../media/as-survey-results.png" alt-text="Screenshot showing the pop-up pane for survey results for Copilot sentiment"::: - -### Update results over time - -:::image type="content" source="../../media/as-update-results.png" alt-text="Screenshot showing the screen for updating survey results for Copilot sentiment" lightbox="../../media/as-update-results.png"::: - -You can upload new survey data as often as you want to keep the Copilot Dashboard updated with the latest feedback from your users. - -:::image type="content" source="../../media/as-delete-survey.png" alt-text="Screenshot showing the screen for deleting survey results for Copilot sentiment"::: - -If you want to delete or overwrite the existing survey data, select the Delete or Overwrite buttons at the bottom of the page. Note, these actions can't be undone. - -### Suggested Copilot survey questions - -To measure Copilot user sentiment in your organization, we recommend delivering a survey to users that asks them to indicate their level of agreement with the following four statements: - -- *Using Copilot helps improve the quality of my work or output* - -- *Using Copilot helps me spend less mental effort on mundane or repetitive tasks* - -- *Using Copilot allows me to complete tasks faster* - -- *When using Copilot, I am more productive* - -For each of these, we recommend allowing users to indicate whether or not they Strongly Disagree, Disagree, Neither Agree Nor Disagree, Agree, or Strongly Agree with the statement. You can then combine the “Agree” and “Strongly Agree” responses to compute the % of users who agreed with each statement and compare results with the Microsoft benchmarks shown in this tab. - -Your user survey doesn't need to be limited to these four statements, but we recommend including them at a minimum for easy comparison with Microsoft’s benchmark results. diff --git a/microsoft-365/admin/basic-mobility-security/capabilities.md b/microsoft-365/admin/basic-mobility-security/capabilities.md index cc2dc2dfe65..ab7c57d8cf9 100644 --- a/microsoft-365/admin/basic-mobility-security/capabilities.md +++ b/microsoft-365/admin/basic-mobility-security/capabilities.md @@ -237,7 +237,7 @@ You can set these additional policy settings by using PowerShell cmdlets: ## Remotely wipe a mobile device -If a device is lost or stolen, you can remove sensitive organizational data and help prevent access to your Microsoft 365 organization resources by doing a wipe from **Microsoft Purview compliance portal** > **Data loss prevention** > **Device management**. You can do a selective wipe to remove only organizational data or a full wipe to delete all information from a device and restore it to its factory settings. +If a device is lost or stolen, you can remove sensitive organizational data and help prevent access to your Microsoft 365 organization resources by doing a wipe from **Microsoft Purview portal** > **Data loss prevention** > **Device management**. You can do a selective wipe to remove only organizational data or a full wipe to delete all information from a device and restore it to its factory settings. For more information, see [Wipe a mobile device in Basic Mobility and Security](wipe-mobile-device.md). diff --git a/microsoft-365/admin/basic-mobility-security/create-an-apns-certificate-for-ios-devices.md b/microsoft-365/admin/basic-mobility-security/create-an-apns-certificate-for-ios-devices.md index a3403b41511..918eefb83e9 100644 --- a/microsoft-365/admin/basic-mobility-security/create-an-apns-certificate-for-ios-devices.md +++ b/microsoft-365/admin/basic-mobility-security/create-an-apns-certificate-for-ios-devices.md @@ -54,4 +54,4 @@ To manage iOS devices like iPad and iPhones, you need to create an Apple Push No 1. Select **Upload**. -To complete setup, go back to [Basic Mobility and Security](https://compliance.microsoft.com/basicmobilityandsecurity). +To complete setup, go back to [Basic Mobility and Security](https://purview.microsoft.com/basicmobilityandsecurity). diff --git a/microsoft-365/admin/basic-mobility-security/create-device-security-policies.md b/microsoft-365/admin/basic-mobility-security/create-device-security-policies.md index 26abc048c91..1b372a1d0cb 100644 --- a/microsoft-365/admin/basic-mobility-security/create-device-security-policies.md +++ b/microsoft-365/admin/basic-mobility-security/create-device-security-policies.md @@ -46,7 +46,7 @@ You can use Basic Mobility and Security to create device policies that help prot Before you can start, make sure you have activated and set up Basic Mobility and Security. For instructions, see [Overview of Basic Mobility and Security](overview.md). -1. From your browser, go to . +1. From your browser, go to . 2. On the **Policies** tab, select **Create**. @@ -66,7 +66,7 @@ The policy is pushed to the device of each user the policy applies to the next t After you’ve created a device policy, check that the policy works as you expect before you deploy it to your organization. -1. From your browser, go to [https://compliance.microsoft.com/basicmobilityandsecurity](https://compliance.microsoft.com/basicmobilityandsecurity). +1. From your browser, go to [https://purview.microsoft.com/basicmobilityandsecurity](https://purview.microsoft.com/basicmobilityandsecurity). 2. Select **View the list of managed devices**. 3. Check the status of user devices that have the policy applied. You want the **State** of devices to be **Managed.** 4. You can also do a full or selective wipe on a device by clicking on **Factory reset** or **Remove company data** from **Manage** button after selecting a device. For instructions, see [Wipe a mobile device in Basic Mobility and Security](wipe-mobile-device.md). @@ -75,7 +75,7 @@ After you’ve created a device policy, check that the policy works as you expec After you’ve created a device policy and verified that it works as expected, deploy it to your organization. -1. From your browser type: [https://compliance.microsoft.com/basicmobilityandsecurity](https://compliance.microsoft.com/basicmobilityandsecurity). +1. From your browser type: [https://purview.microsoft.com/basicmobilityandsecurity](https://purview.microsoft.com/basicmobilityandsecurity). 2. Select the policy you want to deploy, and choose **Edit** next to **Groups applied to.** 3. Search for a group to add and click on **Select**. 4. Select **Close** and **Change setting.** @@ -89,7 +89,7 @@ To help secure your organization information, you should block app access to Mic **To block app access:** -1. From your browser, type [https://compliance.microsoft.com/basicmobilityandsecurity](https://compliance.microsoft.com/basicmobilityandsecurity). +1. From your browser, type [https://purview.microsoft.com/basicmobilityandsecurity](https://purview.microsoft.com/basicmobilityandsecurity). 1. Select **Organization Setting** tab. 3. To block unsupported devices, choose **Access** under **If a device isn't supported by Basic Mobility and Security for Microsoft 365**, and then select **Save**. @@ -100,7 +100,7 @@ To help secure your organization information, you should block app access to Mic If you want to exclude some people from conditional access checks on their mobile devices and you've created one or more security groups for those people, add the security groups here. The people in these groups won't have any policies enforced for their supported mobile devices. This is the recommended option if you no longer want to use Basic Mobility and Security in your organization. -1. From your browser, type [https://compliance.microsoft.com/basicmobilityandsecurity](https://compliance.microsoft.com/basicmobilityandsecurity). +1. From your browser, type [https://purview.microsoft.com/basicmobilityandsecurity](https://purview.microsoft.com/basicmobilityandsecurity). 1. Select **Organization Setting** tab. diff --git a/microsoft-365/admin/basic-mobility-security/frequently-asked-questions.yml b/microsoft-365/admin/basic-mobility-security/frequently-asked-questions.yml index e5df963432c..dc50801ed86 100644 --- a/microsoft-365/admin/basic-mobility-security/frequently-asked-questions.yml +++ b/microsoft-365/admin/basic-mobility-security/frequently-asked-questions.yml @@ -35,14 +35,14 @@ sections: - question: | How can I get Basic Mobility and Security? I don't see it in the Microsoft 365 admin center. answer: | - 1. Activate Basic Mobility and Security by going to the [home page](https://compliance.microsoft.com/basicmobilityandsecurity/). + 1. Activate Basic Mobility and Security by going to the [home page](https://purview.microsoft.com/basicmobilityandsecurity/). - question: | How can I get started with device management in Basic Mobility and Security? answer: | There are four steps to getting started with Basic Mobility and Security: - 1. Activate Basic Mobility and Security by going to the [home page](https://compliance.microsoft.com/basicmobilityandsecurity/). + 1. Activate Basic Mobility and Security by going to the [home page](https://purview.microsoft.com/basicmobilityandsecurity/). 2. Select Policies and then select Create. Create device management policies, and apply them to groups of users that are set up in security groups. We recommend that you start by deploying the policies to a small test group. For more info, see [Create device security policies in Basic Mobility and Security](create-device-security-policies.md). @@ -129,7 +129,7 @@ sections: - question: | How do policies work for Basic Mobility and Security? How do I set them up? Disable them? answer: | - After you complete initial setup for Basic Mobility and Security, you create policies and apply them to groups of users in the Security & Compliance Center. Policies require users of the policies to enroll their devices in Basic Mobility and Security before the device can be used to access Microsoft 365 data. The policies that you set up determine settings for mobile devices, for example, how often passwords must be reset or whether data encryption is required. For more information, see [Create device security policies in Basic Mobility and Security](create-device-security-policies.md) and [Microsoft Purview compliance portal](../../compliance/microsoft-365-compliance-center.md). + After you complete initial setup for Basic Mobility and Security, you create policies and apply them to groups of users in the Security & Compliance Center. Policies require users of the policies to enroll their devices in Basic Mobility and Security before the device can be used to access Microsoft 365 data. The policies that you set up determine settings for mobile devices, for example, how often passwords must be reset or whether data encryption is required. For more information, see [Create device security policies in Basic Mobility and Security](create-device-security-policies.md) and [Microsoft Purview portal](../../compliance/microsoft-365-compliance-center.md). For step-by-step instructions for creating and deploying device policies, see [Create device security policies in Basic Mobility and Security](create-device-security-policies.md). diff --git a/microsoft-365/admin/basic-mobility-security/manage-device-access-settings.md b/microsoft-365/admin/basic-mobility-security/manage-device-access-settings.md index 147074f90c9..b71c4e8d3fc 100644 --- a/microsoft-365/admin/basic-mobility-security/manage-device-access-settings.md +++ b/microsoft-365/admin/basic-mobility-security/manage-device-access-settings.md @@ -35,7 +35,7 @@ Use these steps: 1. Sign in to Microsoft 365 with a [Compliance administrator](/entra/identity/role-based-access-control/permissions-reference) account. -2. In your browser, type: . +2. In your browser, type: . 3. Go to **Organization Setting** tab. @@ -57,7 +57,7 @@ Here's a breakdown for the device details available to you. :::image type="content" source="../../media/basic-mobility-security/bms-7-powershell-parameters.png" alt-text="Basic Mobility and Security PowerShell parameters."::: > [!NOTE] -> The commands and scripts that follow also return details about any devices managed by [Microsoft Intune](https://www.microsoft.com/cloud-platform/microsoft-intune). +> The commands and scripts that follow also return details about any devices managed by [Microsoft Intune](https://www.microsoft.com/security/business/Microsoft-Intune). Here are a few things you need to set up to run the commands and scripts that follow: diff --git a/microsoft-365/admin/basic-mobility-security/manage-enrolled-devices.md b/microsoft-365/admin/basic-mobility-security/manage-enrolled-devices.md index b59cefcb45e..9e5828afa0f 100644 --- a/microsoft-365/admin/basic-mobility-security/manage-enrolled-devices.md +++ b/microsoft-365/admin/basic-mobility-security/manage-enrolled-devices.md @@ -30,7 +30,7 @@ description: "Sign in to Microsoft 365 and set up Basic Mobility and Security to The built-in mobile device management for Microsoft 365 helps you secure and manage your users' mobile devices like iPhones, iPads, Androids, and Windows phones. The first step is to sign in to Microsoft 365 and set up Basic Mobility and Security. For more info, see [Set up Basic Mobility and Security](set-up.md). -After you've set it up, the people in your organization must enroll their devices in the service. For more info, see [Enroll your mobile device using Basic Mobility and Security](enroll-your-mobile-device.md). Then you can use Basic Mobility and Security to help manage devices in your organization. For example, you can use device security policies to help limit email access or other services, view devices reports, and remotely wipe a device. You'll typically go to the Security & Compliance Center to do these tasks. For more info, see [Microsoft Purview compliance portal](../../compliance/microsoft-365-compliance-center.md). +After you've set it up, the people in your organization must enroll their devices in the service. For more info, see [Enroll your mobile device using Basic Mobility and Security](enroll-your-mobile-device.md). Then you can use Basic Mobility and Security to help manage devices in your organization. For example, you can use device security policies to help limit email access or other services, view devices reports, and remotely wipe a device. You'll typically go to the Security & Compliance Center to do these tasks. For more info, see [Microsoft Purview portal](../../compliance/microsoft-365-compliance-center.md). ## Device management tasks @@ -50,7 +50,7 @@ After you've got Basic Mobility and Security set up, here are some ways you can |Block unsupported devices from accessing Exchange email using Exchange ActiveSync|In the Device Management panel, select **Block**.| |Set up device policies like password requirements and security settings|In the Device Management panel, select **Device security policies** > **Add +**. For more info, see [Create device security policies in Basic Mobility and Security](create-device-security-policies.md).| |View list of blocked devices|In the Device Management panel, under **Select a view** select **Blocked**.| -|Unblock noncompliant or unsupported device for a user or group of users|Pick one of the following to unblock devices:
- Remove the user or users from the security group the policy has been applied to. Go to Microsoft 365 admin center > **Groups**, and then select group name. Select **Edit members and admins**.
- Remove the security group the users are a member of from the device policy. Go to [Basic Mobility and Security ](https://compliance.microsoft.com/basicmobilityandsecurity)and select the **Policies** tab. Select device policy name, and then select **Edit** **Deployment**.
- Unblock all noncompliant devices for a device policy. Go to [Basic Mobility and Security](https://compliance.microsoft.com/basicmobilityandsecurity) and select the **Policies** tab. Select device policy name and then select **Edit** > **Access requirements**. Select **Allow access**.
- To unblock a noncompliant or unsupported device for a user or a group of users, go to [Basic Mobility and Security](https://compliance.microsoft.com/basicmobilityandsecurity) and select the **Organization Setting** tab. and select the **Security groups excluded from access control** section. Add a security group with the members you want to exclude from being blocked access to Microsoft 365. For more info, see [Create, edit, or delete a security group in the Microsoft 365 admin center](../../admin/email/create-edit-or-delete-a-security-group.md).| +|Unblock noncompliant or unsupported device for a user or group of users|Pick one of the following to unblock devices:
- Remove the user or users from the security group the policy has been applied to. Go to Microsoft 365 admin center > **Groups**, and then select group name. Select **Edit members and admins**.
- Remove the security group the users are a member of from the device policy. Go to [Basic Mobility and Security ](https://purview.microsoft.com/basicmobilityandsecurity)and select the **Policies** tab. Select device policy name, and then select **Edit** **Deployment**.
- Unblock all noncompliant devices for a device policy. Go to [Basic Mobility and Security](https://purview.microsoft.com/basicmobilityandsecurity) and select the **Policies** tab. Select device policy name and then select **Edit** > **Access requirements**. Select **Allow access**.
- To unblock a noncompliant or unsupported device for a user or a group of users, go to [Basic Mobility and Security](https://purview.microsoft.com/basicmobilityandsecurity) and select the **Organization Setting** tab. and select the **Security groups excluded from access control** section. Add a security group with the members you want to exclude from being blocked access to Microsoft 365. For more info, see [Create, edit, or delete a security group in the Microsoft 365 admin center](../../admin/email/create-edit-or-delete-a-security-group.md).| |Remove users so their devices are no longer managed by Basic Mobility and Security|To remove the user, edit the security group that has device management policies for Basic Mobility and Security. For more info, see [Create, edit, or delete a security group in the Microsoft 365 admin center](../../admin/email/create-edit-or-delete-a-security-group.md).
To remove Basic Mobility and Security from all your Microsoft 365 users, see [Turn off Basic Mobility and Security](turn-off.md).| Live (v14) diff --git a/microsoft-365/admin/basic-mobility-security/set-up.md b/microsoft-365/admin/basic-mobility-security/set-up.md index d321c014ae5..c3d55c6a024 100644 --- a/microsoft-365/admin/basic-mobility-security/set-up.md +++ b/microsoft-365/admin/basic-mobility-security/set-up.md @@ -32,17 +32,17 @@ Check out all of our small business content on [Small business help & learning]( The built-in Basic Mobility and Security for Microsoft 365 helps you secure and manage users' mobile devices such as iPhones, iPads, Androids, and Windows phones. You can create and manage device security policies, remotely wipe a device, and view detailed device reports. -Have questions? For a FAQ to help address common questions, see [Basic Mobility and Security Frequently asked questions (FAQs)](frequently-asked-questions.yml). Be aware that you cannot use a delegated administrator account to manage Basic Mobility and Security. For more info, see [Partners: Offer delegated administration](https://support.microsoft.com/office/partners-offer-delegated-administration-26530dc0-ebba-415b-86b1-b55bc06b073e). +Have questions? For an FAQ to help address common questions, see [Basic Mobility and Security Frequently asked questions (FAQs)](frequently-asked-questions.yml). You can't use a delegated administrator account to manage Basic Mobility and Security. For more info, see [Partners: Offer delegated administration](https://support.microsoft.com/office/partners-offer-delegated-administration-26530dc0-ebba-415b-86b1-b55bc06b073e). ## Activate the Basic Mobility and Security service 1. Sign in to Microsoft 365 with a [Directory writers](/entra/identity/role-based-access-control/permissions-reference) admin account. -1. Go to [Activate Basic Mobility and Security](https://compliance.microsoft.com/basicmobilityandsecurity). +1. Go to [Activate Basic Mobility and Security](https://purview.microsoft.com/basicmobilityandsecurity). 1. Select **Enable feature.** - It can take some time to activate Basic Mobility and Security. If the feature is already activated, the **Enable feature** option will not appear. + It can take some time to activate Basic Mobility and Security. If the feature is already activated, the **Enable feature** option doesn't appear. ## Set up Mobile Device Management @@ -50,52 +50,52 @@ When the service is ready, complete the following steps to finish setup. ### Step 1: (Required) Configure domains for Basic Mobility and Security -If you don't have a custom domain associated with Microsoft 365 or if you're not managing Windows devices, you can skip this section. Otherwise, you'll need to add DNS records for the domain at your DNS host. If you've added the records already, as part of setting up your domain with Microsoft 365, you're all set. After you add the records, Microsoft 365 users in your organization who sign in on their Windows device with an email address that uses your custom domain are redirected to enroll in Basic Mobility and Security. +If you don't have a custom domain associated with Microsoft 365 or if you're not managing Windows devices, you can skip this section. Otherwise, you need to add DNS records for the domain at your DNS host. If you've added the records as part of setting up your domain with Microsoft 365, you're all set. After you add the records, Microsoft 365 users in your organization who sign in on their Windows device with an email address that uses your custom domain are redirected to enroll in Basic Mobility and Security. Need help with setting up the records? Find your domain registrar and select the registrar name to go to step-by-step help for creating DNS records in the list provided in [Add DNS records to connect your domain](/office365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider). Use the following details to create CNAME records: | Type | Host name | Points to | TTL | | --- | --- | --- | --- | -| CNAME | EnterpriseEnrollment.company_domain.com | EnterpriseEnrollment-s.manage.microsoft.us | 1 hour| -|CNAME | EnterpriseRegistration.company_domain.com | EnterpriseRegistration.windows.net | 1 hour | +| CNAME | EnterpriseEnrollment.company_domain.com | EnterpriseEnrollment-s.manage.microsoft.us | One hour| +|CNAME | EnterpriseRegistration.company_domain.com | EnterpriseRegistration.windows.net | One hour | -After you add the two CNAME records, go back to the Security & Compliance Center and go to **Data loss prevention** > **Device management** to complete the next step. +After you add the two CNAME records, go back to the Microsoft Purview portal and go to **Data loss prevention** > **Device management** to complete the next step. -### Step 2: (Required) Configure an APNs Certificate for iOS devices +### Step 2: (Required) Configure an APNS Certificate for iOS devices -To manage iOS devices like iPad and iPhones, you need to create an Apple Push Notification service (APNs) certificate. +To manage iOS devices like iPad and iPhones, you need to create an Apple Push Notification service (APNS) certificate. 1. Sign in to Microsoft Azure with a [Directory writers](/entra/identity/role-based-access-control/permissions-reference) admin account. -1. Go to [Configure MDM Push Certificate](https://portal.azure.com/#view/Microsoft_Intune_Enrollment/APNSCertificateUploadBlade). +1. Go to [Configure Mobile Device Management Push Certificate](https://portal.azure.com/#view/Microsoft_Intune_Enrollment/APNSCertificateUploadBlade). 1. Select **I agree** to authorize Microsoft to communicate with Apple. -1. Select **Download your CSR** and save the certificate signing request to a location on your computer that you'll remember. +1. Select **Download your CSR** and save the certificate signing request to a location on your computer that you remember. 1. Select **Create your MDM push certificate** to open the Apple Push Certificates Portal. 1. Sign in with an Apple ID. > [!IMPORTANT] - > Use a company Apple ID associated with an email account that will remain with your organization even if the user who manages the account leaves. Save this ID because you'll need to use the same ID when it's time to renew the certificate. + > Use a company Apple ID associated with an email account that remains with your organization even if the user who manages the account leaves. Save this ID because you need to use the same ID when it's time to renew the certificate. 1. Select **Create a Certificate** and accept the **Terms of Use**. 1. Browse to the certificate signing request that you downloaded to your computer from Microsoft 365 and then select **Upload**. - 1. Download the APNs certificate created by the Apple Push Certificate Portal to your computer. + 1. Download the APNS certificate created by the Apple Push Certificate Portal to your computer. > [!TIP] > If you're having trouble downloading the certificate, refresh your browser. -1. Go back to Microsoft Azure and browse to the APNs certificate that you downloaded from the Apple Push Certificates Portal. +1. Go back to Microsoft Azure and browse to the APNS certificate that you downloaded from the Apple Push Certificates Portal. 1. Select **Upload**. ## Make sure users enroll their devices -After you've created and deployed a mobile device management policy, each licensed Microsoft 365 user in your organization that the device policy applies receives an enrollment message the next time they sign into Microsoft 365 from their mobile device. They must complete the enrollment and activation steps before they can access Microsoft 365 email and documents. For more info, see [Enroll your mobile device using Basic Mobility and Security](enroll-your-mobile-device.md). +After you create and deploy a mobile device management policy, each licensed Microsoft 365 user in your organization that the device policy applies receives an enrollment message the next time they sign into Microsoft 365 from their mobile device. They must complete the enrollment and activation steps before they can access Microsoft 365 email and documents. For more info, see [Enroll your mobile device using Basic Mobility and Security](enroll-your-mobile-device.md). > [!IMPORTANT] > If a user's preferred language isn't supported by the enrollment process, users might receive enrollment notification and steps on their mobile devices in another language. Not all languages supported in Microsoft 365 are currently supported for the enrollment process on mobile devices. diff --git a/microsoft-365/admin/basic-mobility-security/turn-off.md b/microsoft-365/admin/basic-mobility-security/turn-off.md index 6050ea7aac1..cc1479ea978 100644 --- a/microsoft-365/admin/basic-mobility-security/turn-off.md +++ b/microsoft-365/admin/basic-mobility-security/turn-off.md @@ -37,7 +37,7 @@ These options remove Basic Mobility and Security enforcement for devices in your ## Remove user security groups from Basic Mobility and Security device policies -1. In your browser type: [https://compliance.microsoft.com/basicmobilityandsecurity](https://compliance.microsoft.com/basicmobilityandsecurity). +1. In your browser type: [https://purview.microsoft.com/basicmobilityandsecurity](https://purview.microsoft.com/basicmobilityandsecurity). 2. Select a device policy, and select **Edit policy**. @@ -49,7 +49,7 @@ These options remove Basic Mobility and Security enforcement for devices in your ## Remove Basic Mobility and Security device policies -1. In your browser type: [https://compliance.microsoft.com/basicmobilityandsecurity](https://compliance.microsoft.com/basicmobilityandsecurity). +1. In your browser type: [https://purview.microsoft.com/basicmobilityandsecurity](https://purview.microsoft.com/basicmobilityandsecurity). 2. Select a device policy, and then select **Delete policy**. diff --git a/microsoft-365/admin/create-groups/ownerless-groups-teams.md b/microsoft-365/admin/create-groups/ownerless-groups-teams.md index 9026dca0682..f5a04585ba6 100644 --- a/microsoft-365/admin/create-groups/ownerless-groups-teams.md +++ b/microsoft-365/admin/create-groups/ownerless-groups-teams.md @@ -34,7 +34,7 @@ This article teaches you how to handle ownerless Microsoft 365 groups in the Mic An Exchange administrator or Groups administrator can create a policy that automatically asks the members who are the most active in the group if they accept ownership. -When a member accepts the invitation to become an owner, the action is logged in the compliance portal audit log. +When a member accepts the invitation to become an owner, the action is logged in the Microsoft Purview portal audit log. If there's no group activity, the policy asks random group members to accept ownership. @@ -129,4 +129,4 @@ Admins can see which Microsoft 365 groups remain ownerless by searching the [a - [Overview of Microsoft 365 Groups for administrators](office-365-groups.md). - [Compare types of groups in Microsoft 365](compare-groups.md). -- [Search the audit log in the compliance portal](/microsoft-365/compliance/search-the-audit-log-in-security-and-compliance) +- [Search the audit log in the Microsoft Purview portal](/microsoft-365/compliance/search-the-audit-log-in-security-and-compliance) diff --git a/microsoft-365/admin/email/change-email-address.md b/microsoft-365/admin/email/change-email-address.md index 96eb57a7585..15bb06799ef 100644 --- a/microsoft-365/admin/email/change-email-address.md +++ b/microsoft-365/admin/email/change-email-address.md @@ -5,7 +5,7 @@ f1.keywords: ms.author: efrene author: efrene manager: scotv -ms.date: 08/10/2023 +ms.date: 04/23/2025 audience: Admin ms.topic: how-to ms.service: microsoft-365-business diff --git a/microsoft-365/admin/manage/enable-dev-analytics.md b/microsoft-365/admin/manage/enable-dev-analytics.md new file mode 100644 index 00000000000..9a575902047 --- /dev/null +++ b/microsoft-365/admin/manage/enable-dev-analytics.md @@ -0,0 +1,54 @@ +--- +title: "Enable developers to use app analytics in the Developer Portal for Teams" +f1.keywords: +- CSH +ms.author: kvice +author: kelleyvice-msft +manager: scotv +ms.date: 04/14/2025 +audience: Admin +ms.topic: how-to +ms.service: microsoft-365-enterprise +ms.subservice: administration +ms.localizationpriority: medium +ms.reviewer: luywang +ms.collection: +- scotvorg +- highpri +- M365-subscription-management +- Adm_O365 +- Adm_O365_Setup +- must-keep +ms.custom: +- admindeeplinkMAC +search.appverid: +- MET150 +description: "Enable developers to view and use app analytics for company apps in the Developer Portal using the Developer Portal for Teams setting." +--- + +# Enable developers to use app analytics in the Developer Portal for Teams + +In the Microsoft 365 admin center, the **App usage for custom app** setting allows enterprise app developers to view and use app analytics for company apps in the Developer Portal. Developer Portal is a tool for managing apps and agents built for Copilot and Microsoft 365 apps. By viewing custom app usage, enterprise developers can see the number of active users and get other insights. Admins can allow app usage for your custom apps to be shown in the Developer Portal. + +:::image type="content" source="../../media/enable-dev-analytics/enable-dev-analytics.png" alt-text="Image of the UI for enabling dev analytics" lightbox="../../media/enable-dev-analytics/enable-dev-analytics.png"::: + +To enable the setting, in the Microsoft 365 Admin Center, sign in with the **Teams admin** role, and under **Org settings**, select **Developer Portal for Teams** and then enable the setting in the flyout pane as shown in the following image: + +:::image type="content" source="../../media/enable-dev-analytics/enable-dev-analytics-flyout.png" alt-text="Image of the flyout pane where you can enable the setting"::: + +## How will this setting affect admins and their organization? + +By default, the **App usage for custom apps** setting is disabled. When you enable this setting, enterprise developers are provided with better insights into the performance and user engagement of custom apps, helping them make informed decisions about app improvements. If this setting is disabled, developers may be prevented from understanding app usage and other insights, causing disruptive change to their workflow. + +## What actions are needed from admins? + +To enable enterprise developers to view app usage, enable the setting in **Microsoft 365 admin center -> Settings -> Org settings -> Services -> Developer Portal for Teams**. Developers should be able to take advantage of the new experience right away. + +## What do developers need to do? + +Developers can configure access to analytics for company apps by following the guidance in [Analyze app usage in Developer Portal](/microsoftteams/platform/concepts/build-and-test/analyze-your-apps-usage-in-developer-portal?tabs=custom-apps-built-for-your-org#tabpanel_1_custom-apps-built-for-your-org). + +## Related articles + +- [Analyze App Usage in Developer Portal](/microsoftteams/platform/concepts/build-and-test/analyze-your-apps-usage-in-developer-portal?tabs=custom-apps-built-for-your-org) +- [Microsoft Teams app usage report](/microsoftteams/teams-analytics-and-reports/app-usage-report) diff --git a/microsoft-365/admin/manage/idle-session-timeout-web-apps.md b/microsoft-365/admin/manage/idle-session-timeout-web-apps.md index 28a11c5e2e2..35b07bc94c2 100644 --- a/microsoft-365/admin/manage/idle-session-timeout-web-apps.md +++ b/microsoft-365/admin/manage/idle-session-timeout-web-apps.md @@ -14,7 +14,7 @@ ms.collection: - Tier3 - scotvorg - Adm_TOC -description: "Set how long user's session will last in Microsoft 365 before they're timed out." +description: "Set how long user's session lasts in Microsoft 365 before they're timed out." --- # Idle session timeout for Microsoft 365 @@ -22,29 +22,29 @@ description: "Set how long user's session will last in Microsoft 365 before they > [!IMPORTANT] > Idle session timeout isn't available for Microsoft 365 operated by 21Vianet. -Use idle session timeout to configure a policy on how long users are inactive in your organization before they're signed out of Microsoft 365 web apps. This helps protect sensitive company data and adds another layer of security for end users who work on non-company or shared devices. +Use idle session timeout to configure a policy on how long users are inactive in your organization before they're signed out of Microsoft 365 web apps. This helps protect sensitive company data and adds another layer of security for end users who work on noncompany or shared devices. -When a user reaches the idle timeout session you've set, they'll get a notification that they're about to be signed out. They have to select to stay signed in or they'll be automatically signed out of all Microsoft 365 web apps. +When a user reaches the set idle timeout session, they get a notification that they're about to be signed out. They have to select to stay signed in or they're automatically signed out of all Microsoft 365 web apps. > [!IMPORTANT] > Idle session timeout doesn't affect your Microsoft 365 desktop and mobile apps. ## Turn on Idle session timeout -You must be a member of the Security admin, Application admin, or Cloud Application admin roles to see the idle session timeout setting. The Global admin role is required for initial activation of Idle Session Timeout. All other noted roles can deactivate and/or modify timeout duration settings. +You must be a member of the Security admin, Application admin, or Cloud Application admin roles to see the idle session timeout setting. The Global admin role is required for initial activation of Idle Session Timeout. All other noted roles can deactivate and/or modify timeout duration settings. 1. In the Microsoft 365 admin center, select **Org Settings** **->** [Security & privacy](https://go.microsoft.com/fwlink/p/?linkid=2072756) tab and select **Idle session timeout**. -2. On the **Idle Session Timeout** select the toggle to turn it on. You can choose a default setting or choose your own custom time. It'll take a few minutes before idle session is turned on in your organization. +2. On the **Idle Session Timeout**, select the toggle to turn it on. You can choose a default setting or choose your own custom time. It takes a few minutes before idle session is turned on in your organization. > [!NOTE] -> If you've set up idle session timeout policies for [Outlook web app](https://support.microsoft.com/topic/description-of-the-activity-based-authentication-timeout-for-owa-in-office-365-0c101e1b-020e-69c1-a0b0-26532d60c0a4) and [SharePoint](/sharepoint/sign-out-inactive-users), turning on idle session timeout in the Microsoft 365 admin center will override the Outlook web app and SharePoint settings. +> If you set up idle session timeout policies for [Outlook web app](https://support.microsoft.com/topic/description-of-the-activity-based-authentication-timeout-for-owa-in-office-365-0c101e1b-020e-69c1-a0b0-26532d60c0a4) and [SharePoint](/sharepoint/sign-out-inactive-users), turning on idle session timeout in the Microsoft 365 admin center overrides the Outlook web app and SharePoint settings. Idle session timeout is one of the many security measures in Microsoft 365. To learn about other security tasks in Microsoft 365, see [Top security tasks in Microsoft 365](../../security/top-security-tasks-for-remote-work.md). -## What users will see +## What users see -When a user has been inactive in Microsoft 365 web apps for the time period you chose, they'll see the following prompt. They have to select **Stay signed in** or they'll be signed out. +When a user is inactive in Microsoft 365 web apps for the time period you chose, they see the following prompt. They have to select **Stay signed in** or they're signed out. :::image type="content" source="../../media/idle-session-timeout.png" lightbox="../../media/idle-session-timeout.png" alt-text="Screenshot: Prompt letting you know that your session is about to expire. Select Stay signed in so you don't get signed out of Microsoft 365 web apps"::: @@ -66,30 +66,30 @@ When a user has been inactive in Microsoft 365 web apps for the time period you - Microsoft 365 Admin Center - - M365 Defender Portal + - Microsoft 365 Defender Portal - - Microsoft Purview Compliance Portal + - Microsoft Purview portal - Activity refers to any client-side user interaction happening in the context of the web app. For example, mouse clicks and keyboard presses. -- Idle session timeout works on a per-browser session basis. A user’s activity on Microsoft Edge is treated differently than their activity in other browsers such as Google Chrome. Users will be signed out from all tabs corresponding to their account within that browser session. +- Idle session timeout works on a per-browser session basis. A user’s activity on Microsoft Edge is treated differently than their activity in other browsers such as Google Chrome. Users are signed out from all tabs corresponding to their account within that browser session. - Once you turn on idle session timeout, it applies to your entire organization and can't be scoped to specific users, organizational units, or groups. Use [Microsoft Entra Conditional Access](/azure/active-directory/conditional-access/) policies for different users and groups to access SharePoint and Exchange Online. -- Users must be inactive on all Microsoft 365 web app tabs for the configured duration. If the user is active on one tab (say OWA) while being inactive on another tab (say SPO), they'll be considered active and won't be signed out. +- Users must be inactive on all Microsoft 365 web app tabs for the configured duration. For example, if a user is active on a tab in Outlook web app, while inactive on another tab in SharePoint, they're considered active and aren't signed out. -- Users won’t get signed out in these cases. +- Users don’t get signed out in these cases: - If they get single sign-on (SSO) into the web app from the device joined account. - If they selected **Stay signed in** at the time of sign-in. For more info on hiding this option for your organization, see [Add branding to your organization's sign-in page](/azure/active-directory/fundamentals/customize-branding). - - If they're on a managed device (one that is compliant or joined to a domain) and using a supported browser like Microsoft Edge or Google Chrome (with the [Microsoft Single Sign On](https://chrome.google.com/webstore/detail/windows-accounts/ppnbnpeolgkicgegkbkbjmhlideopiji)) extension. + - If they're on a managed device, that is compliant or joined to a domain and using a supported browser, like Microsoft Edge, or Google Chrome with the [Microsoft Single Sign On](https://chrome.google.com/webstore/detail/windows-accounts/ppnbnpeolgkicgegkbkbjmhlideopiji) extension. ## Trigger idle session timeout only on unmanaged devices -By default, the idle session timeout feature triggers on all device types if the other conditions are met. For this feature to trigger only on an unmanaged device, an eligible Microsoft Entra ID P1 or P2 subscription is required. You'll also need to add a Conditional Access policy in the Microsoft Entra admin center. +By default, the idle session timeout feature triggers on all device types if the other conditions are met. For this feature to trigger only on an unmanaged device, an eligible Microsoft Entra ID P1 or P2 subscription is required. You also need to add a Conditional Access policy in the Microsoft Entra admin center. ## Idle session timeout on unmanaged devices -For idle session timeout to get triggered only on unmanaged devices, you'll need to add a Conditional Access policy in the Microsoft Entra admin center. +For idle session timeout to get triggered only on unmanaged devices, you need to add a Conditional Access policy in the Microsoft Entra admin center. 1. On the **Conditional Access | Policies** page of the Microsoft Entra admin center, select **New policy** and enter a name for the policy. @@ -107,11 +107,11 @@ For idle session timeout to get triggered only on unmanaged devices, you'll need ### Are there any browsers or browser scenarios in which idle session timeout feature doesn't work? -Idle session timeout isn't supported when third party cookies are disabled in the browser. Users won't see any sign-out prompts. We recommend keeping tracking prevention setting to [Balanced (Default)](/microsoft-edge/web-platform/tracking-prevention) for Microsoft Edge, and third-party cookies enabled in your other browsers. Microsoft 365 web apps and services stopped supporting Internet Explorer 11 on August 17, 2021. +Idle session timeout isn't supported when third party cookies are disabled in the browser. Users don't see any sign-out prompts. We recommend keeping tracking prevention setting to [Balanced (Default)](/microsoft-edge/web-platform/tracking-prevention) for Microsoft Edge, and third-party cookies enabled in your other browsers. Microsoft 365 web apps and services stopped supporting Internet Explorer 11 on August 17, 2021. ### How should I prepare if my organization is already using existing Outlook web app and SharePoint idle timeout policies? -If you're already using existing Outlook web app and SharePoint idle timeout policies, you can still turn on idle session timeout feature. When you turn on the idle timeout policy, it takes precedence over the existing Outlook web app and SharePoint Online policies. We're planning to deprecate the existing Outlook web app and SharePoint policies in the near future. To better prepare your organization, we recommend you turn on idle session timeout. +If you're already using existing Outlook web app and SharePoint idle timeout policies, you can still turn on idle session timeout feature. When you turn on the idle timeout policy, it takes precedence over the existing Outlook web app and SharePoint Online policies. We're planning to deprecate the existing Outlook web app and SharePoint policies soon. To better prepare your organization, we recommend you turn on idle session timeout. ### What happens if I'm inactive on an included Microsoft 365 web app, but active on a Microsoft web app or SaaS web app that doesn't have idle session time out turned on? @@ -131,18 +131,18 @@ The following Microsoft 365 web apps are supported. - Microsoft 365 admin center -- M365 Defender Portal +- Microsoft 365 Defender Portal -- Microsoft Purview Compliance Portal +- Microsoft Purview portal -If you're working on a different web app with the same account, the activity in that web app won't be applied to the idle session timeout. +If you're working on a different web app with the same account, the activity in that web app isn't applied to the idle session timeout. -### I'm active in Azure portal, but I'm logged out of other M365 Apps for inactivity. Why am I logged out? +### I'm active in Azure portal, but I'm logged out of other Microsoft 365 Apps for inactivity. Why am I logged out? -Azure portal supports a similar inactivity feature, but is supported by Azure portal only. +Azure portal supports a similar inactivity feature, but is tracked in the Azure portal. > [!Note] -> When initially activated within the Azure portal, the timeout duration by default inherits from M365 admin center Idle Session Timeout Setting. However, the timeout policy for the Azure portal can be explicitly configured within the portal itself. For more information, see [Azure portal: Signing-Out + Notification](/azure/azure-portal/set-preferences#signing-out--notifications). +> When initially activated within the Azure portal, the timeout duration by default inherits from Microsoft 365 admin center idle session timeout setting. However, the timeout policy for the Azure portal can be explicitly configured within the portal itself. For more information, see [Azure portal: Signing-Out + Notification](/azure/azure-portal/set-preferences#signing-out--notifications). ### I want to make changes to the idle session timeout policy or delete it. How can I do that? diff --git a/microsoft-365/admin/manage/manage-addins-in-the-admin-center.md b/microsoft-365/admin/manage/manage-addins-in-the-admin-center.md index a8232fbd140..26479e39f07 100644 --- a/microsoft-365/admin/manage/manage-addins-in-the-admin-center.md +++ b/microsoft-365/admin/manage/manage-addins-in-the-admin-center.md @@ -48,7 +48,7 @@ An add-in can be in either the **On** or **Off** state. |**Active**
|Admin uploaded the add-in and assigned it to users or groups.
|Users and groups assigned to the add-in see it in the relevant clients.
| |**Turned off**
|Admin turned off the add-in.
|Users and groups assigned to the add-in no longer have access to it.
If the add-in state is changed to Active, the users and groups will have access to it again.
| |**Deleted**
|Admin deleted the add-in.
|Users and groups assigned the add-in no longer have access to it.
| - + Consider deleting an add-in if no one is using it anymore. For example, turning off an add-in might make sense if an add-in is used only during specific times of the year. ## Delete an add-in diff --git a/microsoft-365/admin/manage/message-center.md b/microsoft-365/admin/manage/message-center.md index 9c10e899ba0..1f51515526b 100644 --- a/microsoft-365/admin/manage/message-center.md +++ b/microsoft-365/admin/manage/message-center.md @@ -5,7 +5,7 @@ f1.keywords: ms.author: kwekua author: kwekuako manager: scotv -ms.date: 03/14/2024 +ms.date: 04/10/2025 audience: Admin ms.topic: how-to ms.service: microsoft-365-business @@ -295,7 +295,13 @@ When you open a message in a reading pane, you can use the **Up** and **Down** : A lot of actionable information about changes to Microsoft 365 services arrives in the Microsoft 365 message center. It can be difficult to keep track of which changes require tasks to be done, when, and by whom, and to track each task to completion. You also might want to make a note of something and tag it to check on later. You can do all this and more when you sync your messages from the Microsoft 365 admin center to Microsoft Planner. For more information, see [Track your message center tasks in Planner](/office365/planner/track-message-center-tasks-planner). -For an overview of Message center, see [Message center in Microsoft 365](message-center.md). Or, to learn how to set your language preferences to enable machine translation for Message center posts, see [Language translation for Message center posts](language-translation-for-message-center-posts.md). If you'd like to program an alternative way to get real-time service health information and Message center communications, see [Working with service communications API in Microsoft Graph](/graph/api/resources/service-communications-api-overview). +## Set language translation for Message center posts + +To learn how to set your language preferences to enable machine translation for Message center posts, see [Language translation for Message center posts](language-translation-for-message-center-posts.md). + +## Work with service communications API in Microsoft Graph + +If you'd like to program an alternative way to get real-time service health information and Message center communications, see [Working with service communications API in Microsoft Graph](/graph/api/resources/service-communications-api-overview). ## Unsubscribe from Message center emails diff --git a/microsoft-365/admin/manage/release-options-in-office-365.md b/microsoft-365/admin/manage/release-options-in-office-365.md index 47897c322ee..cc51c219ca2 100644 --- a/microsoft-365/admin/manage/release-options-in-office-365.md +++ b/microsoft-365/admin/manage/release-options-in-office-365.md @@ -5,7 +5,7 @@ f1.keywords: ms.author: kvice author: kelleyvice-msft manager: scotv -ms.date: 11/18/2024 +ms.date: 04/09/2025 audience: Admin ms.topic: install-set-up-deploy ms.service: microsoft-365-business @@ -32,7 +32,7 @@ description: "Learn how to set up the release option for new product and feature # Set up the Standard or Targeted release options > [!IMPORTANT] -> The Microsoft 365 updates described in this article apply to OneDrive, SharePoint in Microsoft 365, Microsoft 365 for the web, Microsoft 365 admin center, some components of Exchange Online and Microsoft Teams. These release options are targeted, best effort ways to release changes to Microsoft 365 but can't be guaranteed at all times or for all updates. They don't currently apply to services other than those listed previously. For information about release options for Microsoft 365 Apps, see [Overview of update channels for Microsoft 365 Apps](/deployoffice/overview-update-channels). +> The Microsoft 365 updates described in this article apply to new Outlook, OneDrive, SharePoint in Microsoft 365, Microsoft 365 for the web, Microsoft 365 admin center, some components of Exchange Online and Microsoft Teams. These release options are targeted, best effort ways to release changes to Microsoft 365 but can't be guaranteed at all times or for all updates. They don't currently apply to services other than those listed previously. For information about release options for Microsoft 365 Apps, see [Overview of update channels for Microsoft 365 Apps](/deployoffice/overview-update-channels). With Microsoft 365, you receive new product updates and features as they become available instead of doing costly updates every few years. You can manage how your organization receives these updates. For example, you can sign up for an early release so that your organization receives updates first. You can designate that only certain individuals receive the updates. Or, you can remain on the default release schedule and receive the updates later. This article explains the different release options and how you can use them for your organization. @@ -58,7 +58,7 @@ A good practice is to leave most users in **Standard release** and IT Pros and p With this option, you and your users can be the first to see the latest updates and help shape the product by providing early feedback. You can choose to have individuals or the entire organization receive updates early. > [!IMPORTANT] -> Large or complex updates may take longer than others so that no users are adversely affected. There is no guarantee on the exact timeline of a release. Targeted release is now available for customers with either the Office 365 GCC plan or the Office 365 GCC High plan and DoD plan for the following services: OneDrive, SharePoint in Microsoft 365, Microsoft 365 for web, Microsoft 365 admin center, and some components of Exchange Online. +> Large or complex updates may take longer than others so that no users are adversely affected. There is no guarantee on the exact timeline of a release. Targeted release is now available for customers with either the Office 365 GCC plan or the Office 365 GCC High plan and DoD plan for the following services: new Outlook, OneDrive, SharePoint in Microsoft 365, Microsoft 365 for web, Microsoft 365 admin center, and some components of Exchange Online. > [!NOTE] > If you switch from targeted release back to standard release track, your users may lose access to features that haven't reached standard release yet. diff --git a/microsoft-365/admin/manage/update-phone-number-and-email-address.md b/microsoft-365/admin/manage/update-phone-number-and-email-address.md index 691f86363eb..857e3e108eb 100644 --- a/microsoft-365/admin/manage/update-phone-number-and-email-address.md +++ b/microsoft-365/admin/manage/update-phone-number-and-email-address.md @@ -60,6 +60,5 @@ For answers to billing questions, see: ## Related content [Change a user name and email address](../add-users/change-a-user-name-and-email-address.md) (video)\ -[Add a new employee](../add-users/add-new-employee.md) (video)\ [Remove a former employee](../add-users/remove-former-employee.md) (video)\ [Access and back up a former user's data](../add-users/get-access-to-and-back-up-a-former-user-s-data.md) (article) diff --git a/microsoft-365/admin/misc/create-litigation-hold-mac.md b/microsoft-365/admin/misc/create-litigation-hold-mac.md index 08f6d440dc7..db0d77c371a 100644 --- a/microsoft-365/admin/misc/create-litigation-hold-mac.md +++ b/microsoft-365/admin/misc/create-litigation-hold-mac.md @@ -6,7 +6,7 @@ f1.keywords: ms.author: kwekua author: kwekuako manager: scotv -ms.date: 06/27/2024 +ms.date: 04/10/2025 audience: Admin ms.topic: how-to ms.service: purview-ediscovery diff --git a/microsoft-365/admin/misc/onedrive-recommendations.md b/microsoft-365/admin/misc/onedrive-recommendations.md index 2f9d69e9bfd..20993b21e70 100644 --- a/microsoft-365/admin/misc/onedrive-recommendations.md +++ b/microsoft-365/admin/misc/onedrive-recommendations.md @@ -169,9 +169,9 @@ With a Microsoft 365 subscription, you can add expiration dates and passwords to ## Classify and protect company data -Use the Microsoft Purview compliance portal to enable support for sensitivity labels. For more information, see [Enable sensitivity labels for files in SharePoint and OneDrive](/microsoft-365/compliance/sensitivity-labels-sharepoint-onedrive-files). +Use the Microsoft Purview portal to enable support for sensitivity labels. For more information, see [Enable sensitivity labels for files in SharePoint and OneDrive](/microsoft-365/compliance/sensitivity-labels-sharepoint-onedrive-files). -1. Sign in to [the Microsoft Purview compliance portal](https://compliance.microsoft.com/) as a global administrator. +1. Sign in to [the Microsoft Purview portal](https://purview.microsoft.com/) as a global administrator. 2. Select **Solutions** and then **Information protection**. diff --git a/microsoft-365/admin/misc/organizational-messages-microsoft-365.md b/microsoft-365/admin/misc/organizational-messages-microsoft-365.md index c3d9059c12a..cd775ea6089 100644 --- a/microsoft-365/admin/misc/organizational-messages-microsoft-365.md +++ b/microsoft-365/admin/misc/organizational-messages-microsoft-365.md @@ -80,6 +80,11 @@ Before working with organizational messages, make sure your team satisfies the f - For example, any message configured to be delivered to a Windows channel, like Windows Spotlight, requires that recipients use **Windows 10/11 Enterprise**. +To ensure users can communicate with organizational messages, the following endpoints must be opened: + +- fd.api.orgmsg.microsoft.com +- ris.prod.api.personalization.ideas.microsoft.com + > [!IMPORTANT] > During our preview period, Organizational messages preview experiences weren't restricted based on the licenses held by participating tenants, authors, approvers, or message recipients. However, now that the product is in general availability, some organizational messages experiences are restricted to particular Microsoft licenses. To learn more, see [Advanced features](#advanced-features). @@ -171,7 +176,7 @@ Users with the Organizational Messages Writer Microsoft Entra role described pre - **Recipients** for setting the groups within your organization that should receive the message. -- **Schedule** for configuring the start and end dates as well as the frequency with which the system will send the message to the same user over time. +- **Schedule** for configuring the start and end dates as well as the frequency with which the system will send the message to the same user over time. If users don't select the message, it'll reappear based on the frequency set by the admin when creating organizational messages. If they do select the message, it won't reappear for a year. - **Finish** for reviewing the message before scheduling or sending for approval by your organization’s approvers. diff --git a/microsoft-365/admin/misc/set-up-dns-records-vsb.md b/microsoft-365/admin/misc/set-up-dns-records-vsb.md index 6c684a66ffb..4409c240251 100644 --- a/microsoft-365/admin/misc/set-up-dns-records-vsb.md +++ b/microsoft-365/admin/misc/set-up-dns-records-vsb.md @@ -2,8 +2,8 @@ title: "Connect your domain to Microsoft 365" f1.keywords: - CSH -ms.author: scotv -author: nataliekagole +ms.author: kvice +author: kelleyvice-msft manager: scotv ms.date: 08/01/2024 audience: Admin diff --git a/microsoft-365/admin/setup/domains-faq.yml b/microsoft-365/admin/setup/domains-faq.yml index c1adfdd2d2c..b50fcea2c1c 100644 --- a/microsoft-365/admin/setup/domains-faq.yml +++ b/microsoft-365/admin/setup/domains-faq.yml @@ -137,7 +137,7 @@ sections: ::: moniker range="o365-worldwide" - You cannot change the name of your initial *onmicrosoft.com* domain. + For information about adding or replacing an onmicrosoft.com domain, see [Add or replace your onmicrosoft.com domain](/admin/setup/add-or-replace-your-onmicrosoftcom-domain). ::: moniker-end @@ -148,8 +148,8 @@ sections: ::: moniker-end > [!NOTE] - > Changing the default domain does not impact user credentials or their access to applications or services. Changing the domain that a user is associated with impacts mail, online storage, and login credentials. - + > Changing the default domain affects new accounts only. This change does not impact user credentials or their access to applications or services. Removing or changing a domain on an account can impact mail, online storage, and login credentials. + - question: Can I add custom subdomains or multiple domains to Microsoft 365? answer: | ::: moniker range="o365-worldwide" diff --git a/microsoft-365/admin/setup/upgrade-users-to-latest-office-client.md b/microsoft-365/admin/setup/upgrade-users-to-latest-office-client.md index 38292b48684..7848862833c 100644 --- a/microsoft-365/admin/setup/upgrade-users-to-latest-office-client.md +++ b/microsoft-365/admin/setup/upgrade-users-to-latest-office-client.md @@ -5,7 +5,7 @@ f1.keywords: ms.author: kwekua author: kwekuako manager: scotv -ms.date: 03/04/2024 +ms.date: 04/08/2025 audience: Admin ms.service: microsoft-365-business ms.localizationpriority: medium @@ -43,15 +43,15 @@ If you're the admin responsible for the Microsoft 365 for business subscription ## Upgrade steps The steps below will guide you through the process of upgrading your users to the latest Microsoft 365 desktop apps. We recommend you read through these steps before beginning the upgrade process. - + ## Step 1 - Check system requirements [Check the system requirements](https://www.microsoft.com/microsoft-365/microsoft-365-and-office-resources) to make sure your devices are compatible with the latest version of Office. For example, newer versions of the apps in Microsoft 365 can't be installed on computers running Windows XP or Windows Vista. > [!TIP] -> If you have users in your organization running older versions of Windows on their PCs or laptops, we recommend upgrading to Windows 10. Windows 7 has reached end of support. Read [Support for Windows 7 ends in January 2020](https://www.microsoft.com/microsoft-365/windows/end-of-windows-7-support?rtc=1) for more info. +> If you have users in your organization running older versions of Windows on their PCs or laptops, we recommend upgrading to the latest version of Windows. Windows 7 has reached end of support. Read [Support for Windows 7 ends in January 2020](https://www.microsoft.com/microsoft-365/windows/end-of-windows-7-support?rtc=1) for more info. -Check out the [Windows 10 system requirements](https://www.microsoft.com/windows/windows-10-specifications) to see if you can upgrade their operating systems. +Check out the [Windows 11 system requirements](/windows/whats-new/windows-11-requirements) to see if you can upgrade their operating systems. ### Check application compatibility @@ -65,9 +65,9 @@ Some Microsoft 365 plans don't include the full desktop versions of the apps and Not sure which subscription plan you have? See [What Microsoft 365 for business subscription do I have?](../admin-overview/what-subscription-do-i-have.md) -If your existing plan includes the Office apps, move on to [Step 3 - Uninstall Office](#step-3---uninstall-office). +If your existing plan includes the Microsoft 365 apps, move on to [Step 3 - Uninstall Office](#step-3---uninstall-office). -If your existing plan doesn't include the formerly Office apps, then select from the options below: +If your existing plan doesn't include the Microsoft 365 apps, then select from the options below: ### Upgrade options for plans that don't include the apps in Microsoft 365 @@ -108,11 +108,11 @@ We recommend if you have third-party add-ins, contact the manufacturer to see if If you'd prefer to install your older version side-by-side with the latest version, you can see a list of versions where this is supported in, [Install and use different versions of Office on the same PC](https://support.microsoft.com/office/6ebb44ce-18a3-43f9-a187-b78c513788bf). A side-by-side installation might be the right choice for you, if for example, you've installed third-party add-ins you're using with your older version and you're not yet sure they're compatible with the latest version. -## Step 4 - Assign Office licenses to users +## Step 4 - Assign licenses to users -If you haven't already done so, assign licenses to any users in your organization who need to install the latest version of Microsoft 365, see [Assign licenses to users in Microsoft 365 for business](../manage/assign-licenses-to-users.md). +If you haven't already done so, assign licenses to any users in your organization who need to install the latest version of Microsoft 365. See [Assign licenses to users in Microsoft 365 for business](../manage/assign-licenses-to-users.md). -## Step 5 - Install Microsoft 365 +## Step 5 - Install Microsoft 365 apps After you've verified the users you want to upgrade all have licenses, the final step is to have them install the apps in Microsoft 365. See [Download and install or reinstall Microsoft 365 or Office 2021 on a PC or Mac](https://support.microsoft.com/office/4414eaaf-0478-48be-9c42-23adc4716658). diff --git a/microsoft-365/admin/support-diagnostic-information-collection.md b/microsoft-365/admin/support-diagnostic-information-collection.md new file mode 100644 index 00000000000..32d95fa553a --- /dev/null +++ b/microsoft-365/admin/support-diagnostic-information-collection.md @@ -0,0 +1,85 @@ +--- +title: "Understanding Microsoft 365 case creation and diagnostic data access" +ms.author: camillepack +author: camillepack +manager: scotv +ms.date: 04/07/2025 +audience: Admin +ms.topic: concept-article +ms.service: microsoft-365-business +ms.localizationpriority: medium +ms.collection: +- Tier1 +- scotvorg +- Adm_O365 +- Adm_TOC +description: "Learn about the diagnostic data Microsoft 365 Support engineers access to resolve support cases, including consent, data categories, retention periods, and logging details." +--- + +# Understanding Microsoft 365 case creation and diagnostic data access + +The purpose of this article is to inform Microsoft 365 customers about the type of information that Microsoft Support engineers may collect and use in order to resolve a support case. + +## Consent for diagnostic information + +When you [create a support request](get-help-support.md), you consent to allow a Microsoft Support engineer to remotely run diagnostics on the Microsoft 365 subscription(s) associated with your request. This access allows them to collect diagnostic information that enables them to troubleshoot and solve your problem. + +## How long does Microsoft have this access? + +Access is removed automatically when your support request is closed. If your request is still open, access is removed 30 days from the date of request creation, and you will be prompted to provide access again. If you have multiple requests open, the access expires 30 days from the date of creation of the latest request. + +Depending on the nature of your support request, the data that Microsoft can access would belong under one or more of the following categories: + +- **Support Data** – All data provided to Microsoft by the customer as part of a customer engagement to obtain support services. + - Examples + - Support requests from customers and phone conversations, online chat sessions, or remote assistance sessions between support professionals and customers + - Case notes and/or records related to support requests from customers + - Data provided to Microsoft by the customer as part of support activities + +- **Account Data** – Contact and billing/purchase/payment/license information. + - Examples + - Customer’s provisioning information + - Account configuration and billing data + - Tenant administrator contact information (for example, tenant administrator’s name, address, e-mail address, phone number) + - This also includes Licensing and Purchase Information. + +- **System Metadata** – Data generated in the course of running the service. + - Examples + - Event Logs + - Access Control Logs + - Account information belonging to Microsoft operations personnel + - Microsoft server names/server IPs + - Server patching and vulnerability data + - Service configuration data + - Telemetry (on-prem or cloud) + +- **Organization Identifiable Information (OII)** – Data that can be used to identify a particular tenant/deployment/organization (generally config or usage data) + - Examples + - Tenant ID (non-GUID) + - TenantID (GUID) – due to the existence of many out of boundary TenantID to name mapping tables + - Tenant usage data + - Tenant IP Addresses (IPv4) such as tenant’s firewall IP address + - Global Prefix and Subnet ID (first 64 bits of IPv6 address) + - Tenant Domain name in e-mail address (joe@**contoso.com**) + - Mapping of organizational GUID to organization + +- **End User Identifiable Information (EUII)** – Data that directly identifies or could be used to identify the authenticated user of a Microsoft service. + - Examples + - User-specific IP address (IPv4) + - User Principal Name (joe@company.com) + - Address Book Data + - User’s machine Name + - SIP URI + +- **End User Pseudonymous Identifiers (EUPI)** – An identifier created by Microsoft tied to the user of a Microsoft service. + - Examples + - User GUIDs or PUIDs + - Session IDs + +## How long is diagnostic data retained in Microsoft systems? + +Microsoft retains diagnostic data for up to 28 days after it is collected. After this period, the data is deleted. + +## Where is support activity on a customer tenant logged? + +Activity performed on a customer tenant is available under Microsoft Entra Audit logs. diff --git a/microsoft-365/admin/usage-analytics/active-user-in-usage-reports.md b/microsoft-365/admin/usage-analytics/active-user-in-usage-reports.md index 59f21867890..1a045dcc2cf 100644 --- a/microsoft-365/admin/usage-analytics/active-user-in-usage-reports.md +++ b/microsoft-365/admin/usage-analytics/active-user-in-usage-reports.md @@ -3,7 +3,7 @@ title: "Active user in Microsoft 365 usage reports" ms.author: efrene author: efrene manager: scotv -ms.date: 02/19/2020 +ms.date: 04/23/2025 audience: Admin ms.topic: article ms.service: microsoft-365-business @@ -20,7 +20,7 @@ search.appverid: - MET150 - MOE150 ms.assetid: 093a6d0d-890b-489e-9f46-b15687d3fe4f -description: "Learn about an active user of Microsoft 365 usage analytics, activity reports and adoption metrics." +description: "Learn about an active user of Microsoft 365 usage analytics, activity reports, and adoption metrics." --- # Active user in Microsoft 365 usage reports @@ -31,14 +31,14 @@ An active user of Microsoft 365 products for [Microsoft 365 usage analytics](usa |**Product**|**Definition of an active user**|**Notes**| |:-----|:-----|:-----| -|Exchange Online
|Any user who has performed any of the following actions: Mark as read, send messages, create appointments, send meeting requests, accept (as tentative) or decline meeting requests, cancel meetings.
|No calendar information is represented, this will be added in an upcoming update.
| -|SharePoint Online
|Any user who has interacted with a file by creating, modifying, viewing, deleting, sharing internally or externally, or synchronizing to clients on any site or viewed a page on any site.
|The active user metrics for SharePoint Online in the Microsoft 365 Usage Analytics template app only reflect users who did file activity against a SharePoint Team site or a Group site. The template app will be updated to synchronize the definition to the same as that on the usage reports in the admin center.
| -|OneDrive for Business
|Any user who has interacted with a file by creating, modifying, viewing, deleting, sharing internally or externally, or synchronizing to clients.
|| -|Viva Engage
|Any user who has read, posted, or liked a message on Viva Engage.
|| -|Skype for Business
|Any user who has participated in a peer-to-peer session (including instant messaging, audio and video calls, application sharing, and file transfers) or who has organized or participated in a conference.
|| -|Microsoft 365
|Any user who has activated their Microsoft 365 Apps for enterprise, Visio Pro or Project Pro subscription on at least one device.
|| -|Microsoft 365 Groups
|Any group member that has mailbox activity (if a message has been sent to the group)
|This definition will be enhanced with group site file activity and Viva Engage group activity (file activity on group site and message posted to Viva Engage group associated with the group.) This data is currently not available in the Microsoft 365 Usage Analytics template app
| -|Microsoft Teams
|Any user who has participated in chat messages, private chat messages, calls, meetings, or other activity. Other activity is defined as the number of other team activities by the user some of which include, and not limited to: liking messages, apps, working on files, searching, following teams and channel and favoriting them.
|| +|Exchange Online
|Any user who performed any of the following actions: Mark as read, send messages, create appointments, send meeting requests, accept (as tentative) or decline meeting requests, cancel meetings.
|No calendar information is represented. It is added in an upcoming update.
| +|SharePoint Online
|Any user who interacted with a file by creating, modifying, viewing, deleting, sharing internally or externally, or synchronizing to clients on any site or viewed a page on any site.
|The active user metrics for SharePoint Online in the Microsoft 365 Usage Analytics template app only reflect users who did file activity against a SharePoint Team site or a Group site. The template app will be updated to synchronize the definition to the same as that on the usage reports in the admin center.
| +|OneDrive for Business
|Any user who interacted with a file by creating, modifying, viewing, deleting, sharing internally or externally, or synchronizing to clients.
|| +|Viva Engage
|Any user who read, posted, or liked a message on Viva Engage.
|| +|Skype for Business
|Any user who participated in a peer-to-peer session (including instant messaging, audio and video calls, application sharing, and file transfers) or who has organized or participated in a conference.
|| +|Microsoft 365
|Any user who activated their Microsoft 365 Apps for enterprise, Visio Pro, or Project Pro subscription on at least one device.
|| +|Microsoft 365 Groups
|Any group member that has mailbox activity (if a message was sent to the group)
|This definition will be enhanced with group site file activity and Viva Engage group activity. For example, file activity on group site and message posted to Viva Engage group associated with the group. This data is currently not available in the Microsoft 365 Usage Analytics template app
| +|Microsoft Teams
|Any user who participated in chat messages, private chat messages, calls, meetings, or other activity. Other activity is defined as the number of other team activities by the user some of which include, and not limited to: liking messages, apps, working on files, searching, following teams and channel and favoriting them.
|| ## Adoption Metrics @@ -49,7 +49,7 @@ An active user of Microsoft 365 products for [Microsoft 365 usage analytics](usa |EnabledUsers
|Number of users enabled to use the product in the month.
| |ActiveUsers
|Number of users active in the month.
| |MoMReturningUsers
|Number of users active in the month that were also active in the preceding month.
| -|FirstTimeUsers
|Number of users active in the month that had never used the service before.
| +|FirstTimeUsers
|Number of users active in the month that never used the service before.
| |CumulativeActiveUsers
|Number of users active in the month plus any preceding month.
| |ActiveUsers(%)
|Percent of users, rounded to the nearest tenth, active in the month compared to the number of users enabled in that month.
| |MoMReturningUsers(%)
|Percent of users, rounded to the nearest tenth, active in the month that were also active in the preceding month compared to the number of active users.
| diff --git a/microsoft-365/admin/usage-analytics/enable-usage-analytics.md b/microsoft-365/admin/usage-analytics/enable-usage-analytics.md index 0e6c3f66c93..a2e83b792f8 100644 --- a/microsoft-365/admin/usage-analytics/enable-usage-analytics.md +++ b/microsoft-365/admin/usage-analytics/enable-usage-analytics.md @@ -103,7 +103,7 @@ Global administrators can revert this change for their tenant and show identifia 3. Uncheck the statement **Display concealed user, group, and site names in all reports**, and then save your changes. -It takes a few minutes for these changes to take effect. Showing identifiable user information is a logged event in the Microsoft Purview compliance portal audit log. +It takes a few minutes for these changes to take effect. Showing identifiable user information is a logged event in the Microsoft Purview portal audit log. ## Related content diff --git a/microsoft-365/admin/whats-new-in-preview.md b/microsoft-365/admin/whats-new-in-preview.md index e5c3f473718..f2378aa9749 100644 --- a/microsoft-365/admin/whats-new-in-preview.md +++ b/microsoft-365/admin/whats-new-in-preview.md @@ -44,7 +44,7 @@ And if you'd like to know what's new with other Microsoft cloud services, check - [What's new in Microsoft Entra ID](/azure/active-directory/fundamentals/whats-new) - [What's new in the Exchange admin center](/Exchange/whats-new) - [What's new in Microsoft Intune](/mem/intune/fundamentals/whats-new) -- [What's new in the Microsoft Purview compliance portal](/microsoft-365/compliance/whats-new) +- [What's new in the Microsoft Purview portal](/microsoft-365/compliance/whats-new) - [What's new in Microsoft Defender XDR](../security/mtp/whats-new.md) - [What's new in the SharePoint admin center](/sharepoint/what-s-new-in-admin-center) - [What's new for Teams admins](/OfficeUpdates/teams-admin) diff --git a/microsoft-365/archive/archive-education-offering.md b/microsoft-365/archive/archive-education-offering.md index 3dab626a919..ed55e27a6ed 100644 --- a/microsoft-365/archive/archive-education-offering.md +++ b/microsoft-365/archive/archive-education-offering.md @@ -5,7 +5,7 @@ author: chuckedmonson manager: jtremper audience: admin ms.reviewer: sharonyam -ms.date: 11/01/2024 +ms.date: 04/01/2025 ms.topic: article ms.service: microsoft-365-archive ms.custom: archive @@ -18,9 +18,9 @@ description: Learn about Microsoft 365 Archive for Education, including tenant e # Education offering for Microsoft 365 Archive -This article provides an overview of Microsoft 365 Archive for Education, including tenant eligibility, pricing model, and billing scenarios. +This article provides an overview of Microsoft 365 Archive for Education, including tenant eligibility, pricing model, and billing scenarios. -## Pooled storage eligibility +## Pooled storage eligibility Education customers that are subject to the pooled storage limit are eligible for the Microsoft 365 Archive for Education offering. If your tenant has assigned most (greater than 50%) EDU licenses compared to non-EDU licenses, or if your tenant has purchased more EDU licenses than non-EDU licenses, then the tenant is managed as an EDU tenant and is subject to Education Pooled Storage. For more information on pooled storage, see [Education Pooled Storage limits](/office365/servicedescriptions/office-365-platform-service-description/office-365-education#education-pooled-storage-limits). diff --git a/microsoft-365/archive/archive-end-user.md b/microsoft-365/archive/archive-end-user.md index b54a643a51f..03920d51780 100644 --- a/microsoft-365/archive/archive-end-user.md +++ b/microsoft-365/archive/archive-end-user.md @@ -5,7 +5,7 @@ author: chuckedmonson manager: jtremper audience: admin ms.reviewer: sreelakshmi -ms.date: 11/12/2024 +ms.date: 04/12/2025 ms.topic: how-to ms.service: microsoft-365-archive ms.custom: archive diff --git a/microsoft-365/archive/archive-faq.md b/microsoft-365/archive/archive-faq.md index fa170ba2463..a0f0c21bc9b 100644 --- a/microsoft-365/archive/archive-faq.md +++ b/microsoft-365/archive/archive-faq.md @@ -5,7 +5,7 @@ author: chuckedmonson manager: jtremper audience: admin ms.reviewer: sreelakshmi -ms.date: 09/04/2024 +ms.date: 04/04/2025 ms.topic: faq ms.service: microsoft-365-archive ms.custom: archive diff --git a/microsoft-365/archive/archive-manage.md b/microsoft-365/archive/archive-manage.md index 11d677a9c1d..55158b1df40 100644 --- a/microsoft-365/archive/archive-manage.md +++ b/microsoft-365/archive/archive-manage.md @@ -5,7 +5,7 @@ author: chuckedmonson manager: jtremper audience: admin ms.reviewer: sreelakshmi -ms.date: 10/28/2024 +ms.date: 04/14/2025 ms.topic: how-to ms.service: microsoft-365-archive ms.custom: archive @@ -86,10 +86,10 @@ You can also change the status of an archived site by using the PowerShell cmdle |Template ID |Template |Template name| |---------|---------|---------| -|1|Team site / Document Workspace|STS#0| -|1|Team site / Document Workspace|STS#1| -|1|Team site / Document Workspace|STS#2| -|1|Team site / Document Workspace|STS#3| +|1|Team site (classic experience)|STS#0| +|1|Blank Site|STS#1| +|1|Document Workspace|STS#2| +|1|Team site|STS#3| |68|Communication site|SITEPAGEPUBLISHING#0| |64|Teams site|GROUP#0| |32|News site|SPSNEWS#0| diff --git a/microsoft-365/archive/archive-overview.md b/microsoft-365/archive/archive-overview.md index fa830107fdb..82d8a9b0d95 100644 --- a/microsoft-365/archive/archive-overview.md +++ b/microsoft-365/archive/archive-overview.md @@ -5,7 +5,7 @@ author: chuckedmonson manager: jtremper audience: admin ms.reviewer: sreelakshmi -ms.date: 11/26/2024 +ms.date: 04/26/2025 ms.topic: overview ms.service: microsoft-365-archive ms.custom: archive diff --git a/microsoft-365/archive/archive-pricing.md b/microsoft-365/archive/archive-pricing.md index 47ba8a083a8..1efad24a869 100644 --- a/microsoft-365/archive/archive-pricing.md +++ b/microsoft-365/archive/archive-pricing.md @@ -22,10 +22,8 @@ Microsoft 365 Archive charges you for storage and reactivation. - **Storage consumption** that is charged at a per-GB monthly rate. This meter is charged only when archived storage plus active storage in SharePoint exceeds the included or licensed allocated SharePoint storage capacity limit of the tenant. In other words, there's no additional storage cost for archived sites if the tenant has not consumed its already licensed storage quota. For more information about storage capacity limits, see [SharePoint limits](/office365/servicedescriptions/sharepoint-online-service-description/sharepoint-online-limits). -- **Site reactivation** that is charged at a per-GB rate. The reactivation fee is charged regardless of whether a tenant is over or below its SharePoint capacity limit and only if reactivation is executed more than seven days after the site was most recently put into an archive state. This seven-day grace period provides you with the opportunity to reverse an accidental archival without reaction costs. - - > [!NOTE] - > The reactivation fee for archived sites or content in SharePoint will be eliminated on March 31, 2025. After that date, reactivating archived sites will be free of charge, but re-archiving that content will be restricted for a four-month period. This change doesn't apply to OneDrive accounts. For more information, see the [Microsoft 365 Archive blog](https://techcommunity.microsoft.com/blog/microsoft_365_archive_blog/microsoft-365-archive-eliminates-reactivation-fees-by-march-31-2025/4383215). +> [!NOTE] +> The reactivation fee for archived sites or content in SharePoint was eliminated on March 31, 2025. After that date, reactivating archived sites became free of charge, but re-archiving any newly reactivated content is restricted for a four-month period. This change doesn't apply to OneDrive accounts. For more information, see the [Microsoft 365 Archive blog](https://techcommunity.microsoft.com/blog/microsoft_365_archive_blog/microsoft-365-archive-eliminates-reactivation-fees-by-march-31-2025/4383215). Monthly archive usage is calculated as the sum of the usage of all currently archived sites. Each site’s usage is equal to the site storage usage of that site, which can be seen on the site itself or from the Active sites page in the SharePoint admin center. The size of an archived site, and therefore the storage for which it’s billed, changes only if the content in the site changes. For example, content naturally expiring in the recycle bin or a retention policy deleting content within the site directly from archive to the recycle bin. diff --git a/microsoft-365/archive/archive-states.md b/microsoft-365/archive/archive-states.md index a5752c49f8e..960194a1671 100644 --- a/microsoft-365/archive/archive-states.md +++ b/microsoft-365/archive/archive-states.md @@ -5,7 +5,7 @@ author: chuckedmonson manager: jtremper audience: admin ms.reviewer: sreelakshmi -ms.date: 11/12/2024 +ms.date: 04/12/2025 ms.topic: article ms.service: microsoft-365-archive ms.custom: archive diff --git a/microsoft-365/backup/backup-billing.md b/microsoft-365/backup/backup-billing.md index b93661af28d..7f6e5ec5cc9 100644 --- a/microsoft-365/backup/backup-billing.md +++ b/microsoft-365/backup/backup-billing.md @@ -5,7 +5,7 @@ author: chuckedmonson manager: jtremper audience: admin ms.reviewer: sreelakshmi -ms.date: 02/19/2025 +ms.date: 04/16/2025 ms.topic: how-to ms.service: microsoft-365-backup ms.custom: backup @@ -18,68 +18,6 @@ description: Learn how to set up and manage usage and invoices in the Azure port # Manage consumption and invoices for Microsoft 365 Backup - - You can view actual and accumulated cost breakdown by tenants and service type for OneDrive, SharePoint, and Exchange in Microsoft Cost Management in the Azure portal or access the information by using the [Cost Management public APIs](/rest/api/cost-management/operation-groups). Cost breakdown by application ID is coming soon. 1. Sign in to the [Azure portal](https://portal.azure.com/). @@ -121,6 +59,8 @@ To view tags: - SharePoint site - SiteId of the corresponding SharePoint site. - Azure cost analysis - filter by tag. + + - The tag for OneDrive is its siteID. To convert this back to a userID, you can use the following API: `https://graph.microsoft.com/v1.0/sites//drive?select=owner` 4. In the left navigation, select **Billing** to see monthly invoices. diff --git a/microsoft-365/backup/backup-overview.md b/microsoft-365/backup/backup-overview.md index bc336bae689..8e5a8506103 100644 --- a/microsoft-365/backup/backup-overview.md +++ b/microsoft-365/backup/backup-overview.md @@ -107,12 +107,14 @@ The following table summarizes expected performance for a normally distributed t |1 |30 minutes |2 hours | |50 |3 hours |2.5 hours | |250 |4 hours | 3 hours | -|1,000 |10 hours |4 hours | -|More than 1,000 |250/hour
Up to 3 TB/hour |250+/hour
Up to 2.7 TB/hour | +|1,000+ |Up to 250 protection units per hour |4 hours | +|1,000+|Up to 250 protection units/hour
Up to 2 TB/hour* |250+ protection units/hour
Up to 2 TB/hour* | -*Single protection unit OneDrive and SharePoint restores using express restore points can take on average between 10 minutes and 120 minutes. +Restore performance notes: -**Exchange Online performance times based on an average sized mailbox of 26K items and a size of 10 GB. Actual times will depend on the number and size of the items in each mailbox. For a single mailbox, restore times typically fall in the 200 - 300 item/minute range. +*Single protection unit OneDrive and SharePoint restores using express restore points can take on average between 10 minutes and 120 minutes, depending on site size. For mailboxes, restore times typically fall in the 200 - 300 item/minute range. + +*1,000+ protection unit restore speeds published here are based on internal benchmarking where SharePoint sites have an average of 12GB of stored content per site, Exchange Online mailboxes have an average of 26K items and an aggregate size of 10 GB. Those bulk recoveries use the in-place restore option, which is typical for large scale attack recovery scenarios. Actual times will depend on the number and size of the items in each site/mailbox. ## Pay-as-you-go billing diff --git a/microsoft-365/backup/backup-restore-data.md b/microsoft-365/backup/backup-restore-data.md index b8b0ed9735b..4643745ba6f 100644 --- a/microsoft-365/backup/backup-restore-data.md +++ b/microsoft-365/backup/backup-restore-data.md @@ -173,7 +173,7 @@ Follow these steps to restore data backed up for Exchange. 3. The destination of restored items can be chosen from two options, then select **Next**. - a. **Create a new folder for the backups** where the content will be restored to a newly created folder named *Restored Items YYYY-DD-MM, HH:MM*. + a. **Create a new folder for the backups** where the content will be restored to a newly created folder named *Recovered Items YYYY-DD-MM, HH:MM*. b. **Replace mailbox items with backups** where current version of the item will be overwritten by the restored content. @@ -262,11 +262,13 @@ Microsoft 365 Backup supports the backup and restoration of any site and user ac - For calendar item restore, restoring organizer copy doesn't automatically make attendee copies catch up, it only allows future updates by organizer to work for all users added on the calendar item. - - Only mailbox items that were changed, deleted to the Recoverable Items folder, or purged can be restored. Learn more about the Recoverable Items folder in Exchange Online. + - Only mailbox items that were changed, deleted to the Recoverable Items folder, or purged can be restored. Learn more about the [Recoverable Items folder in Exchange Online](/exchange/security-and-compliance/recoverable-items-folder/recoverable-items-folder). - Items moved to the Deleted Items folder won't be restored by Microsoft 365 Backup. Mailbox users can recover these items themselves by moving them back to the Inbox from the Deleted Items folder. - When choosing to "Replace mailbox items with backups," items are restored to the original location in the user's Inbox. The only exception to this is if an item was edited while in the Deleted Items folder, as this creates a new version of an item where its original location is the Deleted Items folder. + + - If the parent folder of an item has been deleted, the item will be restored to a newly created folder named *Recovered Items YYYY-MM-DD, HH:MM*. - All diff --git a/microsoft-365/backup/backup-setup.md b/microsoft-365/backup/backup-setup.md index be336de7f26..87345ffc7c0 100644 --- a/microsoft-365/backup/backup-setup.md +++ b/microsoft-365/backup/backup-setup.md @@ -19,7 +19,7 @@ description: Learn how to turn on Microsoft 365 Backup, set up pay-as-you-go bil # Set up Microsoft 365 Backup > [!TIP] -> **Already have an Azure subscription and the [necessary admin role](#admin-roles-and-backup-management-privileges)?** Follow these three steps to quickly set up Microsoft 365 Backup in the admin center.

+> **Already have an Azure subscription and are a SharePoint Administrator or Global Administrator?** Follow these three steps to quickly set up Microsoft 365 Backup in the admin center.

> [Step 1. Set up pay-as-you-go billing for Syntex services](https://admin.microsoft.com/#/orgsettings/payasyougo)
> [Step 2. Turn on Microsoft 365 Backup](https://admin.microsoft.com/#/orgsettings/payasyougo/storage)
> [Step 3. Start backing up your data by creating backup policies](https://admin.microsoft.com/#/Settings/enhancedRestore)
@@ -168,4 +168,4 @@ Only tenant-level admins can create and manage backups using Microsoft 365 Backu \ No newline at end of file +---> diff --git a/microsoft-365/backup/backup-view-edit-policies.md b/microsoft-365/backup/backup-view-edit-policies.md index 30151bca02b..339dca686d0 100644 --- a/microsoft-365/backup/backup-view-edit-policies.md +++ b/microsoft-365/backup/backup-view-edit-policies.md @@ -5,7 +5,7 @@ author: chuckedmonson manager: jtremper audience: admin ms.reviewer: sreelakshmi -ms.date: 04/07/2025 +ms.date: 04/21/2025 ms.topic: article ms.service: microsoft-365-backup ms.custom: backup @@ -20,56 +20,11 @@ description: Learn how to create, view, and edit backup policies for OneDrive, S ## Create backup policies -To use Microsoft 365 Backup for OneDrive, SharePoint, or Exchange, you need to create a backup policy for each product. A *policy* represents the backup plan defined by admins for protecting the Microsoft 365 data of an organization. +To use Microsoft 365 Backup for SharePoint, Exchange, or OneDrive, you need to create a backup policy for each product. A *policy* represents the backup plan defined by admins for protecting the Microsoft 365 data of an organization. -A policy contains details of what data (OneDrive accounts, SharePoint sites, and Exchange mailboxes) to protect. Although you see the retention period and backup frequency (which defines the restore point objective), those settings aren't currently variable or modifiable. +A policy contains details of what data (SharePoint sites, Exchange mailboxes, and OneDrive accounts) to protect. Although you see the retention period and backup frequency (which defines the restore point objective), those settings aren't currently variable or modifiable. -Select the **OneDrive**, **SharePoint**, or **Exchange** tab for steps to create a backup policy for that product. - -# [OneDrive](#tab/onedrive) - -Follow these steps to set up a backup policy for OneDrive accounts using Microsoft 365 Backup. - -1. Go to the [Microsoft 365 admin center](https://admin.microsoft.com/Adminportal/Home). - -2. Select **Settings**. - -3. Select **Microsoft 365 Backup** from the list of products. - -4. On the **Microsoft 365 Backup** page, in the **OneDrive** section, select **Set up policy**. - - ![Screenshot of the Microsoft 365 Backup page with OneDrive highlighted.](../media/m365-backup/backup-setup-backup-page-onedrive.png) - -5. On the **Overview** page, review the backup features for OneDrive, and then select **Next**. - - ![Screenshot of the Overview page for OneDrive.](../media/m365-backup/backup-overview-page-onedrive.png) - -6. On the **Choose selection method** page, you can set up OneDrive user accounts using any or all three ways. A protection scope is the scope of user accounts within OneDrive that you want to protect with Microsoft 365 Backup. - - ![Screenshot of the Choose selection method page for OneDrive.](../media/m365-backup/backup-choose-selection-method-onedrive.png) - - a. Under **Upload a list of accounts in a CSV file**, you can upload a list of accounts to back up via a CSV file. - - The CSV upload feature for bulk addition of sites or user accounts in the backup policy creation workflow can accommodate a maximum of 50,000 entries per CSV file. - - b. Under **Back up accounts that match specific filters**, you can select **Distribution lists** or **Security groups**, or both. The distribution list and security group are flattened when added, meaning the policy won't update dynamically if the groups or distribution list are updated later. - - The rule-based feature for bulk addition of user accounts via security groups or distribution lists can accommodate a maximum of three groups at a time. These rules are static and applied one time only. That is, the security groups or distribution lists are flattened at the time of adding to the backup configuration policy. For example, groups or lists won't be dynamically updated in the system if users are added or removed from the original security group. - - > [!NOTE] - > The site last modified feature is in preview. - - c. Under **Select accounts individually**, you can search and select accounts you want to add to a backup policy. - -7. Once you've made the right selections, select **Next** to create the backup policy for OneDrive. - -8. On the **Review OneDrive backup policy** page, review the information to make sure it's how you want it, and then select **Create policy** (or **Update policy** if it's an update). - -9. The backup policy for OneDrive is created. - - ![Screenshot of the OneDrive backup policy created page.](../media/m365-backup/backup-policy-created-onedrive.png) - - Once the sites are added to a backup policy, it might take 15 to 25 minutes per 1,000 sites for restore points to become available for restore. +Select the **SharePoint**, **Exchange**, or **OneDrive** tab for steps to create a backup policy for that product. # [SharePoint](#tab/sharepoint) @@ -99,14 +54,14 @@ Follow these steps to set up a backup policy for SharePoint sites using Microsof b. Under **Back up sites that match specific filters**, you can select **Site name or URL contains** or **Site last modified**, or both. - The rule-based feature for bulk addition of sites via site names or URL in the backup policy creation workflow can accommodate a maximum of 10 keywords at a time. Each keyword can have a minimum of three characters and maximum of 255 characters. + The rule-based feature for bulk addition of sites in the backup policy creation workflow allows you to add up to 10 site names or URLs at a time. Each keyword can have a minimum of three characters and maximum of 255 characters. > [!NOTE] > The site last modified feature is in preview. c. Under **Select sites individually**, you can search and select sites you want to add to a backup policy. -7. Once you've made the right selections, select **Next** to create the backup policy for SharePoint. +7. Once you make the right selections, select **Next** to create the backup policy for SharePoint. 8. On the **Review SharePoint backup policy** page, review the information to make sure it's how you want it, and then select **Create policy** (or **Update policy** if it's an update). @@ -132,16 +87,16 @@ Follow these steps to set up a backup policy for Exchange mailboxes sites using ![Screenshot of the Microsoft 365 Backup page with Exchange highlighted.](../media/m365-backup/backup-setup-backup-page-exchange.png) -5. On the **Overview** page, review and verify the backup policy attributes for Exchange, such as backup frequency, backup retention, cost details, and then select **Next**. +5. On the **Overview** page, review the backup policy attributes for Exchange, and then select **Next**. ![Screenshot of the Overview page for Exchange.](../media/m365-backup/backup-overview-page-exchange.png) -6. On the **Choose selection method** page, you can set up shared or user mailboxes using any or all three ways. Other Exchange recipient types, such as room mailboxes, are not supported at this time. A protection scope is the scope of mailboxes within Exchange that you want to protect with Microsoft 365 Backup. +6. On the **Choose selection method** page, you can select shared or user mailboxes using any of the four available methods. Other Exchange recipient types, such as room mailboxes, aren't supported at this time. A protection scope is the scope of mailboxes within Exchange that you want to protect with Microsoft 365 Backup. > [!NOTE] - > Adding a mailbox to the backup policy will back up the primary and archive mailboxes. + > Adding a mailbox to the backup policy backs up the primary and archive mailboxes. > - > Adding a mailbox might temporarily fail if mailbox setup has not had time to complete. For example, if you recently created the user, licensed the user, or migrated the mailbox from on premises, you might see a transient failure while the mailbox is still being set up. + > Adding a mailbox might temporarily fail if the mailbox setup isn't yet complete. For example, if you recently created the user, licensed the user, or migrated the mailbox from on premises, you might see a transient failure while the mailbox is still being set up. ![Screenshot of the Choose selection method page for Exchange.](../media/m365-backup/backup-choose-selection-method-exchange.png) @@ -149,62 +104,91 @@ Follow these steps to set up a backup policy for Exchange mailboxes sites using The CSV upload feature for bulk addition of mailboxes in the backup policy creation workflow can accommodate a maximum of 50,000 entries per CSV file. - b. Under **Back up mailboxes that match specific filters**, you can select **Distribution lists** or **Security groups**, or both. The distribution list and security group are flattened when added, meaning the policy won't update dynamically if the groups or distribution list are updated later. + b. Under **Using a dynamic rule**, you can select **Distribution lists** or **Security groups**, or both. With dynamic rules, any changes to membership in the selected distribution lists and security groups are automatically reevaluated daily, ensuring the backup policy reflects those membership changes regularly. + + For example, if a user is added to a distribution list included in the dynamic rule, that user is included in the backup policy within a day. After that, Microsoft 365 Backup will create restore points for that user. If a user that was previously in the included distribution list is removed from that list, then they're removed from the backup policy within 24 hours. The user's existing backups remain restorable until they expire based on their retention period. However, new backups aren't taken until the user is re-added to the included distribution list or manually re-added through a static addition. + + > [!NOTE] + > The dynamic rule feature is in preview. - The rule-based feature for bulk addition of mailboxes via security groups or distribution lists can accommodate a maximum of three groups at a time. These rules are static and applied one time only. That is, the security groups or distribution lists are flattened at the time of adding to the backup configuration policy. For example. groups or list won't be dynamically updated in the system if users are added or removed from the original security group. + c. Under **Using filters**, you can select **Distribution lists** or **Security groups**, or both. The distribution list and security group are flattened when added, meaning the policy doesn't update dynamically if the groups or distribution list are updated later. - c. Under **Select mailboxes individually**, you can search and select mailboxes you want to add to a backup policy. + The rule-based feature for bulk addition of mailboxes via security groups or distribution lists can accommodate a maximum of three groups at a time. These rules are static and applied one time only. That is, the security groups or distribution lists are flattened at the time of adding to the backup configuration policy. For example, groups or lists don't dynamically update in the system if users are added or removed from the original security group. > [!NOTE] - > Hybrid deployments, where a user's primary mailbox resides on premises while their archive has been migrated to Exchange Online, are not supported. - -7. Once you've made the right selections, select **Next** to create the backup policy for Exchange. + > The site last modified feature is in preview. -8. On the **Review Exchange backup policy** page, review the information to make sure it's how you want it, and then select **Create policy** (or **Update policy** if it's an update). + d. Under **Select mailboxes individually**, you can search and select mailboxes you want to add to a backup policy. - ![Screenshot of the Review Exchange backup policy page.](../media/m365-backup/backup-policy-review-policy-exchange.png) + > [!NOTE] + > Hybrid deployments, where a user's primary mailbox resides on premises while their archive is migrated to Exchange Online, aren't supported. -9. Wait for status of your policy to show as **Active** in the home screen. This might take between 15 and 60 minutes. The backup policy for Exchange is created. Select **View scope** at any time to verify the details. +7. Once you make the right selections, select **Next** to create the backup policy for Exchange. + +8. On the **Review Exchange backup policy** page, review the information to make sure it's how you want it, and then select **Create policy** (or **Update policy** if it's an update). + +9. The backup policy for Exchange is created. ![Screenshot of the Exchange backup policy created page.](../media/m365-backup/backup-policy-created-exchange.png) Once the mailboxes are added to a backup policy, it might take up to 15 minutes per 1,000 mailboxes for restore points to become available for restore. ---- -## View and edit backup policies - -You can edit the scope of OneDrive accounts, SharePoint sites, and Exchange mailboxes associated with a backup policy. As part of edit, you can either add new accounts, sites, or mailboxes to or remove them from backup. Removing accounts, sites, and mailboxes from Microsoft 365 Backup doesn't mean existing backups will be deleted, rather it means additional backups won't be taken. +# [OneDrive](#tab/onedrive) -Select the **OneDrive**, **SharePoint**, or **Exchange** tab for steps to view and edit backup policies for that product. +Follow these steps to set up a backup policy for OneDrive accounts using Microsoft 365 Backup. -# [OneDrive](#tab/onedrive) +1. Go to the [Microsoft 365 admin center](https://admin.microsoft.com/Adminportal/Home). -Follow these steps to view and edit backup policies for OneDrive. +2. Select **Settings**. -1. In the Microsoft 365 admin center, on the **Microsoft 365 Backup** page, in the **OneDrive** section, in the **Scope** area, select **Edit**. +3. Select **Microsoft 365 Backup** from the list of products. - ![Screenshot showing the view and edit backup policy for OneDrive in the Microsoft 365 admin center.](../media/m365-backup/backup-policy-onedrive.png) +4. On the **Microsoft 365 Backup** page, in the **OneDrive** section, select **Set up policy**. -2. On the **OneDrive accounts backup policy** panel, on the **Policy details** tab, in the **Scope** area, select **Edit**. + ![Screenshot of the Microsoft 365 Backup page with OneDrive highlighted.](../media/m365-backup/backup-setup-backup-page-onedrive.png) -3. You can either add new accounts to or remove accounts from an existing OneDrive backup policy. +5. On the **Overview** page, review the backup policy attributes for OneDrive, and then select **Next**. - a. To add new accounts, on the **Backed up accounts** tab, select **+ Add accounts**. + ![Screenshot of the Overview page for OneDrive.](../media/m365-backup/backup-overview-page-onedrive.png) - b. Select the accounts from the list. Once you add accounts to the list, follow the prompts to update the policy. +6. On the **Choose selection method** page, you can select OneDrive user accounts using any of the four available methods. A protection scope is the scope of user accounts within OneDrive that you want to protect with Microsoft 365 Backup. - ![Screenshot showing how to add user accounts to the existing OneDrive backup policy in the Microsoft 365 admin center.](../media/m365-backup/backup-policy-add-account.png) + ![Screenshot of the Choose selection method page for OneDrive.](../media/m365-backup/backup-choose-selection-method-onedrive.png) - c. To remove accounts from existing backup policy, on the **Backed up accounts** tab, select the accounts from the list, and then select **Remove**. Once you have done your changes, follow the prompts to remove the accounts. + a. Under **Upload a list of accounts in a CSV file**, you can upload a list of accounts to back up via a CSV file. - ![Screenshot showing how to remove user accounts from OneDrive backup policy in the Microsoft 365 admin center.](../media/m365-backup/backup-policy-remove-account.png) + The CSV upload feature for bulk addition of sites or user accounts in the backup policy creation workflow can accommodate a maximum of 50,000 entries per CSV file. -4. Once you have done your changes, follow the prompts to update the policy. + b. Under **Using a dynamic rule**, you can select **Distribution lists** or **Security groups**, or both. With dynamic rules, any changes to membership in the selected distribution lists and security groups are automatically reevaluated daily, ensuring the backup policy reflects those membership changes regularly. - ![Screenshot of the updated OneDrive accounts backup policy panel in the Microsoft 365 admin center.](../media/m365-backup/backup-policy-updated-account.png) + For example, if a user is added to a distribution list included in the dynamic rule, that user is included in the backup policy within a day. After that, Microsoft 365 Backup will create restore points for that user. If a user that was previously in the included distribution list is removed from that list, then they're removed from the backup policy within 24 hours. The user's existing backups remain restorable until they expire based on their retention period. However, new backups aren't taken until the user is re-added to the included distribution list or manually re-added through a static addition. > [!NOTE] - > Removing accounts from backup policy means no future backups will be taken for those removed accounts. Existing backups for those accounts will not be deleted and will be charged. + > The dynamic rule feature is in preview. + + c. Under **Using filters**, you can select **Distribution lists** or **Security groups**, or both. The distribution list and security group are flattened when added, meaning the policy doesn't update dynamically if the groups or distribution list members are updated later. + + The rule-based feature for bulk addition of user accounts via security groups or distribution lists can accommodate a maximum of three groups at a time. These rules are static and applied one time only. That is, the security groups or distribution lists are flattened at the time of adding to the backup configuration policy. For example, groups or lists aren't dynamically updated in the system if users are added or removed from the original security group. + + d. Under **Select accounts individually**, you can search and select accounts you want to add to a backup policy. + +7. Once you make the right selections, select **Next** to create the backup policy for OneDrive. + +8. On the **Review OneDrive backup policy** page, review the information to make sure it's how you want it, and then select **Create policy** (or **Update policy** if it's an update). + +9. The backup policy for OneDrive is created. + + ![Screenshot of the OneDrive backup policy created page.](../media/m365-backup/backup-policy-created-onedrive.png) + + Once the sites are added to a backup policy, it might take 15 to 25 minutes per 1,000 sites for restore points to become available for restore. + +--- + +## View and edit backup policies + +You can edit the scope of OneDrive accounts, SharePoint sites, and Exchange mailboxes associated with a backup policy. As part of edit, you can either add new accounts, sites, or mailboxes to or remove them from backup. Removing accounts, sites, and mailboxes from Microsoft 365 Backup doesn't mean existing backups aren't deleted, rather it means additional backups aren't taken. + +Select the **SharePoint**, **Exchange**, or **OneDrive** tab for steps to view and edit backup policies for that product. # [SharePoint](#tab/sharepoint) @@ -220,61 +204,116 @@ Follow these steps to view and edit backup policies in SharePoint. a. To add new sites, on the **Backed up sites** tab, select **+ Add sites**. - b. Select sites by any method as discussed in the creation section. Once you have added sites to the list, follow the prompts to update the policy. + b. Select sites by any method as discussed in the creation section. Once you add sites to the list, follow the prompts to update the policy. ![Screenshot showing how to add sites to the existing SharePoint backup policy in the Microsoft 365 admin center.](../media/m365-backup/backup-sharepoint-add-site.png) - c. To remove sites from existing SharePoint backup policy, on the **Backed up sites** tab, select the relevant sites, and then select **Remove**. Once you have done your changes, follow the prompts to remove the sites. + c. To remove sites from existing SharePoint backup policy, on the **Backed up sites** tab, select the relevant sites, and then select **Remove**. Once you're done with your changes, follow the prompts to remove the sites. ![Screenshot showing how to remove sites from SharePoint backup policy in the Microsoft 365 admin center.](../media/m365-backup/backup-policy-remove-site.png) -4. Once you have done your changes, follow the prompts to update the policy. +4. Once you make your changes, follow the prompts to update the policy. ![Screenshot of the updated SharePoint sites backup policy panel in the Microsoft 365 admin center.](../media/m365-backup/backup-policy-updated-sites.png) > [!NOTE] - > Removing sites from backup policy means no future backups will be taken for those removed sites. Existing backups for the removed sites will not be deleted and will be charged. + > Removing sites from backup policy means no future backups are taken for those removed sites. Existing backups for the removed sites aren't deleted and will be charged. # [Exchange](#tab/exchange) Follow these steps to view and edit backup policies for Exchange. -1. In the Microsoft 365 admin center, on the **Microsoft 365 Backup** page, in the **Exchange** section, in the **Scope** area, select **Edit**. +1. In the Microsoft 365 admin center, on the **Microsoft 365 Backup** page, in the **Exchange** section, select **View details**. + -2. On the **Exchange mailbox backup policy** panel, on the **Policy details** tab, in the **Scope** area, select **Edit**. +2. You can either add new mailboxes to or remove mailboxes from the existing Exchange backup policy. -3. You can either add new user mailboxes to or remove user mailboxes from the existing Exchange backup policy. + a. To add new shared or user mailboxes, use either one of these two methods: - a. To add new shared or user mailboxes, select **+ Add user mailboxes**. + - On the **Exchange backup policy** panel, on the **Exchange backup policy** panel, on the **Policy details** tab, in the **Scope** area, select **Edit**. + + - Or, on the **Exchange backup policy** panel, select **+ Add mailboxes**. + + Select the mailboxes using any of the four available methods. Once you add the mailboxes, follow the prompts to update the policy. ![Screenshot showing how to add mailboxes to the existing Exchange backup policy in the Microsoft 365 admin center.](../media/m365-backup/backup-exchange-add-mailbox.png) - b. To remove user mailboxes from existing backup policy, on the **Backed up sites** tab, select the user mailboxes from the list, and select **Remove**. + b. To remove user mailboxes from existing backup policy, on the **Included mailboxes** tab, select the user mailboxes from the list, and select **Remove**. + + Mailboxes added to a backup policy through a dynamic rule can't be individually removed. To exclude these mailboxes from the backup policy, you must modify the rule conditions. For example, if User A is part of Distribution List P, removing User A from the list excludes them from the policy. Alternatively, removing the entire distribution list from the rule removes all mailboxes that were added through that list from the backup policy. ![Screenshot showing how to remove user mailboxes from Exchange backup policy in the Microsoft 365 admin center.](../media/m365-backup/backup-policy-remove-mailbox.png) -4. Once you have done your changes, follow the prompts to update the policy. +3. The removed mailboxes are moved to the **Removed mailboxes** tab. ![Screenshot of the updated Exchange mailbox backup policy panel in the Microsoft 365 admin center.](../media/m365-backup/backup-policy-updated-mailbox.png) > [!NOTE] - > Removing mailboxes from backup policy means no future backups will be taken for those removed mailboxes. Existing backups for those mailboxes will not be deleted and will be charged. + > Removing mailboxes from backup policy means no future backups are taken for those removed mailboxes. Existing backups for those mailboxes aren't deleted and will be charged. + +# [OneDrive](#tab/onedrive) + +Follow these steps to view and edit backup policies for OneDrive. + +1. In the Microsoft 365 admin center, on the **Microsoft 365 Backup** page, in the **OneDrive** section, select **View details**. + + + +2. You can either add new accounts to or remove accounts from an existing OneDrive backup policy. + + a. To add new accounts, use either one of these two methods: + + - On the **OneDrive accounts backup policy** panel, on the **Policy details** tab, in the **Scope** area, select **Edit**. + + - Or, on the **OneDrive accounts backup policy** panel, select **+ Add accounts**. + + Select the accounts using any of the four available methods. Once you add the accounts, follow the prompts to update the policy. + + ![Screenshot showing how to add user accounts to the existing OneDrive backup policy in the Microsoft 365 admin center.](../media/m365-backup/backup-policy-add-account.png) + + b. To remove accounts from existing backup policy, on the **Included accounts** tab, select the accounts from the list, and then select **Remove**. Once you make your changes, follow the prompts to remove the accounts. + + Accounts added to a backup policy through a dynamic rule can't be individually removed. To exclude these accounts from the backup policy, you must modify the rule conditions. For example, if User A is part of Distribution List P, removing User A from the list excludes them from the policy. Alternatively, removing the entire distribution list from the rule removes all accounts that were added through that list from the backup policy. + + ![Screenshot showing how to remove user accounts from OneDrive backup policy in the Microsoft 365 admin center.](../media/m365-backup/backup-policy-remove-account.png) + +3. The removed accounts are moved to the **Removed accounts** tab. + + ![Screenshot of the updated OneDrive accounts backup policy panel in the Microsoft 365 admin center.](../media/m365-backup/backup-policy-updated-account.png) + + > [!NOTE] + > Removing accounts from backup policy means no future backups are taken for those removed accounts. Existing backups for those accounts aren't deleted and will be charged. --- +## Delete a dynamic rule + +When deleting a dynamic rule, you have two options that determine how existing accounts are treated in the backup policy. + +#### Delete rule but continue backups + +The dynamic rule is converted into a static list. Backup continues for all user accounts that were included through the rule at the time of deletion. However, future changes to the original distribution lists or security groups—such as users being added or removed—are no longer reflected in the backup policy. For example, if a user is added to a previously included group after the rule is deleted, they aren't automatically added to the backup policy. + +#### Delete rule and stop new backups + +The dynamic rule is removed, and no new backups are taken for accounts previously included through the rule. Existing backups for these users remain restorable until they expire based on the configured retention period. You can re-enable backup for these users by manually adding them or by creating a new dynamic rule that includes them. + ## States of backup |States |Definition | |---------|---------| |Active | Protection scope selected under backup policy is being actively backed up. | -|Paused | No further backups will be taken but already taken backups will be preserved. | +|Paused | No further backups are taken but already taken backups are preserved. | |Not set up | No backup policy is set up for this scope. | |Processing | A change to backup policy or a restore is in progress. | ## Multi-geo environments -Microsoft 365 Backup supports the backup of sites and user accounts from both the central and satellite locations if the multi-geo feature is enabled on your tenant. This means that you can add the sites or user accounts from all geos while creating the backup configuration policy via the CSV file upload method. Adding sites via the site picker, search, or filter rules doesn't currently support multi-geo. Those user interface experiences today only support addition of sites in the tenant's central location. +Microsoft 365 Backup supports the backup of sites and user accounts from both the central and satellite locations if the multi-geo feature is enabled on your tenant. This means that you can add the sites or user accounts from all geos while creating the backup configuration policy via the CSV file upload method. Adding sites via the site picker, search, or filter rules don't currently support multi-geo. The user interface experiences today only support addition of sites in the tenant's central location. -Most importantly, data in the backups will honor the multi-geo residency requirements and keep data in the geo you've defined it to live. +Most importantly, data in the backups honor the multi-geo residency requirements and keep data in the geo you define for it to live. diff --git a/microsoft-365/bookings/TOC.yml b/microsoft-365/bookings/TOC.yml index f0a35bd94a2..b630862f475 100644 --- a/microsoft-365/bookings/TOC.yml +++ b/microsoft-365/bookings/TOC.yml @@ -42,11 +42,7 @@ items: - name: Configure SMS text notifications and reminders href: bookings-sms.md - name: Configure service availability - href: configure-service-availability.md - - name: Use buffer time to add prep time - href: set-buffer-time.md - - name: Hide services from your booking page - href: hide-service-on-booking-page.md + href: configure-service-availability.md - name: Manage your customers for Shared Bookings items: - name: Let customers manage their bookings diff --git a/microsoft-365/bookings/add-staff.md b/microsoft-365/bookings/add-staff.md index 80be63fa53c..fb3045e01f6 100644 --- a/microsoft-365/bookings/add-staff.md +++ b/microsoft-365/bookings/add-staff.md @@ -3,7 +3,7 @@ title: "Add team members to Bookings" ms.author: kwekua author: kwekuako manager: scotv -ms.date: 07/11/2024 +ms.date: 04/10/2025 audience: Admin ms.topic: how-to ms.service: bookings @@ -34,20 +34,20 @@ Although Bookings is a feature of Microsoft 365, not all of your staff members a 2. Go to staff option in left pane and select **Staff**, and then **Add new staff**. -3. When adding staff from within your organization, type their name in the search field and select them when they appear in the drop-down menu. The other fields will automatically populate. +3. When adding staff from within your organization, type their name in the search field and select them when they appear in the drop-down menu. The other fields automatically populate. > [!NOTE] > To add staff from outside of your organization, manually fill in their email and other information. Staff from outside your tenant will not be able to share free/busy information with Bookings. 4. For each staff member, select a role: Team member, Scheduler, Viewer, or Guest. To learn more about staff roles, see [Understanding staff roles](staff-roles.md). -5. Select **Notify all staff via email when a booking assigned to them is created or changed** to enable staff emails. The following is an example email: +5. Select **Notify all staff via email when a booking assigned to them is created or changed** to enable staff emails. The following email shows an example: :::image type="content" source="media/bookings-notify-all-email.jpg" alt-text="A notification email from Bookings."::: 6. Select **Events on Microsoft 365 calendar affect availability** if you want the free/busy information from staff members’ calendars to impact availability for booking services through Bookings. - For example, if a staff member has a team meeting or a personal appointment scheduled for 3pm on a Wednesday, Bookings will show that staff member as unavailable to be booked in that time slot. That time will appear as busy or tentative in the Bookings Page view, as shown in the below example. + For example, if a staff member has a team meeting or a personal appointment scheduled for 3pm on a Wednesday, Bookings shows that staff member as unavailable to be booked in that time slot. That time appears as busy or tentative in the Bookings Page view, as shown in the image below. :::image type="content" source="media/bookings-busy-tentative-view-2.png" alt-text="A view of a Bookings Page." lightbox="media/bookings-busy-tentative-view-2.png"::: diff --git a/microsoft-365/bookings/configure-service-availability.md b/microsoft-365/bookings/configure-service-availability.md index 42f7b9067b4..4c0ad07ea1c 100644 --- a/microsoft-365/bookings/configure-service-availability.md +++ b/microsoft-365/bookings/configure-service-availability.md @@ -3,7 +3,7 @@ title: "Configure service availability" ms.author: kwekua author: kwekuako manager: scotv -ms.date: 07/11/2024 +ms.date: 04/10/2025 audience: Admin ms.topic: how-to ms.service: bookings @@ -47,3 +47,23 @@ To configure your services as "Not bookable" for the specified dates, follow the :::image type="content" source="media/bookable-staff-free.png" alt-text="Screenshot showing the availability of a staff member for a service in Bookings." lightbox="media/bookable-staff-free.png"::: Configuring service availability in Microsoft Bookings offers a tailored approach to appointment scheduling, aligning staff availability with customer bookings seamlessly. Whether it's recurring sessions or custom date ranges, Bookings empowers businesses to optimize their resources and enhance customer experience. + +## Set buffer time in Microsoft Bookings + +Some of your appointments might require time before or after you meet with your customer to set up, clean up, or reset your room and equipment. Or if you’re on the road between customer appointments, you may need time to ensure you and your team can travel between appointments without making the customer wait. + +You can set buffer time before appointments start, after appointments end, or both to give staff the extra time they need to prepare for their next appointment. + +### Set buffer time defaults + +Buffer time defaults are set on the **Service details** page in Bookings. Like all service defaults set on this page, these defaults can be edited by you for a specific booking to meet specific customer needs. + +The buffer time setting can be found on the **Service details** page. Before it can be set for a given service, you must enable the buffer time setting by selecting the buffer time toggle. This causes the **Before** and **After** drop-downs to appear, which are used to pick the default amount of time to hold before and after each booking, as shown here: + + ![Screenshot showing Bookings with buffer time enabled.](../media/bookings-buffertime.png) + +### Buffer time and availability + +Your customers don’t directly see and cannot change the buffer times you set. However, because buffer time is used to calculate overall service duration, customers will see you and your relevant staff as booked during both buffer and regular appointment times. Customers also only see availability for you and your staff if there is enough time for both the appointment and its buffer time. + +As an example, a one-hour appointment with a 15-minute pre-appointment buffer time requires an available time block of at least 1 hour and 15 minutes. An appointment for this service would therefore fill a 75-minute block of time on your calendar and needs 75 minutes of availability to book without conflict. diff --git a/microsoft-365/bookings/create-a-manual-booking.md b/microsoft-365/bookings/create-a-manual-booking.md index 0a1758969b0..9ce6e1b0f4d 100644 --- a/microsoft-365/bookings/create-a-manual-booking.md +++ b/microsoft-365/bookings/create-a-manual-booking.md @@ -3,7 +3,7 @@ title: "Create an appointment on behalf of a customer" ms.author: kwekua author: kwekuako manager: scotv -ms.date: 05/28/2024 +ms.date: 04/10/2025 audience: Admin ms.topic: how-to ms.service: bookings diff --git a/microsoft-365/bookings/create-new-meeting-type.md b/microsoft-365/bookings/create-new-meeting-type.md index 06a43128e62..24260f292b9 100644 --- a/microsoft-365/bookings/create-new-meeting-type.md +++ b/microsoft-365/bookings/create-new-meeting-type.md @@ -1,7 +1,7 @@ ---- +--- title: "Create a new meeting type in Bookings" -ms.author: pritikar -author: kwekuako +ms.author: kwekua +author: pritikar manager: scotv ms.date: 07/11/2024 ms.topic: how-to @@ -15,9 +15,9 @@ ms.custom: QuickDraft AI_Usage: - AI-Assisted description: Learn how to create a new meeting type in Microsoft Bookings. ---- +--- -# Create a new meeting type in Bookings + # Create a new meeting type in Bookings In this article, you'll learn about meeting types, public and private meetings, and how to create and edit meeting types. diff --git a/microsoft-365/bookings/define-service-offerings.md b/microsoft-365/bookings/define-service-offerings.md index 401f9ac40a2..72ea8b2d095 100644 --- a/microsoft-365/bookings/define-service-offerings.md +++ b/microsoft-365/bookings/define-service-offerings.md @@ -122,3 +122,20 @@ The number of services should be limited to 50. - **Publishing options** Choose whether to have this service appear as bookable on the Self-service page, or to make the service bookable only on the Calendar tab within the Bookings Web app. 1. Select **Save changes** to create the new service. + +## How to hide a service on your booking page + +There could be situations when you want to hide a service from your booking page so customers can't book appointments for that service. This can be helpful in situations such as: + +- You are still configuring the service details and settings, and you're not ready for customers to book. +- The service is temporarily unavailable due to staff shortage, maintenance, or date of the service. +- The service is only offered to specific customers or groups, and you don't want to make it public. + +To hide a service from your booking page link, follow these steps: + +1. Open the **Microsoft Bookings** app and go to the **Services** tab. +2. Choose the service that you want to hide and toggle the switch under **Publishing options** to **Off**. The switch should turn from blue to gray, indicating that the service is hidden. +3. To confirm that the service is hidden, go to the **Booking page** tab and copy the booking page link. Open the link in a new browser window and check if the service is listed. If it's not showing, then the service is successfully hidden. +4. To unhide the service, repeat steps 1 and 2, but turn the toggle switch to **On** instead of **Off**. The switch should turn from gray to blue, indicating that the service is visible. You can verify this by checking the booking page link again. + +Hiding a service from your booking page link doesn't delete the service or affect the existing bookings for that service. You can still manage the service details, settings, and bookings in the Microsoft Bookings app. diff --git a/microsoft-365/bookings/employee-hours.md b/microsoft-365/bookings/employee-hours.md index d4aa7aaa70f..e92e37887d9 100644 --- a/microsoft-365/bookings/employee-hours.md +++ b/microsoft-365/bookings/employee-hours.md @@ -3,7 +3,7 @@ title: "Employee working hours - Microsoft Bookings" ms.author: kwekua author: kwekuako manager: scotv -ms.date: 05/24/2024 +ms.date: 04/10/2025 audience: Admin ms.topic: how-to ms.service: bookings diff --git a/microsoft-365/bookings/granular-controls-shared-bookings.md b/microsoft-365/bookings/granular-controls-shared-bookings.md index 59e6bb07a7e..ae8acde5c6b 100644 --- a/microsoft-365/bookings/granular-controls-shared-bookings.md +++ b/microsoft-365/bookings/granular-controls-shared-bookings.md @@ -3,7 +3,7 @@ title: "Manage granular controls for Shared Bookings" ms.author: kwekua author: kwekuako manager: scotv -ms.date: 05/23/2024 +ms.date: 04/10/2025 audience: Admin ms.topic: how-to ms.service: bookings diff --git a/microsoft-365/bookings/hide-service-on-booking-page.md b/microsoft-365/bookings/hide-service-on-booking-page.md deleted file mode 100644 index 0a7e1a3b4f9..00000000000 --- a/microsoft-365/bookings/hide-service-on-booking-page.md +++ /dev/null @@ -1,32 +0,0 @@ ---- -title: "Hide a service on your booking page" -ms.author: kwekua -author: kwekuako -manager: scotv -ms.date: 07/11/2024 -ms.topic: how-to -ms.service: bookings -ms.localizationpriority: medium -ms.collection: -- scotvorg -ms.custom: QuickDraft -ai-usage: ai-assisted -description: "Learn how to hide specific services on your booking page." ---- - -# How to hide a service on your booking page - -There could be situations when you want to hide a service from your booking page so customers can't book appointments for that service. This can be helpful in situations such as: - -- You are still configuring the service details and settings, and you're not ready for customers to book. -- The service is temporarily unavailable due to staff shortage, maintenance, or date of the service. -- The service is only offered to specific customers or groups, and you don't want to make it public. - -To hide a service from your booking page link, follow these steps: - -1. Open the **Microsoft Bookings** app and go to the **Services** tab. -2. Choose the service that you want to hide and toggle the switch under **Publishing options** to **Off**. The switch should turn from blue to gray, indicating that the service is hidden. -3. To confirm that the service is hidden, go to the **Booking page** tab and copy the booking page link. Open the link in a new browser window and check if the service is listed. If it's not showing, then the service is successfully hidden. -4. To unhide the service, repeat steps 1 and 2, but turn the toggle switch to **On** instead of **Off**. The switch should turn from gray to blue, indicating that the service is visible. You can verify this by checking the booking page link again. - -Hiding a service from your booking page link doesn't delete the service or affect the existing bookings for that service. You can still manage the service details, settings, and bookings in the Microsoft Bookings app. diff --git a/microsoft-365/bookings/manage-attendees-bookings.md b/microsoft-365/bookings/manage-attendees-bookings.md index 47131d8c3e0..f897512266e 100644 --- a/microsoft-365/bookings/manage-attendees-bookings.md +++ b/microsoft-365/bookings/manage-attendees-bookings.md @@ -3,7 +3,7 @@ title: "Manage group attendees in Bookings" ms.author: kwekua author: kwekuako manager: scotv -ms.date: 05/17/2024 +ms.date: 04/10/2025 audience: Admin ms.topic: how-to ms.service: bookings diff --git a/microsoft-365/bookings/preview-share-personal-booking-page.md b/microsoft-365/bookings/preview-share-personal-booking-page.md index ff2e39d801a..8533d3219d2 100644 --- a/microsoft-365/bookings/preview-share-personal-booking-page.md +++ b/microsoft-365/bookings/preview-share-personal-booking-page.md @@ -1,7 +1,7 @@ --- title: "Preview and share your personal booking page" -ms.author: pritikar -author: kwekuako +ms.author: kwekua +author: pritikar manager: scotv ms.date: 07/11/2024 ms.topic: article diff --git a/microsoft-365/bookings/reporting-info.md b/microsoft-365/bookings/reporting-info.md index 5a7cb4a2e15..12f0c9ea7ac 100644 --- a/microsoft-365/bookings/reporting-info.md +++ b/microsoft-365/bookings/reporting-info.md @@ -3,7 +3,7 @@ title: "Reporting information for Shared Bookings" ms.author: kwekua author: kwekuako manager: scotv -ms.date: 05/26/2024 +ms.date: 04/10/2025 audience: Admin ms.topic: how-to ms.service: bookings diff --git a/microsoft-365/bookings/schedule-closures-time-off-vacation.md b/microsoft-365/bookings/schedule-closures-time-off-vacation.md index df9bcfa4dda..cfddb3a4f33 100644 --- a/microsoft-365/bookings/schedule-closures-time-off-vacation.md +++ b/microsoft-365/bookings/schedule-closures-time-off-vacation.md @@ -3,7 +3,7 @@ title: "Schedule business closures, time off, and vacation time" ms.author: kwekua author: kwekuako manager: scotv -ms.date: 05/24/2024 +ms.date: 04/10/2025 audience: Admin ms.topic: how-to ms.service: bookings diff --git a/microsoft-365/bookings/set-buffer-time.md b/microsoft-365/bookings/set-buffer-time.md deleted file mode 100644 index fbc10b162f5..00000000000 --- a/microsoft-365/bookings/set-buffer-time.md +++ /dev/null @@ -1,35 +0,0 @@ ---- -title: "Set Bookings buffer time" -ms.author: kwekua -author: kwekuako -manager: scotv -ms.date: 10/02/2024 -audience: Admin -ms.topic: how-to -ms.service: bookings -ms.localizationpriority: medium -ms.collection: -- Tier1 -- scotvorg -description: "Set buffer time before or after an appointment in Microsoft Bookings to allow time for cleaning up or resetting equipment." ---- - -# Set buffer time in Microsoft Bookings - -Some of your appointments might require time before or after you meet with your customer to set up, clean up, or reset your room and equipment. Or if you’re on the road between customer appointments, you may need time to ensure you and your team can travel between appointments without making the customer wait. - -You can set buffer time before appointments start, after appointments end, or both to give staff the extra time they need to prepare for their next appointment. - -## Set buffer time defaults - -Buffer time defaults are set on the **Service details** page in Bookings. Like all service defaults set on this page, these defaults can be edited by you for a specific booking to meet specific customer needs. - -The buffer time setting can be found on the **Service details** page. Before it can be set for a given service, you must enable the buffer time setting by selecting the buffer time toggle. This causes the **Before** and **After** drop-downs to appear, which are used to pick the default amount of time to hold before and after each booking, as shown here: - - ![Image of Bookings with buffer time enabled.](../media/bookings-buffertime.png) - -## Buffer time and availability - -Your customers don’t directly see and cannot change the buffer times you set. However, because buffer time is used to calculate overall service duration, customers will see you and your relevant staff as booked during both buffer and regular appointment times. Customers also only see availability for you and your staff if there is enough time for both the appointment and its buffer time. - -As an example, a one-hour appointment with a 15-minute pre-appointment buffer time requires an available time block of at least 1 hour and 15 minutes. An appointment for this service would therefore fill a 75-minute block of time on your calendar and needs 75 minutes of availability to book without conflict. diff --git a/microsoft-365/bookings/share-shared-bookings-page.md b/microsoft-365/bookings/share-shared-bookings-page.md index 6a1e28f1f7f..1c2cc2f1054 100644 --- a/microsoft-365/bookings/share-shared-bookings-page.md +++ b/microsoft-365/bookings/share-shared-bookings-page.md @@ -3,7 +3,7 @@ title: "Sharing your shared booking page" ms.author: kwekua author: kwekuako manager: scotv -ms.date: 05/23/2024 +ms.date: 04/10/2025 audience: Admin ms.topic: article ms.service: bookings diff --git a/microsoft-365/business-premium/m365bp-protect-against-malware-cyberthreats.md b/microsoft-365/business-premium/m365bp-protect-against-malware-cyberthreats.md index d9bffe1c45e..9f42bd0196a 100644 --- a/microsoft-365/business-premium/m365bp-protect-against-malware-cyberthreats.md +++ b/microsoft-365/business-premium/m365bp-protect-against-malware-cyberthreats.md @@ -168,7 +168,7 @@ The following image shows some of the default policies that are included with Mi ### View your alert policies -1. Go to the Microsoft Purview compliance portal at and sign in. +1. Go to the Microsoft Purview portal at and sign in. 2. In the navigation pane, choose **Policies**, and then choose **Alert policies**. @@ -181,12 +181,12 @@ The following image shows some of the default policies that are included with Mi ### How to view alerts -You can view your alerts in either the Microsoft Defender portal or the Microsoft Purview compliance portal. +You can view your alerts in either the Microsoft Defender portal or the Microsoft Purview portal. |Type of alert|What to do| |---|---| |Security alert, such as when a user selects a malicious link, an email is reported as malware or phish, or a device is detected as containing malware|Go to the Microsoft Defender portal at and under **Email & collaboration** select **Policies & rules** \> **Alert policy**. Alternatively, you can go directly to .| -|Compliance alert, such as when a user shares sensitive or confidential information (data loss prevention alert) or there's an unusual volume of external file sharing (information governance alert)|Go to the Microsoft Purview compliance portal at , and then select **Policies** \> **Alert** \> **Alert policies**.| +|Compliance alert, such as when a user shares sensitive or confidential information (data loss prevention alert) or there's an unusual volume of external file sharing (information governance alert)|Go to the Microsoft Purview portal at , and then select **Policies** \> **Alert** \> **Alert policies**.| For more information, see [View alerts](/purview/alert-policies#view-alerts). diff --git a/microsoft-365/business-premium/m365bp-set-up-compliance.md b/microsoft-365/business-premium/m365bp-set-up-compliance.md index b94d37e1d11..7c6c3e7a664 100644 --- a/microsoft-365/business-premium/m365bp-set-up-compliance.md +++ b/microsoft-365/business-premium/m365bp-set-up-compliance.md @@ -38,7 +38,7 @@ Microsoft 365 Business Premium includes Compliance Manager, which can help you g Here's how to get started: -1. Go to and sign in. +1. Go to and sign in. 2. In the navigation pane, choose **Compliance Manager**. diff --git a/microsoft-365/business-premium/microsoft-365-business-faqs.yml b/microsoft-365/business-premium/microsoft-365-business-faqs.yml index 0c761d5b868..0eabc2bd7b0 100644 --- a/microsoft-365/business-premium/microsoft-365-business-faqs.yml +++ b/microsoft-365/business-premium/microsoft-365-business-faqs.yml @@ -12,7 +12,7 @@ metadata: ms.collection: - tier2 - m365-security - ms.date: 03/05/2025 + ms.date: 04/16/2025 ms.localizationpriority: medium audience: microsoft-business keywords: Microsoft 365 Business Premium, Microsoft 365, SMB, FAQ, frequently asked questions, answers, business @@ -119,6 +119,14 @@ sections: To get help with setting up your trial, see [Trial user guide for Microsoft 365 Business Premium](/microsoft-365/business-premium/m365bp-trial-playbook-microsoft-business-premium). + - question: What if my Microsoft 365 Business Premium organization has some Microsoft Defender for Business servers licenses, and I want to switch all users to Microsoft 365 E5 Security? + answer: | + You need to change your server plan to Microsoft Defender for Endpoint for servers or Microsoft Defender for Servers. + + - question: Is Microsoft 365 E5 Security available as an add-on for Microsoft 365 Business Premium for Nonprofits? + answer: | + Yes! Microsoft 365 E5 Security is available as an add-on for the commercial and non-profit offerings of Microsoft 365 Business Premium. + - name: Deployment questions: - question: What should customers consider when planning a Microsoft 365 Business Premium deployment? diff --git a/microsoft-365/commerce/billing-and-payments/manage-billing-notifications.md b/microsoft-365/commerce/billing-and-payments/manage-billing-notifications.md index 2229908f755..c28c0e21ab4 100644 --- a/microsoft-365/commerce/billing-and-payments/manage-billing-notifications.md +++ b/microsoft-365/commerce/billing-and-payments/manage-billing-notifications.md @@ -52,12 +52,26 @@ You can choose to receive your organization's invoices as email attachments. How If you have an MCA billing account type, the option to receive your invoice as an attachment to your invoice notification emails is linked with your billing profile. To turn on the invoice email attachment setting for a specific billing profile, use the following steps. -1. In the admin center, go to the **Billing** > [Billing accounts](https://go.microsoft.com/fwlink/p/?linkid=2102895"") page. +1. In the admin center, go to the **Billing** > Billing accounts page. 1. On the **Overview** tab, select a billing account. 1. On the billing account details page, select the **Billing profiles** tab. The tab lists all billing profiles associated with the selected billing account. 1. Select a billing profile name to view its details page. -1. In the **Invoice and Billing Notifications** section, select **Edit settings**. -1. In the **Invoice email settings** pane, under **Get invoices in email attachments**, switch the toggle to **On**. +1. In the **Invoice and Billing Notifications** section, select **Manage settings** under **Invoice and payment contact settings**. +1. In the **Edit invoice and contacts settings** pane, under **Get invoices in email attachments**, switch the toggle to **On**. +1. If needed, add any additional recipient email addresses, then select **Save Changes**. + +#### Manage accounts payable contacts + +If you have an MCA billing account type and the default payment instrument is check or wire transfer, at least one Accounts payable contact is required. This contact receives copies of the invoice by email along with statements and payment inquiries. You have full control to add, edit, and delete Accounts payable contacts as needed. While the Billing group owner, contributor, and Invoice manager roles continue to receive invoice-ready emails and access invoices in the portals, they don't receive statements and payment reminders. If your default payment instrument isn't check or wire transfer, these contacts are optional. + +1. In the admin center, go to the **Billing** > Billing accounts page. +1. On the **Overview** tab, select a billing account. +1. On the billing account details page, select the **Billing profiles** tab. The tab lists all billing profiles associated with the selected billing account. +1. Select a billing profile name to view its details page. +1. In the **Invoice and Billing Notifications** section, under **Invoice and payment contact settings**, select **Manage settings**. +1. Select **Add account payable contact**. +1. Enter the required information and select **Save**. +1. The **Get invoices in email attachments** toggle is on by default so contacts get copies of the invoice. 1. If needed, add any additional recipient email addresses, then select **Save Changes**. ### Receive your invoice as an email attachment for MOSA billing account types @@ -67,7 +81,7 @@ If you have an MOSA billing account type, the option to receive your invoice as > [!NOTE] > Billing admins can also do the following steps. -1. In the admin center, go to the **Billing** > [Billing notifications](https://go.microsoft.com/fwlink/p/?linkid=853212"") page. +1. In the admin center, go to the **Billing** > Billing notifications page. 1. Under **Billing notification settings**, select **Edit notification settings**. 1. In the **Billing notification settings** pane, under **Invoice PDF**, select the **Attach a PDF to your invoice emails** checkbox, then select **Save**. @@ -93,7 +107,7 @@ To learn more about billing profile roles and how to manage them, see [Understan You can receive a copy of your invoice attached as a pdf to your invoice ready email. -1. In the admin center, go to the **Billing** > [Billing accounts](https://go.microsoft.com/fwlink/p/?linkid=2102895"") page. +1. In the admin center, go to the **Billing** > Billing accounts page. 1. Select the Billing account that includes the Billing profile that you want to add email recipients to. 1. Select the **Billing profiles** tab. 1. Select the Billing profile that you want to update. @@ -105,7 +119,7 @@ You can receive a copy of your invoice attached as a pdf to your invoice ready e In case your primary email address isn't configured to receive emails, or if you want to receive the notifications at different email addresses, you can add them by using the following steps. -1. In the admin center, go to the **Billing** > Billing accounts page. +1. In the admin center, go to the **Billing** > Billing accounts page. 2. Select the Billing account that includes the Billing profile that you want to add email recipients to. 3. Select the **Billing profiles** tab. 4. Select the Billing profile that you want to update. @@ -156,7 +170,7 @@ You can change the primary email address of other admins in your organization. H In addition to your Global and Billing admins, we send billing notifications to your organization's contact email address. 1. In the admin center, go to the **Billing** > Billing notifications page. -2. Under **Organization contact receiving billing notifications**, select the organization contact. +1. Under **Organization contact receiving billing notifications**, select the organization contact. 1. In the organization details pane, type the email address that you want to use, then select **Save**. ## Related content diff --git a/microsoft-365/commerce/billing-and-payments/pay-for-your-subscription.md b/microsoft-365/commerce/billing-and-payments/pay-for-your-subscription.md index 8aa44317395..ec6267f8cf4 100644 --- a/microsoft-365/commerce/billing-and-payments/pay-for-your-subscription.md +++ b/microsoft-365/commerce/billing-and-payments/pay-for-your-subscription.md @@ -123,6 +123,164 @@ If you have an MOSA billing account type, and you personally added the payment m > [!NOTE] > If you must pay the membership fee for the Microsoft Partner Network (MPN) program (Action Pack subscription, Silver or Gold competencies), see [Pay the Solutions partner designation fee](/partner-center/mpn-pay-fee-silver-gold-competency) for information about how to make an MPN payment. +### Bank details used to send wire transfer payments + +Find payment instructions for your country/region in the following list: + +> [!div class="op_single_selector"] +> - **Choose your country or region** +> - [Afghanistan](/legal/pay/afghanistan) +> - [Albania](/legal/pay/albania) +> - [Algeria](/legal/pay/algeria) +> - [Angola](/legal/pay/angola) +> - [Argentina](/legal/pay/argentina) +> - [Armenia](/legal/pay/armenia) +> - [Australia](/legal/pay/australia) +> - [Austria](/legal/pay/austria) +> - [Azerbaijan](/legal/pay/azerbaijan) +> - [Bahamas](/legal/pay/bahamas) +> - [Bahrain](/legal/pay/bahrain) +> - [Bangladesh](/legal/pay/bangladesh) +> - [Barbados](/legal/pay/barbados) +> - [Belarus](/legal/pay/belarus) +> - [Belgium](/legal/pay/belgium) +> - [Belize](/legal/pay/belize) +> - [Bermuda](/legal/pay/bermuda) +> - [Bolivia](/legal/pay/bolivia) +> - [Bosnia and Herzegovina](/legal/pay/bosnia-and-herzegovina) +> - [Botswana](/legal/pay/botswana) +> - [Brazil](/legal/pay/brazil) +> - [Brunei](/legal/pay/brunei) +> - [Bulgaria](/legal/pay/bulgaria) +> - [Cameroon](/legal/pay/cameroon) +> - [Canada](/legal/pay/canada) +> - [Cabo Verde](/legal/pay/cape-verde) +> - [Cayman Islands](/legal/pay/cayman-islands) +> - [Chile](/legal/pay/chile) +> - [China (PRC)](/legal/pay/china-prc) +> - [Colombia](/legal/pay/colombia) +> - [Costa Rica](/legal/pay/costa-rica) +> - [Côte d'Ivoire](/legal/pay/cote-divoire) +> - [Croatia](/legal/pay/croatia) +> - [Curacao](/legal/pay/curacao) +> - [Cyprus](/legal/pay/cyprus) +> - [Czech Republic](/legal/pay/czech-republic) +> - [Democratic Republic of Congo](/legal/pay/democratic-republic-of-congo) +> - [Denmark](/legal/pay/denmark) +> - [Dominican Republic](/legal/pay/dominican-republic) +> - [Ecuador](/legal/pay/ecuador) +> - [Egypt](/legal/pay/egypt) +> - [El Salvador](/legal/pay/el-salvador) +> - [Estonia](/legal/pay/estonia) +> - [Ethiopia](/legal/pay/ethiopia) +> - [Faroe Islands](/legal/pay/faroe-islands) +> - [Fiji](/legal/pay/fiji) +> - [Finland](/legal/pay/finland) +> - [France](/legal/pay/france) +> - [French Guiana](/legal/pay/french-guiana) +> - [Georgia](/legal/pay/georgia) +> - [Germany](/legal/pay/germany) +> - [Ghana](/legal/pay/ghana) +> - [Greece](/legal/pay/greece) +> - [Grenada](/legal/pay/grenada) +> - [Guadeloupe](/legal/pay/guadeloupe) +> - [Guam](/legal/pay/guam) +> - [Guatemala](/legal/pay/guatemala) +> - [Guyana](/legal/pay/guyana) +> - [Haiti](/legal/pay/haiti) +> - [Honduras](/legal/pay/honduras) +> - [Hong Kong SAR](/legal/pay/hong-kong) +> - [Hungary](/legal/pay/hungary) +> - [Iceland](/legal/pay/iceland) +> - [India](/legal/pay/india) +> - [Indonesia](/legal/pay/indonesia) +> - [Iraq](/legal/pay/iraq) +> - [Ireland](/legal/pay/ireland) +> - [Israel](/legal/pay/israel) +> - [Italy](/legal/pay/italy) +> - [Jamaica](/legal/pay/jamaica) +> - [Japan](/legal/pay/japan) +> - [Jordan](/legal/pay/jordan) +> - [Kazakhstan](/legal/pay/kazakhstan) +> - [Kenya](/legal/pay/kenya) +> - [Korea](/legal/pay/korea) +> - [Kuwait](/legal/pay/kuwait) +> - [Kyrgyzstan](/legal/pay/kyrgyzstan) +> - [Latvia](/legal/pay/latvia) +> - [Lebanon](/legal/pay/lebanon) +> - [Libya](/legal/pay/libya) +> - [Liechtenstein](/legal/pay/liechtenstein) +> - [Lithuania](/legal/pay/lithuania) +> - [Luxembourg](/legal/pay/luxembourg) +> - [Macao Special Administrative Region](/legal/pay/macao) +> - [Malaysia](/legal/pay/malaysia) +> - [Malta](/legal/pay/malta) +> - [Mauritius](/legal/pay/mauritius) +> - [Mexico](/legal/pay/mexico) +> - [Moldova](/legal/pay/moldova) +> - [Monaco](/legal/pay/monaco) +> - [Mongolia](/legal/pay/mongolia) +> - [Montenegro](/legal/pay/montenegro) +> - [Morocco](/legal/pay/morocco) +> - [Namibia](/legal/pay/namibia) +> - [Nepal](/legal/pay/nepal) +> - [Netherlands](/legal/pay/netherlands) +> - [New Zealand](/legal/pay/new-zealand) +> - [Nicaragua](/legal/pay/nicaragua) +> - [Nigeria](/legal/pay/nigeria) +> - [North Macedonia, Republic of](/legal/pay/macedonia) +> - [Norway](/legal/pay/norway) +> - [Oman](/legal/pay/oman) +> - [Pakistan](/legal/pay/pakistan) +> - [Palestinian Authority](/legal/pay/palestinian-authority) +> - [Panama](/legal/pay/panama) +> - [Paraguay](/legal/pay/paraguay) +> - [Peru](/legal/pay/peru) +> - [Philippines](/legal/pay/philippines) +> - [Poland](/legal/pay/poland) +> - [Portugal](/legal/pay/portugal) +> - [Puerto Rico](/legal/pay/puerto-rico) +> - [Qatar](/legal/pay/qatar) +> - [Romania](/legal/pay/romania) +> - [Russia](/legal/pay/russia) +> - [Rwanda](/legal/pay/rwanda) +> - [Saint Kitts and Nevis](/legal/pay/saint-kitts-and-nevis) +> - [Saint Lucia](/legal/pay/saint-lucia) +> - [Saint Vincent and the Grenadines](/legal/pay/saint-vincent-and-the-grenadines) +> - [Saudi Arabia](/legal/pay/saudi-arabia) +> - [Senegal](/legal/pay/senegal) +> - [Serbia](/legal/pay/serbia) +> - [Singapore](/legal/pay/singapore) +> - [Slovakia](/legal/pay/slovakia) +> - [Slovenia](/legal/pay/slovenia) +> - [South Africa](/legal/pay/south-africa) +> - [Spain](/legal/pay/spain) +> - [Sri Lanka](/legal/pay/sri-lanka) +> - [Suriname](/legal/pay/suriname) +> - [Sweden](/legal/pay/sweden) +> - [Switzerland](/legal/pay/switzerland) +> - [Taiwan](/legal/pay/taiwan) +> - [Tajikistan](/legal/pay/tajikistan) +> - [Tanzania](/legal/pay/tanzania) +> - [Thailand](/legal/pay/thailand) +> - [Trinidad and Tobago](/legal/pay/trinidad-and-tobago) +> - [Turkmenistan](/legal/pay/turkmenistan) +> - [Tunisia](/legal/pay/tunisia) +> - [Türkiye](/legal/pay/turkey) +> - [Uganda](/legal/pay/uganda) +> - [Ukraine](/legal/pay/ukraine) +> - [United Arab Emirates](/legal/pay/united-arab-emirates) +> - [United Kingdom](/legal/pay/united-kingdom) +> - [United States](/legal/pay/united-states) +> - [Uruguay](/legal/pay/uruguay) +> - [Uzbekistan](/legal/pay/uzbekistan) +> - [Venezuela](/legal/pay/venezuela) +> - [Vietnam](/legal/pay/vietnam) +> - [Virgin Islands, US](/legal/pay/virgin-islands) +> - [Yemen](/legal/pay/yemen) +> - [Zambia](/legal/pay/zambia) +> - [Zimbabwe](/legal/pay/zimbabwe) + ## Wire transfer payment processing time Payments made by wire transfer have processing times that vary, depending on the type of transfer: diff --git a/microsoft-365/commerce/licenses/buy-licenses.md b/microsoft-365/commerce/licenses/buy-licenses.md index 65f3d9a903a..31e57462f04 100644 --- a/microsoft-365/commerce/licenses/buy-licenses.md +++ b/microsoft-365/commerce/licenses/buy-licenses.md @@ -28,7 +28,7 @@ ms.custom: - campaignIDs-batch1 search.appverid: MET150 description: "Learn how to buy more licenses or reduce the number of licenses for your business subscription in the Microsoft 365 admin center." -ms.date: 03/25/2025 +ms.date: 04/09/2025 --- # Buy or remove licenses for a Microsoft business subscription diff --git a/microsoft-365/commerce/licenses/contracts-faq.yml b/microsoft-365/commerce/licenses/contracts-faq.yml deleted file mode 100644 index 7b49003f759..00000000000 --- a/microsoft-365/commerce/licenses/contracts-faq.yml +++ /dev/null @@ -1,187 +0,0 @@ -### YamlMime:FAQ -metadata: - title: "Contracts FAQ" - author: cmcatee-MSFT - ms.author: cmcatee - manager: scotv - ms.reviewer: aasthatiwari, atuldubey - audience: Admin - ms.topic: faq - ms.service: microsoft-365-business - ms.subservice: m365-commerce-volume-licensing - ms.collection: - - Tier1 - - scotvorg - ms.custom: - - commerce_vl - - empty - search.appverid: MET150 - ms.localizationpriority: medium - description: "Frequently asked questions about Microsoft 365 licensing agreements." - ms.date: 09/04/2024 - -title: Contracts Frequently Asked Questions -summary: | - -sections: - - name: General - questions: - - question: | - Why can I see the Contracts list? - answer: | - You can see the Contracts list if you're a valid Volume Licensing (VL) user. You're a VL user if you meet one of the following requirements: - - - You're listed as a contact for the agreements in a legal Volume Licensing Program form. Contact types include Primary Contact, Notices Correspondent, Online Access Contact, Software Assurance Manager, Online Services Manager, or Subscriptions Manager. - - You're an Administrator with access to the agreements. - - - question: | - What is a Licensing ID? - answer: | - A Licensing ID identifies the program level at which orders can be placed by an organization. It can represent any of the following: - - - Enrollment (Enterprise or Select programs) - - Agreement (Open Value program) - - License (Open License program) - - Public Customer Number (PCN) (Select Plus program) - - Entitlements and site permissions are determined by the Licensing IDs available to your organization. - - - question: | - Where are my MPSA contracts? - answer: | - Microsoft Products and Services Agreement (MPSA) license information is managed in the [Microsoft Business Center](https://businessaccount.microsoft.com/Customer). No MPSA information is displayed in this contracts list. To learn more about the MPSA, see [Microsoft Products and Services Agreement](https://www.microsoft.com/Licensing/MPSA?rtc=1). - - - question: | - Why are some Licensing IDs for my organization not displayed in the list? - answer: | - A Licensing ID is displayed only if the user who is signed in has permission to view the Licensing ID details. Permission to view a specific Licensing ID on behalf of your organization is granted if you meet one of the following criteria: - - - You're listed as a contact for the agreements in a legal Volume Licensing Program form. Contact types include Primary Contact, Notices Correspondent, Online Access Contact, Software Assurance Manager, Online Services Manager, or Subscriptions Manager. - - You're Administrator with access to the agreements. - - For more information about Volume Licensing permission roles and their allowable actions, see the [Permissions FAQ](/licensing/permissions-faq). - - - question: | - How long does it take for new license orders to appear in the contracts list? - answer: | - Recently purchased licenses are typically displayed in the list within 10 hours of Microsoft receiving your order from the Microsoft partner. Delays of a few days to a few weeks can occur if your partner delays forwarding the purchase order to Microsoft. Licenses display in the summary when the Coverage Start period for the order is met for all programs except Open License. - - The following data is available in the contacts list: - - |Name of the Column|Description| - |---|---| - |Licensing ID|Key contacts and related licenses of your organization by specific Licensing ID| - |Parent Program Details|Key contacts and related Licensing IDs for your organization by licensing program| - |MBSA Details|Key contacts and related Licensing IDs for your organization as associated with a Microsoft Business and Services Agreement (MBSA)| - |Organization|The License Organization| - |Location|The combination of city and county of the License Organization| - |End date|The End date of the License| - |Status|The status of the License| - |Roles|Your permissions on the Contracts| - - - question: | - Why am I seeing "Organization not approved" message? - answer: | - If you see an "Organization not approved" message, it means your organization is not yet ready to use Microsoft products and services because the review is incomplete. Until this review is complete, the License ID isn't displayed in **Volume Licensing** > **Contracts**, and you can't access software downloads or volume licensing keys or manage user access to the contract. Please use the Help & Support option to contact our support team. - - - question: | - What is the License Summary? - answer: | - The License Summary displays real-time Volume License entitlements per Microsoft product family and version for all active and inactive Licensing IDs in your permission set. - The License Summary displays purchase information related to traditional Microsoft Volume License programs beginning in 1994. These programs include, but are not limited to, Open, Open Value, Select, Select Plus, and Enterprise. - Licenses purchased under the MPSA program are not included in the VLSC Relationship Summary and can be viewed separately in the [Microsoft Business Center](https://businessaccount.microsoft.com/customer). - - Access and create the License Summary - - 1. Sign into the Microsoft 365 admin center. - 2. Go to **Billing** > **Your products** > **Volume licensing** > **Contracts**. - - Filter the Licensing IDs for display in the License Summary - - 1. Use the check boxes to select the License IDs to be included in this summary. - 2. Select **Create License Summary**. The License Summary is generated only for the selected Licensing IDs. - - - name: Understanding the License Summary - questions: - - question: | - What is a License Entitlement? - answer: | - A License Entitlement represents your right to install and use software products as detailed in the license agreement. - - - question: | - What is the Effective Quantity? - answer: | - The Effective Quantity is the number of license entitlements per product and version with upgrades. It's used to determine whether your organization has license shortfalls or surpluses by product and version. - - - question: | - What is the Active SA (Software Assurance) Quantity? - answer: | - The Active SA Quantity is displayed in the License Summary. It represents the number of licenses covered by Software Assurance (version upgrade protection) across all Microsoft Volume License programs. The Active SA Quantity includes all types of Software Assurance, including: - - - License and Software Assurance (L&SA) - - Software Assurance (SA) - - SA Step-Up - - - question: | - Why am I seeing Effective Quantity and/or Active SA Quantity as zero (0)? - answer: | - The license summary is intended to show the licenses your organization is entitled to deploy and use. - If the Effective Quantity in the generated license statement is shown as zero, it means that your organization isn't entitled to use the license under the terms of the set of licensing IDs selected for that statement. - If the Active SA Quantity is shown as zero, it means that the licenses under the set of licensing IDs used to generate the statement don't have any valid or active Software Assurance coverage. - - > [!Note] - > For Online Services licenses, the Active SA Quantity is always zero, because Online Services don't have SAs associated with them. - - - question: | - Why does the License Summary display more upgrade licenses than the number of qualifying full licenses? - answer: | - This may be for a number of reasons. Microsoft Volume Licensing organizes products into three pools: - - Full licenses acquired through OEM or Retail purchases are not visible to Microsoft volume licensing admin center. - - Licenses may have been ordered separately from their underlying base license (for example, Maintenance, Upgrade Advantage, or Software Assurance). - - You may not have a complete list of Licensing IDs: Full licenses may have been acquired under Licensing IDs you do not have permissions to view. - - Licenses purchased in a very recent order with your Microsoft partner may not yet be processed by the Microsoft Partner. - - > [!Note] - > We do not display an “Unresolved Quantity” in the M365 Admin Center license summary view. This follows feedback that it was not helpful to customers trying to understand their license position and set a false expectation that an action needed to be taken within the site. We welcome your feedback on this decision. - - - question: | - Does the License Summary include Original Equipment Manufacturer (OEM) or retail license information? - answer: | - No. The License Summary only displays licenses acquired by your organization through Volume Licensing programs. - - - question: | - Does the License Summary display what software is deployed in my organization? - answer: | - No. It's not possible for Microsoft to provide a list of product deployment details in the License Summary. The License Summary shows you the software your organization is entitled to install and use, but not what is currently deployed. - - - question: | - What is a Product Pool? - answer: | - A License Pool groups licenses by product type. Microsoft Volume Licensing organizes products into three pools: - - - Applications (for example, editions of Microsoft 365) - - Systems (for example, versions of the Windows operating system) - - Servers (for example, Exchange Server, SQL Server, and Windows Server) - - - question: | - What is a License Grant? - answer: | - Occasionally, Microsoft Volume Licensing offers a promotion where purchase of a specific product entitles the customer to the use of another product. Promotions are typically conditional on active Software Assurance or Upgrade Advantage coverage on the purchased product. For example: - - - A customer purchases one license for Exchange Server 2016. - - The transaction has active Software Assurance or Upgrade Advantage coverage during the offer. - - Microsoft offers a promotion for one license of Skype for Business Server with a purchase of Exchange Server 2016. - - The License Grant is what entitles, or "grants," the customer to use the promotional product. In the example above, the customer is granted the use of Skype for Business Server. - - For more information about License Grants, see the [Microsoft Product Terms](https://www.microsoft.com/licensing/terms/welcome/welcomepage). - - - question: | - How can I see my License Grants? - answer: | - License Grants are reflected in the Contracts list and in Downloads & Keys. In the products list, products received from License Grants are shown with an asterisk (*) to indicate that they weren't part of the original purchase. - - - question: | - How can I contact Microsoft Support? - answer: | - To contact support by phone or by Web Form, see [Contact Us](/licensing/contact-us). Microsoft responds to Web Form submissions within 24 hours. diff --git a/microsoft-365/commerce/licenses/e3-extra-features-licenses.md b/microsoft-365/commerce/licenses/e3-extra-features-licenses.md index fcd6618b605..f50113694af 100644 --- a/microsoft-365/commerce/licenses/e3-extra-features-licenses.md +++ b/microsoft-365/commerce/licenses/e3-extra-features-licenses.md @@ -20,7 +20,7 @@ ms.custom: - original owners paprud, marketing search.appverid: MET150 description: "Learn about Microsoft 365 E3 and E5 Extra Features and how to assign licenses for it to your users." -ms.date: 04/07/2025 +ms.date: 04/13/2025 --- # Understand the Microsoft 365 E3 and E5 Extra Features license diff --git a/microsoft-365/commerce/licenses/manage-license-requests.md b/microsoft-365/commerce/licenses/manage-license-requests.md index 996158c2870..fcc0a1511e9 100644 --- a/microsoft-365/commerce/licenses/manage-license-requests.md +++ b/microsoft-365/commerce/licenses/manage-license-requests.md @@ -26,6 +26,7 @@ ms.custom: search.appverid: MET150 description: "Learn how to review and approve or deny license requests for products and services from users in the Microsoft 365 admin center." ms.date: 04/07/2025 +ROBOTS: NOINDEX, NOFOLLOW --- # Manage self-service license requests in the Microsoft 365 admin center @@ -86,9 +87,8 @@ When you return to the **Requests** list, you see the message **You're using you - A grayed-out option typically signifies that the security groups are either unlicensed or not yet configured. - For more information about how to assign licenses to a security group, see [Assign or unassign licenses to a group using the Microsoft 365 admin center](../../admin/manage/manage-group-licenses.md) - When multiple security groups are available, select the one to which you want to assign licenses. -7. In the text box at the bottom of the pane, type a message (optional). The user receives an email containing either the default message or your customized message. -8. When you're finished, select **Submit**. The details pane shows the details of the request. -9. Close the details pane. Users receive an email that says their request was approved or denied. +7. When you're finished, select **Submit**. The details pane shows the details of the request. +8. Close the details pane. Users receive an email that says their request was approved or denied. ## Share a license request by email @@ -101,7 +101,7 @@ If you don't have the authority within your organization to make decisions about 5. In the **Share license request details** pane, type an email address, then select the recipient name. > [!NOTE] > You can select more than one recipient, but if the email that you entered doesn't resolve into a user name, you can't share the request. -1. To personalize the email, select the **Include a personalized message** check box. Type a **Subject** and **Message** in the corresponding fields. +1. To personalize the email, select the **Include a personalized message** check box, then type a **Message**. 7. When you're finished, select **Share request**. ## Related content diff --git a/microsoft-365/commerce/licenses/online-service-activation-vl.md b/microsoft-365/commerce/licenses/online-service-activation-vl.md new file mode 100644 index 00000000000..8b51dbcb682 --- /dev/null +++ b/microsoft-365/commerce/licenses/online-service-activation-vl.md @@ -0,0 +1,243 @@ +--- +title: "Activate online services in volume licensing" +f1.keywords: NOCSH +author: cmcatee-MSFT +ms.author: cmcatee +manager: scotv +ms.reviewer: aasthatiwari, atuldubey +audience: Admin +ms.topic: how-to +ms.service: microsoft-365-business +ms.subservice: m365-commerce-volume-licensing +ms.collection: +- Tier1 +- scotvorg +ms.custom: +- commerce_vl +- AdminTemplateSet +search.appverid: MET150 +ms.localizationpriority: medium +description: "Learn how to activate online services obtained via volume licensing." +ms.date: 04/10/2025 +--- + +# Activate online services in volume licensing + +This article describes how to activate non-Azure Microsoft online services obtained via the following volume licensing (VL) agreement types: Enterprise, Enterprise Subscription, Enterprise Agreement (EA) for Government Partners (USG), and Campus and Schools. + +## Before you begin + +To view or activate Microsoft online services obtained via volume licensing, you must have one of the following VL roles: + +- VL Administrator, also known as online admin (OLA) +- Online Services Manager (OSM) + +For more information about VL roles in the Microsoft 365 admin center, see [Understand volume licensing roles](manage-user-roles-vl.md#understand-volume-licensing-roles). + +## Definitions of key terms + +To help you understand this article, this section contains a list of key terms and their definitions. + +### License ID + +Each signed VL agreement has a unique License ID associated with it. Microsoft uses the License ID to identify a specific VL agreement for reference and support purposes. + +### Microsoft Entra tenant + +Every organization that subscribes to Microsoft online services must have a Microsoft Entra tenant. For more information, see [Quickstart - Access and create new tenant - Microsoft Entra | Microsoft Learn](/entra/fundamentals/create-new-tenant). + +### Global administrator + +By default, the person who sets up the Microsoft Entra tenant becomes the Global Administrator and can add other Global Administrators. The Global Administrator assigns subscription licenses to users and administers Microsoft online services in the tenant. + +> [!CAUTION] +> Global Administrators have almost unlimited access to your organization's settings and most of its data. To help keep your organization secure, we recommend that you limit the number of Global Administrators as much as possible. + +### Online Services Manager + +The Online Services Manager (OSM) is a VL user with permission to view orders for online services. The OSM is the person invited to assign those services to a Microsoft Entra tenant. + +When you assign the OSM role to someone who also has the Global Administrator role, you enable them to see what online services were ordered. This view is in addition to their Global Admin view of end user subscription assignment. + +> [!IMPORTANT] +> Microsoft Entra tenant roles are separate from VL roles in the Microsoft 365 admin center. By default, Global Administrators don't have VL access or roles. For more information, see [Assign roles to volume licensing users](manage-user-roles-vl.md#understand-volume-licensing-roles). + +### Public Customer Number + +Every organization with a VL agreement with Microsoft has at least one Public Customer Number (PCN). Some organizations have multiple unique PCNs for different VL agreements. + +## Subscribe to Microsoft online services via volume licensing + +If there are no licenses for any Microsoft online services under your License ID, ask your Microsoft seller or partner to order the services for you. + +Alternatively, Enterprise, Enterprise Subscription, and US Government (USG) customers can get started immediately for many online services by placing a VL reservation. To learn more about VL reservations, see [Manage License Reservations for volume licensing](manage-license-reservations-vl.md). + +After the first online services order or a reservation is processed for a License ID, Microsoft either automatically assigns the services to your organization's tenant or invites the OSM to sign up for an online services account profile. + +## Automatic assignment of online services via volume licensing + +Online services ordered via VL are automatically provisioned to an organization's Microsoft Entra tenant if one or more of the following conditions are met: + +- The OSM email address associated with the License ID is either a Global Administrator or Billing Administrator of an existing tenant. +- Online services previously ordered on the License ID are already activated. +- The PCN provided on a renewal contract previously had online services assigned. + +## Find the Microsoft Entra tenant your services are activated on + +VL users can see what tenant their License ID contains activated online services by going to the Microsoft 365 admin center > **Billing** > **Your products** > **Volume licensing** > **Contracts** > **View contract details** page. + +- If the License ID is activated on a tenant, the tenant domain is displayed. +- If the License ID isn't activated on a tenant, a message indicates that online services aren't activated. + +## Invitation to activate an online service profile + +If no Microsoft Entra tenant is detected and automatic assignment isn't possible, Microsoft sends an online service activation email to ask you to complete an online services account profile. The email contains the subject line "Complete your profile to set up your services." The email is sent to the OSM on the License ID when the first order or reservation for an online service is placed. For contracts without an OSM, the invitation is sent to the Notice Contact or Online Administrator. + +You're presented with two options: + +1. Create a new online services profile (Microsoft Entra tenant) to assign the services to.\ +OR +2. Sign into an existing tenant and assign the services there. + +For troubleshooting help, see [Common reasons why you might not receive an activation email](#common-reasons-why-you-might-not-receive-an-activation-email). + +## Sign up to create an online services account for your organization + +If your organization has no Microsoft online service subscriptions, or if you need to associate the subscriptions to a new Microsoft Entra ID, use the following steps: + +1. Have the OSM locate the online services activation email from Microsoft that contains the subject line "Action required: Complete your profile to set up your services." + + > [!NOTE] + > OSMs might prefer to forward the online services activation email to their IT administrator to complete the sign-up process and become the organization's online services Global Administrator. + +2. To avoid unintentionally assigning services to a Microsoft online service account that's already in use, we recommend that you take the following steps before selecting any links in the email: + + - Sign out of other Microsoft services (like Microsoft 365 email) that you use. + - Close all your open browser windows. + - Copy and paste the link from the email into a private browser window. + +3. In the activation email, go to the option "My organization does not use any Microsoft services" and select **Register for a new work or school account**. +4. Provide the information required to create a new account profile (Microsoft Entra tenant) for your organization. +5. After you save the new account profile, all online services ordered under this License ID are automatically assigned to the tenant (see assignment section). For more information, see [Assign online services to volume licensing users](#assign-online-services-to-volume-licensing-users). + +## Your organization already uses Microsoft online services + +If your organization already uses Microsoft online services from a paid or trial subscription, it already has a Microsoft Entra tenant. The Global Administrator can sign in and activate online services ordered under this License ID. + +> [!NOTE] +> OSMs without Global Administrator permissions must forward the online services activation email to their Global Administrator. + +1. Read the instructions in the activation email for option 1, "My organization already uses Microsoft services." +2. To avoid unintentionally assigning services to a Microsoft online service account that's already in use, we recommend that you take the following steps before selecting any links in the email: + + - Sign out of other Microsoft services (like Microsoft 365 email) that you use. + - Close all your open browser windows. + - Copy and paste the link from the email into a private browser window. + +3. To assign the online subscriptions and any future orders under this License ID to the Microsoft Entra tenant, sign in with your existing Microsoft Entra ID account. + +## Common reasons why you might not receive an activation email + +This section contains information about why you might not receive an activation email. + +### The service activation email was sent, but not received + +- You aren't the OSM for the License ID. +- The email was blocked by your inbox settings or went to your junk mail folder. + +### No service activation email could be sent + +- The OSM contact information isn't configured to receive emails. For example, user\@contoso.onmicrosoft.com has no email subscription. +- The OSM email address is in a public domain like outlook.com or gmail.com, not an organization's email domain. +- It's more than 48 hours before the licensed usage period start date. To see the usage date, in the Microsoft 365 admin center, go to the **Billing** > **Your products** > **Volume licensing** > **Contracts** > **View order details** page. +- Your Microsoft partner or seller hasn't yet placed an order. To check the order status, in the Microsoft 365 admin center, go to **Billing** > **Your products** > **Volume licensing** > **Contracts** > **View Orders** or **View license summary**. +- Your OSM hasn't yet placed a License Reservation. To check reservations, in the Microsoft 365 admin center, go to **Billing** > **Your products** > **Volume licensing** > **View reservations**. + +### Online services were automatically assigned + +- The OSM email address is on record as an existing Global Administrator or Billing Administrator. +- Service activation was already completed following a previous order. No other emails are sent. + +## Assign online services to volume licensing users + +After online services obtained via VL are activated on your organization's Microsoft Entra tenant, the Global Administrator must assign the newly purchased licenses to individual users. OSMs without Global Administrator permission must inform the Global Administrator that newly purchased services are now available and can be assigned. + +> [!NOTE] +> License assignment permissions are separate from VL permissions and are managed on different pages in the Microsoft 365 admin center. + +- VL users can view VL orders or license reservations in the **Billing** > **Your products** > **Volume licensing** area. +- Licenses are assigned to individual users by Global Administrators or Billing Administrators on the **Billing** > **Licenses** page. For more information, see [Assign or unassign licenses for users in the Microsoft 365 admin center](../../admin/manage/assign-licenses-to-users.md). + +### Subscription licenses aren't available to Global Administrators to assign + +The following list contains some common reasons why you might not see licenses available to assign: + +- It can take up to 24 hours from the start of the licensed usage date on the order or license reservation for services to become available. +- Add-on subscriptions don't display if they aren't ordered on the same License ID as the base subscription. To resolve this scenario, contact your Microsoft partner or seller. +- There are subscriptions on the existing account which aren't compatible with the subscriptions you now want to activate. For assistance, [contact volume licensing support](/licensing/contact-us). +- The licenses were activated on the wrong Microsoft Entra tenant account. For assistance, [contact volume licensing support](/licensing/contact-us). +- The service isn't available in the location where the Microsoft Entra ID account is set up. To resolve this scenario, contact your Microsoft partner or seller. + +## Renew online services via volume licensing + +This section contains information about what happens when you renew online services. + +### Activating services after volume licensing renewal + +For most renewals, online services are automatically assigned to the Microsoft Entra tenant, and no service activation email is sent. + +Auto assignments happen when your Microsoft partner or seller uses the same Public Customer Number (PCN) on your renewal contracts. If a different PCN was used, auto assignment isn't possible, and a service activation email is sent to the OSM. + +VL admins can verify the PCN on a particular licensing ID by going to Microsoft 365 admin center > **Your products** > **Volume licensing** > **Contracts** > **View contract details**. + +### Assign services to users when licenses are renewed + +After a VL contract is renewed, the Global Administrator must sign in to the admin center to verify the licenses are available to assign. + +- If you renewed with the same subscriptions, the licenses are automatically assigned to their users. +- If you switched subscriptions when you renewed (like from E3 to E5), the Global Administrator must assign the licenses for the new subscription to users. If licenses aren't assigned to users, they'll lose access to their services after the grace period expires. + +## Upon renewal, the number of services is temporarily doubled + +The renewal process can cause temporary discrepancies between the number of licenses ordered and the number of licenses available to assign in the Microsoft 365 admin center. + +When online subscriptions ordered under one License ID are renewed on another License ID, subscriptions ordered on the original License ID display with a status of **In Grace**, while the subscriptions ordered under the new license ID display with a status of **Active**. Only licenses with the **Active** status are relevant to your licensed quantity. + +After a certain period, subscriptions with the **In Grace** status are automatically removed from the account and the data is deleted. For detailed information about status durations, see "Lifecycle status durations for volume licensing customers" in [Lifecycle status durations for volume licensing customers](../subscriptions/what-if-my-subscription-expires.md#lifecycle-status-durations-for-volume-licensing-customers). + +## Map License IDs to tenants + +This section contains information about mapping License IDs to tenants, how to assign licenses to multiple tenants, and what to do if you activated licenses on the wrong tenant. + +### Assign multiple License IDs to the same Microsoft Entra tenant + +You can assign multiple License IDs to one tenant, but you can't associate one License ID to more than one tenant. + +For example, you can assign License ID 1234 and License ID 56789 to tenant contoso.com. However, you can't assign License ID 12345 to both contoso.com and fabrikam.com if they belong to separate tenants. + +### Separate License IDs and PCNs required to assign licenses to multiple tenants + +To determine if the necessary VL agreement structure is in place, contact your Microsoft partner or seller. + +### Licenses were activated on the wrong online services account (tenant) + +If you clicked an activation link in the service activation email while signed in to an existing Microsoft service, the licenses might be activated on the wrong tenant. This activation can also happen if you didn't realize the licenses would meet the criteria for automatic licenses assignment. + +Global Administrators can't move licenses from one Microsoft Entra tenant to another. [Contact support](/licensing/contact-us) to get help with a *tenant remap*. A tenant remap involves moving all subscriptions and License IDs associated with a PCN to a new organizational account that you provide. When a tenant remap occurs, no user data is migrated. Global Administrators might have to complete subscription management tasks after the licenses become available on the correct tenant. + +To ensure that support can quickly solve the incorrect activation issue, when you open the case, you must provide the following information: + +- License ID or enrollment number +- Incorrect Organizational Account (xxx.onmicrosoft.com) +- Correct Organizational Account (xxx.onmicrosoft.com) +- If possible, contact details of the Global Administrators from both Organizational Accounts + +## Contact volume licensing support + +Submit a case in the admin center > Help & Support. If you can't access the admin center, see [Contacting volume licensing support](/licensing/contact-us). + +## Other resources + +For activation of Azure purchased in Enterprise volume licensing, see [EA Billing administration on the Azure portal - Microsoft Cost Management | Microsoft Learn](/azure/cost-management-billing/manage/direct-ea-administration). + +For more information about assigning licenses to end users, see [Microsoft 365 admin center - Overview - Microsoft 365 admin | Microsoft Learn](/microsoft-365/admin/admin-overview/admin-center-overview). diff --git a/microsoft-365/commerce/licenses/view-vl-contracts.md b/microsoft-365/commerce/licenses/view-vl-contracts.md new file mode 100644 index 00000000000..391ee839ed5 --- /dev/null +++ b/microsoft-365/commerce/licenses/view-vl-contracts.md @@ -0,0 +1,235 @@ +--- +title: "View volume licensing contracts in the Microsoft 365 admin center" +f1.keywords: +- CSH +author: cmcatee-MSFT +ms.author: cmcatee +manager: scotv +ms.reviewer: aasthatiwari, atuldubey +audience: Admin +ms.topic: how-to +ms.service: microsoft-365-business +ms.subservice: m365-commerce-volume-licensing +ms.collection: +- Tier1 +- scotvorg +ms.custom: +- commerce_vl +- AdminTemplateSet +search.appverid: MET150 +ms.localizationpriority: medium +description: "Learn how to find and get detailed information about your volume licensing contracts in the Microsoft 365 admin center." +ms.date: 04/22/2025 +--- + +# View volume licensing contracts in the Microsoft 365 admin center + +If you're a named volume licensing (VL) contact or have a VL role, you can view the Contracts page in the Microsoft 365 admin center. This page lists VL contracts you have permission for, with links to view license summaries, order details, and product keys. You can also see which users have roles for each License ID. + +> [!NOTE] +> Each signed VL agreement has a unique License ID associated with it. Microsoft uses the License ID to identify a specific VL agreement for reference and support purposes. + +## Before you begin + +To see the VL **Contracts** page you must meet either of the following requirements: + +- You're a named contact (sometimes referred to as "legal participant") on the VL agreement at the time of contract creation. +- You were assigned a VL role in the Microsoft 365 admin center. + +> [!IMPORTANT] +> If you're a VL Administrator of a Parent Agreement or Microsoft Business and Services Agreement (MBSA), due to the principle of administrator inheritance, you see all License IDs under that parent or MBSA. + +## View the Contracts page + +The **Contracts** page displays License IDs and other information. This information is typically available within 10 hours after Microsoft receives an order from your Microsoft partner or seller. You can sort by the agreement end date, change the default filters settings, create a license summary, and export the list as a downloadable .CSV file. + +The default list view on the **Contracts** page displays all License IDs you have access to, sorted by the closest agreement coverage **End date**. + +1. Go to the Microsoft 365 admin center. +2. In the **Navigation** pane, select **Billing** > **Your products**, then select the **Volume licensing** tab. +3. In the **Contracts** section, select **View contracts**. + +> [!TIP] +> If you don't see License IDs or related license entitlement data on the **Contracts** page, go to the **Your products** page and select the **Volume licenses** tab. In the **Preferences** section, select **Edit preferences**, then select **Sync Permissions**. + +The following table describes the columns displayed on the **Contracts** page: + +|Column name |Description | +|---------|---------| +|License ID |The ID of the contract-level agreement where products and services, like Enterprise Enrollment, are ordered, or the parent-level contract, like Enterprise Agreement, that it's part of is ordered. | +|Organization |The licensed customer organization named on the contract. | +|Location |The combination of city and country/region of the licensed organization. | +|Parent Program |The higher-level agreement that your License ID is linked to, like an Enterprise Agreement, a Select Plus Agreement, or a Microsoft Business and Services Agreement (MBSA). | +|End date |The end date of the license and any Software Assurance (SA) coverage. | +|Status |The status of the License ID and any SA benefits or subscriptions. | +|Volume licensing roles |The VL roles with access to the contracts. | + +## View the license summary + +The **License summary** page displays real-time VL entitlements grouped by Microsoft product family and version for all License IDs you have permission to view. The page includes purchase information related to traditional Microsoft VL programs including Open License, Open Value, Open Value Subscription, Select, Select Plus, Enterprise, and Enterprise Subscription. + +Licenses display in the license summary at the start of the licensed coverage period stated on the order. + +> [!NOTE] +> Licenses purchased under the Microsoft Products and Services Agreement (MPSA) program aren't included in a license summary. + +1. Go to the admin center. +2. In the **Navigation** pane, select **Billing** > **Your products**, then select the **Volume licensing** tab. +3. In the **Contracts** section, select **View contracts**. +4. On the **Contracts** page, select the check boxes next to the License IDs you want to include in the summary. +5. At the top of the page, select **Create License Summary**, or select the three dots (**More actions** button) next to a License ID and select **View license summary**. + + > [!NOTE] + > It can take a few minutes to create the license summary, but you can go to other parts of the admin center while you wait. + +6. When the summary is ready, you see a message that says "Your license summary is ready. Please click on the button to view the summary." To view the summary, select the **License Summary** button. + +## View orders + +The **Order details** page displays a list of purchase orders for the selected License IDs. The orders list can be exported to a CSV downloadable file, sorted by clicking column headers, or filtered using predefined filters to narrow your search. + +1. Go to the admin center. +2. In the **Navigation** pane, select **Billing** > **Your products**, then select the **Volume licensing** tab. +3. In the **Contracts** section, select **View contracts**. +4. On the **Contracts** page, next to a License ID, select the three dots (**More actions** button), then select **View orders**. + +The following table describes the columns displayed on the **Orders details** page: + +|Column name |Description | +|---------|---------| +|Reseller order number |The purchase order number used by your reseller when placing the order. | +|Customer order number |The order number, if one was provided, to Microsoft. | +|Ordered on |The date the seller submitted the order to Microsoft, which might be a different date from when the customer placed the order with the seller. | +|Usage start date |The date from when you can use the products or services you ordered. | +|Reseller |The name of the reseller who placed the order. | + +For a deeper view into the order details select any item in an order to see the following information: + +|Column name |Description | +|---------|---------| +|Part number |The number for the product or service. This number might not match the seller's part number, | +|Product description |A description of the product or service. | +|Quantity |The number of licenses ordered. | +|Country |The country/region where users of the service or product are based. | +|Up for Renewal* |The due date to renew the offering. Select Plus only. | +|Step-up* |Indicates if the product or service can be "stepped up" to higher editions. Select Plus only. | + +*There's no action that the VL user can perform in the Microsoft 365 admin center that relates to renewal or step -up orders. Instead, customers should speak with their Microsoft Partner or seller. + +### View order information for multiple license IDs + +1. Go to the admin center. +2. In the **Navigation** pane, select **Billing** > **Your products**, then select the **Volume licensing** tab. +3. In the **Transactions** section, select **View orders**. Each order line item includes the License ID the order belongs to. + +## View product keys + +The **Product keys** panel displays the available product keys for a particular contract. For each product, you see the following information: + +- The product name. +- The product key or a link to **Manage activations**. +- The type of licensing key. +- The number of used and available activations or seats. +- The status of the product key (Redeemed or Available). + +For more information, see [Find and use product keys for volume licensing | Microsoft Learn](product-keys-for-vl.md). + +1. Go to the admin center. +2. In the **Navigation** pane, select **Billing** > **Your product**s, then select the **Volume licensing** tab. +3. In the **Contracts** section, select **View contracts**. +4. On the **Contracts** page, next to a License ID, select the three dots (**More actions** button), then select **View product keys**. + +## View contract details + +The **Contract details** panel displays information about your License ID contract, like license type, agreement type, start date, and renewal end date. The panel also includes tabs with detailed information about **Offerings**, **Contacts**, and **Tenants** related to the contract. + +1. Go to the admin center. +2. In the **Navigation** pane, select **Billing** > **Your products**, then select the **Volume licensing** tab. +3. In the **Contracts** section, select **View contracts**. +4. On the **Contracts** page, next to a License ID, select the three dots (**More actions** button), then select **View contract details**. + +The tabs on **Contract details** panel contain detailed information for the following areas: + +|Tab name |Description | +|---------|---------| +|Offerings |Lists the types of products and services, including SA, available for purchase under the specific contract. | +|Contacts |The agreement participants (sometimes referred to as legal participants) submitted by your Microsoft Partner or seller at the time of contract creation. To make any changes to these contacts, contact your Microsoft Partner or seller.

**NOTE**
VL users who are given access after the contract creation aren't included in the contacts list. For more information, see [Manage volume licensing user roles \| Microsoft Learn](manage-user-roles-vl.md). | +|Tenants |The list of tenants where online services are activated or if the services need to be activated This only applies to Enterprise, Enterprise Subscription, Campus, Schools, and US Gov (USG). | + +## Find the Licensing Solution Partner for a volume licensing contract + +You can find your Licensing Solution Partner on the **Contacts** tab of the **Contract details** panel. You might have different License Solution Partners for different License IDs. + +If you want to find a new partner, go to [https://aka.ms/pinpoint](https://aka.ms/pinpoint), provide your location and organization size, and then search for either "volume licensing" or for a service or product you want a solution for. + +1. Go to the admin center. +2. In the **Navigation** pane, select **Billing** > ****Your products**, then select the Volume licensing** tab. +3. In the **Contracts** section, select **View contracts**. +4. On the **Contracts** page, select a specific License ID. +5. In the **Contract details** panel, select the **Contacts** tab. Your partner or seller is displayed in the list of contacts. + +> [!NOTE] +> The contact details displayed might only include the partner's organization name, so you might need to search for the organization's "contact us" details. Alternatively, your IT or Procurement departments might have specific contacts you can work with. + +## View license grants in contracts + +Occasionally, Microsoft Volume Licensing offers a promotion where the purchase of a specific product entitles the customer to the use of another product. This promotion is called a *license grant*. License grants appear in the **Contract details** panel and on the **Products and services** page. Products received from license grants have an asterisk (*) to indicate that they weren't part of the original purchase. + +## View MPSA licenses + +MPSA license information is displayed separately from other VL information in a site called the Microsoft Business Center. If you register an MPSA Purchase Account with the same account you use to access the Microsoft 365 admin center, you can view MPSA licenses, software downloads and keys, and other MPSA licensing functions on the admin center > **Billing** > **Your products** > **MPSA products** tab. + +## Understand the License summary page + +The **License summary** page displays the list of software your organization is entitled to install and use. However, the summary doesn't show product deployment details or status. The following table describes the columns displayed on the **License summary** page. + +|Column name |Description | +|---------|---------| +|Product family |A group of related Microsoft products categorized together based on their functionality or purpose. | +|Version |The product version refers to a specific iteration or release of a product within a product family. For example, the Windows product family includes different versions like Windows 10, Windows 11, and Windows Server 2022.

The version is distinct from the term *edition*, which refers to different functional offerings within a product family that are usually released at the same time. For example, Windows Server 2022 has different editions like Standard, Datacenter, and Datacenter: Azure Edition. | +|Product pool |Microsoft organizes products purchased via VL into three pools. These pools are used to determine volume discounts, help with VL key assignment, and activation rules and processes. These rules and processes can vary by product pool. A product pool can be one of the following:
  • Applications, like editions of Microsoft 365
  • Systems, like versions of the Windows operating system
  • Servers, like Exchange Server, Microsoft SQL Server, and Windows Server
| +|Type |License types include the following:
  • On-premise software
  • Online services and subscriptions
  • Subscriptions such as Visual Studio
| +|Effective quantity |The number of license entitlements per product and version with upgrades. This number is used to determine whether your organization has license shortfalls or surpluses by product and version. | +|Active SA quantity |The number of licenses covered by all types of SA (version upgrade protection) across all Microsoft VL programs, including:
  • License and Software Assurance (L&SA)
  • Software Assurance (SA)
  • SA Step-Up
| + +## Troubleshooting + +This section contains information about how to resolve common issues with VL contracts. + +### The License ID for your organization isn't displayed on the Contracts page + +- You might not be the VL Administrator on all your organization's License IDs. VL contracts might have been in place before you took on your VL Administrator role, or a different part of your organization might have its own License IDs under the one parent agreement. Ask an active VL Administrator of any such License IDs to add you as a VL Administrator. +- You might have registered under a different account for some License IDs. For example, your work email address changed, or you previously signed in to the VL area of the admin center with a different account used just for volume licensing. For more information, see [Sign in to the Microsoft 365 admin center (volume licensing)](vl-sign-in.md). +- The **Show inherited contracts** toggle in your preferences is set to not include all License IDs under a Parent agreement you administer. For more information, see [Manage volume licensing user roles | Microsoft Learn](manage-user-roles-vl.md). +- Licenses purchased via a Microsoft Product and Services Agreement (MPSA), Cloud Service Provider (CSP), Modern Customer Agreement (MCA), Original Equipment Manufacturer (OEM), or retail purchases aren't included in VL contracts. + +### Organization not approved + +If you see the message "Organization not approved," it means your organization isn't yet ready to use Microsoft products and services because the review is incomplete. Until the review is complete, the License ID isn't displayed on the **Contracts** page, and you can't access software downloads or VL keys, or manage user access to the contract. To contact our support team, see [Contact volume licensing support](#contact-volume-licensing-support). + +### The Effective Quantity or Active SA Quantity is zero + +- If the Effective Quantity is zero, it means that your organization isn't entitled to use the license under the terms of the set of License IDs selected for the generated license summary. +- If the Active SA Quantity is zero, it means that the licenses under the set of License IDs used to generate the license summary don't have any valid or active SA coverage. + +> [!NOTE] +> Online services don't have SA, so the Active SA Quantity is always zero. + +### There are more upgrade licenses than the number of qualifying full licenses + +If you have more upgrade license than underlying base licenses displayed in the License summary, this can happen for several reasons: + +- Full licenses acquired through OEM or Retail purchases aren't visible in the VL pages of the Microsoft 365 admin center. +- Licenses might have been ordered separately from their underlying base license, like Maintenance, Upgrade Advantage, or Software Assurance. +- You might not have a complete list of License IDs. You might have acquired full licenses under License IDs you don't have permission to view. +- Licenses purchased in a recent order with your Microsoft partner might not yet be processed by the Microsoft Partner. + +### Contact volume licensing support + +Submit a case in the admin center > Help & Support. If you're unable to access the admin center, see [Contacting volume licensing support](/licensing/contact-us). + +## Related content + +[Sign in to the Microsoft 365 admin center (volume licensing)](vl-sign-in.md)
+[Manage volume licensing user roles | Microsoft Learn](manage-user-roles-vl.md)
+[Find and use product keys for volume licensing | Microsoft Learn](product-keys-for-vl.md) diff --git a/microsoft-365/commerce/licenses/vl-sign-in.md b/microsoft-365/commerce/licenses/vl-sign-in.md index 9f4263596c4..4231eee60b7 100644 --- a/microsoft-365/commerce/licenses/vl-sign-in.md +++ b/microsoft-365/commerce/licenses/vl-sign-in.md @@ -134,7 +134,8 @@ If you don't see the Microsoft 365 admin center. +As a user, you can acquire free trials or buy subscriptions to certain products and assign licenses for those subscriptions to people in your team. You're responsible for paying for any self-service purchases you make. You can manage your subscriptions in the Microsoft 365 admin center. [!INCLUDE [O365 21Vianet admin center link](../../includes/office-365-operated-by-21vianet-admin-center-link.md)] @@ -35,7 +35,7 @@ Your admin has a read-only view into any subscriptions that you buy. They can se ## View your subscriptions -You can view a list of all self-service purchased subscriptions that you bought. +You can view a list of all your self-service free trials and purchased subscriptions. 1. Go to the Microsoft 365 admin center, then go to the **Billing** > Your products page. 2. On the **Products** tab, select the filter icon, then select **Self-service**. diff --git a/microsoft-365/commerce/toc.yml b/microsoft-365/commerce/toc.yml index 312e1e9c74d..17f6c07888d 100644 --- a/microsoft-365/commerce/toc.yml +++ b/microsoft-365/commerce/toc.yml @@ -56,8 +56,8 @@ items: href: licenses/vl-sign-in.md - name: Sign your volume licensing agreement href: licenses/sign-vl-agreement.md - - name: Contracts FAQs - href: licenses/contracts-faq.yml + - name: View volume licensing contracts + href: licenses/view-vl-contracts.md - name: Manage volume licensing user roles href: licenses/manage-user-roles-vl.md - name: Download volume licensing products @@ -66,7 +66,9 @@ items: href: licenses/product-keys-for-vl.md - name: Manage License Reservations href: licenses/manage-license-reservations-vl.md - - name: Online service activation FAQ + - name: Activate online services + href: licenses/online-service-activation-vl.md + - name: Online service activation for Open programs href: licenses/online-service-activation-faq.yml - name: Volume licensing invoices href: licenses/volume-licensing-invoices.md diff --git a/microsoft-365/enterprise/administering-a-multi-geo-environment.md b/microsoft-365/enterprise/administering-a-multi-geo-environment.md index f01829427fb..470095ee7e0 100644 --- a/microsoft-365/enterprise/administering-a-multi-geo-environment.md +++ b/microsoft-365/enterprise/administering-a-multi-geo-environment.md @@ -40,13 +40,13 @@ BCS, Secure Store, and Apps all have separate instances in each satellite locati ## Compliance admin center -There's one central Microsoft Purview compliance portal for a Multi-Geo _Tenant_: [Microsoft Purview admin center](https://compliance.microsoft.com/). +There's one central Microsoft Purview portal for a Multi-Geo _Tenant_: [Microsoft Purview portal](https://purview.microsoft.com/). ## eDiscovery By default, an eDiscovery Manager or Administrator of a Multi-Geo _Tenant_ will be able to conduct eDiscovery tasks only in the _Primary Provisioned Geography_ of that _Tenant_. A member of the **Organization Management** role group or a user with the **Role Management** role must assign eDiscovery Manager permissions in the Microsoft Purview portal to allow others to perform eDiscovery tasks and assign a "Region" parameter in their applicable Compliance Security Filter to specify the _Geography_ for conducting eDiscovery as _Satellite Geography_ location. Otherwise, no eDiscovery activities will be carried out for the _Satellite Geography_ location. Only one "Region" security filter per user is supported. -See [Assign eDiscovery permissions in the compliance portal](/purview/ediscovery-assign-permissions#before-you-assign-permissions) for more information. To configure the Compliance Security Filter for a Region, see [Configure Office 365 Multi-Geo eDiscovery](multi-geo-ediscovery-configuration.md). +See [Assign eDiscovery permissions in the Microsoft Purview portal](/purview/ediscovery-assign-permissions#before-you-assign-permissions) for more information. To configure the Compliance Security Filter for a Region, see [Configure Office 365 Multi-Geo eDiscovery](multi-geo-ediscovery-configuration.md). ## Exchange Online mailboxes diff --git a/microsoft-365/enterprise/cloud-microsoft-domain.md b/microsoft-365/enterprise/cloud-microsoft-domain.md index 85fca73c9ef..bdffc4262ed 100644 --- a/microsoft-365/enterprise/cloud-microsoft-domain.md +++ b/microsoft-365/enterprise/cloud-microsoft-domain.md @@ -4,7 +4,7 @@ description: Describes the new cloud.microsoft domain for Microsoft 365 apps ms.author: kvice author: kelleyvice-msft manager: scotv -ms.date: 01/13/2025 +ms.date: 04/09/2025 ms.topic: overview ms.service: microsoft-365-enterprise ms.subservice: network @@ -27,6 +27,8 @@ The growth of Microsoft cloud services led to the expansion of the domain space The `.microsoft` top-level domain is exclusive to Microsoft. The new domain doesn’t have traditional suffixes such as `.com` or `.net` in the end. This is by design. `cloud.microsoft` resides under the `.microsoft` top-level domain, for which Microsoft is a registry operator and the sole registrant. This domain allows for extra security, privacy, and protection against spoofing when you interact with apps within that domain. You can trust that any website or app that ends with `cloud.microsoft` is an official Microsoft product or service. +Some Microsoft 365 products that are already using the `cloud.microsoft` domain include Microsoft 365 Copilot Chat, Word, Excel, PowerPoint, Outlook, OneNote, Planner, Microsoft Loop, Mesh, Viva Engage, Viva Insights, Viva Learning, Viva Pulse, and more. These are just some examples, and over time you will see even more Microsoft 365 product experiences to be delivered from the `cloud.microsoft` domain. + ## Benefits of a unified domain Consolidating authenticated user-facing Microsoft 365 experiences to a single domain benefits customer in several ways. For end users, it streamlines the overall experience by reducing sign-ins, redirects, and delays when navigating across apps. For admins, it reduces the complexity of allowlists that are required to connect to Microsoft 365 services and help your organization stay secure and productive. For all our customers – and our developers – this change helps align for better and tighter integration across the Microsoft 365 ecosystem by streamlining development and improving performance of cross-app experiences. @@ -35,40 +37,13 @@ Consolidating authenticated user-facing Microsoft 365 experiences to a single do ## Security considerations -To ensure that customers and users can treat everything under the *.cloud.microsoft domain as fully trusted, the entire domain hierarchy is isolated, purpose built, and dedicated to hosting only secure and compliant Microsoft product experiences. The domain is managed to the highest standards of domain security and reputation, and is kept free of scenarios such as third-party websites, IaaS/PaaS resources (such as file and blob storage), and hosting of active content, code or scripts that may affect the trust and integrity of products and applications residing in the domain. +To ensure that customers and users can treat everything under the `*.cloud.microsoft` domain as fully trusted, the entire domain hierarchy is isolated, purpose built, and dedicated to hosting only secure and compliant Microsoft product experiences. The domain is managed to the highest standards of domain security and reputation, and is kept free of scenarios such as third-party websites, IaaS/PaaS resources (such as file and blob storage), and hosting of active content, code, or scripts that might affect the trust and integrity of products and applications residing in the domain. -The `.microsoft` gTLD is on the HTTP Strict-Transport-Security preload list in all popular browsers, meaning that all non-secure HTTP requests are automatically upgraded to use HTTPS, and users are blocked from overriding certificate errors that could indicate an active network attacker is attempting to compromise the security of the connection. All *.cloud.microsoft subdomains inherit this protection. +The `.microsoft` gTLD (Generic Top-Level Domain) is on the HTTP Strict-Transport-Security preload list in all popular browsers, meaning that all nonsecure HTTP requests are automatically upgraded to use HTTPS, and users are blocked from overriding certificate errors that could indicate an active network attacker is attempting to compromise the security of the connection. All `*.cloud.microsoft` subdomains inherit this protection. ## Requirements for admins -Since 2023, *.cloud.microsoft and other domains related to the domain unification initiative are part of the [Microsoft 365 network guidance on domains and service endpoints](/microsoft-365/enterprise/urls-and-ip-address-ranges). Customers who use the Microsoft 365 web service API to automate network settings have been getting the network settings since then. Customers who manually update endpoints should ensure that *.cloud.microsoft and other required domains are included in their allow-list to prevent connectivity and service incidents for their users.  - -## Microsoft product and service URLs -| Service | URL | -|:-----|:-----| -|Microsoft 365 |[m365.cloud.microsoft](https://m365.cloud.microsoft)| -|Microsoft 365 Copilot Chat |[m365.cloud.microsoft/chat](https://m365.cloud.microsoft/chat)| -|Microsoft Excel | [excel.cloud.microsoft](https://excel.cloud.microsoft)| -|Microsoft PowerPoint | [powerpoint.cloud.microsoft](https://powerpoint.cloud.microsoft)| -|Microsoft Word | [word.cloud.microsoft](https://word.cloud.microsoft)| -|Microsoft Outlook | [outlook.cloud.microsoft](https://outlook.cloud.microsoft)| -|Microsoft 365 Service Health Status Page |[status.cloud.microsoft](https://status.cloud.microsoft)| -|Microsoft Admin Center| [admin.cloud.microsoft](https://admin.cloud.microsoft)| -|Microsoft Loop | [loop.cloud.microsoft](https://loop.cloud.microsoft)| -|Microsoft Mesh | [mesh.cloud.microsoft](https://mesh.cloud.microsoft)| -|Microsoft OneNote | [onenote.cloud.microsoft](https://onenote.cloud.microsoft)| -|Microsoft Places | [places.cloud.microsoft](https://places.cloud.microsoft)| -|Microsoft Planner | [planner.cloud.microsoft](https://planner.cloud.microsoft)| -|Microsoft Setup | [setup.cloud.microsoft](https://setup.cloud.microsoft)| -|Microsoft Sway | [sway.cloud.microsoft](https://sway.cloud.microsoft)| -|Microsoft Viva Engage | [engage.cloud.microsoft](https://engage.cloud.microsoft)| -|Microsoft Viva Goals | [goals.cloud.microsoft](https://goals.cloud.microsoft)| -|Microsoft Viva Home | [viva.cloud.microsoft](https://viva.cloud.microsoft)| -|Microsoft Viva Insights | [insights.cloud.microsoft](https://insights.cloud.microsoft)| -|Microsoft Viva Learning | [learning.cloud.microsoft](https://learning.cloud.microsoft)| -|Microsoft Viva Pulse | [pulse.cloud.microsoft](https://pulse.cloud.microsoft)| - -The above list provides examples of individual URLs for applications that users can use through the web browser. It does not represent the full set of endpoints required for functionality of these applications and should not be used to granularly control access through network allow-lists and other network settings. To configure network settings, customers should follow Microsoft official network guidance. +Since 2023, `*.cloud.microsoft` and other domains related to the domain unification initiative are part of the [Microsoft 365 network guidance on domains and service endpoints](/microsoft-365/enterprise/urls-and-ip-address-ranges). Customers who use the Microsoft 365 web service API to automate network settings have been getting the network settings since then. Customers who manually update endpoints should ensure that `*.cloud.microsoft` and other required domains are included in their allowlist to prevent connectivity and service incidents for their users.  ## See also diff --git a/microsoft-365/enterprise/configure-exchange-server-for-hybrid-modern-authentication.md b/microsoft-365/enterprise/configure-exchange-server-for-hybrid-modern-authentication.md index 4c8f67d6efe..6ab59de508e 100644 --- a/microsoft-365/enterprise/configure-exchange-server-for-hybrid-modern-authentication.md +++ b/microsoft-365/enterprise/configure-exchange-server-for-hybrid-modern-authentication.md @@ -130,16 +130,17 @@ Run the commands that assign your on-premises web service URLs as Microsoft Entr Get-MgServicePrincipal -Filter "AppId eq '00000002-0000-0ff1-ce00-000000000000'" | select -ExpandProperty ServicePrincipalNames ``` - Note down the output of this command, which should include an `https://*autodiscover.yourdomain.com*` and `https://*mail.yourdomain.com*` URL, but mostly consist of SPNs that begin with `00000002-0000-0ff1-ce00-000000000000/`. If there are `https://` URLs from your on-premises that are missing, those specific records should be added to this list. + Take note of (and screenshot for later comparison) the output of this command, which should include an `https://*autodiscover.yourdomain.com*` and `https://*mail.yourdomain.com*` URL, but mostly consist of SPNs that begin with `00000002-0000-0ff1-ce00-000000000000/`. If there are `https://` URLs from your on-premises Exchange Server organization that are missing, those specific records should be added to this list. -5. If you don't see your internal and external `MAPI/HTTP`, `EWS`, `ActiveSync`, `OAB`, and `AutoDiscover` records in this list, you must add them. Use the following command to add all URLs that are missing. In our example, the URLs that are added are `mail.corp.contoso.com` and `owa.contoso.com`. Make sure that they're replaced by the URLs that are configured in your environment. +5. If you don't see your internal and external MAPI/HTTP, EWS, ActiveSync, OAB, and Autodiscover records in this list, you must add them using the command below (the example URLs are `mail.corp.contoso.com` and `owa.contoso.com`, but you'd **replace the example URLs with your own**). Ensure that the generic AutoDiscover record for your domain (for example `autodiscover.contoso.com`) is included as well: ```powershell - $x = Get-MgServicePrincipal -Filter "AppId eq '00000002-0000-0ff1-ce00-000000000000'" - $x.ServicePrincipalNames += "https://mail.corp.contoso.com/" - $x.ServicePrincipalNames += "https://owa.contoso.com/" - Update-MgServicePrincipal -ServicePrincipalId $x.Id -ServicePrincipalNames $x.ServicePrincipalNames - ``` + $x= Get-MsolServicePrincipal -AppPrincipalId 00000002-0000-0ff1-ce00-000000000000 + $x.ServicePrincipalnames.Add("https://mail.corp.contoso.com/") + $x.ServicePrincipalnames.Add("https://owa.contoso.com/") + $x.ServicePrincipalnames.Add("https://autodiscover.contoso.com/") + Set-MSOLServicePrincipal -AppPrincipalId 00000002-0000-0ff1-ce00-000000000000 -ServicePrincipalNames $x.ServicePrincipalNames + ``` 6. Verify that your new records were added by running the `Get-MgServicePrincipal` command from step 4 again, and validate the output. Compare the list from before to the new list of SPNs. You might also note down the new list for your records. If you're successful, you should see the two new URLs in the list. Going by our example, the list of SPNs now includes the specific URLs `https://mail.corp.contoso.com` and `https://owa.contoso.com`. diff --git a/microsoft-365/enterprise/cross-tenant-mailbox-migration.md b/microsoft-365/enterprise/cross-tenant-mailbox-migration.md index 253074abee1..483a8e35ce0 100644 --- a/microsoft-365/enterprise/cross-tenant-mailbox-migration.md +++ b/microsoft-365/enterprise/cross-tenant-mailbox-migration.md @@ -80,7 +80,7 @@ All users in both the source and target organizations must be licensed with the ### Prepare the target (destination) tenant by creating the migration application and secret -1. Sign in to your Microsoft Entra admin center () with your target tenant administrator credentials. +1. Sign in to your Microsoft Entra admin center () with your target tenant administrator credentials. ![Azure Logon](../media/tenant-to-tenant-mailbox-move/74f26681e12df3308c7823ee7d527587.png) diff --git a/microsoft-365/enterprise/cross-tenant-onedrive-migration-step1.md b/microsoft-365/enterprise/cross-tenant-onedrive-migration-step1.md index 1ee15a156ae..ed2a6f16b93 100644 --- a/microsoft-365/enterprise/cross-tenant-onedrive-migration-step1.md +++ b/microsoft-365/enterprise/cross-tenant-onedrive-migration-step1.md @@ -3,7 +3,7 @@ title: OneDrive Cross-tenant OneDrive migration Step 1 ms.author: heidip author: MicrosoftHeidi manager: jtremper -ms.date: 10/13/2023 +ms.date: 04/14/2025 recommendations: true audience: ITPro ms.topic: how-to @@ -14,8 +14,9 @@ ms.collection: - M365-collaboration - m365initiative-migratetom365 search.appverid: MET150 -description: "Step 1 of the OneDrive Cross-tenant migration feature" +description: "Step 1 of the OneDrive Cross-tenant migration feature." --- + # Step 1: Connect to the source and target tenants This article details Step 1 in a solution designed to complete a Cross-tenant OneDrive migration. To learn more, see [Cross-tenant OneDrive migration overview](cross-tenant-onedrive-migration.md). @@ -23,7 +24,7 @@ This article details Step 1 in a solution designed to complete a Cross-tenant On - **Step 1: [Connect to the source and the target tenants](cross-tenant-onedrive-migration-step1.md)** - Step 2: [Establish trust between the source and the target tenant](cross-tenant-onedrive-migration-step2.md) - Step 3: [Verify trust is established](cross-tenant-onedrive-migration-step3.md) -- Step 4: [Pre-create users and groups](cross-tenant-onedrive-migration-step4.md) +- Step 4: [Precreate users and groups](cross-tenant-onedrive-migration-step4.md) - Step 5: [Prepare identity mapping](cross-tenant-onedrive-migration-step5.md) - Step 6: [Start a Cross-tenant OneDrive migration](cross-tenant-onedrive-migration-step6.md) - Step 7: [Post migration steps](cross-tenant-onedrive-migration-step7.md) @@ -31,14 +32,14 @@ This article details Step 1 in a solution designed to complete a Cross-tenant On ## Before you begin - **Microsoft SharePoint Online Powershell**. Confirm you have the most recent version installed. If not, [Download SharePoint Online Management Shell from Official Microsoft Download Center](https://www.microsoft.com/download/details.aspx?id=35588). -- Be a SharePoint Online admin or Microsoft 365 Global admin on both the source and target tenants +- Be a SharePoint in Microsoft 365 admin or Microsoft 365 Global admin on both the source and target tenants. >[!IMPORTANT] >Microsoft recommends that you use roles with the fewest permissions. Using lower permissioned accounts helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role. ### Connect to both tenants -1. Sign in to the SharePoint Management Shell as a SharePoint Online admin or Microsoft 365 Global admin. +1. Sign in to the SharePoint Management Shell as a SharePoint in Microsoft 365 admin or Microsoft 365 Global admin. 2. Run the following entering the **source** tenant URL: ```powershell diff --git a/microsoft-365/enterprise/cross-tenant-onedrive-migration-step2.md b/microsoft-365/enterprise/cross-tenant-onedrive-migration-step2.md index 0d4fded5dff..8ab297c1f47 100644 --- a/microsoft-365/enterprise/cross-tenant-onedrive-migration-step2.md +++ b/microsoft-365/enterprise/cross-tenant-onedrive-migration-step2.md @@ -18,19 +18,19 @@ description: "Step 2 of the OneDrive Cross-tenant migration feature" --- # Step 2: Establishing trust between the source and target tenants -This is Step 2 in a solution designed to complete a Cross-tenant OneDrive migration. To learn more, see [Cross-tenant OneDrive migration overview](cross-tenant-onedrive-migration.md). +This article is Step 2 in a solution designed to complete a Cross-tenant OneDrive migration. To learn more, see [Cross-tenant OneDrive migration overview](cross-tenant-onedrive-migration.md). - Step 1: [Connect to the source and the target tenants](cross-tenant-onedrive-migration-step1.md) - **Step 2: [Establish trust between the source and the target tenant](cross-tenant-onedrive-migration-step2.md)** -- Step 3: [Verify trust has been established](cross-tenant-onedrive-migration-step3.md) +- Step 3: [Verify trust is established](cross-tenant-onedrive-migration-step3.md) - Step 4: [Precreate users and groups](cross-tenant-onedrive-migration-step4.md) - Step 5: [Prepare identity mapping](cross-tenant-onedrive-migration-step5.md) - Step 6: [Start a Cross-tenant OneDrive migration](cross-tenant-onedrive-migration-step6.md) - Step 7: [Post migration steps](cross-tenant-onedrive-migration-step7.md) -After connecting to the source and target tenant, the next step in performing a cross-tenant OneDrive migration is establishing trust between the tenants. +After you connect to the source and target tenant, the next step in performing a cross-tenant OneDrive migration is establishing trust between the tenants. -To establish trust, each SharePoint tenant administrator must run specific commands on both source and target tenants. Once the trust has been requested, the administrator of the target tenant will receive an email informing them that another tenant is trying to establish a trust relationship. +To establish trust, each SharePoint tenant administrator must run specific commands on both source and target tenants. Once the trust is requested, the administrator of the target tenant receives an email informing them that another tenant is trying to establish a trust relationship. > [!NOTE] > The "trust" command is specific to SharePoint. It only grants permission for the SharePoint administrator on the source tenant to execute OneDrive Migration operations to the identified target tenant. @@ -38,11 +38,11 @@ To establish trust, each SharePoint tenant administrator must run specific comma > Granting trust *doesn't* give the administrator any visibility, permission, or ability to collaborate between the source tenant and the target tenant. > [!IMPORTANT] -> If you are Microsoft 365 Multi-Geo customer, you must establish trust between each geography involved in your migration project. +> If you're a Microsoft 365 Multi-Geo customer, you must establish trust between each geography involved in your migration project. ## Before you begin -Before running the trust commands, obtain the cross-tenant host URLs for both the source and target tenants. You'll need these URLs when establishing the trust relationship between source-to-target and target-to-source. +Before running the trust commands, obtain the cross-tenant host URLs for both the source and target tenants. You need these URLs when establishing the trust relationship between source-to-target and target-to-source. **To obtain the cross-tenant host URLs:** @@ -54,11 +54,11 @@ Get-SPOCrossTenantHostURL *Example:* Run command on Source tenant: - :::image type="content" source="../media/cross-tenant-migration/t2t-onedrive-hosturl-source.png" alt-text="example of how to obtain host url for source"::: + :::image type="content" source="../media/cross-tenant-migration/t2t-onedrive-hosturl-source.png" alt-text="Screenshot of an example of how to obtain host url for a source, it shows the running of the Get-SPOCrossTenantHostURL, which returns a my.sharepoint.com URL in the example."::: *Example:* Run command on target tenant: -:::image type="content" source="../media/cross-tenant-migration/t2t-onedrive-hosturl-target.png" alt-text="example of how to obtain host url for target"::: +:::image type="content" source="../media/cross-tenant-migration/t2t-onedrive-hosturl-target.png" alt-text="Screenshot of an example of how to obtain host url for target it shows the running of the Get-SPOCrossTenantHostURL, which returns a my.sharepoint.com URL in the example."::: ## Run the trust commands @@ -78,19 +78,19 @@ These commands send a request to the tenant with whom you want to establish trus ### Parameter definitions -|Parameter|Definition| -|---|---| -|PartnerRole|Roles of the partner tenant you're establishing trust with. Use *source* if partner tenant is the source of the OneDrive migrations, and *target* if the partner tenant is the Destination. -|PartnerCrossTenantHostURL|The cross-tenant host URL of the partner tenant. The partner tenant can determine this for you by running: *Get-SPOCrossTenantHostURL* on each of the tenants.| +|Parameter |Definition | +|--------------------------|-----------| +|PartnerRole |Roles of the partner tenant you're establishing trust with. Use *source* if partner tenant is the source of the OneDrive migrations, and *target* if the partner tenant is the Destination. | +|PartnerCrossTenantHostURL |The cross-tenant host URL of the partner tenant. You can determine the URL by running: *Get-SPOCrossTenantHostURL* on each of the tenants.| ## Sample trust email -The following in an example of the email that is sent to global admins: +The following screenshot is an example of the email sent to global admins: -:::image type="content" source="../media/cross-tenant-migration/t2t-onedrive-trust-email.png" alt-text="example of trust email"::: +:::image type="content" source="../media/cross-tenant-migration/t2t-onedrive-trust-email.png" alt-text="A screenshot showing an example of a trust email from SharePoint to multiple test accounts."::: **Subject:** SPO Tenant [https://a830edad9050849mnaus093022-my.sharepoint.com/] [setuporupdate] Organization Relation [Scenario=MnA, Role=Source] with us **Message:** SPO Tenant [https://a830edad9050849mnaus093022-my.sharepoint.com/] [setuporupdate] Organization Relation [Scenario=MnA, Role=Source] with us -## Step 3: [Verify that trust has been established](cross-tenant-onedrive-migration-step3.md) +## Step 3: [Verify that trust is established](cross-tenant-onedrive-migration-step3.md) diff --git a/microsoft-365/enterprise/cross-tenant-onedrive-migration-step3.md b/microsoft-365/enterprise/cross-tenant-onedrive-migration-step3.md index c236a11fcb1..f19ad9858d9 100644 --- a/microsoft-365/enterprise/cross-tenant-onedrive-migration-step3.md +++ b/microsoft-365/enterprise/cross-tenant-onedrive-migration-step3.md @@ -3,7 +3,7 @@ title: OneDrive Cross-tenant OneDrive migration Step 3 ms.author: heidip author: MicrosoftHeidi manager: jtremper -ms.date: 10/13/2023 +ms.date: 04/14/2025 recommendations: true audience: ITPro ms.topic: how-to @@ -14,7 +14,7 @@ ms.collection: - M365-collaboration - m365initiative-migratetom365 search.appverid: MET150 -description: "Step 3 of the OneDrive Cross-tenant migration feature" +description: "Step 3 of the OneDrive Cross-tenant migration feature, involving trust verification." --- # Step 3: Verifying trust @@ -22,15 +22,15 @@ This step is Step 3 in a solution designed to complete a Cross-tenant OneDrive m - Step 1: [Connect to the source and the target tenants](cross-tenant-onedrive-migration-step1.md) - Step 2: [Establish trust between the source and the target tenant](cross-tenant-onedrive-migration-step2.md) -- **Step 3: [Verify trust has been established](cross-tenant-onedrive-migration-step3.md)** -- Step 4: [Pre-create users and groups](cross-tenant-onedrive-migration-step4.md) +- **Step 3: [Verify trust is established](cross-tenant-onedrive-migration-step3.md)** +- Step 4: [Precreate users and groups](cross-tenant-onedrive-migration-step4.md) - Step 5: [Prepare identity mapping](cross-tenant-onedrive-migration-step5.md) - Step 6: [Start a Cross-tenant OneDrive migration](cross-tenant-onedrive-migration-step6.md) - Step 7: [Post migration steps](cross-tenant-onedrive-migration-step7.md) Before proceeding with your migration, you need to verify the trust is complete. A status of *GoodToProceed* confirms that the trust is verified. -## To verify trust has been established +## To verify trust is established 1. On the **source tenant** run: @@ -50,13 +50,12 @@ Verify-SPOCrossTenantRelationship -Scenario MnA -PartnerRole Source -PartnerCros When verifying trust, possible values -|Value|Description| -|:-----|:-----| -|NotEstablished|Trust wasn't requested locally.| -|NotEstablishedByPartner|Partner hasn't requested the Trust.| -|DormantByPartner|Partner’s requested trust is within the seven days waiting period after creation.| -|CouldNotContactPartner|Couldn't contact the partner to determine status.| -|GoodToProceed|Verified to proceed.| +|Value |Description | +|:-----------------------|:---------------------------------------------------------------------------------| +|NotEstablished |Trust wasn't requested locally. | +|NotEstablishedByPartner |Partner didn't request the Trust. | +|DormantByPartner |Partner’s requested trust is within the seven days waiting period after creation. | +|CouldNotContactPartner |Couldn't contact the partner to determine status. | +|GoodToProceed |Verified to proceed. | - -## Step 4: [Pre-create users and groups](cross-tenant-onedrive-migration-step4.md) +## Step 4: [Precreate users and groups](cross-tenant-onedrive-migration-step4.md) diff --git a/microsoft-365/enterprise/cross-tenant-onedrive-migration-step4.md b/microsoft-365/enterprise/cross-tenant-onedrive-migration-step4.md index 307e9f8a165..8e3d1490601 100644 --- a/microsoft-365/enterprise/cross-tenant-onedrive-migration-step4.md +++ b/microsoft-365/enterprise/cross-tenant-onedrive-migration-step4.md @@ -3,7 +3,7 @@ title: OneDrive Cross-tenant OneDrive migration Step 4 ms.author: heidip author: MicrosoftHeidi manager: jtremper -ms.date: 10/13/2023 +ms.date: 04/14/2025 recommendations: true audience: ITPro ms.topic: how-to @@ -14,17 +14,17 @@ ms.collection: - M365-collaboration - m365initiative-migratetom365 search.appverid: MET150 -description: "Step 4 of the OneDrive Cross-tenant migration feature" +description: "Step 4 of the OneDrive Cross-tenant migration feature, involving group precreation." --- # Step 4: Precreating users and groups -This is Step 4 in a solution designed to complete a Cross-tenant OneDrive migration. To learn more, see [Cross-tenant OneDrive migration overview](cross-tenant-onedrive-migration.md). +This article is Step 4 in a solution designed to complete a Cross-tenant OneDrive migration. To learn more, see [Cross-tenant OneDrive migration overview](cross-tenant-onedrive-migration.md). - Step 1: [Connect to the source and the target tenants](cross-tenant-onedrive-migration-step1.md) - Step 2: [Establish trust between the source and the target tenant](cross-tenant-onedrive-migration-step2.md) -- Step 3: [Verify trust has been established](cross-tenant-onedrive-migration-step3.md) -- **Step 4: [Pre-create users and groups](cross-tenant-onedrive-migration-step4.md)** +- Step 3: [Verify trust is established](cross-tenant-onedrive-migration-step3.md) +- **Step 4: [Precreate users and groups](cross-tenant-onedrive-migration-step4.md)** - Step 5: [Prepare identity mapping](cross-tenant-onedrive-migration-step5.md) - Step 6: [Start a Cross-tenant OneDrive migration](cross-tenant-onedrive-migration-step6.md) - Step 7: [Post migration steps](cross-tenant-onedrive-migration-step7.md) @@ -34,8 +34,8 @@ This is Step 4 in a solution designed to complete a Cross-tenant OneDrive migrat To ensure that OneDrive permissions are retained as part of the migration, a mapping file needs to be created to align users from the source tenant to the target tenant. -1. Identify the full list of OneDrive sites that will be migrated from the source to the target tenant. -2. Prepare a complete list of users and groups that will be migrated to the target tenant. +1. Identify the full list of OneDrive sites to be migrated from the source to the target tenant. +2. Prepare a complete list of users and groups to be migrated to the target tenant. ## Precreate users and groups on the target tenant @@ -43,11 +43,11 @@ To ensure that OneDrive permissions are retained as part of the migration, a map 2. All users whose OneDrive accounts are migrating to the target tenant must have new user identities created for them in the target tenant. 3. All users whose OneDrive accounts are migrating to the target tenant must be assigned the appropriate OneDrive license. 4. Any users who remain in the source tenant but need access to resources migrating to the target tenant should have new guest identities created for them in the target tenant. -5. Precreated users must be added as members of any appropriate security groups or unified groups before the OneDrive migration begins. +5. Precreated users must be added as members of any appropriate security groups or unified groups before the OneDrive migration begins. 6. If the user or group name already exists in the target tenant, create a user or group with a different name and make a note of it for the next step. 7. We recommend that OneDrive site creations are restricted in the target tenant to prevent users from creating OneDrive sites. >[!Note] ->To learn more on restricting OneDrive site creation, see [Disable OneDrive creation for some users](/sharepoint/manage-user-profiles#disable-onedrive-creation-for-some-users) +>To learn more on restricting OneDrive site creation, see [Disable OneDrive creation for some users](/sharepoint/manage-user-profiles#disable-onedrive-creation-for-some-users). ## Step 5: [Prepare the identity mapping file](cross-tenant-onedrive-migration-step5.md) diff --git a/microsoft-365/enterprise/cross-tenant-onedrive-migration-step5.md b/microsoft-365/enterprise/cross-tenant-onedrive-migration-step5.md index 5ec16177fab..809fa26b2b3 100644 --- a/microsoft-365/enterprise/cross-tenant-onedrive-migration-step5.md +++ b/microsoft-365/enterprise/cross-tenant-onedrive-migration-step5.md @@ -3,7 +3,7 @@ title: OneDrive Cross-tenant OneDrive migration Step 5 ms.author: heidip author: MicrosoftHeidi manager: jtremper -ms.date: 10/13/2023 +ms.date: 04/15/2025 recommendations: true audience: ITPro ms.topic: how-to @@ -14,16 +14,17 @@ ms.collection: - M365-collaboration - m365initiative-migratetom365 search.appverid: MET150 -description: "Step 5 of the OneDrive Cross-tenant migration feature" +description: "Step 5 of the OneDrive Cross-tenant migration feature, involving identity mapping." --- + # Step 5: Identity mapping -This is Step 5 in a solution designed to complete a Cross-tenant OneDrive migration. To learn more, see [Cross-tenant OneDrive migration overview](cross-tenant-onedrive-migration.md). +This article is Step 5 in a solution designed to complete a Cross-tenant OneDrive migration. To learn more, see [Cross-tenant OneDrive migration overview](cross-tenant-onedrive-migration.md). - Step 1: [Connect to the source and the target tenants](cross-tenant-onedrive-migration-step1.md) - Step 2: [Establish trust between the source and the target tenant](cross-tenant-onedrive-migration-step2.md) -- Step 3: [Verify trust has been established](cross-tenant-onedrive-migration-step3.md) -- Step 4: [Pre-create users and groups](cross-tenant-onedrive-migration-step4.md) +- Step 3: [Verify trust is established](cross-tenant-onedrive-migration-step3.md) +- Step 4: [Precreate users and groups](cross-tenant-onedrive-migration-step4.md) - **Step 5: [Prepare identity mapping](cross-tenant-onedrive-migration-step5.md)** - Step 6: [Start a Cross-tenant OneDrive migration](cross-tenant-onedrive-migration-step6.md) - Step 7: [Post migration steps](cross-tenant-onedrive-migration-step7.md) @@ -34,43 +35,43 @@ In this step of the cross-tenant migration process, you're going to create a sin We recommend that you take the time to verify your mappings, ensuring they're accurate before starting any migrations to the target tenant. -There's a one-to-one relationship in the identity mapping file. You can't map the same user to multiple users in the target tenant. For example, if you have instances where the admin is the owner of multiple OneDrive accounts, the ownership must be changed to match the corresponding user you wish to migrate from Source to Target. If you don't, those account files won't migrate. +There's a one-to-one relationship in the identity mapping file. You can't map the same user to multiple users in the target tenant. For example, you may have instances where the admin is the owner of multiple OneDrive accounts. In this circumstance, the ownership must be changed to match the corresponding user you wish to migrate from Source to Target. If you don't, those account files don't migrate. **Example:** In this example, the admin owns multiple OneDrive accounts. -|Source Tenant Owner|Target Tenant User| -|---|---| -|admin@source.com|new.userA@target.com| -|admin@source.com|new.userB@target.com| -|admin@source.com|new.userC@target.com| +|Source Tenant Owner |Target Tenant User | +|--------------------|---------------------| +|admin@source.com |new.userA@target.com | +|admin@source.com |new.userB@target.com | +|admin@source.com |new.userC@target.com | Cross-tenant migration supports this scenario: **Example**: -|Source Tenant Owner|Target Tenant User| -|---|---| -|userA@source.com|new.userA@target.com| -|userB@source.com|new.userB@target.com| -|userC@source.com|new.userC@target.com| +|Source Tenant Owner |Target Tenant User | +|--------------------|---------------------| +|userA@source.com |new.userA@target.com | +|userB@source.com |new.userB@target.com | +|userC@source.com |new.userC@target.com | ### Create the CSV file There are six columns needed in your CSV file. The first three are your source values, each providing detail about where your data is currently located. The remaining three columns are the corresponding info on the target tenant. All six columns must be accounted for in the file. Create your file in Excel and save it as a .csv file. -Users and groups are included in the same file. Depending on whether it's a user or group, what you enter in the column is different. In each of the columns enter values as shown in the examples. **Do NOT include column headings.** +Users and groups are included in the same file. Depending on whether it's a user or group, what you enter in the column is different. In each of the columns enter values as shown in the examples. **DON'T include column headings.** -|Column|User|Group| -|---|---|---| -|1|User|Group| -|2|SourceTenantCompanyID|SourceTenantCompanyID| -|3|SourceUserUpn|SourceGroupObjectID| -|4|TargetUserUpn|TargetGroupObjectID| -|5|TargetUserEmail|GroupName| -|6|UserType|GroupType| +|Column |User |Group | +|-------|----------------------|----------------------| +|1 |User |Group | +|2 |SourceTenantCompanyID |SourceTenantCompanyID | +|3 |SourceUserUpn |SourceGroupObjectID | +|4 |TargetUserUpn |TargetGroupObjectID | +|5 |TargetUserEmail |GroupName | +|6 |UserType |GroupType | > [!IMPORTANT] -> **Do NOT include column headings in your CSV file.** In the examples below we include them for illustrative purposes only. +> **DON'T include column headings in your CSV file.** In the examples below we include them for illustrative purposes only. **Users**. Enter your values as shown in this example for Users: @@ -79,15 +80,14 @@ Users and groups are included in the same file. Depending on whether it's a user :::image type="content" source="../media/cross-tenant-migration/t2t-onedrive-csv-mapping-users-example.png" alt-text="example of csv for users"::: **Groups**. Enter your values as shown in this example for Groups: -
+ :::image type="content" source="../media/cross-tenant-migration/t2t-onedrive-csv-mapping-groups-columns.png" alt-text="format for csv file for groups"::: -
*Example*: :::image type="content" source="../media/cross-tenant-migration/t2t-onedrive-csv-group-example.png" alt-text="example of adding groups to csv file"::: -**Guest users**. You can map guest accounts in the source tenant to member accounts in the target tenant. You can also map a guest account in the source to a guest account in the target if the guest has been previously created. Enter your values as shown in this example for guests: +**Guest users**. You can map guest accounts in the source tenant to member accounts in the target tenant. You can also map a guest account in the source to a guest account in the target if the guest was previously created. Enter your values as shown in this example for guests: :::image type="content" source="../media/cross-tenant-migration/t2t-onedrive-csv-mapping-users-guests.png" alt-text="csv example when mapping a guest to a member"::: @@ -106,15 +106,15 @@ To obtain Source Tenant Company ID: 1. Sign in as Admin to your [Azure portal](https://ms.portal.azure.com/) 2. Select or Search for **Microsoft Entra ID**. 3. Scroll down on the left-hand panel and select **Properties**. -4. Locate the **Tenant ID Field**. The required Tenant ID will be in that box. +4. Locate the **Tenant ID Field**. The required Tenant ID is in that box. :::image type="content" source="../media/cross-tenant-migration/t2t-onedrive-azure-tenant-id.png" alt-text="getting the source tenant ID"::: ## To obtain source group object ID: 1. Sign in to source tenant as Admin to [Azure Groups](https://ms.portal.azure.com). -2. Search for your required group(s). -3. Select the required Group instance and then **Copy to clipboard**. Paste this value in the sourceGroupObjectId column of your mapping CSV file. +2. Search for your required groups. +3. Select the required group instance and then **Copy to clipboard**. Paste this value in the sourceGroupObjectId column of your mapping CSV file. 4. If you have multiple Groups to map, then repeat these steps for each group. :::image type="content" source="../media/cross-tenant-migration/t2t-onedrive-source-group-objectid.png" alt-text="getting the source group object ID"::: @@ -122,34 +122,34 @@ To obtain Source Tenant Company ID: ### To obtain target group object ID: 1. Sign in to Target tenant as Admin to [Azure Groups](https://ms.portal.azure.com) -2. Search for your required group(s). +2. Search for your required groups. 3. Select the required group instance and then **Copy to clipboard**. Paste this value in the targetGroupObjectId column of your mapping CSV file. -4. If you have multiple groups to map, then repeat the above process to obtain those specific targetGroupObjectId's. +4. If you have multiple groups to map, then repeat this process to obtain those specific targetGroupObjectIds. 5. For the GroupName, use the same ID as the *TargetGroupObjectId* you obtained. :::image type="content" source="../media/cross-tenant-migration/t2t-onedrive-target-group-objectid.png" alt-text="how to get the target object ID"::: ## Upload the identity map -Once the identity mapping file has been prepared, the SharePoint Administrator on the target tenant uploads the file to SharePoint. This will allow identity mapping to occur automatically as part of the cross-tenant migration. +Once the identity mapping file is prepared, the SharePoint Administrator on the target tenant uploads the file to SharePoint. This file allows identity mapping to occur automatically as part of the cross-tenant migration. > [!IMPORTANT] -> Before you run the *Add-SPOTenantIdentityMap -IdentityMapPath* command, save and close the identitymap.csv file on your Desktop/OneDrive/SharePoint. If the file remains open, you will receive the following error. +> Before you run the *Add-SPOTenantIdentityMap -IdentityMapPath* command, save and close the identitymap.csv file on your Desktop/OneDrive/SharePoint. If the file remains open, you receive the following error: > > *Add-SPOTenantIdentityMap: The process cannot access the file 'C:\Users\myuser\Test-Identity-Map.csv' because it is being used by another process.* -1. To upload the identity Map on the target tenant, run the following command. For *-IdentityMapPath*, provide the full path and filename of the identity mapping CSV file. +1. To upload the identity Map on the target tenant, run the following command. For *-IdentityMapPath*, provide the full path and filename of the identity mapping CSV file. ```powershell Add-SPOTenantIdentityMap -IdentityMapPath ``` > [!IMPORTANT] -> If you make or need to make any changes to your Identity Map during the lifecycle of the migration you must run the `Add-SPOTenantIdentityMap -IdentityMapPath ` command **every time** a change is made to ensure those changes are applied to the migration. +> If you make or need to make any changes to your Identity Map during the lifecycle of the migration, you must run the `Add-SPOTenantIdentityMap -IdentityMapPath ` command **every time** a change is made to ensure those changes are applied to the migration. -Uploading any new identity map will overwrite the current one. Make sure that any revision or addition includes ALL users and groups for the full migration. Your identity map should always include everyone you're wanting to migrate. +Uploading any new identity map overwrites the current one. Make sure that any revision or addition includes ALL users and groups for the full migration. Your identity map should always include everyone you're wanting to migrate. -To look at the mapping entries in the identity mapping file for a particular user, use the command *Get-SPOTenantIdentityMappingUser* with Field as *SourceUserKey* and Value as the UPN of the user you are moving. +You can look at the mapping entries in the identity mapping file for a particular user. Use the command *Get-SPOTenantIdentityMappingUser,* with Field as *SourceUserKey* and Value as the UPN of the user you're moving. **Example:** @@ -161,7 +161,7 @@ get-spoTenantIdentityMappingUser -Field SourceUserKey -Value usera@Contoso.onmic Before starting any cross-tenant migrations, make sure that both SharePoint database schemas are up to date and compatible between source and target. -To perform this check, run the below cmdlet on your Source tenant. +To perform this check, run the following cmdlet on your Source tenant: ```powershell Get-SPOCrossTenantCompatibilityStatus -PartnerCrossTenantHostURL [Target tenant hostname] @@ -170,17 +170,17 @@ Get-SPOCrossTenantCompatibilityStatus -PartnerCrossTenantHostURL https://m365x12 ``` - If the tenant status shows as **Compatible** or **Warning**, you can then proceed with the next step of starting cross-tenant migrations. -- If the tenant status shows as **Incompatible**, your tenants will need to be patched/updated to ensure compatibility. +- If the tenant status shows as **Incompatible**, your tenants need to be patched/updated to ensure compatibility. -|Status|Can proceed with migration| -|---|---| -|Compatible|Yes| -|Warning|Yes| -|Incompatible|No| +|Status |Can proceed with migration | +|-------------|---------------------------| +|Compatible |Yes | +|Warning |Yes | +|Incompatible |No | > [!NOTE] -> We recommend waiting a period of 48 hours. If your tenants are still reporting as *incompatible*, contact support. +> We recommend waiting a period of 48 hours. If your tenants still report as *incompatible*, contact support. > -> We recommend performing the compatibility status check on a frequent basis and prior to starting ANY instances of cross tenant migrations. If the tenants are not compatible, this can result in cross-tenant migrations failing. +> We recommend performing the compatibility status check on a frequent basis and before starting ANY instances of cross tenant migrations. If the tenants aren't compatible, it can result in cross-tenant migrations failing. ## Step 6: [Start a OneDrive cross-tenant migration](cross-tenant-onedrive-migration-step6.md) diff --git a/microsoft-365/enterprise/cross-tenant-onedrive-migration-step6.md b/microsoft-365/enterprise/cross-tenant-onedrive-migration-step6.md index 0e4297583bb..174f4adb99b 100644 --- a/microsoft-365/enterprise/cross-tenant-onedrive-migration-step6.md +++ b/microsoft-365/enterprise/cross-tenant-onedrive-migration-step6.md @@ -3,7 +3,7 @@ title: OneDrive Cross-tenant OneDrive migration Step 6 ms.author: heidip author: MicrosoftHeidi manager: jtremper -ms.date: 10/13/2023 +ms.date: 04/15/2025 recommendations: true audience: ITPro ms.topic: how-to @@ -16,14 +16,15 @@ ms.collection: search.appverid: MET150 description: "Step 6 of the OneDrive Cross-tenant migration feature" --- + # Step 6: Start a OneDrive cross-tenant migration -This is Step 6 in a solution designed to complete a Cross-tenant OneDrive migration. To learn more, see [Cross-tenant OneDrive migration overview](cross-tenant-onedrive-migration.md). +This article is Step 6 in a solution designed to complete a Cross-tenant OneDrive migration. To learn more, see [Cross-tenant OneDrive migration overview](cross-tenant-onedrive-migration.md). - Step 1: [Connect to the source and the target tenants](cross-tenant-onedrive-migration-step1.md) - Step 2: [Establish trust between the source and the target tenant](cross-tenant-onedrive-migration-step2.md) -- Step 3: [Verify trust has been established](cross-tenant-onedrive-migration-step3.md) -- Step 4: [Precreate users and groups](cross-tenant-onedrive-migration-step4.md) +- Step 3: [Verify trust is established](cross-tenant-onedrive-migration-step3.md) +- Step 4: [Precreate users and groups](cross-tenant-onedrive-migration-step4.md) - Step 5: [Prepare identity mapping](cross-tenant-onedrive-migration-step5.md) - **Step 6: [Start a Cross-tenant OneDrive migration](cross-tenant-onedrive-migration-step6.md)** - Step 7: [Post migration steps](cross-tenant-onedrive-migration-step7.md) @@ -31,9 +32,9 @@ This is Step 6 in a solution designed to complete a Cross-tenant OneDrive migrat >[!IMPORTANT] >Microsoft recommends that you use roles with the fewest permissions. Using lower permissioned accounts helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role. -Now you're ready to start your OneDrive migration. Before starting any cross-tenant migration, do the following steps. +Now you're ready to start your OneDrive migration. Before starting any cross-tenant migration, do the following steps. -1. Ensure you have verified the compatibility status. If you see a status of either **Compatible** or **Warning** on your source tenant, you can continue. Run: +1. Make sure you verified the compatibility status. If you see a status of either **Compatible** or **Warning** on your source tenant, you can continue. Run: ```powershell Get-SPOCrossTenantCompatibilityStatus –PartnerCrossTenantHostURL [Target tenant hostname] @@ -42,40 +43,39 @@ Now you're ready to start your OneDrive migration. Before starting any cross-te 2. To start the migration, a SharePoint Admin or Microsoft 365 Global Admin of the source tenant must run the following command: ```PowerShell -Start-SPOCrossTenantUserContentMove -SourceUserPrincipalName <...> -TargetUserPrincipalName <...> -TargetCrossTenantHostUrl <...> +Start-SPOCrossTenantUserContentMove -SourceUserPrincipalName <...> -TargetUserPrincipalName <...> -TargetCrossTenantHostUrl <...> ``` -|Parameters|Description| -|---|---| -|SourceUserPrincipalName|User principal name of the user who owns the OneDrive on the Source tenant.| -|TargetUserPrincipalName|User principal name of the user who owns the OneDrive on the Target tenant.| -|TargetCrossTenantHostUrl|The Cross-tenant Host URL of the target tenant. To find the TargetCrossTenantHostUrl, run *Get-SPOCrossTenantHostUrl* on the tenant.| +|Parameters |Description | +|-------------------------|------------| +|SourceUserPrincipalName |User principal name of the user who owns the OneDrive on the Source tenant. | +|TargetUserPrincipalName |User principal name of the user who owns the OneDrive on the Target tenant. | +|TargetCrossTenantHostUrl |The Cross-tenant Host URL of the target tenant. To find the TargetCrossTenantHostUrl, run *Get-SPOCrossTenantHostUrl* on the tenant. | Example: ```Powershell -Start-SPOCrossTenantUserContentMove -SourceUserPrincipalName DiegoS@M365x016651.OnMicrosoft.com -TargetUserPrincipalName - Test-Diego@M365x946316.OnMicrosoft.com -TargetCrossTenantHostUrl https://m365x946316-my.sharepoint.com/ +Start-SPOCrossTenantUserContentMove -SourceUserPrincipalName DiegoS@M365x016651.OnMicrosoft.com -TargetUserPrincipalName Test-Diego@M365x946316.OnMicrosoft.com -TargetCrossTenantHostUrl https://m365x946316-my.sharepoint.com/ ``` -To Schedule a migration for a later time, you can use and append the above command with the one of the following parameters. +To Schedule a migration for a later time, you can use and append the previous command with the one of the following parameters: -These commands can be useful when planning bulk batches of OneDrive migrations. You can queue/migrate up to 4,000 OneDrive migrations per batch. If your user count exceeds 4,000, create separate batches, and schedule them to run once the current batch is close to completion. +|Parameter |Description | +|-----------------------|------------| +|PreferredMoveBeginDate |The migration likely begins at this specified time. Time must be specified in Coordinated Universal Time (UTC). | +|PreferredMoveEndDate |The migration likely completes by this specified time, on a best effort basis. Time must be specified in Coordinated Universal Time (UTC). | -|Parameter|Description| -|---|---| -|PreferredMoveBeginDate|The migration will likely begin at this specified time. Time must be specified in Coordinated Universal Time (UTC).| -|PreferredMoveEndDate|The migration will likely be completed by this specified time, on a best effort basis. Time must be specified in Coordinated Universal Time (UTC).| +These commands can be useful when planning bulk batches of OneDrive migrations. You can queue/migrate up to 4,000 OneDrive migrations per batch. If your user count exceeds 4,000, create separate batches, and schedule them to run once the current batch is close to completion. ## OneDrive status premigration -Before you start the migration, the users current source OneDrive status is similar to the example below. This example is from the users source tenant, showing their current files and folders. +Before you start the migration, the users' current source OneDrive status is similar to the following screenshot. This example is from the users' source tenant, showing their current files and folders. -:::image type="content" source="../media/cross-tenant-migration/t2t-onedrive-status-premigration.png" alt-text="pre-migration status"::: +:::image type="content" source="../media/cross-tenant-migration/t2t-onedrive-status-premigration.png" alt-text="A screenshot showing a premigration status. There are files and folders displayed in a window, and a red box is drawn around the address of the OneDrive."::: ## Cancelling a OneDrive migration -You can stop the cross-tenant migration of a user's OneDrive by using the following command, provided the migration doesn't have a status of *In Progress*, *Rescheduled* or *Success*. +You can stop the cross-tenant migration of a user's OneDrive by using the following command, provided the migration doesn't have a status of *In Progress*, *Rescheduled*, or *Success*. ```powershell Stop-SPOCrossTenantUserContentMove – SourceUserPrincipalName [UPN name of user who you wish to stop] @@ -100,7 +100,7 @@ Get-SPOCrossTenantUserContentMoveState -PartnerCrossTenantHostURL [Target URL] Example: ```Powershell -Get-SPOCrossTenantUserContentMoveState -PartnerCrossTenantHostURL https://m365x946316-my.sharepoint.com/ +Get-SPOCrossTenantUserContentMoveState -PartnerCrossTenantHostURL https://m365x946316-my.sharepoint.com/ ``` **Target command:** @@ -112,7 +112,7 @@ Get-SPOCrossTenantUserContentMoveState -PartnerCrossTenantHostURL [Source URL] Example: ```powershell -Get-SPOCrossTenantUserContentMoveState -PartnerCrossTenantHostURL https://m365x016551-my.sharepoint.com/ +Get-SPOCrossTenantUserContentMoveState -PartnerCrossTenantHostURL https://m365x016551-my.sharepoint.com/ ``` To find the status of a specific user's migration, use the *SourceUserPrincipalName* parameter: @@ -137,20 +137,20 @@ Get-SPOCrossTenantUserContentMoveState -PartnerCrossTenantHostURL https://ttestt ## Migration States -|Status|Description| -|---|---| -|NotStarted|The migration hasn't yet started.| -|Scheduled|The migration is now in the queue and is scheduled to run when a slot becomes available.| -|ReadytoTrigger|The Migration is in its preflight stage and will start the Migration shortly.| -|InProgress|The migration is in progress in one of the following states:
- Validation
- Backup
- Restore
- Cleanup| -|Success|The Migration completed successfully.| -|Rescheduled|The migration may not have completed and has been requeued for another pass.| -|Failed|The migration failed to complete.| +|Status |Description | +|---------------|------------| +|NotStarted |The migration isn't started.| +|Scheduled |The migration is now in the queue and is scheduled to run when a slot becomes available.| +|ReadytoTrigger |The Migration is in its preflight stage. The Migration starts shortly. | +|InProgress |The migration is in progress in one of the following states:
- Validation
- Backup
- Restore
- Cleanup | +|Success |The Migration completed successfully. | +|Rescheduled |The migration may not be completed and is requeued for another pass. | +|Failed |The migration failed to complete. | ## Post-migration status checks **Target tenant**: After the migration successfully completes, check the status of the user on the target tenant by logging into their new OneDrive account. -**Source tenant**: Since the user has successfully migrated to the target tenant, they no longer have an active OneDrive account on the source. +**Source tenant**: Since the user was successfully migrated to the target tenant, they no longer have an active OneDrive account on the source. ## Step 7: [Post migration steps](cross-tenant-onedrive-migration-step7.md) diff --git a/microsoft-365/enterprise/cross-tenant-onedrive-migration.md b/microsoft-365/enterprise/cross-tenant-onedrive-migration.md index 824ee4a9498..f0a6d1cfa6c 100644 --- a/microsoft-365/enterprise/cross-tenant-onedrive-migration.md +++ b/microsoft-365/enterprise/cross-tenant-onedrive-migration.md @@ -3,7 +3,7 @@ title: Cross-tenant OneDrive migration overview ms.author: jtremper author: MicrosoftHeidi manager: pamgreen -ms.date: 05/31/2024 +ms.date: 04/14/2025 recommendations: true audience: ITPro ms.topic: upgrade-and-migration-article @@ -14,7 +14,7 @@ ms.collection: - M365-collaboration - m365initiative-migratetom365 search.appverid: MET150 -description: "Cross-tenant OneDrive migration" +description: "Cross-tenant OneDrive migration overview article. Information about migrating content from one tenant to another, including requirements, limitations, licensing, and government clouds, including GCC (government community cloud), GCC High, and DoD." --- # Cross-tenant OneDrive migration @@ -27,41 +27,41 @@ During mergers or divestitures, you commonly need the ability to move users OneD SharePoint administrators of two separate tenants can use the *Set-SPOCrossTenantRelationship* cmdlet to establish an organization relationship, and the *Start-SPOCrossTenantUserContentMove* command to begin cross-tenant OneDrive moves. -Up to 4,000 OneDrive accounts can be scheduled for migration in advance at a given time. Once scheduled, migrations occur without the user's data ever leaving the Microsoft 365 cloud and with minimal disruption, requiring only a few minutes where a user's OneDrive will be read-only. When migrations are complete, a redirect is placed in the location of the user's original OneDrive, so any links to files and folders can continue working in the new location. +Up to 4,000 OneDrive accounts can be scheduled for migration in advance at a given time. Once scheduled, migrations occur without the user's data ever leaving the Microsoft 365 cloud and with minimal disruption, requiring only a few minutes where a user's OneDrive is read-only. When migrations are complete, a redirect is placed in the location of the user's original OneDrive, so any links to files and folders can continue working in the new location. >[!Important] ->Cross-Tenant moves are a one and done migration activity. The content will be **moved** from the Source to Target, leaving behind a redirect link on Source. **Incremental and delta migration passes cannot be performed.** +>Cross-Tenant moves are a one and done migration activity. The content is **moved** from the Source to Target, leaving behind a redirect link on Source. **Incremental and delta migration passes cannot be performed.** > [!NOTE] -> This feature is not supported for users of the Government Cloud, including GCC, Consumer, GCC High, or DoD. +> This feature isn't supported for users of the Government Cloud, including GCC, Consumer, GCC High, or DoD. ## Licensing >[!Important] >As of Nov. 2022, Cross Tenant User Data Migration is available as an add-on to the following Microsoft 365 subscription plans for Enterprise Agreement customers, and is required for cross-tenant migrations. User licenses are per migration (one-time fee) and can be assigned either on the source or target user object. This license also covers Cross-tenant mailbox migration. Contact your Microsoft account team for details. > ->The Cross Tenant User Data Migration add-on is available as a separate purchase for Microsoft 365 Business Basic, Standard, and Premium; Microsoft 365 F1/F3/E3/E5; Office 365 F3/E1/E3/E5; Exchange Online; SharePoint Online; and OneDrive for Business. +>The Cross Tenant User Data Migration add-on is available as a separate purchase for Microsoft 365 Business Basic, Standard, and Premium; Microsoft 365 F1/F3/E3/E5; Office 365 F3/E1/E3/E5; Exchange Online; SharePoint in Microsoft 365; and OneDrive for Business. >[!Warning] ->You must have purchased, or verified that you can purchase, cross tenant user data migration licenses prior to the next steps. Migrations fail if this step has not been completed. Microsoft does not offer exceptions for this licensing requirement. +>You must have purchased, or verified that you can purchase, cross tenant user data migration licenses prior to the next steps. Migrations fail if this step isn't completed. Microsoft doesn't offer exceptions for this licensing requirement. ## Prerequisites and settings - **Microsoft SharePoint Online Powershell**. Confirm you have the most recent version installed. [Download SharePoint Online Management Shell from the official Microsoft Download Center](https://www.microsoft.com/download/details.aspx?id=35588). -- **Confirm that the source OneDrive tenant does not have Service encryption with Microsoft Purview Customer Key enabled.** If enabled on the source tenant, the migration will fail. [Learn more on Service encryption with Microsoft Purview Customer Key](/microsoft-365/compliance/customer-key-overview). +- **Confirm that the source OneDrive tenant doesn't have Service encryption with Microsoft Purview Customer Key enabled**. If enabled on the source tenant, the migration fails. [Learn more on Service encryption with Microsoft Purview Customer Key](/microsoft-365/compliance/customer-key-overview). -- Source OneDrive accounts must be set to Read/Write. If set to Read only, they'll fail. +- **Source OneDrive accounts must be set to Read/Write**. If set to Read only, they fail. -## Pre-create target accounts +## Precreate target accounts -- Ensure all users and groups identified for migration have been pre-created on the target tenant. +- Ensure all users and groups identified for migration are precreated on the target tenant. - Assign the appropriate licenses to each user on the target tenant. > [!IMPORTANT] > OneDrive sites should **NOT** be created before **OR** during a migration. > -> OneDrive site creation should be restricted in the target tenant to prevent users from creating OneDrive sites. If a OneDrive site already exists for the user on the target tenant, the migration will fail. You can't overwrite an existing site. +> OneDrive site creation should be restricted in the target tenant to prevent users from creating OneDrive sites. If a OneDrive site already exists for the user on the target tenant, the migration fails. You can't overwrite an existing site. > > If users continue to access resources in the source tenant, you should restrict OneDrive creation in the source tenant to prevent creating new OneDrive sites. @@ -70,11 +70,11 @@ Up to 4,000 OneDrive accounts can be scheduled for migration in advance at a giv ## Path size limits -Microsoft limits the number of characters in a path to not exceed 400 characters. This is the full path limit, not just the file name. In planning your migrations, review the length of OneDrive URL names in your target tenant. Failure often occurs when files or folder paths from the source, combined with the OneDrive URL on the target exceed the 400-character path limit. +Microsoft limits the number of characters in a path to not exceed 400 characters. This limit is for the full path limit, not just the file name. In planning your migrations, review the length of OneDrive URL names in your target tenant. Failure often occurs when files or folder paths from the source, combined with the OneDrive URL on the target exceed the 400-character path limit. -A migration will detect if you have exceeded the character limit. Work with the site owner to update the file/folder directory structure to reduce file path lengths. +A migration detects if the character limit is exceeded. Work with the site owner to update the file/folder directory structure to reduce file path lengths. -Any legal URL will be accepted when creating your Identity Map from Source to Target for your migrations. At this current time usernames/URLs that contain an apostrophe character ( **'** ) in a username/URL will fail with an "invalid character" error when attempting the migration. +Any legal URL is accepted when creating your Identity Map from Source to Target for your migrations. At this current time usernames/URLs that contain an apostrophe character ( **'** ) in a username/URL fails with an "invalid character" error when attempting the migration. > [!TIP] > We recommend keeping your target OneDrive URL names short to avoid exceeding the character limit. @@ -84,22 +84,21 @@ Any legal URL will be accepted when creating your Identity Map from Source to Ta Each OneDrive account can have a maximum of 5 TB of content or 1 million items. > [!IMPORTANT] -> The 1 million item limit can be any "item", including files (including versions), folders, and list line entries if it is a list or library. +> The 1 million item limit can be any *item*, including files (and versions), folders, and list line entries if it's a list or library. > ->If you attempt to migrate any OneDrive site that exceeds the 5 TB quota, the transfer will fail. +>If you attempt to migrate any OneDrive site that exceeds the five-terabyte quota, the transfer fails. ## Permissions -All users and groups included in the identity mapping file that you uploaded to the target tenant will maintain permissions in the target tenant related to the migrated OneDrive site. +All users and groups included in the identity mapping file that you uploaded to the target tenant maintain permissions in the target tenant related to the migrated OneDrive site. ## Legal holds -OneDrive accounts with a Hold policy applied will be blocked from migration. -To migrate these OneDrive accounts, remove the hold policy, migrate, then reapply the hold as needed on the target tenant. +OneDrive accounts with a Hold policy applied are blocked from migration. To migrate these OneDrive accounts, remove the hold policy, migrate, then reapply the hold as needed on the target tenant. ## Shared files -After a OneDrive account is migrated, anyone clicking on a shared link to the old location will be redirected to the new one, provided they still have access to the destination. +After a OneDrive account is migrated, anyone clicking on a shared link to the old location is redirected to the new one, provided they still have access to the destination. Those redirects remain until the source tenant is deprovisioned. The admin can also selectively remove redirects site-by-site. @@ -107,8 +106,8 @@ Those redirects remain until the source tenant is deprovisioned. The admin can a - **Step 1:** [Connect to the source and the target tenants](cross-tenant-onedrive-migration-step1.md). - **Step 2:** [Establish trust between the source and the target tenant](cross-tenant-onedrive-migration-step2.md) -- **Step 3:** [Verify trust has been established](cross-tenant-onedrive-migration-step3.md) -- **Step 4:** [Pre-create users and groups](cross-tenant-onedrive-migration-step4.md) +- **Step 3:** [Verify trust is established](cross-tenant-onedrive-migration-step3.md) +- **Step 4:** [Precreate users and groups](cross-tenant-onedrive-migration-step4.md) - **Step 5:** [Prepare identity mapping](cross-tenant-onedrive-migration-step5.md) - **Step 6:** [Start a Cross-tenant OneDrive migration](cross-tenant-onedrive-migration-step6.md) - **Step 7:** [Post migration steps](cross-tenant-onedrive-migration-step7.md) diff --git a/microsoft-365/enterprise/disable-access-to-services-with-microsoft-365-powershell.md b/microsoft-365/enterprise/disable-access-to-services-with-microsoft-365-powershell.md index ce8b63e676f..9b80968ba5f 100644 --- a/microsoft-365/enterprise/disable-access-to-services-with-microsoft-365-powershell.md +++ b/microsoft-365/enterprise/disable-access-to-services-with-microsoft-365-powershell.md @@ -146,15 +146,15 @@ The following example updates a user with **SPE_E5** (Microsoft 365 E5) and turn ```powershell ## Get the services that have already been disabled for the user. $userLicense = Get-MgUserLicenseDetail -UserId "belinda@fdoau.onmicrosoft.com" -$userDisabledPlans = $userLicense.ServicePlans | ` +$userDisabledPlans = @($userLicense.ServicePlans | ` Where ProvisioningStatus -eq "Disabled" | ` - Select -ExpandProperty ServicePlanId + Select -ExpandProperty ServicePlanId) ## Get the new service plans that are going to be disabled $e5Sku = Get-MgSubscribedSku -All | Where SkuPartNumber -eq 'SPE_E5' -$newDisabledPlans = $e5Sku.ServicePlans | ` +$newDisabledPlans = @($e5Sku.ServicePlans | ` Where ServicePlanName -in ("SWAY", "FORMS_PLAN_E5") | ` - Select -ExpandProperty ServicePlanId + Select -ExpandProperty ServicePlanId) ## Merge the new plans that are to be disabled with the user's current state of disabled plans $disabledPlans = ($userDisabledPlans + $newDisabledPlans) | Select -Unique diff --git a/microsoft-365/enterprise/essentials-compliance.md b/microsoft-365/enterprise/essentials-compliance.md index cdf12e2fdd3..70d83a2d839 100644 --- a/microsoft-365/enterprise/essentials-compliance.md +++ b/microsoft-365/enterprise/essentials-compliance.md @@ -127,4 +127,4 @@ If your business requires information barriers, see [Learn about information bar [Windows Privacy Compliance Guide](/windows/privacy/windows-10-and-privacy-compliance) -[Microsoft Purview Compliance Portal](/purview/purview-compliance-portal) +[Microsoft Purview portal](/purview/purview-compliance-portal) diff --git a/microsoft-365/enterprise/ipv6-support.md b/microsoft-365/enterprise/ipv6-support.md index 2c5767d7767..1fd27d09823 100644 --- a/microsoft-365/enterprise/ipv6-support.md +++ b/microsoft-365/enterprise/ipv6-support.md @@ -3,7 +3,7 @@ title: "IPv6 support in Microsoft 365 services" ms.author: kvice author: kelleyvice-msft manager: scotv -ms.date: 03/21/2024 +ms.date: 04/09/2025 audience: ITPro ms.topic: article ms.service: microsoft-365-enterprise diff --git a/microsoft-365/enterprise/m365-dr-commitments.md b/microsoft-365/enterprise/m365-dr-commitments.md index 787cf22fee0..57f42169c0d 100644 --- a/microsoft-365/enterprise/m365-dr-commitments.md +++ b/microsoft-365/enterprise/m365-dr-commitments.md @@ -79,7 +79,7 @@ The following customer data is stored in the _Local Region Geography_: The following customer data is stored at rest in the _Local Region Geography_: - DLP Admin Configuration -- DLP policies in Compliance Portal +- DLP policies in Microsoft Purview portal - DLP monitored activities - Violation history - Activity Explorer and Microsoft 365 unified audit logs diff --git a/microsoft-365/enterprise/m365-dr-overview.md b/microsoft-365/enterprise/m365-dr-overview.md index dca87b469a7..777fc4bd273 100644 --- a/microsoft-365/enterprise/m365-dr-overview.md +++ b/microsoft-365/enterprise/m365-dr-overview.md @@ -75,15 +75,15 @@ You can use the Microsoft 365 admin center to understand where your data for a g Some examples: -**Example 1:** For a _Tenant_ with the sign-up country/region as "France" that has a new subscription that includes Exchange Online, SharePoint, OneDrive and Microsoft Teams, then the customer data for those services will be provisioned into the French _Local Region Geography_. Why? Because those services are deployed into the French data centers and the _Tenant_ has a France sign up country/region. +**Example 1:** For a _Commercial Tenant_ with the sign-up country/region as "France" that has a new subscription that includes Exchange Online, SharePoint, OneDrive and Microsoft Teams, then the customer data for those services will be provisioned into the French _Local Region Geography_. Why? Because those services are deployed into the French data centers and the _Tenant_ has a France sign up country/region. -**Example 2:** For a _Tenant_ with the sign-up country/region as "Belgium" that has a new subscription that includes Exchange Online, SharePoint, OneDrive and Microsoft Teams, then the customer data for those services will be provisioned into the _Macro Region Geography 1 – EMEA_. Why? Because there are no Microsoft 365 data centers in Belgium and the closest Geography is _Macro Region Geography 1 - EMEA_. +**Example 2:** For a _Commercial Tenant_ with the sign-up country/region as "Belgium" that has a new subscription that includes Exchange Online, SharePoint, OneDrive and Microsoft Teams, then the customer data for those services will be provisioned into the _Macro Region Geography 1 – EMEA_. Why? Because there are no Microsoft 365 data centers in Belgium and the closest Geography is _Macro Region Geography 1 - EMEA_. -**Example 3:** For a _Tenant_ with the sign-up country/region as "Japan" that has a new subscription that includes Microsoft Forms, then the customer data for Forms will be provisioned into the _Macro Region Geography 3 - Americas_. Why? Because Forms is only deployed in _Macro Region Geography 3 - Americas_ and _Macro Region Geography 1 – EMEA_ (EU _Tenants_ only). +**Example 3:** For a _Commercial Tenant_ with the sign-up country/region as "Japan" that has a new subscription that includes Microsoft Forms, then the customer data for Forms will be provisioned into the _Macro Region Geography 3 - Americas_. Why? Because Forms is only deployed in _Macro Region Geography 3 - Americas_ and _Macro Region Geography 1 – EMEA_ (EU _Tenants_ only). -**Example 4a:** For a _Tenant_ with the sign-up country/region as "Sweden" that has a new subscription that includes Microsoft Viva Engage, then the customer data for Viva Engage will be provisioned into the _Macro Region Geography 1 - EMEA_. Why? Because Viva Engage is deployed in _Macro Region Geography 1 - EMEA_ and Swedish _Tenants_ are best served out of that _Geography_. +**Example 4a:** For a _Commercial Tenant_ with the sign-up country/region as "Sweden" that has a new subscription that includes Microsoft Viva Engage, then the customer data for Viva Engage will be provisioned into the _Macro Region Geography 1 - EMEA_. Why? Because Viva Engage is deployed in _Macro Region Geography 1 - EMEA_ and Swedish _Tenants_ are best served out of that _Geography_. -**Example 4b:** For a _Tenant_ with the sign-up country/region as "Sweden" that has a subscription that includes Microsoft Viva Engage from before Viva Engage was deployed to _Macro Regional Geography 1 - EMEA_, then the customer data for Viva Engage will be located in _Macro Region Geography 3 - Americas_. Why? Because, at that time, Viva Engage only had a single deployment for all customers in _Macro Region Geography 3 - Americas_. +**Example 4b:** For a _Commercial Tenant_ with the sign-up country/region as "Sweden" that has a subscription that includes Microsoft Viva Engage from before Viva Engage was deployed to _Macro Regional Geography 1 - EMEA_, then the customer data for Viva Engage will be located in _Macro Region Geography 3 - Americas_. Why? Because, at that time, Viva Engage only had a single deployment for all customers in _Macro Region Geography 3 - Americas_. ### Migrations/Moves @@ -259,7 +259,7 @@ Microsoft 365 uses service-side technologies that encrypt customer data at rest
Select to expand -Review the [Products available by region](https://go.microsoft.com/fwlink/p/?linkid=2093451) page to find data residency information for Microsoft Azure. +Review the [Product availability by region](https://azure.microsoft.com/explore/global-infrastructure/products-by-region/table) page to find data residency information for Microsoft Azure.
diff --git a/microsoft-365/enterprise/microsoft-365-ediscovery-throttling-service-advisory.md b/microsoft-365/enterprise/microsoft-365-ediscovery-throttling-service-advisory.md index 6ed475c35d1..8b57c246814 100644 --- a/microsoft-365/enterprise/microsoft-365-ediscovery-throttling-service-advisory.md +++ b/microsoft-365/enterprise/microsoft-365-ediscovery-throttling-service-advisory.md @@ -34,7 +34,7 @@ These service advisories are displayed in the Microsoft 365 admin center. To vie ## What does this service advisory indicate? -The service advisories for eDiscovery throttling inform admins about their tenant being throttled due to number of Search and Export jobs exceeding the limit set by Microsoft. Various limits are applied to eDiscovery search tools in the [Microsoft Purview](~/compliance/index.yml) compliance portal. This includes searches run on the [Content Search](~/compliance/search-for-content.md) page and searches that are associated with an eDiscovery case on the [eDiscovery (Standard)](~/compliance/get-started-core-ediscovery.md) page. These limits help to maintain the health and quality of services provided to organizations. These advisories provide awareness so that you can take these limits into consideration when planning, running, and troubleshooting eDiscovery searches and exports. +The service advisories for eDiscovery throttling inform admins about their tenant being throttled due to number of Search and Export jobs exceeding the limit set by Microsoft. Various limits are applied to eDiscovery search tools in the [Microsoft Purview](~/compliance/index.yml) Microsoft Purview portal. This includes searches run on the [Content Search](~/compliance/search-for-content.md) page and searches that are associated with an eDiscovery case on the [eDiscovery (Standard)](~/compliance/get-started-core-ediscovery.md) page. These limits help to maintain the health and quality of services provided to organizations. These advisories provide awareness so that you can take these limits into consideration when planning, running, and troubleshooting eDiscovery searches and exports. For limits related to the Microsoft Purview eDiscovery (Standard) tool, see [Limits for Content search and eDiscovery (Standard) in the compliance center](~/compliance/limits-for-content-search.md?viewFallbackFrom=o365-worldwide%20for%20service%20limits). diff --git a/microsoft-365/enterprise/microsoft-365-vpn-stream-and-live-events.md b/microsoft-365/enterprise/microsoft-365-vpn-stream-and-live-events.md index e630fc009fb..558c6f7d957 100644 --- a/microsoft-365/enterprise/microsoft-365-vpn-stream-and-live-events.md +++ b/microsoft-365/enterprise/microsoft-365-vpn-stream-and-live-events.md @@ -53,16 +53,9 @@ To implement the forced tunnel exception for Teams Events, the following steps s Clients need external, recursive DNS resolution to be available so that the following host names can be resolved to IP addresses. For the **Commercial** cloud: -- \*.media.azure.net - \*.bmc.cdn.office.net - \*.ml.cdn.office.net -**\*.media.azure.net** and **\*.bmc.cdn.office.net** are used for Teams-produced Live Events (Quick Start events and RTMP-In supported events) scheduled from the Teams client. - -**\*.media.azure.net**, **\*.bmc.cdn.office.net** and **\*.ml.cdn.office.net** are used for Teams Town hall events. - -> [!NOTE] -> Some of these endpoints are shared with other elements outside of Teams events. For the **Government** clouds **(GCC, GCC High, DoD)**: - \*.cdn.ml.gcc.teams.microsoft.com @@ -376,7 +369,7 @@ function Get-TeamsEventsConfiguration { break } default { - @('*.bmc.cdn.office.net', '*.ml.cdn.office.net', '*.media.azure.net') + @('*.bmc.cdn.office.net', '*.ml.cdn.office.net') break } } diff --git a/microsoft-365/enterprise/modern-desktop-deployment-and-management-lab.md b/microsoft-365/enterprise/modern-desktop-deployment-and-management-lab.md index aeff0eba4f4..ad9ddd813a9 100644 --- a/microsoft-365/enterprise/modern-desktop-deployment-and-management-lab.md +++ b/microsoft-365/enterprise/modern-desktop-deployment-and-management-lab.md @@ -1,13 +1,13 @@ --- -title: Windows and Office 365 deployment lab kit +title: Windows and Microsoft 365 deployment lab kit description: Learn about where to access the Windows and Office deployment lab kit. f1.keywords: - NOCSH ms.author: aaroncz author: cdmm12 manager: aaroncz -ms.reviewer: alainme -ms.date: 03/24/2025 +ms.reviewer: hdhaliwal +ms.date: 04/10/2025 ms.audience: ITPro ms.topic: install-set-up-deploy ms.service: microsoft-365-enterprise @@ -18,11 +18,11 @@ ms.collection: - Strat_O365_Enterprise --- -# Windows 11 and Office 365 deployment lab kit +# Windows 11 and Microsoft 365 deployment lab kit -The deployment lab kit for Windows 11 and Office 365 can help you plan, test, and validate your deployment and management of desktops. The labs in the kit include Windows 11 Enterprise, Microsoft 365 Apps, and use of Microsoft Intune and Microsoft Configuration Manager. This kit is highly recommended for organizations preparing for desktop upgrades. As an isolated environment, the lab is also ideal for exploring deployment tool updates and testing your deployment-related automation. +The deployment lab kit for Windows 11 and Microsoft 365 can help you plan, test, and validate your deployment and management of desktops. The labs in the kit include Windows 11 Enterprise, Microsoft 365 Apps, Microsoft Intune, and Microsoft Configuration Manager. This kit is highly recommended for organizations preparing for desktop upgrades. As an isolated environment, the lab is also ideal for exploring deployment tool updates and testing your deployment-related automation. -[**Download the Windows 11 and Office 365 lab kit**](https://info.microsoft.com/ww-landing-windows-11-office-365-lab-kit.html) +[**Download the Windows 11 and Microsoft 365 lab kit**](https://info.microsoft.com/ww-landing-windows-11-office-365-lab-kit.html) ## A complete lab environment diff --git a/microsoft-365/enterprise/multi-geo-ediscovery-configuration.md b/microsoft-365/enterprise/multi-geo-ediscovery-configuration.md index 8e1590bcd58..e6a9f192f27 100644 --- a/microsoft-365/enterprise/multi-geo-ediscovery-configuration.md +++ b/microsoft-365/enterprise/multi-geo-ediscovery-configuration.md @@ -25,9 +25,9 @@ description: Learn how to use the Region parameter to configure eDiscovery for u Without eDiscovery (Premium) capabilities, an eDiscovery manager or administrator of a Multi-Geo _Tenant_ will be able to conduct eDiscovery only in the _Primary Provisioned Geography_ location of that _Tenant_. To support the ability to conduct eDiscovery for _Satellite Geography_ locations, a new compliance security filter parameter named "Region" is available via PowerShell. This parameter can be used by _Tenants_ whose _Primary Provisioned Geography_ location is in North America, Europe, or Asia Pacific. eDiscovery (Premium) is recommended for _Tenants_ whose _Primary Provisioned Geography_ location isn't in North America, Europe, or Asia Pacific and who need to perform eDiscovery across _Satellite Geography_ locations. -A member of the **Organization Management** role group or a user with the **Role Management** role must assign eDiscovery Manager permissions in the Microsoft Purview compliance portal to allow others to perform eDiscovery tasks and assign a "Region" parameter in their applicable Compliance Security Filter to specify the _Geography_ for conducting eDiscovery as _Satellite Geography_ location. Otherwise, no eDiscovery activities will be carried out for the _Satellite Geography_ location. Only one "Region" security filter per user is supported. +A member of the **Organization Management** role group or a user with the **Role Management** role must assign eDiscovery Manager permissions in the Microsoft Purview portal to allow others to perform eDiscovery tasks and assign a "Region" parameter in their applicable Compliance Security Filter to specify the _Geography_ for conducting eDiscovery as _Satellite Geography_ location. Otherwise, no eDiscovery activities will be carried out for the _Satellite Geography_ location. Only one "Region" security filter per user is supported. -See [Assign eDiscovery permissions in the compliance portal](/purview/ediscovery-assign-permissions#before-you-assign-permissions) for more information. To configure the Compliance Security Filter for a Region, see [Configure Office 365 Multi-Geo eDiscovery](multi-geo-ediscovery-configuration.md). +See [Assign eDiscovery permissions in the Microsoft Purview portal](/purview/ediscovery-assign-permissions#before-you-assign-permissions) for more information. To configure the Compliance Security Filter for a Region, see [Configure Office 365 Multi-Geo eDiscovery](multi-geo-ediscovery-configuration.md). When the eDiscovery Manager or Administrator role is set for a particular _Satellite Geography_ location, the eDiscovery Manager or Administrator will only be able to perform eDiscovery search actions against the SharePoint sites and OneDrive sites located in that _Satellite Geography_ location. If an eDiscovery Manager or Administrator attempts to search SharePoint or OneDrive sites outside the specified _Satellite Geography_ location, no results will be returned. Also, when the eDiscovery Manager or Administrator for a _Satellite Geography_ location triggers an export, data is exported to the Azure instance of that region. This helps organizations stay in compliance by not allowing content to be exported across controlled borders. diff --git a/microsoft-365/enterprise/network-planning-and-performance.md b/microsoft-365/enterprise/network-planning-and-performance.md index 666c053c1bc..10d684292f3 100644 --- a/microsoft-365/enterprise/network-planning-and-performance.md +++ b/microsoft-365/enterprise/network-planning-and-performance.md @@ -3,7 +3,7 @@ title: "Network planning and performance tuning for Microsoft 365" ms.author: kvice author: kelleyvice-msft manager: scotv -ms.date: 03/15/2024 +ms.date: 04/09/2025 audience: Admin ms.topic: article ms.service: microsoft-365-enterprise diff --git a/microsoft-365/enterprise/office-365-network-mac-location-services.md b/microsoft-365/enterprise/office-365-network-mac-location-services.md index ae3c49cb740..16657253098 100644 --- a/microsoft-365/enterprise/office-365-network-mac-location-services.md +++ b/microsoft-365/enterprise/office-365-network-mac-location-services.md @@ -3,7 +3,7 @@ title: "Microsoft 365 Network Connectivity Location Services" ms.author: kvice author: kelleyvice-msft manager: scotv -ms.date: 04/05/2024 +ms.date: 04/09/2025 audience: Admin ms.topic: article ms.service: microsoft-365-enterprise @@ -22,7 +22,9 @@ description: "Microsoft 365 Network Connectivity Location Services" # Microsoft 365 Network Connectivity Location Services -The Microsoft 365 admin center now shows **Network Insights and performance recommendations**, which are live performance metrics that are collected from your Microsoft 365 tenant. These metrics can only be viewed by administrative users in your tenant. Organizational network connectivity is designed per office location through a network egress location to the Internet. Microsoft 365 client connectivity uses that route and then across the Internet to Microsoft service front door servers. Identifying office locations is key to being able to show these network insights. +The Microsoft 365 admin center now shows **Network Insights and performance recommendations**, which are live performance metrics that are collected from your Microsoft 365 tenant. These metrics can only be viewed by administrative users in your tenant from **Health | Network Connectivity** in the Microsoft 365 Admin Center. For more information about the Network Connectivity tool, see [Network connectivity in the Microsoft 365 Admin Center](office-365-network-mac-perf-overview.md). + +Organizational network connectivity is designed per office location through a network egress location to the Internet. Microsoft 365 client connectivity uses that route and then across the Internet to Microsoft service front door servers. Identifying office locations is key to being able to show these network insights. ## Location in network measurements @@ -30,7 +32,7 @@ An organization's administrator can opt in for location to be included in the ne ## Location in the Microsoft 365 Admin Center -In the Microsoft 365 admin center, Bing map controls are used to show where organization office locations are. The controls also show network perimeter topology for a selected office location. When an administrator adds specific address details for office locations, Bing Maps is also used to suggest addresses to make data entry easier. +In the Microsoft 365 admin center, you can access this information by going to **Health | Network Connectivity**. Bing map controls are used to show where organization office locations are. The controls also show network perimeter topology for a selected office location. When an administrator adds specific address details for office locations, Bing Maps is also used to suggest addresses to make data entry easier. ## Terms of Use diff --git a/microsoft-365/enterprise/office-365-network-mac-perf-insights.md b/microsoft-365/enterprise/office-365-network-mac-perf-insights.md index b405af25437..e0f33d35bed 100644 --- a/microsoft-365/enterprise/office-365-network-mac-perf-insights.md +++ b/microsoft-365/enterprise/office-365-network-mac-perf-insights.md @@ -25,6 +25,9 @@ Network insights are actionable issues that might affect user experience when u Insights are intended to help address issues at your network perimeters for your office locations. Each insight provides live details about a specific issue for each geographic location where users are accessing your tenant. +> [!TIP] +> Admins can now view Service health notifications in Microsoft 365 admin center for Network insights detected for their tenant. You may also receive an email if you opted to receive email notifications. The service health notification has a deep link that takes you directly to the detected network insight for your tenant. You will receive one notification per insight detected. + These are network insights that might be shown for each office location: #### 1. Your connectivity to critical Microsoft 365 domains is failing diff --git a/microsoft-365/enterprise/prepare-for-directory-synchronization.md b/microsoft-365/enterprise/prepare-for-directory-synchronization.md index 6f28431200e..4ac4e40666b 100644 --- a/microsoft-365/enterprise/prepare-for-directory-synchronization.md +++ b/microsoft-365/enterprise/prepare-for-directory-synchronization.md @@ -47,9 +47,6 @@ However, directory synchronization requires planning and preparation to ensure t Follow these steps in order for the best results. -> [!NOTE] -> Non-ASCII characters don't sync for any attributes on the AD DS user account. - ## AD DS Preparation To help ensure a seamless transition to Microsoft 365 by using synchronization, you must prepare your AD DS forest before you begin your Microsoft 365 directory synchronization deployment. diff --git a/microsoft-365/enterprise/protect-your-global-administrator-accounts.md b/microsoft-365/enterprise/protect-your-global-administrator-accounts.md index ee63c1ac8e5..46bba1774b9 100644 --- a/microsoft-365/enterprise/protect-your-global-administrator-accounts.md +++ b/microsoft-365/enterprise/protect-your-global-administrator-accounts.md @@ -146,7 +146,7 @@ For more information, see [Learn about privileged access management](/microsoft- ### Security information and event management (SIEM) software for Microsoft 365 logging -SIEM software run on a server performs real-time analysis of security alerts and events created by applications and network hardware. To allow your SIEM server to include Microsoft 365 security alerts and events in its analysis and reporting functions, integrate Microsoft Entra ID into your SEIM. See [Introduction to Azure Log Integration](/azure/security/security-azure-log-integration-overview). +SIEM software run on a server performs real-time analysis of security alerts and events created by applications and network hardware. To allow your SIEM server to include Microsoft 365 security alerts and events in its analysis and reporting functions, integrate Microsoft Entra ID into your SIEM environment. See [Introduction to Azure Log Integration](/azure/security/security-azure-log-integration-overview). ## Next step diff --git a/microsoft-365/enterprise/setup-guides-for-microsoft-365.md b/microsoft-365/enterprise/setup-guides-for-microsoft-365.md index 13b526d002b..725262fe4bc 100644 --- a/microsoft-365/enterprise/setup-guides-for-microsoft-365.md +++ b/microsoft-365/enterprise/setup-guides-for-microsoft-365.md @@ -87,7 +87,7 @@ Advanced deployment guides in the admin center require authentication to a Micro |Guide - [Setup Portal](https://go.microsoft.com/fwlink/?linkid=2220880) |Guide - [Admin Center](https://go.microsoft.com/fwlink/?linkid=2224913) |Description | |---------|---------|---------| -| | [Configure multi-factor authentication (MFA) guide](https://go.microsoft.com/fwlink/?linkid=2224780) |The Configure multifactor authentication (MFA) guide provides customers who have the Microsoft Entra ID P1 or Microsoft Entra ID P2 license with customizable Conditional Access templates that include the most common and least intrusive security standards. Customers with the P2 license can also use risk-based Conditional Access policies. Customers without a P1 or P2 license can use a one-click solution to enable security defaults, a baseline protection policy for all users. They can also enable legacy (per-user) MFA.| +|| [Configure multi-factor authentication (MFA) guide](https://go.microsoft.com/fwlink/?linkid=2258035) | The **Configure multi-factor authentication (MFA) guide** provides customers with Microsoft Entra ID P1 or Microsoft Entra ID P2 customizable Conditional Access templates that include the most common and least intrusive security standards. When Microsoft Entra ID P1 or P2 licensing isn’t available, we provide a one-click solution to enable Security Defaults, a baseline protection policy for all users, or we provide steps to enable legacy (per-user) MFA. | ||[Identity security for Teams guide](https://go.microsoft.com/fwlink/?linkid=2224786)|The **Identity security for Teams guide** helps you with some basic security steps you can take to ensure your users are safe and have the most productive time using Teams.| |[Microsoft Entra setup guide](https://go.microsoft.com/fwlink/?linkid=2223229)|[Microsoft Entra setup guide](https://go.microsoft.com/fwlink/?linkid=2224193)|The **Microsoft Entra setup guide** provides information to ensure your organization has a strong security foundation. In this guide you'll set up initial features, like Azure Role-based access control (Azure RBAC) for admins, Microsoft Entra Connect for your on-premises directory, and Microsoft Entra Connect Health, so you can monitor your hybrid identity's health during automated syncs.
It also includes essential information on enabling self-service password resets, conditional access, and integrated third party sign-on including optional advanced identity protection and user provisioning automation.| |[Add or sync users to Microsoft Entra ID guide](https://go.microsoft.com/fwlink/?linkid=2223230)|[Add or sync users to Microsoft Entra ID guide](https://go.microsoft.com/fwlink/?linkid=2224811)|The **Add or sync users to Microsoft Entra ID guide** will help streamline the process of getting your user accounts set up in Microsoft 365. Based on your environment and needs, you can choose to add users individually, migrate your on-premises directory with Microsoft Entra Cloud Sync or Microsoft Entra Connect, or troubleshoot existing sync problems when necessary.| @@ -115,6 +115,7 @@ Advanced deployment guides in the admin center require authentication to a Micro |[Microsoft Defender for Cloud Apps setup guide](https://go.microsoft.com/fwlink/?linkid=2222969)|[Microsoft Defender for Cloud Apps setup guide](https://go.microsoft.com/fwlink/?linkid=2224814)|The **Microsoft Defender for Cloud Apps setup guide** provides easy to follow deployment and management guidance to set up your Cloud Discovery solution. With Cloud Discovery, you'll integrate your supported security apps, and then you'll use traffic logs to dynamically discover and analyze the cloud apps that your organization uses. You'll also set up features available through the Defender for Cloud Apps solution, including threat detection policies to identify high-risk use, information protection policies to define access, and real-time session controls to monitor activity. With these features, your environment gets enhanced visibility, control over data movement, and analytics to identify and combat cyberthreats across all your Microsoft and third party cloud services.| |[Microsoft Purview Auditing solutions in Microsoft 365 guide](https://go.microsoft.com/fwlink/?linkid=2223153)|[Microsoft 365 Auditing solutions in Microsoft 365 guide](https://go.microsoft.com/fwlink/?linkid=2224816)|The **Microsoft Purview Auditing solutions in Microsoft 365 guide** provides an integrated solution to help organizations effectively respond to security events, forensic investigations, and compliance obligations. When you use the auditing solutions in Microsoft 365, you can search the audit log for activities performed in different Microsoft 365 services.| |[Microsoft Purview eDiscovery solutions setup guide](https://go.microsoft.com/fwlink/?linkid=2223416)|[Microsoft Purview eDiscovery solutions setup guide](https://go.microsoft.com/fwlink/?linkid=2224465)|eDiscovery is the process of identifying and delivering electronic information that can be used as evidence in legal cases. The **Microsoft Purview eDiscovery solutions setup guide** assists in the use of eDiscovery tools in Microsoft Purview that allow you to search for content in Exchange Online, OneDrive for Business, SharePoint Online, Microsoft Teams, Microsoft 365 Groups, and Viva Engage communities.| +|[Secure by default with Purview](https://go.microsoft.com/fwlink/?linkid=2310737)|[Secure by default with Purview](https://go.microsoft.com/fwlink/?linkid=2310839)|Microsoft Purview's "secure by default" deployment model enhances data protection through encryption and configured sensitivity labels. This approach simplifies compliance and strengthens security across your organization's data estate with label publishing defaults, auto-labeling, and contextual defaults in SharePoint to achieve high labeling volumes with minimal user interaction.| ## Guides for collaboration diff --git a/microsoft-365/enterprise/turn-off-directory-synchronization.md b/microsoft-365/enterprise/turn-off-directory-synchronization.md index 08fd83fe548..ee39753e97a 100644 --- a/microsoft-365/enterprise/turn-off-directory-synchronization.md +++ b/microsoft-365/enterprise/turn-off-directory-synchronization.md @@ -30,17 +30,17 @@ description: In this article, find information about using PowerShell to turn of # Turn off directory synchronization for Microsoft 365 -You can use PowerShell to turn off directory synchronization and convert your synchronized users to cloud-only. However, it isn't recommended that you turn off directory synchronization as a troubleshooting step. If you need assistance with troubleshooting directory synchronization, see the [Fixing problems with directory synchronization for Microsoft 365](fix-problems-with-directory-synchronization.md) article. +You can use PowerShell to turn off directory synchronization and convert your synchronized users and groups to cloud-only. However, it isn't recommended that you turn off directory synchronization as a troubleshooting step. If you need assistance with troubleshooting directory synchronization, see the [Fixing problems with directory synchronization for Microsoft 365](fix-problems-with-directory-synchronization.md) article. [Contact support](https://support.office.com/article/32a17ca7-6fa0-4870-8a8d-e25ba4ccfd4b) if you need help with this procedure. > [!NOTE] > If your goal is to permanently disable synchronization in the tenant, you should first uninstall the synchronization client (such as Connect Sync or Cloud Sync). -> Disabling synchronization before uninstalling the sync client might result in the Entra Id Portal showing directory synchronization as **disabled**, but optional features such as Password Hash Synchronization show as **enabled**. Although this should not cause any issues, and the optional feature would not work when directory synchronization is disabled, it may lead to an unexpected status in the Portal. +> Disabling synchronization before uninstalling the sync client might result in the Entra Id Portal showing directory synchronization as **disabled**, but optional features such as Password Hash Synchronization show as **enabled**. Although this shouldn't cause any issues, and the optional feature wouldn't work when directory synchronization is disabled, it may lead to an unexpected status in the Portal. ## Turn off directory synchronization -To turn off Directory synchronization: +To turn off directory synchronization: 1. First, install the required software and connect to your Microsoft 365 subscription. For instructions, see [Connect with the Microsoft Graph PowerShell module for Windows PowerShell](/microsoft-365/enterprise/connect-to-microsoft-365-powershell#connect-with-microsoft-graph-powershell). diff --git a/microsoft-365/enterprise/use-the-centralized-deployment-powershell-cmdlets-to-manage-add-ins.md b/microsoft-365/enterprise/use-the-centralized-deployment-powershell-cmdlets-to-manage-add-ins.md index 236b6692bb4..7bf82e313d1 100644 --- a/microsoft-365/enterprise/use-the-centralized-deployment-powershell-cmdlets-to-manage-add-ins.md +++ b/microsoft-365/enterprise/use-the-centralized-deployment-powershell-cmdlets-to-manage-add-ins.md @@ -28,9 +28,14 @@ description: "Use the Centralized Deployment PowerShell cmdlets to help you depl # Use the Centralized Deployment PowerShell cmdlets to manage add-ins -As a Microsoft 365 user admin, you can deploy Office Add-ins to users via the Centralized Deployment feature (see [Deploy Office Add-ins in the admin center](../admin/manage/manage-deployment-of-add-ins.md)). In addition to deploying Office Add-ins via the Microsoft 365 admin center, you can also use Microsoft PowerShell. Install the [O365 Centralized Add-In Deployment Module for Windows PowerShell](https://www.powershellgallery.com/packages/O365CentralizedAddInDeployment). +As a Microsoft 365 global admin, you can deploy Office Add-ins to users via the Centralized Deployment feature (see [Deploy Office Add-ins in the admin center](../admin/manage/manage-deployment-of-add-ins.md). In addition to deploying Office Add-ins via the Microsoft 365 admin center, you can also use Microsoft PowerShell. -After you download the module, open a regular Windows PowerShell window and run the following cmdlet: +Open a regular Windows PowerShell window and run the following cmdlet to install the module: + +```powershell +Install-Module -Name O365CentralizedAddInDeployment +``` +Run the following cmdlet to import the module: ```powershell Import-Module -Name O365CentralizedAddInDeployment diff --git a/microsoft-365/frontline/TOC.yml b/microsoft-365/frontline/TOC.yml index 04a19c2beb9..3f28e90e337 100644 --- a/microsoft-365/frontline/TOC.yml +++ b/microsoft-365/frontline/TOC.yml @@ -32,8 +32,8 @@ items: href: flw-setup-microsoft-365.md - name: Choosing between dynamic and static frontline teams href: frontline-team-options.md - - name: Deploy frontline dynamic teams at scale - href: deploy-dynamic-teams-at-scale.md + - name: Deploy frontline teams with flexible membership + href: deploy-flexible-membership-teams-at-scale.md - name: Deploy frontline static teams at scale with PowerShell href: deploy-teams-at-scale.md - name: Frontline usage reporting diff --git a/microsoft-365/frontline/deploy-dynamic-teams-at-scale.md b/microsoft-365/frontline/deploy-dynamic-teams-at-scale.md deleted file mode 100644 index dcde5e234c7..00000000000 --- a/microsoft-365/frontline/deploy-dynamic-teams-at-scale.md +++ /dev/null @@ -1,228 +0,0 @@ ---- -title: Deploy frontline dynamic teams at scale -author: lana-chin -ms.author: jtremper -manager: jtremper -ms.reviewer: arnavgupta, aaglick -ms.topic: how-to -audience: admin -ms.service: microsoft-365-frontline -search.appverid: MET150 -description: Learn how to deploy dynamic teams at scale for your organization. -ms.localizationpriority: medium -ms.collection: - - M365-collaboration - - m365-frontline -appliesto: - - Microsoft Teams - - Microsoft 365 for frontline workers -ms.date: 09/13/2024 - ---- - -# Deploy frontline dynamic teams at scale - -## Overview - -Frontline teams are a collection of people, content, and tools within an organization for different frontline worker locations. Membership of frontline dynamic teams is determined and managed by a set of Microsoft Entra attributes. [Learn more about Microsoft Entra attributes](/azure/active-directory/external-identities/customers/how-to-define-custom-attributes). - -In the setup process, you define the following information with Microsoft Entra attributes: - -- Who your frontline workers are -- What locations they work at -- Department and job titles of your frontline workers (optional) - -You also determine team structure and team owners. - -Then, you can choose which locations you want to create dynamic frontline teams for. - -Team membership is automatically managed over time through the power of dynamic teams. As frontline workers are onboarded and offboarded, and as they change locations, their memberships in these teams are updated accordingly. - -Check out this [Microsoft Mechanics video](https://www.youtube.com/watch?v=gdkTnPdIRS4&t=461s) for an overview of how to set up and deploy your frontline dynamic teams. - -> [!NOTE] -> If you would like to provide feedback and improve this feature, please fill out [this form](https://forms.microsoft.com/r/DWaJXA6Dax). - -## Before you begin - -### Prerequisites - -- Users must have a Microsoft 365 F3, F1, E3, or E5 license. If a user doesn't have one of these licenses, they need a Microsoft Entra ID P1 add-on license to use dynamic teams. [Learn more about frontline licensing](flw-licensing-options.md). -- Ensure you can define your frontline workers and their work locations through data available in Microsoft Entra ID. If you don't have this data in Microsoft Entra ID, you can sync it through a [human capital management (HCM) connector](/azure/active-directory/app-provisioning/plan-cloud-hr-provision) or [use the PowerShell solution](deploy-teams-at-scale.md) to create static teams at scale. -- If you want to enable [targeted communications](set-up-targeted-communications.md), ensure you can map the attributes of your frontline workers through data available in Microsoft Entra ID. If user profile information doesn’t yet include job title or department, you can add it. [Learn more about how to add or update a user’s profile information in Microsoft Entra ID](/entra/fundamentals/how-to-manage-user-profile-info). - -### Admin role to run the deployment - -To complete the steps in this article, you must be a Global Administrator or a Teams Administrator who is assigned a custom role (as described in this section) in Microsoft Entra ID with specific permissions. - -> [!IMPORTANT] -> Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use a less-privileged role. - -To give Teams Administrators the ability to complete setup and deploy frontline dynamic teams, follow these steps to create the custom role and assign it to Teams Administrators. - -#### Create the custom role - -1. Sign in to the Microsoft Entra admin center as at least a [Privileged Role Administrator](/entra/identity/role-based-access-control/permissions-reference#privileged-role-administrator). -1. Go to the [Roles and administrators](https://entra.microsoft.com/#view/Microsoft_AAD_IAM/RolesManagementMenuBlade/~/AllRoles) page, and then select **New custom role**. -1. On the **Basics** tab: - 1. Provide a name for the role. Optionally, enter a description. - 1. Make sure **Baseline permissions** is set to **Start from scratch** (the default setting). -1. On the **Permissions** tab, select the following permissions: - - **microsoft.directory/groups/create** - - **microsoft.directory/groups/dynamicMembershipRule/update** - - **microsoft.directory/servicePrincipals/create** -1. On the **Review + create** tab, review the role definition, and then choose **Create**. - - :::image type="content" source="media/dtas-custom-role.png" alt-text="Screenshot of the Review + create tab for reviewing the role definition of the new custom role." lightbox="media/dtas-custom-role.png"::: - -#### Assign the custom role - -1. Sign in to the Microsoft Entra admin center as at least a [Privileged Role Administrator](/entra/identity/role-based-access-control/permissions-reference#privileged-role-administrator). -1. Go to the [Roles and administrators](https://entra.microsoft.com/#view/Microsoft_AAD_IAM/RolesManagementMenuBlade/~/AllRoles) page, and then select the name of the new custom role you created. -1. Choose **Add assignments**. -1. Under **Select member(s)**, choose **No member selected**. - - :::image type="content" source="media/dtas-custom-role-members.png" alt-text="Screenshot of the No member selected option."::: -1. Select the Teams Administrators to which you want to assign the custom role. Choose **Next**. -1. On the **Setting** tab, set **Assignment type** as **Active**. - - :::image type="content" source="media/dtas-custom-role-assignment-type.png" alt-text="Screenshot of the Setting tab, showing assignment type and justification."::: -1. Provide a justification, and then choose **Assign**. - -## Set up your frontline dynamic teams - -1. In the left navigation of the [Teams admin center](https://admin.teams.microsoft.com), choose **Frontline deployment** > **Manage frontline teams**. -2. In the table, choose **Set up**. - - :::image type="content" source="media/dtas-manage-setup.png" alt-text="Screenshot of the Manage frontline teams page, showing the Set up button." lightbox="media/dtas-manage-setup.png"::: - -1. Review the setup and prerequisites information. - -1. On the Identify your frontline workers page, select the Microsoft Entra attribute that defines your frontline workers. You can only choose one Microsoft Entra attribute, but you can define multiple values by separating them with commas. - - :::image type="content" source="media/dtas-frontline-worker-attribute.png" alt-text="Screenshot showing where to enter your Microsoft Entra attribute and values to identify your frontline workforce." lightbox="media/dtas-frontline-worker-attribute.png"::: - -1. On the Location page, select a Microsoft Entra attribute or a [custom user attribute](/entra/external-id/user-flow-add-custom-attributes) that defines the location your frontline employees work in. You can only choose one location attribute. - - All custom attributes are case sensitive and must start with an "extension_" prefix. Only custom attributes of the String data type are supported. - - :::image type="content" source="media/dtas-location-attribute.png" alt-text="Screenshot showing where to enter your Microsoft Entra attribute that identifies the location where your frontline employees work." lightbox="media/dtas-location-attribute.png"::: - -1. On the Team settings page, define a naming pattern for your teams by choosing a prefix. The prefix is applied using the "prefix-location" format to all your teams. - - :::image type="content" source="media/dtas-team-settings.png" alt-text="Screenshot of team settings options showing the prefix, team template, and team owner fields." lightbox="media/dtas-team-settings.png"::: - -1. Optionally, choose a team template. The team template you choose defines the channel structure for all your frontline teams. [Learn more about team templates](/microsoftteams/get-started-with-teams-templates-in-the-admin-console). - - > [!NOTE] - > Currently, only team templates that are set to the English (United States) locale are supported. Keep in mind that the locale doesn't affect translation of the template or data residency. The locale setting is used only to distinguish between templates that have the same name that are created in different languages. - -1. Enter the object ID of the user account who you want as the team owner. This account will be the owner of all frontline teams. We recommend you choose a shared account rather than an individual person. - 1. To get a user's object ID, go to the [Azure portal](https://portal.azure.com). - 1. Select **Microsoft Entra ID**. - 1. Select **Users**, and then choose your user. - 1. Copy the user's object ID. - - > [!NOTE] - > After your teams are deployed, you can also add more team owners through the [PowerShell solution](deploy-teams-at-scale.md) or by using any other manual methods. - -1. On the Map frontline attributes page, select the Microsoft Entra attributes that most accurately reflect the departments and job titles in your organization. You can set the **Department attribute**, **Job title attribute**, or both. - - > [!NOTE] - > This step is optional. If you choose not to map frontline attributes, leave the values as **None**. You can always come back and map them later on the [Dynamic teams settings page](#edit-your-frontline-team-settings). - - :::image type="content" source="media/dtas-frontline-attributes.png" alt-text="Screenshot showing where to map your Microsoft Entra attributes for Job title and Department." lightbox="media/dtas-frontline-attributes.png"::: - - These attributes map departments and job titles in your organization, which allows you to deliver targeted communications features, such as [automatic tags](set-up-targeted-communications.md#automatic-tags), to your frontline. Your frontline workers can quickly and easily reach the right group of people through tags that are automatically created based on the attribute mappings. [Learn more about attribute mapping and targeted communications](set-up-targeted-communications.md). - -1. Review your settings, and then choose **Finish setup.** - - :::image type="content" source="media/dtas-setup-submitted.png" alt-text="Screenshot of the Manage frontline teams page with a banner showing that setup is in progress." lightbox="media/dtas-setup-submitted.png"::: - - > [!NOTE] - > Setup can take several hours to run. Refresh the Manage frontline teams page to get the latest status. - -## Deploy your frontline dynamic teams - -1. After setup is completed, go to the Manage frontline teams page, and then select the **Deploy** button. - - :::image type="content" source="media/dtas-deploy.png" alt-text="Screenshot of the Manage frontline teams page, showing the Deploy button." lightbox="media/dtas-deploy.png"::: - -1. From here, you can review your settings and view the list of locations that don't yet have a frontline dynamic team created. - -1. In the table, select the locations that you want to create teams for. - - :::image type="content" source="media/dtas-deploy-locations.png" alt-text="Screenshot of the table of locations." lightbox="media/dtas-deploy-locations.png"::: - -1. Select **Deploy**. This process can take several hours depending on how many teams you're creating. - - After deployment is completed, you'll see the number of deployed frontline teams in the **Frontline teams** card. You can also download a CSV file with a list of those teams. - - :::image type="content" source="media/dtas-deploy-completed.png" alt-text="Screenshot of where you can get the CSV file on the Manage frontline teams page." lightbox="media/dtas-deploy-completed.png"::: - - If an error occurred during the deployment process, you can download the error CSV file on the **Last deployment health** card. Use the information in it to help resolve the errors, and then rerun the deployment experience - -1. You can repeat this process for any frontline locations that don't have a team. - -## Managing your frontline dynamic teams - -You can manage your teams when changes happen in your organization. - -### Create new teams for newly opened locations - -1. In the left navigation of the [Teams admin center](https://admin.teams.microsoft.com), choose **Frontline deployment** > **Manage frontline teams**. - -1. In the table, choose **Deploy**. - -1. Select the **Refresh location** button, and then proceed when prompted by the dialog box. This process can take several hours depending on your number of new locations. - - :::image type="content" source="media/dtas-refresh-locations.png" alt-text="Screenshot of the Refresh location button." lightbox="media/dtas-refresh-locations.png"::: - -1. After the refresh is completed, your setup status shows as **Complete**. You can proceed to [deploy your new teams](#deploy-your-frontline-dynamic-teams). Deployment can take several hours depending on how many new teams you're deploying. - -### Edit your frontline team settings - -1. In the left navigation of the [Teams admin center](https://admin.teams.microsoft.com), choose **Frontline deployment** > **Manage frontline teams**. -1. In the **Deployment settings** column, choose **Deploy teams with dynamic membership**. -1. On the Dynamic teams settings page, edit your settings, and then select **Apply**. Your settings might take several hours to update. - - :::image type="content" source="media/dtas-edit-settings.png" alt-text="Screenshot of the Dynamic teams settings page, showing options to edit frontline team settings" lightbox="media/dtas-edit-settings.png"::: - - See the following table for the effects of updating your settings. - - |Setting |Effect on existing frontline teams |Effect on new frontline teams | - |--------|-----------------------------------|------------------------------| - |Define your frontline worker attribute. |All existing frontline teams will be members that have the new Microsoft Entra attribute defined. |All new frontline teams members will have the new Microsoft Entra attribute defined. | - |Choose the values applicable to your frontline Microsoft Entra attribute. |All existing frontline team members will reflect your updated values. |All new teams will be populated with members who have the updated Microsoft Entra attributes that you defined. | - |Map your frontline attributes for department and job title. |All existing frontline team members will reflect the Microsoft Entra attribute you defined for department and job title. |All new frontline team members will use the Microsoft Entra attribute you defined for department and job title.| - |Define your frontline locations. | Existing teams will continue to persist. If a team is no longer tied to a location, there will be no users in that team, and users are put in their respective location teams. |You can create new frontline teams based on the locations defined by your new Microsoft Entra attribute. | - |Set your team name prefix. |All existing team names will be updated to reflect the prefix and location name if that was changed. |All new teams will have the updated naming convention. | - |Select your team template. |No updates to the team structure will occur. |All new teams will use the updated team template. | - |Select your team owner. |The team owner will be updated for all existing teams. Team owners that were added through [PowerShell](deploy-teams-at-scale.md) or any other manual methods won't be removed.|All new teams will have the updated team owner.| - -## Get analytics on frontline teams usage - -The [Teams frontline usage report](frontline-usage-report.md) on the usage dashboard of the Manage frontline teams page gives you an overview of usage activity in Teams for each of your frontline locations. You can view data, such as the number of active users and last activity date, to quickly see how many users at your frontline locations are using Teams to communicate and collaborate. - -## Frequently asked questions - -### Why are channels missing when I create my teams? - -It can take time for channels to propagate in Teams. The General channel is created first and the remaining channels are added over time. All channels should be available within 24 hours of team creation. - -### How do I delete a frontline team? - -You can delete a team by using the [Teams client](https://support.microsoft.com/office/delete-a-team-in-microsoft-teams-c386f91b-f7e6-400b-aac7-8025f74f8b41), [Teams admin center](/microsoftteams/archive-or-delete-a-team), [PowerShell](/powershell/module/teams/remove-team), or [Graph](/graph/api/group-delete). - -Keep in mind that it can take up to 24 hours for a team and the Microsoft 365 group associated with the team to be fully deleted. - -If you need to redeploy a frontline location team that was deleted, follow these steps: - -1. [Refresh locations](#managing-your-frontline-dynamic-teams). -1. After the refresh is completed, choose the location you want to deploy. -1. Select **Deploy**. - -## Related articles - -- [Learn where to start with a frontline deployment](flw-deploy-overview.md) -- [How to find the best frontline team solution for your organization](frontline-team-options.md) diff --git a/microsoft-365/frontline/deploy-flexible-membership-teams-at-scale.md b/microsoft-365/frontline/deploy-flexible-membership-teams-at-scale.md new file mode 100644 index 00000000000..2644e60b68d --- /dev/null +++ b/microsoft-365/frontline/deploy-flexible-membership-teams-at-scale.md @@ -0,0 +1,171 @@ +--- +title: Deploy frontline teams with flexible membership +author: ducnguye +ms.author: jtremper +manager: jtremper +ms.reviewer: Vishal.Seshagirirao +ms.topic: how-to +audience: admin +ms.service: microsoft-365-frontline +search.appverid: MET150 +description: Learn how to deploy and manage frontline teams in bulk to drive collaboration for every location in your frontline workforce. +ms.localizationpriority: high +ms.collection: + - M365-collaboration + - m365-frontline + - highpri +appliesto: + - Microsoft Teams + - Microsoft 365 for frontline workers +ms.date: 04/24/2025 +--- + +# Deploy frontline teams with flexible membership + +## Overview + +Create and manage frontline teams in bulk to drive collaboration for every location in your frontline workforce. Team membership of your frontline teams is automatically synced with your frontline workers’ Microsoft Entra attributes. As team owners, frontline managers at each of your locations, like department heads, store leads, and warehouse managers, can manually add or remove members. + +> [!NOTE] +> If you would like to provide feedback and help improve this feature, fill out this [form](https://forms.office.com/r/MPfxrGG9h4). + +## How it works + +> [!VIDEO https://learn-video.azurefd.net/vod/player?id=da722184-92a5-4775-8585-d354a5c174c1] + +In the setup process, you: + +1. Select the frontline workers for who you want to create teams for by inputting groups from Microsoft Entra that include your frontline workers. + +2. Select an Entra attribute or custom extension attribute that represents where each frontline worker works to group them into location-based teams. + +3. Choose a team template to set a standardized set of Teams channels and apps for all your frontline teams. + +4. Select the frontline managers who should be team owners of their respective frontline teams by inputting groups from Microsoft Entra that include your frontline managers. + +After submitting your setup, you can view and select which locations you want to create frontline teams for. You can always go back and edit your frontline settings. +Team membership is automatically managed over time based on your frontline workers’ Microsoft Entra attributes provided in setup. As frontline workers enter and leave your organization or change locations, their memberships in these teams are updated accordingly. Additionally, frontline managers who are given the team owner role have the flexibility to add or remove frontline workers. + +> [!IMPORTANT] +> Changes that frontline managers make override any changes made based on Microsoft Entra attributes. Here are some examples: +> - User1 is added to a team based on their Entra attributes. The frontline manager of the team then manually removes user1. In this scenario, user1 won't be added to the team again unless the frontline manager manually adds user1 back to the team. +> - A frontline manager adds a user from the Location A team to their Location B team. In this scenario, the user is still a member of the Location A team based on their Entra attributes and now part of the Location B team by the manual addition. This user won't be removed from the Location B team unless the frontline manager manually removes the user. In this way, frontline workers can be part of multiple teams at the same time. +> - Owner1 is added to Location A team based on their Entra attributes. Owner1 gets transferred to a new Location B. Owner1 would be added to Location B as an owner. But Owner1 won’t be removed from Location A for business continuity purposes. + +## Before you begin + +### Admin role to run the deployment + +To complete the steps in this article, you must be a Global Administrator or a Teams Administrator. + +> [!IMPORTANT] +> Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to scenarios when you can't use a less-privileged role. + +### Prerequisites +- Admin using the Frontline Deployment tool must have a Microsoft 365 F1, F3, E3 or E5 license. +- Teams owners and users must have a Microsoft 365 F3, F1, E3, or E5 license. If a user doesn't have one of these licenses, they need a Microsoft Entra ID P1 add-on license. [Learn more](flw-licensing-options.md) about frontline licensing. +- Ensure you can define your frontline workers and managers and their work locations through data available in Microsoft Entra ID. If you don't have this data in Microsoft Entra ID, you can sync it through a human capital management (HCM) connector or use [the PowerShell solution](deploy-teams-at-scale.md) to create static teams at scale. + - All your frontline workers should be added to up to 32 groups in Microsoft Entra. + - All your frontline managers at each of your frontline locations should be added to up to 20 groups on Microsoft Entra. + - There must be one attribute consistent across all frontline workers and managers that represents their frontline location. + +## Set up your frontline teams + +> [!IMPORTANT] +> Team owners must have a Teams license. Before you use these steps to deploy your teams, make sure that all teams owners have a license. + +1. In the left navigation of the [Teams admin center](https://admin.teams.microsoft.com), choose **Frontline deployment** > **Manage frontline teams**. +2. In the table, choose **Set up**. + +:::image type="content" source="media/flw-teams-admin-center.png" alt-text="Screenshot showing how to manage frontline teams in Teams admin center." lightbox="media/flw-teams-admin-center.png"::: + +3. On the **Overview** page, review the setup and prerequisites information. +4. On the **Frontline workers** page, select the Entra groups that include your frontline workers. You can choose up to 10 Entra groups. You can change these groups, as needed, after you submit your setup. + +:::image type="content" source="media/dtas-add-frontline-groups.png" alt-text="Screenshot showing how to add frontline groups to frontline teams settings." lightbox="media/dtas-add-frontline-groups.png"::: + +5. On the **Location** page, select a Microsoft Entra attribute or a custom user attribute that defines the location your frontline employees work in. You can only choose one location attribute. You can change the attribute, as needed, after you submit your setup. For example, if you would like to create a team for each city, enter the “City” attribute and we will group frontline workers in the same city into teams. +All custom attributes are case sensitive and must start with an "extension_" prefix. Only custom attributes of the String data type are supported. + +:::image type="content" source="media/dtas-appoint-attr-for-location.png" alt-text="Screenshot showing how to choose the Microsoft Entra attribute to define location in an organization." lightbox="media/dtas-appoint-attr-for-location.png"::: + +6. On the **Team settings** page, define a naming pattern for your teams by choosing a prefix. The prefix is applied using the "prefix-location" format to all your teams. + +:::image type="content" source="media/dtas-select-team-template-prefix.png" alt-text="Screenshot showing how to choose a template for created team." lightbox="media/dtas-select-team-template-prefix.png"::: + +7. Choose a team template. The team template you choose defines the channel structure for all your frontline teams. [Learn more](/microsoftteams/get-started-with-teams-templates-in-the-admin-console) about team templates. +> [!NOTE] +> Currently, only team templates that are set to the English (United States) locale are supported. Keep in mind that the locale doesn't affect translation of the template or data residency. The locale setting is used only to distinguish between templates that have the same name that are created in different languages. +8. Select up to 10 Microsoft Entra groups that include at least one frontline worker from each location to be made team owner. +Every location you want to deploy must have at least one frontline worker set as team owner. Team owners can add or remove membership from their frontline teams. For example, team owners can be your frontline managers, department heads, and/or leads. +You can change these groups, as needed, after you submit your setup. +9. Review your settings, and then choose **Submit**. + +:::image type="content" source="media/dtas-review-summary.png" alt-text="Screenshot showing where you review selections and submit." lightbox="media/dtas-review-summary.png"::: + +> [!NOTE] +> Setup can take several hours to run. Refresh the **Manage frontline teams** page to get the latest status. + +## Deploy your frontline teams +1. After setup is completed, go to the **Manage frontline teams** page, and then select the **Deploy** button. + +:::image type="content" source="media/dtas-frontline-teams-deploy.png" alt-text="Screenshot for how to manage frontline teams for teams deployment." lightbox="media/dtas-frontline-teams-deploy.png"::: + +2. On the **Deploy frontline teams** page, you can review your settings and view the list of locations that don't yet have a frontline team created. +3. In the table, select the locations that you want to create teams for. + +:::image type="content" source="media/dtas-frontline-teams-for-deployment.png" alt-text="Screenshot selecting locations for a deployment." lightbox="media/dtas-frontline-teams-for-deployment.png"::: + +4. Select **Deploy**. This process can take several hours depending on how many teams you're creating. +After deployment is completed, you'll see the number of deployed frontline teams in the Frontline teams card. You can also download a CSV file with a list of those teams. +If an error occurred during the deployment process, you can download the error CSV file on the Deployment health card. Use the information in it to help resolve the errors, and then rerun the deployment experience. + +:::image type="content" source="media/dtas-manage-frontline-after-deploy.png" alt-text="Screenshot showing how to manage frontline teams after a teams deployment." lightbox="media/dtas-manage-frontline-after-deploy.png"::: + +5. You can repeat this process for any frontline locations that don't have a team. + +## Manage your frontline teams +You can manage your teams when changes happen in your organization. + +Create new teams for newly opened locations: +1. In the left navigation of the [Teams admin center](https://admin.teams.microsoft.com), choose **Frontline deployment** > **Manage frontline teams**. +2. In the table, choose **Deploy**. +3. Select the **Refresh location** button, and then proceed when prompted by the dialog box. This process can take several hours depending on the number of new locations. + +:::image type="content" source="media/dtas-refresh-frontline-teams.png" alt-text="Screenshot showing the refresh locations in deploy frontline teams page." lightbox="media/dtas-refresh-frontline-teams.png"::: + +4. After the refresh is completed, your setup status shows as Complete. You can proceed to deploy your new teams. Deployment can take several hours depending on how many new teams you're deploying. + +## Edit your frontline teams settings +1. In the left navigation of the [Teams admin center](https://admin.teams.microsoft.com), choose **Frontline deployment** > **Manage frontline teams**. +2. In the Deployment settings column, choose **Deploy frontline teams**. +3. On the **Frontline teams** settings page, edit your settings, and then select **Apply**. Your settings might take several hours to update. + +See the following table for the effects of updating your settings. + +| Setting | Effect on existing frontline teams | Effect on new frontline teams | +|---------|---------|---------| +| Frontline workers | All existing frontline teams will be updated with members that are part of the new groups you selected. Members added or removed by frontline managers won't be affected.| All new frontline teams members will include members that are part of the new groups you selected.| +| Location | Existing teams will continue to persist. If a team is no longer tied to a location, there will be no frontline workers in that team.| You can create new frontline teams based on the locations defined by your new Microsoft Entra attribute. | +| Map your frontline attributes | All existing frontline team members will reflect the Microsoft Entra attribute you defined for department and job title.| All new frontline team members will use the Microsoft Entra attribute you defined for department and job title. | +| Team settings - team name prefix | All existing team names will be updated to reflect the prefix and location name if it was changed. | All new teams will have the updated naming convention. | +| Team settings - team template | No updates to the team structure will occur. | All new teams will have the updated naming convention. | +| Identify your team owners | Frontline managers that were already assigned team owner won't be removed or reprieved of their team owner role. New team owners from the new groups you selected will be added as team owners to their respective teams. | All new teams will have team owners that are part of the new groups you selected. There must be at least one team owner for every new team. | + +:::image type="content" source="media/dtas-edit-frontline-settings.png" alt-text="Screenshot showing how to edit frontline teams settings." lightbox="media/dtas-edit-frontline-settings.png"::: + +## Get analytics on frontline teams usage +The [Teams frontline usage report](frontline-usage-report.md) on the usage dashboard of the Manage frontline teams page gives you an overview of usage activity in Teams for each of your frontline locations. You can view data, such as the number of active users and last activity date, to quickly see how many users at your frontline locations are using Teams to communicate and collaborate. + +## Frequently asked questions +### Why are channels missing when I create my teams? +It can take time for channels to propagate in Teams. The General channel is created first and the remaining channels are added over time. All channels should be available within 24 hours of team creation. +Why am I seeing 0 users while trying to deploy? +Seeing zero users next to a location name (ex. “Redmond”) in the deploy teams table indicates that there is a user in the provided owner groups with the specified location value (ex. Manager_A with city attribute equal to “Redmond”) but no users in the provided frontline worker groups has that same location value (i.e. no users with the city attribute equal to “Redmond”). The admin should reexamine their selected frontline groups or investigate if this is a data hygiene issue. + +### Why am I not seeing some locations? +The locations displayed in the deploy teams table are the list of unique location values from the users in the selected owner groups. This is to ensure the team deploys successfully as owners are mandatory. This means that an admin can create a team with only owners and no members as well (please see “Why am I seeing 0 users while trying to deploy?” FAQ for more information on this scenario). + +## Related articles +- [Learn where to start with a frontline deployment](flw-deploy-overview.md) +- [How to find the best frontline team solution for your organization](frontline-team-options.md) diff --git a/microsoft-365/frontline/media/dtas-add-frontline-groups.png b/microsoft-365/frontline/media/dtas-add-frontline-groups.png new file mode 100644 index 00000000000..95ae43d7504 Binary files /dev/null and b/microsoft-365/frontline/media/dtas-add-frontline-groups.png differ diff --git a/microsoft-365/frontline/media/dtas-appoint-attr-for-location.png b/microsoft-365/frontline/media/dtas-appoint-attr-for-location.png new file mode 100644 index 00000000000..fb1da574d8c Binary files /dev/null and b/microsoft-365/frontline/media/dtas-appoint-attr-for-location.png differ diff --git a/microsoft-365/frontline/media/dtas-edit-frontline-settings.png b/microsoft-365/frontline/media/dtas-edit-frontline-settings.png new file mode 100644 index 00000000000..103a2928439 Binary files /dev/null and b/microsoft-365/frontline/media/dtas-edit-frontline-settings.png differ diff --git a/microsoft-365/frontline/media/dtas-frontline-teams-deploy.png b/microsoft-365/frontline/media/dtas-frontline-teams-deploy.png new file mode 100644 index 00000000000..ff719261a7d Binary files /dev/null and b/microsoft-365/frontline/media/dtas-frontline-teams-deploy.png differ diff --git a/microsoft-365/frontline/media/dtas-frontline-teams-for-deployment.png b/microsoft-365/frontline/media/dtas-frontline-teams-for-deployment.png new file mode 100644 index 00000000000..317c2f9479a Binary files /dev/null and b/microsoft-365/frontline/media/dtas-frontline-teams-for-deployment.png differ diff --git a/microsoft-365/frontline/media/dtas-manage-frontline-after-deploy.png b/microsoft-365/frontline/media/dtas-manage-frontline-after-deploy.png new file mode 100644 index 00000000000..90a925923de Binary files /dev/null and b/microsoft-365/frontline/media/dtas-manage-frontline-after-deploy.png differ diff --git a/microsoft-365/frontline/media/dtas-refresh-frontline-teams.png b/microsoft-365/frontline/media/dtas-refresh-frontline-teams.png new file mode 100644 index 00000000000..219abad0f0c Binary files /dev/null and b/microsoft-365/frontline/media/dtas-refresh-frontline-teams.png differ diff --git a/microsoft-365/frontline/media/dtas-review-summary.png b/microsoft-365/frontline/media/dtas-review-summary.png new file mode 100644 index 00000000000..11221642bc9 Binary files /dev/null and b/microsoft-365/frontline/media/dtas-review-summary.png differ diff --git a/microsoft-365/frontline/media/dtas-select-team-template-prefix.png b/microsoft-365/frontline/media/dtas-select-team-template-prefix.png new file mode 100644 index 00000000000..29b9dc1b18e Binary files /dev/null and b/microsoft-365/frontline/media/dtas-select-team-template-prefix.png differ diff --git a/microsoft-365/frontline/media/flw-teams-admin-center.png b/microsoft-365/frontline/media/flw-teams-admin-center.png new file mode 100644 index 00000000000..9ec9a1e02fc Binary files /dev/null and b/microsoft-365/frontline/media/flw-teams-admin-center.png differ diff --git a/microsoft-365/includes/office-365-worldwide-endpoints.md b/microsoft-365/includes/office-365-worldwide-endpoints.md index af913dc3d34..96f922692f7 100644 --- a/microsoft-365/includes/office-365-worldwide-endpoints.md +++ b/microsoft-365/includes/office-365-worldwide-endpoints.md @@ -51,7 +51,7 @@ ID | Category | ER | Addresses | Ports 53 | Default
Required | No | `ajax.aspnetcdn.com, apis.live.net, officeapps.live.com, www.onedrive.com` | **TCP:** 443 56 | Allow
Required | Yes | `*.auth.microsoft.com, *.msftidentity.com, *.msidentity.com, account.activedirectory.windowsazure.com, accounts.accesscontrol.windows.net, adminwebservice.microsoftonline.com, api.passwordreset.microsoftonline.com, autologon.microsoftazuread-sso.com, becws.microsoftonline.com, ccs.login.microsoftonline.com, clientconfig.microsoftonline-p.net, companymanager.microsoftonline.com, device.login.microsoftonline.com, graph.microsoft.com, graph.windows.net, login-us.microsoftonline.com, login.microsoft.com, login.microsoftonline-p.com, login.microsoftonline.com, login.windows.net, logincert.microsoftonline.com, loginex.microsoftonline.com, nexus.microsoftonline-p.com, passwordreset.microsoftonline.com, provisioningapi.microsoftonline.com`
`20.20.32.0/19, 20.190.128.0/18, 20.231.128.0/19, 40.126.0.0/18, 2603:1006:2000::/48, 2603:1007:200::/48, 2603:1016:1400::/48, 2603:1017::/48, 2603:1026:3000::/48, 2603:1027:1::/48, 2603:1036:3000::/48, 2603:1037:1::/48, 2603:1046:2000::/48, 2603:1047:1::/48, 2603:1056:2000::/48, 2603:1057:2::/48` | **TCP:** 443, 80 59 | Default
Required | No | `*.hip.live.com, *.microsoftonline-p.com, *.microsoftonline.com, *.msauth.net, *.msauthimages.net, *.msecnd.net, *.msftauth.net, *.msftauthimages.net, *.phonefactor.net, enterpriseregistration.windows.net` | **TCP:** 443, 80 -64 | Allow
Required | Yes | `*.protection.office.com, *.security.microsoft.com, compliance.microsoft.com, defender.microsoft.com, protection.office.com, purview.microsoft.com, security.microsoft.com`
`13.107.6.192/32, 13.107.9.192/32, 2620:1ec:4::192/128, 2620:1ec:a92::192/128` | **TCP:** 443 +64 | Allow
Required | Yes | `*.protection.office.com, *.security.microsoft.com, purview.microsoft.com, defender.microsoft.com, protection.office.com, purview.microsoft.com, security.microsoft.com`
`13.107.6.192/32, 13.107.9.192/32, 2620:1ec:4::192/128, 2620:1ec:a92::192/128` | **TCP:** 443 66 | Default
Required | No | `*.portal.cloudappsecurity.com` | **TCP:** 443 69 | Default
Required | No | `*.aria.microsoft.com, *.events.data.microsoft.com` | **TCP:** 443 70 | Default
Required | No | `*.o365weve.com, amp.azure.net, appsforoffice.microsoft.com, assets.onestore.ms, auth.gfx.ms, c1.microsoft.com, dgps.support.microsoft.com, docs.microsoft.com, msdn.microsoft.com, platform.linkedin.com, prod.msocdn.com, shellprod.msocdn.com, support.microsoft.com, technet.microsoft.com` | **TCP:** 443 diff --git a/microsoft-365/includes/purview-preview.md b/microsoft-365/includes/purview-preview.md index d5ea8376a70..3a6a9332d5e 100644 --- a/microsoft-365/includes/purview-preview.md +++ b/microsoft-365/includes/purview-preview.md @@ -2,4 +2,4 @@ ms.date: 09/30/2022 --- > [!TIP] -> If you're not an E5 customer, use the 90-day Microsoft Purview solutions trial to explore how additional Purview capabilities can help your organization manage data security and compliance needs. Start now at the [Microsoft Purview compliance portal trials hub](https://compliance.microsoft.com/trialHorizontalHub?sku=ComplianceE5&ref=DocsRef). Learn details about [signing up and trial terms](/microsoft-365/compliance/compliance-easy-trials). +> If you're not an E5 customer, use the 90-day Microsoft Purview solutions trial to explore how additional Purview capabilities can help your organization manage data security and compliance needs. Start now at the [Microsoft Purview portal trials hub](https://purview.microsoft.com/trialHorizontalHub?sku=ComplianceE5&ref=DocsRef). Learn details about [signing up and trial terms](/microsoft-365/compliance/compliance-easy-trials). diff --git a/microsoft-365/lighthouse/m365-lighthouse-data-privacy-and-compliance.md b/microsoft-365/lighthouse/m365-lighthouse-data-privacy-and-compliance.md index 5add80fe1e5..e3eed7af2c7 100644 --- a/microsoft-365/lighthouse/m365-lighthouse-data-privacy-and-compliance.md +++ b/microsoft-365/lighthouse/m365-lighthouse-data-privacy-and-compliance.md @@ -16,6 +16,7 @@ ms.collection: - M365-subscription-management - Adm_O365 - essentials-privacy +- essentials-compliance ms.custom: - AdminSurgePortfolib - M365-Lighthouse diff --git a/microsoft-365/loop/loop-compliance-summary.md b/microsoft-365/loop/loop-compliance-summary.md index 65ebfabbb1a..6fa25af586c 100644 --- a/microsoft-365/loop/loop-compliance-summary.md +++ b/microsoft-365/loop/loop-compliance-summary.md @@ -1,5 +1,5 @@ --- -ms.date: 03/06/2025 +ms.date: 04/22/2025 title: "Summary of governance, lifecycle, and compliance capabilities for Copilot Pages and Loop experiences" ms.reviewer: dancost, tonchan ms.author: jenz @@ -24,78 +24,69 @@ search.appverid: description: "Learn about the governance, data lifecycle management, and compliance capabilities for Copilot Pages and Loop experiences." --- -# Summary of governance, lifecycle, and compliance capabilities for Copilot Pages and Loop +# Summary of governance, lifecycle, and compliance capabilities for Copilot Pages, Copilot Notebooks, and Loop As a Compliance Manager or IT administrator, it's crucial to stay up-to-date on the latest governance, data lifecycle, and compliance posture for the software solutions being used in your organization. This article details the capabilities available and not available yet for [Microsoft Loop](https://www.microsoft.com/en-us/microsoft-loop). -## Summary table of admin management, governance, lifecycle, and compliance capabilities based on where Loop content is stored - -|Category|OneDrive or SharePoint|SharePoint Embedded| -|-----|-----|-----| -| |This column applies to Loop content:
  • Created in all other places without tightly associated collaborative storage (for example, Teams chat, Outlook email, Word for the web, Whiteboard) ➡️️ in the creator's OneDrive
  • Created in places with dedicated shared storage (for example, Teams channels) ➡️️ SharePoint
|This column applies to Loop content:
  • Created inside the Loop app: Workspaces, Ideas ➡️ in SharePoint Embedded, one container per Loop workspace
  • Learn more about [Loop storage](/microsoft-365/loop/loop-workspaces-storage-permission#loop-storage), which is combined with SharePoint in your tenant.
| -|***Foundations***|---|---| -|Admin toggles |**[Admin Toggles](/microsoft-365/loop/loop-components-configuration#available-policy-settings)** exist to turn on or off creation of and live rendering of Loop components in the Microsoft 365 ecosystem. If you enable Loop components in the Microsoft 365 ecosystem via the primary toggle, there are additional toggles to turn on or off Loop components in Outlook or Teams chats and channels. There's also an additional toggle to turn on or off Loop components for collaborative meeting notes.|**[Admin Toggle](/microsoft-365/loop/loop-workspaces-configuration)** exists to turn on or off creation of content stored in SharePoint Embedded, including Loop Ideas and new workspaces.| -|GDPR |**GDPR** data subject requests can be serviced as part of the [Microsoft Purview portal](/compliance/regulatory/gdpr-data-subject-requests#data-subject-request-admin-tools) and [Purview eDiscovery workflows](/purview/ediscovery)|**GDPR** data subject requests can be serviced as part of the [Microsoft Purview portal](/compliance/regulatory/gdpr-data-subject-requests#data-subject-request-admin-tools) and [Purview eDiscovery workflows](/purview/ediscovery)| -|EUDB |**EUDB** compliant - [What is the EU Data Boundary?](/privacy/eudb/eu-data-boundary-learn)|**EUDB** compliant - [What is the EU Data Boundary?](/privacy/eudb/eu-data-boundary-learn)| -|***Data Security, Devices***|---|---| -|Intune |Basic **Intune** [Device Management Support](/mem/intune/remote-actions/device-management) exists for Loop app on iOS and Android.|Basic **Intune** [Device Management Support](/mem/intune/remote-actions/device-management) exists for Loop app on iOS and Android.| -|Conditional Access |**[Conditional Access](/sharepoint/control-access-from-unmanaged-devices)** is supported.|**[Conditional Access](/sharepoint/control-access-from-unmanaged-devices)** supported.| -|Information Barriers |**[Information Barriers](/purview/information-barriers-sharepoint)** are enforced.|**[Information Barriers](/purview/information-barriers-sharepoint)** are enforced.| -|Customer Key |**[Customer Lockbox](/purview/customer-lockbox-requests)** is supported.|**[Customer Lockbox](/purview/customer-lockbox-requests)** is supported.| -|Programmatic APIs for Loop content |Yes, they're files in OneDrive or SharePoint and all current functionality applies.|Guest app access to Loop workspace containers is available. This enables third party export and eDiscovery tools, migration tools, tools used to communicate in bulk to end-users about their content such as compliance requirements, and developer APIs. Use PowerShell to [Get](/powershell/module/sharepoint-online/get-spoapplication) and [Set](/powershell/module/sharepoint-online/set-spoapplicationpermission) guest app permissions.| -|***Data Lifecycle***|---|---| -|Multi-Geo |**[Multi-Geo](/microsoft-365/enterprise/microsoft-365-multi-geo)** capabilities are supported, including creation of .loop files in a user's OneDrive in the geo that matches the user's [preferred data location](/microsoft-365/enterprise/plan-for-multi-geo#best-practices) and ability to move the user's OneDrive when their preferred data location changes.|**[Multi-Geo](/microsoft-365/enterprise/microsoft-365-multi-geo)** capabilities for Loop workspaces are supported using the [same mechanism as SharePoint sites](/microsoft-365/enterprise/m365-dr-workload-spo#move-a-sharepoint-site-or-sharepoint-embedded-container-site), including rehome and creation in the tenant's default geo. Manage the location of shared Loop workspaces like you would other collaboration artifacts, like SharePoint Communication sites.

**[Multi-Geo](/microsoft-365/enterprise/microsoft-365-multi-geo)** capabilities for Copilot Pages are supported. Copilot Pages is a user-owned workspace, and is created in the geo that matches the user's preferred data location.

**Not Yet Available**:
Shared workspaces aren't yet created in the user's preferred data location, they're instead created in the tenant's default geo, like SharePoint Communication sites are.| -|User leaves organization |When a user leaves an organization, [OneDrive retention policies](/sharepoint/retention-and-deletion) apply to the .loop files in their OneDrive just as they do to other content created by the user. See [Loop storage](/microsoft-365/loop/loop-workspaces-storage-permission#storage-management-after-user-departure) for more information.|Manage the lifetime of shared Loop workspaces like you would other collaboration artifacts, like SharePoint sites.

Manage the lifetime of user-owned personal Loop workspaces like Copilot Pages, like you would manage the user's OneDrive. See [Loop storage](/microsoft-365/loop/loop-workspaces-storage-permission#storage-management-after-user-departure) for more information.| -|Loop workspaces |n/a|See [Available](#available-admin-capabilities) and [Admin Management not yet available](#admin-management-not-yet-available).| -|Recycle bin |End user Recycle bin for deleted content is available.|End user Recycle bin for deleted content is available in each Loop workspace.

**Not Yet Available**:
End user Recycle bin for deleted Loop workspaces.| -|Version history |**Version History** [export in Purview](/purview/ediscovery-export-search-results#step-1-prepare-search-results-for-export) or via [Graph API](/graph/api/driveitem-get-content-format) is available. Loop files in OneDrive or SharePoint follow the same file versioning settings as other files.|**Version History** [export in Purview](/purview/ediscovery-export-search-results#step-1-prepare-search-results-for-export) or via [Graph API](/graph/api/driveitem-get-content-format) is available. Loop files in SharePoint Embedded are configured at 50 versions and no admin setting is available to change this.| -|Quota |Loop files in their OneDrive and SharePoint locations follow the quotas of those storage containers. |One Loop workspace corresponds to one SharePoint Embedded container. Loop SharePoint Embedded containers have no default storage limit, they accrue to the overall storage limits for SharePoint storage quota in the tenant. See [storage quota](/microsoft-365/loop/loop-workspaces-storage-permission#loop-apps-usage-of-organizations-storage-quota) for more information. There's no admin setting available to set storage quotas per SharePoint Embedded container.| -|Audit logs and events |**Audit** logs for all events: search and export Microsoft 365 service events for security and compliance investigations
  1. Use the [Microsoft Purview portal](https://purview.microsoft.com/auditlogsearch)
  2. Search audit logs for "loop" or "loot" or "fluid"
  3. Further filter exported results by "SourceFileExtension":"loop" or "SourceFileExtension":"loot" (templates) or "SourceFileExtension":"fluid" (deprecated)|**Audit** logs for all events: search and export Microsoft 365 service events for security and compliance investigations
    1. Use the [Microsoft Purview portal](https://purview.microsoft.com/auditlogsearch)
    2. Search audit logs for Loop Web Application ID `a187e399-0c36-4b98-8f04-1edc167a0996` and Loop Mobile Application ID `0922ef46-e1b9-4f7e-9134-9ad00547eb41`
    Note: Loop workspaces create and update .pod files to manage content in the workspace.| -|Audit log access |**Audit** logs are retained, can be exported, and can be streamed to third party tools|**Audit** logs are retained, can be exported, and can be streamed to third party tools| -|***eDiscovery***|---|---| -|Search, Collection, Review, Export (Purview) |Microsoft **[Purview eDiscovery](/microsoft-365/loop/loop-components-teams#do-loop-and-fluid-files-support-ediscovery)** supports search and collection, review (premium license required for admin), and export (premium license required for admin) as HTML or original. You can also download and reupload the files to any OneDrive to view them in their native format.

    **Not Yet Available**:
    Full text search of content within .loop files in Purview review sets.|Microsoft **[Purview eDiscovery](/microsoft-365/loop/loop-components-teams#do-loop-and-fluid-files-support-ediscovery)** supports search and collection, review (premium license required for admin), and export (premium license required for admin) as HTML or original. You can also download and reupload the files to any OneDrive to view them in their native format.

    **Not Yet Available**:
    Full text search of content within .loop files in Purview review sets.| -|Export (Third Party Tools) |Microsoft **[Graph API](/graph/api/driveitem-get-content-format)** export support.|Microsoft **[Graph API](/graph/api/driveitem-get-content-format)** export support.

    Use [Get-SPOApplication](/powershell/module/sharepoint-online/get-spoapplication) to view guest application permissions.
    Use [Set-SPOApplication](/powershell/module/sharepoint-online/set-spoapplicationpermission) to manage guest application permissions.| -|Legal Hold |**Legal Hold** support to ensure content isn't deleted (as related to litigation and security investigations) and stored in the [Preservation Hold Library](/sharepoint/governance/ediscovery-and-in-place-holds-in-sharepoint-server).|**Legal Hold** support to ensure content isn't deleted (as related to litigation and security investigations) and stored in the [Preservation Hold Library](/sharepoint/governance/ediscovery-and-in-place-holds-in-sharepoint-server).| -|***Microsoft 365 retention and deletion***|---|---| -|Retention policies |**[Retention policies](/purview/create-retention-policies?tabs=other-retention)** from Microsoft Purview Data Lifecycle Management are enforced for all .loop files.|**[Retention policies](/purview/create-retention-policies?tabs=other-retention)** from Microsoft Purview Data Lifecycle Management configured for all SharePoint sites are enforced for all .loop files or alternatively can be configured per Loop workspace *.| -|Retention labels |**[Retention labels](/purview/retention#retention-labels)** from Microsoft Purview Data Lifecycle Management and Microsoft Purview Records Management are supported for .loop files by [applying published labels](/purview/create-apply-retention-labels?tabs=spo-onedrive) in OneDrive or SharePoint, or [automatically applying](/purview/apply-retention-labels-automatically) the labels.| **[Retention labels](/purview/retention#retention-labels)** from Microsoft Purview Data Lifecycle Management and Microsoft Purview Records Management are supported for .loop files by [applying published labels](/purview/create-apply-retention-labels?tabs=spo-onedrive) in SharePoint and [automatically applying](/purview/apply-retention-labels-automatically) the labels. There's limited support for [manually applying retention labels in the Loop app and to Loop components in apps](/purview/create-apply-retention-labels?tabs=loop%2Cdefault-label-for-sharepoint#manually-apply-retention-labels).

    **Not Yet Available**:
    Retention labels cannot be viewed or applied directly from a Loop component outside the Loop app. Instead, the user must navigate to the Loop component within the Loop app itself to view or apply a retention label on a Loop component or page. Retention labels that mark the content as a record or regulatory record can't be manually applied in the Loop app and if content is automatically labeled as a record, locking and unlocking this record is not yet available. -| -|***Information Protection***|---|---| -|Sensitivity labels |**[Sensitivity labeling](/purview/sensitivity-labels-loop)** is available for Loop pages and components.|**[Sensitivity labeling](/purview/sensitivity-labels-loop)** is available for Loop pages and components, and admin configurable for individual Loop workspaces via PowerShell and rolling out in the Loop app for end users.| -|Data Loss Prevention |**[Data Loss Prevention](/purview/dlp-learn-about-dlp)** (DLP) rules are enforced on content with end-user policy tip support.|**[Data Loss Prevention](/purview/dlp-learn-about-dlp)** (DLP) rules are enforced on content with end-user policy tip support.| +## Summary table of admin management, governance, lifecycle, and compliance capabilities based on experience + +|Category|Copilot Pages and Notebooks support|Loop content support|Notes| +|-----|-----|-----|-----| +| |This column applies to Copilot Pages and Copilot Notebooks, which create .loop files and are stored in user-owned SharePoint Embedded containers. Learn more about [storage](/microsoft-365/loop/loop-workspaces-storage-permission#storage)|This column applies to Loop content stored in OneDrive, SharePoint, and SharePoint Embedded. Learn more about [storage](/microsoft-365/loop/loop-workspaces-storage-permission#storage)|| +|***Foundations***|---|---|---| +|Admin toggles |**[Admin Toggle](/microsoft-365/loop/loop-components-configuration#available-policy-settings)** exists to turn on or off creation of both Copilot Pages and Copilot Notebooks.

    If Loop components are enabled, Copilot Pages can be shared and used like a Loop component in all the applications that support Loop components.|**[Admin Toggle](/microsoft-365/loop/loop-workspaces-configuration)** exist to turn on or off creation of Loop components, pages, and workspaces. When switching Loop component creation on or off in the Microsoft 365 ecosystem, it also controls rendering as a hyperlink vs. a live and interactive experience.

    If you enable Loop components in the Microsoft 365 ecosystem via the primary toggle, there are secondary toggles to turn on or off Loop components in Outlook or Teams chats and channels. There's also a secondary toggle to turn on or off Loop components for collaborative meeting notes.|| +|GDPR |**GDPR** data subject requests can be serviced as part of the [Microsoft Purview portal](/compliance/regulatory/gdpr-data-subject-requests#data-subject-request-admin-tools) and [Purview eDiscovery workflows](/purview/ediscovery)|⬅️same as Copilot Pages & Copilot Notebooks.|| +|EUDB |**EUDB** compliant - [What is the EU Data Boundary?](/privacy/eudb/eu-data-boundary-learn)|⬅️same as Copilot Pages & Copilot Notebooks.|| +|***Data Security, Devices***|---|---|---| +|Intune |**Intune** [Device Management Support](/mem/intune/remote-actions/device-management) exists for Microsoft 365 app, Teams app, and Loop app, on iOS and Android.|⬅️same as Copilot Pages & Copilot Notebooks.|| +|Conditional Access |**[Conditional Access](/sharepoint/control-access-from-unmanaged-devices)** is supported.|⬅️same as Copilot Pages & Copilot Notebooks.|| +|Information Barriers |**[Information Barriers](/purview/information-barriers-sharepoint)** are enforced.|⬅️same as Copilot Pages & Copilot Notebooks.|| +|Customer Key |**[Customer Lockbox](/purview/customer-lockbox-requests)** is supported.|⬅️same as Copilot Pages & Copilot Notebooks.|| +|Programmatic APIs for Loop content |Guest app access to Copilot Pages and Copilot Notebooks containers is available. Guest app access enables third party export and eDiscovery tools, migration tools, tools used to evaluate compliance requirements, and developer APIs. Use PowerShell to [Get](/powershell/module/sharepoint-online/get-spoapplication) and [Set](/powershell/module/sharepoint-online/set-spoapplicationpermission) guest app permissions.|Loop stores content as files in OneDrive or SharePoint, so all current file functionality applies.

    Guest app access to Loop workspace containers is available. Guest app access enables third party export and eDiscovery tools, migration tools, tools used to evaluate compliance requirements, and developer APIs. Use PowerShell to [Get](/powershell/module/sharepoint-online/get-spoapplication) and [Set](/powershell/module/sharepoint-online/set-spoapplicationpermission) guest app permissions.|| +|***Data Lifecycle***|---|---|---| +|Multi-Geo |**[Multi-Geo](/microsoft-365/enterprise/microsoft-365-multi-geo)** capabilities for Copilot Pages and Copilot Notebooks are supported. Copilot Pages and Copilot Notebooks are both stored in the same user-owned SharePoint Embedded container. This container is created in the geo that matches the user's [preferred data location](/microsoft-365/enterprise/plan-for-multi-geo#best-practices). Like OneDrive, admins have the ability to manually move the user's Copilot Pages and Copilot Notebooks container to a new geo when their preferred data location changes.|**[Multi-Geo](/microsoft-365/enterprise/microsoft-365-multi-geo)** capabilities for My workspace are supported. My workspace is a user-owned SharePoint Embedded container and is created in the geo that matches the user's [preferred data location](/microsoft-365/enterprise/plan-for-multi-geo#best-practices).

    Loop content created in OneDrive and SharePoint follow the multi-geo capabilities of OneDrive and SharePoint.

    Multi-Geo capabilities for Loop workspaces are supported using the [same mechanism as SharePoint Communication sites](/microsoft-365/enterprise/m365-dr-workload-spo#move-a-sharepoint-site-or-sharepoint-embedded-container-site), including rehome and creation in the tenant's default geo. Manage the location of shared Loop workspaces like you would other collaboration artifacts, like SharePoint Communication sites.|**Not Yet Available**:

    **Loop**: Shared workspaces aren't created in the user's preferred data location, they're instead created in the tenant's default geo, like SharePoint Communication sites.| +|User leaves organization |See [Storage management after user departure](/microsoft-365/loop/loop-workspaces-storage-permission#copilot-pages) for detailed information on Copilot Pages and Copilot Notebooks.|See [Storage management after user departure](/microsoft-365/loop/loop-workspaces-storage-permission#copilot-pages) for detailed information on Loop content based on the storage location.

    See [storage](/microsoft-365/loop/loop-workspaces-storage-permission#storage) for more information on where Loop content is stored.|**Not Yet Available**:

    **Copilot Pages & Copilot Notebooks**: Unlike OneDrive, for Copilot Pages and Copilot Notebooks, there is no workflow for content stored in the user-owned SharePoint Embedded container after user departure. The container is deleted on the same schedule as the default OneDrive settings. See [Storage management after user departure](/microsoft-365/loop/loop-workspaces-storage-permission#copilot-pages) for detailed information.

    **Loop**: The same limits apply to My workspace| +|Storage containers |[Manage SharePoint Embedded containers in SharePoint Admin Center](/sharepoint/dev/embedded/concepts/admin-exp/consuming-tenant-admin/ctaux) - Learn more about storage, which is combined with SharePoint in your tenant.

    [SharePoint Embedded container management in PowerShell](/sharepoint/dev/embedded/concepts/admin-exp/consuming-tenant-admin/ctapowershell)|⬅️same as Copilot Pages & Copilot Notebooks.|| +|Recycle bin |There is no end user recycle bin for Copilot Pages or Copilot Notebooks.|End user Recycle bin for deleted Loop components and pages is available within the Loop workspace, OneDrive, or SharePoint site.|**Not Yet Available**:

    **Copilot Pages**: End user Recycle bin

    **Copilot Notebooks**: End user Recycle bin

    **Loop**: End user Recycle bin for deleted Loop workspaces.| +|Version history |**Version History** [export in Purview](/purview/ediscovery-export-search-results#step-1-prepare-search-results-for-export) or via [Graph API](/graph/api/driveitem-get-content-format) is available. Copilot Pages and Copilot Notebooks version history is configured to save 50 versions per file and no admin setting is available to change this configuration.|**Version History** [export in Purview](/purview/ediscovery-export-search-results#step-1-prepare-search-results-for-export) or via [Graph API](/graph/api/driveitem-get-content-format) is available. Loop workspace content stored in SharePoint Embedded (See [storage](/microsoft-365/loop/loop-workspaces-storage-permission#storage) for more information), version history is configured to save 50 versions and no admin setting is available to change this configuration. Loop files in OneDrive or SharePoint follow the same file versioning settings as other files.|| +|Quota |Copilot Pages and Copilot Notebooks create a single user-owned SharePoint Embedded container, identified by Loop application. Loop SharePoint Embedded containers have no default storage limit. They accrue to the overall storage limits for SharePoint [storage quota](/microsoft-365/loop/loop-workspaces-storage-permission#storage-quota) in the tenant. There's no admin setting available to set storage quotas per SharePoint Embedded container.|Loop workspaces create a SharePoint Embedded container. Loop SharePoint Embedded containers have no default storage limit. They accrue to the overall storage limits for SharePoint [storage quota](/microsoft-365/loop/loop-workspaces-storage-permission#storage-quota) in the tenant. There's no admin setting available to set storage quotas per SharePoint Embedded container.

    Loop files in their OneDrive and SharePoint locations follow the quotas of those storage containers.|| +|Audit logs and events |**Audit** logs for all events: search and export Microsoft 365 service events for security and compliance investigations
    1. Use the [Microsoft Purview portal](https://purview.microsoft.com/auditlogsearch)
    2. Search audit logs for "loop"
    3. Further filter exported results by "SourceFileExtension":"loop"
    Copilot Notebooks create and update .pod files to manage content in the notebook.|**Audit** logs for all events: search and export Microsoft 365 service events for security and compliance investigations
    1. Use the [Microsoft Purview portal](https://purview.microsoft.com/auditlogsearch)
    2. Search audit logs for "loop" or "loot" or "fluid" or for the Loop Web Application ID `a187e399-0c36-4b98-8f04-1edc167a0996` or Loop Mobile Application ID `0922ef46-e1b9-4f7e-9134-9ad00547eb41`
    3. Further filter exported results by "SourceFileExtension":"loop" or "SourceFileExtension":"loot" (templates) or "SourceFileExtension":"fluid" (deprecated)
    Loop workspaces create and update .pod files to manage content in the workspace.| +|Audit log access |**Audit** logs are retained, can be exported, and can be streamed to third party tools|⬅️same as Copilot Pages & Copilot Notebooks.|| +|***eDiscovery***|---|---|---| +|Search, Collection, Review, Export (Purview) |Microsoft **[Purview eDiscovery](/microsoft-365/loop/loop-components-teams#do-loop-and-fluid-files-support-ediscovery)** supports search and collection, review (premium license required for admin), and export (premium license required for admin) as HTML or original. You can also download and reupload the files to any OneDrive to view them in their native format.|⬅️same as Copilot Pages & Copilot Notebooks.|**Not Yet Available**:

    **Copilot Pages & Copilot Notebooks**: Full text search of content within .loop files in Purview review sets is not available.

    **Loop**: Full text search of content within .loop files in Purview review sets is not available.| +|Export (Third Party Tools) |Microsoft **[Graph API](/graph/api/driveitem-get-content-format)** export support. Use PowerShell to [Get](/powershell/module/sharepoint-online/get-spoapplication) and [Set](/powershell/module/sharepoint-online/set-spoapplicationpermission) guest application permissions.|⬅️same as Copilot Pages & Copilot Notebooks.|| +|Legal Hold |**Legal Hold** support to ensure content isn't deleted (as related to litigation and security investigations) and stored in the [Preservation Hold Library](/sharepoint/governance/ediscovery-and-in-place-holds-in-sharepoint-server).|⬅️same as Copilot Pages & Copilot Notebooks.|**Not Yet Available**:

    **Copilot Pages & Copilot Notebooks**: Unlike OneDrive, Copilot Pages and Copilot Notebooks are not automatically included when a user is placed on Litigation Hold, the Copilot Pages and Copilot Notebooks container must be manually added for that user.

    **Loop**: The same conditions apply to the My workspace.| +|***Microsoft 365 retention and deletion***|---|---|---| +|Retention policies |**[Retention policies](/purview/create-retention-policies?tabs=other-retention)** from Microsoft Purview Data Lifecycle Management configured for all SharePoint sites are enforced for all Copilot Pages and Copilot Notebooks.|**[Retention policies](/purview/create-retention-policies?tabs=other-retention)** from Microsoft Purview Data Lifecycle Management configured for all SharePoint sites are enforced for all .loop files or alternatively can be configured per Loop workspace *.|| +|Retention labels |**[Retention labels](/purview/retention#retention-labels)** from Microsoft Purview Data Lifecycle Management and Microsoft Purview Records Management are supported for Copilot Pages (.loop files) and Copilot Pages in Copilot Notebooks by [applying published labels](/purview/create-apply-retention-labels?tabs=spo-onedrive) in OneDrive or SharePoint, or [automatically applying](/purview/apply-retention-labels-automatically) the labels. There's limited support for [manually applying retention labels](/purview/create-apply-retention-labels?tabs=loop%2Cdefault-label-for-sharepoint#manually-apply-retention-labels).|⬅️same as Copilot Pages & Copilot Notebooks.|**Not Yet Available**:

    **Copilot Pages**: Retention labels cannot be viewed or applied directly from a Copilot Page. Instead, the user must navigate to the Copilot Page within the Loop app itself to view or apply a retention label on a Loop component or page.

    **Copilot Pages & Copilot Notebooks**: Retention labels that mark the content as a record or regulatory record can't be manually applied in either the Copilot Page or when the content is opened in the Loop app. If content is automatically labeled as a record, locking and unlocking this record is not yet available.

    **Loop**: The same limits apply to Loop components and pages.| +|***Information Protection***|---|---|---| +|Sensitivity labels |**[Sensitivity labeling](/purview/sensitivity-labels-loop)** is available for Copilot Pages.

    Because Copilot Notebooks are stored in the same container as all Copilot Pages, not one Copilot Notebook per unique container, Copilot Notebooks do not have container sensitivity labels.|**[Sensitivity labeling](/purview/sensitivity-labels-loop)** is available for Loop pages and components. Workspace sensitivity labels are available for Loop workspaces. They are configurable per Loop workspaces (at the container level) via SharePoint Admin Center and PowerShell.|| +|Data Loss Prevention |**[Data Loss Prevention](/purview/dlp-learn-about-dlp)** (DLP) rules are enforced on content with end-user policy tip support.|⬅️same as Copilot Pages & Copilot Notebooks.|| -\* If you need to specify an individual Loop workspace for a retention policy or another compliance feature, specify the workspace as you would a SharePoint site, by its URL. To locate this URL, sign in to the SharePoint admin center with the [SharePoint Embedded administrator role](/sharepoint/dev/embedded/concepts/admin-exp/adminrole). Then navigate to **Containers** > **Active containers** or **Deleted containers** where you can view the details of a selected Loop workspace. From the flyout pane, **General** tab, copy the container URL. +\* If you need to specify an individual Loop workspace or the Copilot Pages and Copilot Notebooks container for a retention policy or another compliance feature, specify the workspace as you would a SharePoint site, by its URL. To locate this URL, sign in to the SharePoint admin center with the [SharePoint Embedded administrator role](/sharepoint/dev/embedded/concepts/admin-exp/adminrole). Then navigate to **Containers** > **Active containers** or **Deleted containers** where you can view the details of a selected Loop workspace or Copilot Pages and Copilot Notebooks container. From the flyout pane, **General** tab, copy the container URL. ## Summary of governance, data lifecycle, and compliance capabilities **not yet available** -### Available admin capabilities - -For detailed information on existing capabilities in SharePoint Admin Center and PowerShell: - - Available: [Manage SharePoint Embedded containers in SharePoint Admin Center](/sharepoint/dev/embedded/concepts/admin-exp/consuming-tenant-admin/ctaux) - Learn more about [Loop storage](/microsoft-365/loop/loop-workspaces-storage-permission#loop-storage), which is combined with SharePoint in your tenant. - - Available: [SharePoint Embedded container management in PowerShell](/sharepoint/dev/embedded/concepts/admin-exp/consuming-tenant-admin/ctapowershell) - -### Not yet available - -The following sections detail capabilities that are **not yet available** for Microsoft Loop to make it easier to evaluate the smaller list of capabilities your organization might require before using Microsoft Loop. As denoted in the summary table, the content applies to Loop workspaces only. +The following sections detail capabilities that are **not yet available** to make it easier to evaluate the smaller list of capabilities your organization might require. ### Admin Management not yet available -- When users delete an entire Loop workspace, that Loop workspace isn't available in an **end-user visible Recycle bin**. Furthermore, restoring the Loop workspace using admin tooling doesn't update in the Loop app user experience. The user would need to visit a saved page link for a restored workspace in order to see it again. Microsoft Roadmap ID 421615 addresses this. -- When an **admin deletes** a Loop workspace, it **will not be removed from the user's view** of Loop workspaces. When users click on the deleted Loop workspace, it displays an error. Microsoft Roadmap ID 421613 addresses this. -- When an **admin modifies the list of owners or members** of a Loop workspace through the SharePoint Admin Center or via PowerShell, the **changes won't be visible to the users within that Loop workspace**. Changes to the workspace membership are only updated in the user's view of the Loop app if they're made directly within the Loop app itself. Microsoft Roadmap ID 421613 addresses this. -- All shared Loop workspaces, including Ideas, are created as tenant-owned, in the tenant default geo like SharePoint Communication sites, not in the creator's preferred data location. Copilot Pages is created as user-owned, in the geo that matches the user's preferred data location. See [storage management after user departure](/microsoft-365/loop/loop-workspaces-storage-permission#storage-management-after-user-departure) for more information on managing workspaces. Microsoft Roadmap ID 422729 addresses Ideas functioning as a shared Loop workspace. -- **Individual controls for guest or external sharing** of a specific Loop workspace isn't available. +- **Copilot Pages, Copilot Notebooks, My workspace**: Unlike OneDrive, for Copilot Pages, Copilot Notebooks, and the My workspace, there is no workflow for content stored in the user-owned SharePoint Embedded container after user departure. It is deleted on the same schedule as the default OneDrive settings. See [storage management after user departure](/microsoft-365/loop/loop-workspaces-storage-permission#storage-management-after-user-departure) for detailed information. +- **Copilot Pages, Copilot Notebooks**: An end-user recycle bin for deleted Copilot Pages or Copilot Notebooks isn't available. +- **Loop**: When users delete an entire Loop workspace, that Loop workspace isn't available in an **end-user visible Recycle bin**. Furthermore, restoring the Loop workspace using admin tooling doesn't update in the Loop app user experience. The user would need to visit a saved page link for a restored workspace in order to see it again. Microsoft Roadmap ID 421615 addresses this. +- **Loop**: All shared Loop workspaces are created as tenant-owned, in the tenant default geo. This behavior is consistent with SharePoint Communication sites created in the SharePoint UX, where the creator's preferred data location is not used. See [storage management after user departure](/microsoft-365/loop/loop-workspaces-storage-permission#storage-management-after-user-departure) for more information on managing workspaces. +- **Loop**: **Individual controls for guest or external sharing** of a specific Loop workspace isn't available. ### eDiscovery capabilities not yet available -- Full text search of content within .loop files in review sets. +- **Copilot Pages, Copilot Notebooks, Loop**: Full text search of content within .loop files in review sets isn't available. ### Microsoft 365 retention and deletion capabilities not available -- Retention labels cannot be viewed or applied directly from a Loop component outside the Loop app. Instead, the user must navigate to the Loop component within the Loop app itself to view or apply a retention label on a Loop component or page. -- Retention labels that mark the content as a record or regulatory record can't be manually applied in the Loop app and if content is automatically labeled as a record, locking and unlocking this record is not yet available. -- For clarification only, not a limitation: retention labels have never been applied to containers like SharePoint sites or Loop workspaces; instead, use retention policies for these containers. See [retention](/purview/retention) to learn more. +- **Copilot Pages, Loop**: Retention labels cannot be viewed or applied directly from a Copilot Page or Loop component outside the Loop app. Instead, the user must navigate to the Copilot Page or Loop component within the Loop app itself to view or apply a retention label on a Loop component or page. +- **Copilot Pages, Copilot Notebooks, My workspace**: Retention labels that mark the content as a record or regulatory record can't be manually applied in the Loop app. If content is automatically labeled as a record, locking and unlocking this record is not yet available. +- For clarification only, not a limitation: retention labels do not apply to containers like SharePoint sites or Loop workspaces; instead, use retention policies for these containers. See [retention](/purview/retention) to learn more. ## Managing Loop in your organization diff --git a/microsoft-365/loop/loop-components-configuration.md b/microsoft-365/loop/loop-components-configuration.md index d85cf60b211..1092d07f0ef 100644 --- a/microsoft-365/loop/loop-components-configuration.md +++ b/microsoft-365/loop/loop-components-configuration.md @@ -1,6 +1,6 @@ --- -ms.date: 03/06/2025 -title: "Manage Copilot Pages and Loop components in your organization" +ms.date: 04/22/2025 +title: "Manage Copilot Pages, Copilot Notebooks, and Loop components in your organization" ms.reviewer: dancost, tonchan ms.author: jenz author: jenzamora @@ -21,36 +21,44 @@ ms.collection: search.appverid: - SPO160 - MET150 -description: "Manage Copilot Pages and Loop in your organization" +description: "Manage Copilot Pages, Copilot Notebooks, and Loop in your organization" --- -# Loop admin policies for Copilot Pages, Loop components, and Loop workspaces +# Loop admin policies for Copilot Pages, Copilot Notebooks, Loop components, and Loop workspaces -Loop components and integrations are backed by `.loop` files (earlier releases of Loop created these as `.fluid` files), stored in OneDrive, SharePoint, or [SharePoint Embedded](/sharepoint/dev/embedded/concepts/admin-exp/consuming-tenant-admin/cta). Learn more about [Loop storage](/microsoft-365/loop/loop-workspaces-storage-permission#loop-storage), which is combined with SharePoint in your tenant. IT administrators need to manage creation of Loop content and integrations using **BOTH**: +Copilot Pages, Copilot Notebooks, and Loop components and integrations are backed by `.loop` files (earlier releases of Loop created these as `.fluid` files), stored in OneDrive, SharePoint, or [SharePoint Embedded](/sharepoint/dev/embedded/concepts/admin-exp/consuming-tenant-admin/cta). Learn more about [storage](/microsoft-365/loop/loop-workspaces-storage-permission#storage), which is quota combined with SharePoint in your tenant. -1. Cloud Policy -1. SharePoint PowerShell command (Teams only) +Copilot Pages, Copilot Notebooks, Loop workspaces, and the `.loop` files and content created are stored in SharePoint Embedded containers. IT admins can manage creation of Copilot Pages, Copilot Notebooks, and Loop workspaces using Cloud Policy. + +IT administrators can manage the creation of Loop components in the Microsoft 365 ecosystem using **BOTH**: -Loop workspaces, Copilot Pages, and the `.loop` files and content created in Loop workspaces are stored in SharePoint Embedded containers. IT admins can manage creation of Loop workspaces using Cloud Policy. +1. Cloud Policy +1. SharePoint PowerShell command (Loop experiences in Teams only) ## Requirements -Just like other Microsoft 365 experiences, Loop and Copilot Pages also leverage core services across SharePoint and Microsoft 365. To effectively enable creation of Loop content and Loop integration experiences, Copilot Pages, or OneDrive and SharePoint files-backed experiences powered by Fluid Framework, follow the instructions in the [Office 365 URLs and IP address ranges](/microsoft-365/enterprise/urls-and-ip-address-ranges) to ensure connections to Loop services are available and enabled. +Just like other Microsoft 365 experiences, Copilot Pages, Copilot Notebooks, and Loop also leverage core services across SharePoint and Microsoft 365. To effectively enable creation of Copilot Pages, Copilot Notebooks, Loop content and Loop integration experiences, follow the instructions in the [Office 365 URLs and IP address ranges](/microsoft-365/enterprise/urls-and-ip-address-ranges) to ensure connections to Loop services (also used by Copilot Pages and Copilot Notebooks) are available and enabled. ### WebSocket connections -Loop's near real-time communications are enabled by the core services that run a WebSocket server. Coauthors in the same session need to establish secured WebSocket connections to this service to send and receive collaborative data such as changes made by others, live cursors, presence, and so on. These experiences are crucial to Loop, and to all the scenarios powered by Fluid framework. Allow list WebSocket traffic to the `*.svc.ms` and `*.office.com` endpoints. +Copilot Pages, Copilot Notebooks, and Loop's near real-time communications are enabled by the core services that run a WebSocket server. Coauthors in the same session need to establish secure WebSocket connections to this service to send and receive collaborative data such as changes made by others, live cursors, presence, and so on. Allow list WebSocket traffic to the `*.svc.ms` and `*.office.com` endpoints. ### License requirements -Licensing through the new Loop with workspaces service plan covers the creation of new workspaces and management of workspace members. The full set of experiences enabled and the specific licenses that include the Loop with workspaces service plan are covered in [Loop access via Microsoft 365 subscriptions](https://support.microsoft.com/office/loop-access-via-microsoft-365-subscriptions-92915461-4b14-49a4-9cd4-d1c259292afa). Loop components are available to anyone in Entra ID accounts with a OneDrive or SharePoint license. +Copilot Pages are available to anyone in Entra ID accounts with a OneDrive license. Copilot pages require a OneDrive site to function. However, if a OneDrive site exists and the license is later removed, Copilot pages continue to work. + +Copilot Notebooks require the [Microsoft 365 Copilot license](/copilot/microsoft-365/microsoft-365-copilot-licensing). + +Loop components are available to anyone in Entra ID accounts with a OneDrive or SharePoint license. + +Licensing through the Loop with workspaces service plan covers the creation of new workspaces and management of workspace members. The full set of experiences enabled and the specific licenses that include the Loop with workspaces service plan are covered in [Loop access via Microsoft 365 subscriptions](https://support.microsoft.com/office/loop-access-via-microsoft-365-subscriptions-92915461-4b14-49a4-9cd4-d1c259292afa). ### Microsoft 365 Groups for Cloud Policy If you want to scope the Cloud Policy settings to only some users in your tenant, you must create or use an existing Microsoft 365 group that defines which users in your organization this policy will apply to. To create a Microsoft 365 group, see [Create a Microsoft 365 group](/microsoft-365/admin/create-groups/create-groups). > [!NOTE] -> This section isn't required if you choose to apply the Loop settings to all the users in your tenant. +> This section isn't required if you choose to apply the Cloud Policy settings to all the users in your tenant. You'll be able to use this group for the Cloud Policy setup procedure specified in [Settings management in Cloud Policy](#settings-management-in-cloud-policy). @@ -62,13 +70,13 @@ To utilize all Loop app features, including workspace sharing and at mentions, i ## Available policy settings -There are several IT Admin policy settings provided to enable creation of Loop content across Microsoft 365: +There are several IT Admin policy settings provided to enable creation of Copilot Pages, Copilot Notebooks, and Loop content across Microsoft 365: |Configure |Setting Type |Specific Policy |Notes | |---------|---------|---------|---------| +|Copilot Pages & Copilot Notebooks creation | Cloud Policy | **Create and view Copilot Pages** | Applies to: Copilot Pages and Copilot Notebooks (cloud policy will be retitled soon) | |Loop workspaces creation | Cloud Policy | **Create Loop workspaces in Loop** | Applies to: Loop workspaces (previously titled Create and view Loop workspaces in Loop) | |Loop component creation and integration across Microsoft 365 | Cloud Policy | **Create and view Loop files in Microsoft apps that support Loop** | Applies to:
    - Outlook integration
    - [Teams New Calendar](https://support.microsoft.com/en-us/office/get-started-with-the-new-calendar-in-microsoft-teams-98f3b637-5da2-43e2-91b3-f312ab3e4dc5) integration
    - OneNote integration
    - Whiteboard integration
    Does **NOT** apply to:
    - Loop workspaces
    - Teams integration
    - Copilot Pages | -|Copilot Pages creation and integration | Cloud Policy | **Create and view Copilot Pages** | Applies to: Copilot Pages in a Copilot chat experience | |Outlook creation and integration of Loop experiences | Cloud Policy | **Create and view Loop files in Outlook** | First checks **Create and view Loop files in Microsoft apps that support Loop**; then applies **Create and view Loop files in Outlook**, if applicable.

    Applies to:
    - Outlook
    - [Teams New Calendar](https://support.microsoft.com/en-us/office/get-started-with-the-new-calendar-in-microsoft-teams-98f3b637-5da2-43e2-91b3-f312ab3e4dc5) | |Teams creation and integration | SharePoint property | See [Settings management for Loop components in Teams](#settings-management-for-loop-functionality-in-teams) | Teams only checks the settings in this row. | @@ -78,8 +86,10 @@ Configure the creation of content in these locations by using the appropriate po |Loop content originally created in|️️️Manage with this policy|Loop content storage| |-----|-----|-----| -|Loop app|Cloud Policy: **Create Loop workspaces in Loop**|SharePoint Embedded: ✔️in Loop workspace| -|Copilot Pages|Cloud Policy: **Create and view Copilot Pages**|SharePoint Embedded: ✔️in Loop workspace| +|Copilot Pages|Cloud Policy: **Create and view Copilot Pages**|SharePoint Embedded: ✔️in user-owned container| +|Copilot Notebooks|Cloud Policy: **Create and view Copilot Pages**|SharePoint Embedded: ✔️in user-owned container| +|Loop app, My workspace|Cloud Policy: **Create Loop workspaces in Loop**|SharePoint Embedded: ✔️in user-owned container| +|Loop app, shared workspace|Cloud Policy: **Create Loop workspaces in Loop**|SharePoint Embedded: ✔️in shared container| |Teams channel meeting (Teams Classic Calendar)|SharePoint property `Set-SPOTenant -IsCollabMeetingNotesFluidEnabled $true`|SharePoint Site: 📁`Meetings`| |Teams channel meeting ([Teams New Calendar](https://support.microsoft.com/en-us/office/get-started-with-the-new-calendar-in-microsoft-teams-98f3b637-5da2-43e2-91b3-f312ab3e4dc5))|Cloud Policy: **Create and view Loop files in Microsoft apps that support Loop** -or- **Create and view Loop files in Outlook**|SharePoint Site: 📁`Meetings`| |Teams channel|SharePoint property `Set-SPOTenant -IsCollabMeetingNotesFluidEnabled $true`|SharePoint Site: ✔️in Channel folder| @@ -94,20 +104,20 @@ Configure the creation of content in these locations by using the appropriate po |Scenario | Policies Configured | |---------|---------| -|✅Enable Loop workspaces creation and Loop component creation and integration everywhere | ✅ **Create Loop workspaces in Loop** = Enabled (or Not Configured)
    ✅ **Create and view Loop files in Microsoft apps that support Loop** = Enabled (or Not Configured)
    ✅ **Create and view Copilot Pages** = Enabled (or Not Configured)
    ✅ [Teams-only] `Set-SPOTenant -IsLoopEnabled $true`, `Set-SPOTenant -IsCollabMeetingNotesFluidEnabled $true` | -|✅Enable Loop workspaces creation and Loop component creation and integration everywhere, but ⛔Disable Loop component creation and integration in Communication apps (Outlook, Teams) | ✅ **Create Loop workspaces in Loop** = Enabled (or Not Configured)
    ✅ **Create and view Loop files in Microsoft apps that support Loop** = Enabled (or Not Configured)
    ✅ **Create and view Copilot Pages** = Enabled (or Not Configured)
    ⛔ **Create and view Loop files in Outlook** = Disabled
    ⛔ [Teams-only] `Set-SPOTenant -IsLoopEnabled $false`, `Set-SPOTenant -IsCollabMeetingNotesFluidEnabled $false` | -|⛔Disable Loop workspace creation and Loop component creation and integration everywhere | ⛔ **Create Loop workspaces in Loop** = Disabled
    ⛔ **Create and view Loop files in Microsoft apps that support Loop** = Disabled
    ⛔ **Create and view Copilot Pages** = Disabled
    ⛔ [Teams-only] `Set-SPOTenant -IsLoopEnabled $false`, `Set-SPOTenant -IsCollabMeetingNotesFluidEnabled $false` | +|✅Enable Copilot Pages, Copilot Notebooks, Loop workspaces creation and Loop component creation and integration everywhere | ✅ **Create and view Copilot Pages** = Enabled (or Not Configured)
    ✅ **Create Loop workspaces in Loop** = Enabled (or Not Configured)
    ✅ **Create and view Loop files in Microsoft apps that support Loop** = Enabled (or Not Configured)
    ✅ [Teams-only] `Set-SPOTenant -IsLoopEnabled $true`, `Set-SPOTenant -IsCollabMeetingNotesFluidEnabled $true` | +|✅Enable Copilot Pages, Copilot Notebooks, Loop workspaces creation and Loop component creation and integration everywhere, but ⛔Disable Loop component creation and integration in Communication apps (Outlook, Teams) | ✅ **Create and view Copilot Pages** = Enabled (or Not Configured)
    ✅ **Create Loop workspaces in Loop** = Enabled (or Not Configured)
    ✅ **Create and view Loop files in Microsoft apps that support Loop** = Enabled (or Not Configured)
    ⛔ **Create and view Loop files in Outlook** = Disabled
    ⛔ [Teams-only] `Set-SPOTenant -IsLoopEnabled $false`, `Set-SPOTenant -IsCollabMeetingNotesFluidEnabled $false` | +|✅Enable Copilot Pages and Copilot Notebooks, but⛔Disable Loop workspace creation and Loop component creation and integration everywhere | ✅ **Create and view Copilot Pages** = Enabled (or Not Configured)
    ⛔ **Create Loop workspaces in Loop** = Disabled
    ⛔ **Create and view Loop files in Microsoft apps that support Loop** = Disabled
    ⛔ [Teams-only] `Set-SPOTenant -IsLoopEnabled $false`, `Set-SPOTenant -IsCollabMeetingNotesFluidEnabled $false` | ## User experience expectations when admin settings are configured -As described in this topic, you can control the ability for users in your environment to create new Loop content. **You cannot prevent access to existing content using the admin controls.** You can configure the admin controls via select groups or for your entire tenant (except for the Teams controls, which apply to the entire tenant only). +As described in this topic, you can control the ability for users in your environment to create new Copilot Pages, Copilot Notebooks, and Loop content. **You cannot prevent access to existing content using the admin controls.** You can configure the admin controls via select groups or for your entire tenant (except for the Teams controls, which apply to the entire tenant only). - To prevent collaboration between certain groups in your organization, refer to [Information Barriers](/en-us/purview/information-barriers-sharepoint). - To prevent access to existing content and the Loop app with workspaces, refer to [Conditional Access policies](/sharepoint/control-access-from-unmanaged-devices). -### Here's what you should expect when using the Loop IT admin controls configured to Disabled +### Here's what you should expect when using the IT admin controls configured to Disabled -When Loop IT admin controls are set to Disabled, the creation of new Loop files and SharePoint Embedded containers is prevented. Existing user data isn't deleted, and users can still find, see, and access existing Loop files and Loop workspaces. +When the IT admin controls in this article are set to Disabled, the creation of new Loop files and creation of new SharePoint Embedded containers is prevented. Existing user data isn't deleted, and users can still find, see, and access existing Copilot Pages, Copilot Notebooks, Loop files and Loop workspaces in both application experiences and in searches. Even with the admin policies disabled, Loop content and icons may still appear in certain places. Files created before disabling new creation can still be found in Microsoft365.com, the Loop component viewer and editor (loop.cloud.microsoft), and links shared in messages or documents. Access to these files is determined by their permissions, so users with edit access can still open and edit them. @@ -128,13 +138,15 @@ If you're looking for a simple way to turn on or off the creation of only Loop w The Microsoft Admin Center configures the Cloud Policy setting **Create Loop workspaces in Loop**, described in the next section, targeted at All users (your full tenant). See the next section if you wish to perform more advanced controls. If you configured **Create Loop workspaces in Loop** in Cloud Policy, review your Cloud Policy settings to confirm they still match your expectation after configuring in the Microsoft Admin Center. +This same approach is not available for Copilot Pages or Copilot Notebooks. Refer to [settings management in Cloud Policy](#settings-management-in-cloud-policy). + ## Settings management in Cloud Policy -The Loop experiences (except for Microsoft Teams) check the following [Cloud Policy](/deployoffice/admincenter/overview-cloud-policy) settings. See [Available policy settings](#available-policy-settings) to understand how each app checks these settings: +Copilot Pages, Copilot Notebooks, and the Loop experiences (except for Microsoft Teams) check the following [Cloud Policy](/deployoffice/admincenter/overview-cloud-policy) settings. See [Available policy settings](#available-policy-settings) to understand how each app checks these settings: +- **Create and view Copilot Pages** (which also applies to Copilot Notebooks) - **Create Loop workspaces in Loop** - **Create and view Loop files in Microsoft apps that support Loop** -- **Create and view Copilot Pages** - **Create and view Loop files in Outlook** 1. Sign in to https://config.office.com/ with your Microsoft 365 admin credentials. @@ -143,6 +155,12 @@ The Loop experiences (except for Microsoft Teams) check the following [Cloud Pol 1. Create a new policy configuration or edit an existing one. 1. From the **Choose the scope** dropdown list, choose either **All users** or select the group for which you want to apply the policy. For more information, see [Microsoft 365 Groups for Cloud Policy](#microsoft-365-groups-for-cloud-policy). 1. In **Configure Settings**, choose one of the following settings: + - For **Create and view Copilot Pages** (which also applies to Copilot Notebooks) + - **Enabled**: Copilot Pages and Copilot Notebooks creation and integration are available to the users. + - **Disabled**: Copilot Pages and Copilot Notebooks creation and integration aren't available to the users. + - **Not configured**: Copilot Pages and Copilot Notebooks creation and integration are available to the users. + >[!NOTE] + >If your organization has [disabled the creation of OneDrive](/sharepoint/manage-user-profiles#disable-onedrive-creation-for-some-users), regardless of the setting noted here, these people in your organization won't be able to create Copilot Pages or Copilot Notebooks. - For **Create Loop workspaces in Loop**: - **Disabled**: Creation of Loop workspaces isn't available to the users. - Loop app will open Loop components when workspaces is disabled. @@ -159,15 +177,10 @@ The Loop experiences (except for Microsoft Teams) check the following [Cloud Pol - Loop workspaces - Teams integration (see [Settings management for Loop components in Teams](#settings-management-for-loop-functionality-in-teams)) - Copilot Pages + - Copilot Notebooks - **Enabled**: Creation of Loop components and integration is available to the users. - **Disabled**: Creation of Loop components and integration isn't available to the users. - **Not configured**: Creation of Loop components and integration is available to the users. - - For **Create and view Copilot Pages** - - **Enabled**: Copilot pages creation and integration are available to the users. - - **Disabled**: Copilot pages creation and integration aren't available to the users. - - **Not configured**: Copilot pages creation and integration are available to the users. - >[!NOTE] - >If your organization has [disabled the creation of OneDrive](/sharepoint/manage-user-profiles#disable-onedrive-creation-for-some-users), regardless of the setting noted here, these people in your organization won't be able to create a Copilot Pages workspace. - For **Create and view Loop files in Outlook** (includes Outlook and [Teams New Calendar](https://support.microsoft.com/en-us/office/get-started-with-the-new-calendar-in-microsoft-teams-98f3b637-5da2-43e2-91b3-f312ab3e4dc5)): - **Enabled**: Creation of Loop components and integration is available to the users. - **Disabled**: Creation of Loop components and integration isn't available to the users. @@ -181,7 +194,7 @@ In case you create a new policy configuration or change the configuration for an - If there were no policy configurations prior to the change, then it will take 24 hours for the change to be reflected. > [!NOTE] -> In order to target only a group of users in your organization to be able to create and view Loop content in workspaces, create a second group that targets All users, set this group to Disabled, and make it a priority number that evaluates *after* your first target group that is set to Enabled. In Cloud Policy, priority 0 evaluates first, followed by priority 1, then 2, and so on. This configuration will override the default Not Configured state to Disabled for all users but your target group. +> In order to target only a subset of users in your organization as Enabled for one of these Cloud Policies, create a Group A to target these users, set the Cloud Policy to Enabled in this group. Then create a Group B that targets All users, set the Cloud Policy to Disabled in this group. Then, configure Group A with a priority that evaluates *before* Group B. In Cloud Policy, priority 0 evaluates first, followed by priority 1, then 2, and so on. So for example, Group A with priority 0 will Enable your subset of users, and Group B with priority 1 will only evaluate for users not in Group A, and Disable for the remainder of your users. ## Settings management for Loop functionality in Teams diff --git a/microsoft-365/loop/loop-workspaces-storage-permission.md b/microsoft-365/loop/loop-workspaces-storage-permission.md index 7d7800ec02e..57761186aa9 100644 --- a/microsoft-365/loop/loop-workspaces-storage-permission.md +++ b/microsoft-365/loop/loop-workspaces-storage-permission.md @@ -7,7 +7,7 @@ audience: Admin ms.topic: article ms.service: loop ms.reviewer: michalbr, dancost -ms.date: 01/08/2025 +ms.date: 04/22/2025 ms.localizationpriority: medium search.appverid: MET150 ms.collection: @@ -24,18 +24,18 @@ appliesto: - Microsoft Teams --- -# Overview of Copilot Pages and Loop workspaces storage and permissions +# Overview of Copilot Pages, Copilot Notebooks, and Loop workspaces storage and permissions -## Loop Storage +## Storage -Where Loop content is stored impacts the admin management, governance, data lifecycle, and compliance capabilities available. Microsoft Loop is built on top of SharePoint, OneDrive, and [SharePoint Embedded](/sharepoint/dev/embedded/concepts/admin-exp/consuming-tenant-admin/cta), which means that most of these capabilities work just like existing files in your ecosystem. Because Loop pages and components are files, they can be managed in a familiar way, within your existing workflows. The table should help clarify how Loop content is stored in the Microsoft ecosystem. +Loop content is stored in SharePoint, OneDrive, and [SharePoint Embedded](/sharepoint/dev/embedded/concepts/admin-exp/consuming-tenant-admin/cta), allowing familiar management within existing file management workflows. Where the content was originally created determines its storage location: -Where the Loop content was originally created determines its storage location: - -|Loop content originally created in|️️️Loop content stored in SharePoint Embedded|Loop content stored in SharePoint Site|Loop content stored in User's OneDrive| +|Content content originally created in|Content stored in SharePoint Embedded|Content stored in SharePoint Site|Content stored in User's OneDrive| |-----|-----|-----|-----| -|Loop app|✔️in Loop workspace||| -|Copilot Pages|✔️in Loop workspace||| +|Copilot Pages|✔️in user-owned container||| +|Copilot Notebooks|✔️in user-owned container||| +|Loop app, My workspace|✔️in user-owned container||| +|Loop app, shared workspace|✔️in shared container||| |Teams channel meeting||✔️in 📁`Meetings`|| |Teams channel||✔️in Channel folder|| |Teams private chat|||✔️in 📁`Microsoft Teams Chat files`| @@ -44,104 +44,118 @@ Where the Loop content was originally created determines its storage location: |OneNote for Windows or for the web|||✔️in 📁`OneNote Loop files`| |Whiteboard|||✔️in 📁`Whiteboard\Components`| -## Loop app's usage of organization's storage quota +## Storage quota + +Copilot Pages, Copilot Notebooks, and Loop workspaces are stored within your tenant in SharePoint Embedded. Copilot Pages, Copilot Notebooks and My workspace all use the same container. All shared Loop workspaces create their own unique container. The user-owned container is named 'Pages' or 'My workspace' depending on which location the person visits first, either Copilot Pages or Copilot Notebooks, the Loop app. -Loop app workspaces are stored inside your tenant, within SharePoint Embedded. All Loop workspaces and pages, including Shared workspaces, Personal workspaces, Ideas, and Copilot Pages, count against your tenant's SharePoint storage quota. +All Copilot Pages, Copilot Notebooks, and Loop workspaces count against your tenant's SharePoint storage quota. -SharePoint Embedded also offers a platform to build your own applications. This usage pattern which bills per use, is different from Loop, and should not be confused with Loop. As described above, Loop's storage in SharePoint Embedded is combined and measured with your tenant's SharePoint storage quota. +SharePoint Embedded also offers a platform for developers to build their own applications. This alternate usage pattern which bills per use is different from Loop and Copilot Pages storage quota management. -## Loop workspace storage limits +## Storage limits -Loop workspaces have a maximum size of 25TB per workspace. This limit can't be increased or decreased. Workspace content counts towards a user's storage quota, and since this per-user storage quota is always less than 25TB, the 25TB limit should never be reached, in practice. Loop workspaces are implemented as SharePoint Embedded containers. Learn more about [SharePoint Embedded container limits](/sharepoint/dev/embedded/concepts/app-concepts/limits-calling). +Copilot Pages + Copilot Notebooks, and Loop workspaces have a maximum size of 25 TB. This limit can't be increased or decreased. Learn more about [SharePoint Embedded container limits](/sharepoint/dev/embedded/concepts/app-concepts/limits-calling). ## Content permissions mechanism -Each Loop app workspace uses storage for the workspace in [SharePoint Embedded](/sharepoint/dev/embedded/concepts/admin-exp/consuming-tenant-admin/cta). Additionally, the Loop app creates a roster for that workspace to govern access to the full workspace. When pages are shared from the workspace, we create a sharing link using your company's default sharing link type as configured for OneDrive and SharePoint. +Copilot Pages, Copilot Notebooks, and Loop workspace are stored in [SharePoint Embedded](/sharepoint/dev/embedded/concepts/admin-exp/consuming-tenant-admin/cta) containers. -Sharing the workspace in Loop adds the user to the workspace roster. All workspace roster members have access and "*editing*" permissions to all the Loop pages in that workspace. +### Sharing Mechanism -:::image type="content" source="media/share-workspace-in-loop.png" alt-text="Share Workspace in Loop"::: +- **Page Sharing**: Grants access to a specific page (not the whole workspace) with options for edit or read-only access. The user can choose to use a company share link or people-specific share link, based on your organizational sharing settings. +- **Workspace Sharing**: ONLY applies to shared Loop workspaces: Invites users to the entire workspace by adding owners and members to the SharePoint Embedded container, and sends an email invite. All members have access and *editing* permissions to all the Loop pages in that workspace. -There's a distinction between sharing a specific Loop page with a user versus inviting them to a Workspace. +:::image type="content" source="media/share-workspace-in-loop.png" alt-text="Screenshot showing the Share workspace option in Loop"::: -When you invite a user to a workspace, that user has access to all the pages in that workspace. Loop only supports inviting users to a workspace via this Workspace roster management flow, which enables access and sends an email invite to the invited users. +## Guest/External sharing -When you share only a Loop page, you're giving users access to that specific page exclusively (not the whole workspace). The user can choose to use a company share link or people-specific share link; unless their tenant admin disabled some of the share link types. When sharing a page, you can choose to grant the user *edit*, or *read only* access. +You can share individual Copilot Pages, entire Loop workspaces, or individual Loop pages and Loop components with external users (guests) if your organization allows it. You can't share the entire Copilot Pages container, any Copilot Notebook, or My workspace in Loop. -## Guest/External sharing +### Guest sharing requirements -You can share Loop workspaces, pages, and components with users external to your company (guests) so they can collaborate with you. There are a few requirements that must be met for guest sharing to be possible: +- Organization-level external sharing enabled. Learn how to [manage this policy](/sharepoint/turn-external-sharing-on-or-off#change-the-organization-level-external-sharing-setting). +- Guest account in your tenant or [Business-to-Business Invitation Manager is enabled](/entra/external-id/what-is-b2b). +- Sensitivity labels and conditional access settings not restricting sharing. -- Your organization must allow sharing files with guests. Learn how to [manage this policy](/sharepoint/turn-external-sharing-on-or-off#change-the-organization-level-external-sharing-setting). -- The user you're sharing with must have a guest account in your tenant or [Business-to-Business Invitation Manager is enabled](/entra/external-id/what-is-b2b). -- Sensitivity labels and conditional access can further restrict sharing, so when testing guest sharing, ensure these features aren't configured to prevent it. +Shared Loop workspaces can only be shared with users that have an existing guest account in your tenant. If Business-to-business Invitation Manager is enabled, users can share a page or component with a guest, which enables the flow to create a guest account for the user. -Workspaces can only be shared with users that have an existing guest account in your tenant. If Business-to-business Invitation Manager is enabled, users can share a page or component with a guest, which enables the flow to create a guest account for the user. +### Sharing steps -If the above conditions are met, then you can share with guest by: +Once conditions are met, share with guests by: -1. Navigate to the Loop workspace or page you want to share (or, navigate to the Loop file within OneDrive). -1. Open the share menu in the top right of the screen within Loop (or, open the share menu next to the file while viewing it within OneDrive). -1. Choose if you want to share the workspace or page (only applies within Loop). -1. Enter the user's email address you wish to share with. +1. Navigate to the Loop workspace or page. +1. Open the share menu. +1. Choose if you want to share the page or workspace (only applies within Loop). +1. Enter the guest's email address. 1. Select **Send** or **Invite**. -Sharing with external participants is done through "Share with specific people" links. Company-wide share links don't work with external participants. You must designate the guest explicitly in the share dialog. +Sharing with external participants is done through "Share with specific people" links. You must designate the guest explicitly in the share dialog. External participants can't be added to Company-wide share links. When a guest accesses the Loop workspace, page, or component from the link from your organization, they sign in and access the shared content using their guest account. They'll need to utilize the share link again to access the Loop workspace, page, or component in the future, as the content from your organization isn't accessible via their standard account. -If you would like to disable guest sharing of Loop workspaces independently of your organization-level OneDrive and SharePoint sharing setting, see [application external sharing override](/sharepoint/dev/embedded/concepts/app-concepts/sharing-and-perm#application-external-sharing-override) and the OwningApplicationID `a187e399-0c36-4b98-8f04-1edc167a0996`. +### More sharing controls + +If you would like to disable guest sharing of Copilot Pages, Copilot Pages within Copilot Notebooks, or Loop workspaces independently of your organization-level OneDrive and SharePoint sharing setting, see [application external sharing override](/sharepoint/dev/embedded/concepts/app-concepts/sharing-and-perm#application-external-sharing-override) and the Loop OwningApplicationID `a187e399-0c36-4b98-8f04-1edc167a0996`. All of these sharing settings are controlled by the Loop OwningApplicationId. Unlike SharePoint sites, there's no admin setting to configure guest sharing of specific Loop workspaces. Direct users toward [sensitivity labeling](/purview/sensitivity-labels-loop) for per-workspace external sharing configuration. Admin's can also [configure sensitivity labels](/sharepoint/dev/embedded/concepts/security-and-compliance#security-features) on containers. -## Loop workspace membership and Microsoft 365 groups +## Workspace membership and Microsoft 365 groups -Loop workspaces currently have one type, with membership visible and manageable within the Loop app by the workspace owner. However, there's no integration with Microsoft 365 groups or Security groups. Microsoft Roadmap ID 422728 addresses this for Microsoft 365 groups. +This section doesn't apply to Copilot Pages, Copilot Notebooks, or My workspace, which are personal, have only one member, and aren't shared. -Currently, owners can't assign new members as owners. If the owner leaves the company, the workspace becomes ownerless, remain in the tenant, and isn't automatically deleted. Administrators can't assign new owners to ownerless workspaces. Microsoft Roadmap ID 362124 and 421613 address this. +Shared Loop workspaces are managed within the Loop app by the workspace owners. Integration with Microsoft 365 groups is planned (Microsoft Roadmap ID 422728). -PowerShell support for number of owners on a SharePoint Embedded container isn't yet available. Once it is, to find ownerless workspaces, query Loop workspace containers in SharePoint Embedded. For more information, see [Consuming Tenant Admin](/sharepoint/dev/embedded/concepts/admin-exp/cta), and [Get-SPO Container](/powershell/module/sharepoint-online/get-spocontainer). The Loop Application ID is listed in [Summary of governance, lifecycle, and compliance capabilities](/microsoft-365/loop/loop-compliance-summary). +Owners can assign more members as owners. If all the owners leave the company, the workspace becomes ownerless, remains in the tenant, and isn't automatically deleted. Administrators can assign new owners to ownerless workspaces. -There are other types of groups and membership lists in the Microsoft ecosystem, such as Microsoft 365 groups and Security groups. Currently, Loop workspace membership doesn't use these groups or lists. Microsoft Roadmap ID 422728 addresses this for Microsoft 365 groups. +IT admins can use SharePoint Admin Center and PowerShell to find ownerless workspaces. For more information, see [Consuming Tenant Admin](/sharepoint/dev/embedded/concepts/admin-exp/cta), and [Get-SPO Container](/powershell/module/sharepoint-online/get-spocontainer). The Loop Application ID is listed in [Summary of governance, lifecycle, and compliance capabilities](/microsoft-365/loop/loop-compliance-summary). ## Storage management after user departure -### In the Loop app - -The Loop app is designed for both shared and personal workspaces. - -#### Shared Workspaces +### Shared Workspaces -- Shared workspaces are permissioned with a roster. If the owner leaves the company, the workspace becomes ownerless, remains in the tenant, and isn't automatically deleted. -- If the creator of the workspace is the person who left the company, others can't delete the workspace. +- Shared Loop workspaces are permissioned with a roster. If all the owners leave the company, the workspace becomes ownerless, remains in the tenant, and isn't automatically deleted. +- You must be an owner to delete a workspace. If all the owners left the company, members can't delete the workspace until an IT administrator adds new owners. -#### Personal Workspaces +### Personal Workspaces -- There are currently two types of personal workspaces: Ideas and Copilot Pages. +- [Copilot Pages](#copilot-pages), [Copilot Notebooks](#copilot-notebooks), and [My workspace](#my-workspace) all store content within the same user-owned SharePoint Embedded container named 'Pages' or 'My workspace' depending on which experience the person visits first (Copilot Pages or Copilot Notebooks, or Loop). - Personal content is private by default, allowing users to work without forced sharing or coauthoring, similar to OneDrive. -##### Ideas +#### Copilot Pages -- Ideas is a tenant-owned personal workspace, permissioned with a roster but designed for single-person use. -- When a user leaves the company, like a shared workspace, their Ideas workspace becomes ownerless, remains in the tenant, and isn't automatically deleted. +- Copilot Pages are stored in a user-owned SharePoint Embedded container, created by Copilot. The container is lifecycle managed with the user account, deleted when the user account is deleted from the organization. +- Copilot Pages can't be permanently reassigned to a new owner. It follows the same cleanup schedule as OneDrive: 30 days active, then soft deleted, and permanently purged 93 days after soft deletion. +- Admins can recover content during the soft delete period using the SharePoint Admin Center or PowerShell. -##### Copilot Pages +#### Copilot Notebooks -- Copilot Pages is a user-owned workspace, created only by Copilot, and is lifecycle managed with the user account. -- Copilot Pages is deleted when the user account is deleted from the organization. -- User-owned workspaces can't be permanently reassigned to a new owner. These workspaces follow the same cleanup schedule as OneDrive: 30 days active, then soft deleted, and permanently purged 93 days after soft deletion. +- Copilot Notebooks are stored in a user-owned SharePoint Embedded container, created by Copilot. The container is lifecycle managed with the user account, deleted when the user account is deleted from the organization. +- Copilot Notebooks can't be permanently reassigned to a new owner. It follows the same cleanup schedule as OneDrive: 30 days active, then soft deleted, and permanently purged 93 days after soft deletion. - Admins can recover content during the soft delete period using the SharePoint Admin Center or PowerShell. > [!NOTE] -> A feature for IT admins to assign additional temporary custodians during the cleanup period of user-owned workspaces to make copies of content isn't yet available. Microsoft Roadmap ID 421612 addresses this. +> A feature for IT admins to assign temporary custodians during the cleanup period of user-owned workspaces isn't yet available. This capability for Copilot Pages, Copilote Notebooks, and My workspace is planned (Microsoft Roadmap ID 421612). + +#### My workspace + +- My workspace is stored in a user-owned SharePoint Embedded container, created by Loop. The container is lifecycle managed with the user account, deleted when the user account is deleted from the organization. +- My workspace can't be permanently reassigned to a new owner. It follows the same cleanup schedule as OneDrive: 30 days active, then soft deleted, and permanently purged 93 days after soft deletion. +- Admins can recover content during the soft delete period using the SharePoint Admin Center or PowerShell. + +#### Ideas + +- The Ideas workspace is deprecated, no longer created by default, and replaced with the My workspace personal workspace. +- Ideas was the first default workspace, was tenant-owned, permissioned with a single-person roster. +- The Ideas workspace isn't deleted by the Loop app, a user or an admin must delete it if desired. +- When a user leaves the company, if they haven't added multiple owners to their Ideas workspace, the Ideas workspaces becomes ownerless, remains in the tenant, and isn't automatically deleted. -### In Loop components created in Microsoft 365 outside of the Loop app +### Loop components created in Microsoft 365 outside of the Loop app or Copilot Pages -Loop components created outside of Loop are stored in the OneDrive of the person who created the component, or if created in a place with shared storage like a Teams channel, they're stored in the SharePoint folder for that channel. When stored in OneDrive, if that user leaves the organization, the standard OneDrive IT policy is applied. When stored in SharePoint, the standard SharePoint IT policy is applied. +See [Storage](#storage). When content is stored in OneDrive, if that user leaves the organization, the standard OneDrive IT policy is applied. When content is stored in SharePoint, the standard SharePoint IT policy is applied. Learn more about [OneDrive and SharePoint Retention and Deletion](/sharepoint/retention-and-deletion). -## Management of Loop content +## Management of Loop and Copilot Pages content -For more information, see [available admin capabilities](/microsoft-365/loop/loop-compliance-summary#available-admin-capabilities) section of the [Summary of governance, lifecycle, and compliance capabilities](/microsoft-365/loop/loop-compliance-summary). +Refer to [Summary of governance, lifecycle, and compliance capabilities](/microsoft-365/loop/loop-compliance-summary). ## Pricing and licensing model for Loop app diff --git a/microsoft-365/loop/media/share-workspace-in-loop.png b/microsoft-365/loop/media/share-workspace-in-loop.png index 4417abee962..6bda54c9473 100644 Binary files a/microsoft-365/loop/media/share-workspace-in-loop.png and b/microsoft-365/loop/media/share-workspace-in-loop.png differ diff --git a/microsoft-365/lti/index.md b/microsoft-365/lti/index.md index 3b8382830e3..1293430ac6c 100644 --- a/microsoft-365/lti/index.md +++ b/microsoft-365/lti/index.md @@ -33,6 +33,11 @@ These tools include: For general information on managing Microsoft LTI apps, see [Manage Microsoft LTI apps for any LMS](manage-microsoft-one-lti.md). +> [!IMPORTANT] +> We're streamlining the LTI® (Learning Tools Interoperability) experiences for education customers who may be using different LMS systems. We're simplifying onboarding and usage by consolidating the capabilities of multiple LTI® tools available today into fewer and more functional tools. +> +> The capabilities of the Class Teams LTI® and Meetings LTI® tools are among the first tools updated in this consolidation. Microsoft is announcing the end of support for the Class Teams LTI® and Meetings LTI® tools on 15th June, 2025, as their capabilities will be superseded by a new, unified experience. Release details for the unified experience are forthcoming. + ## OneDrive LTI apps Learn more about using Microsoft OneDrive with your Learning Management System (LMS). diff --git a/microsoft-365/media/ai-as-org-message-create.png b/microsoft-365/media/ai-as-org-message-create.png new file mode 100644 index 00000000000..07d29e2929a Binary files /dev/null and b/microsoft-365/media/ai-as-org-message-create.png differ diff --git a/microsoft-365/media/ai-as-org-message.png b/microsoft-365/media/ai-as-org-message.png new file mode 100644 index 00000000000..4d862f21d6b Binary files /dev/null and b/microsoft-365/media/ai-as-org-message.png differ diff --git a/microsoft-365/media/ai-as-resources.png b/microsoft-365/media/ai-as-resources.png new file mode 100644 index 00000000000..9792eac386b Binary files /dev/null and b/microsoft-365/media/ai-as-resources.png differ diff --git a/microsoft-365/media/ai-assistance.png b/microsoft-365/media/ai-assistance.png index 8dd7954259c..9c085697a18 100644 Binary files a/microsoft-365/media/ai-assistance.png and b/microsoft-365/media/ai-assistance.png differ diff --git a/microsoft-365/media/ai-time-trend.png b/microsoft-365/media/ai-time-trend.png new file mode 100644 index 00000000000..bac2b5a8210 Binary files /dev/null and b/microsoft-365/media/ai-time-trend.png differ diff --git a/microsoft-365/media/ai-using-copilot.png b/microsoft-365/media/ai-using-copilot.png index 3b74e61b4f0..1002dca867e 100644 Binary files a/microsoft-365/media/ai-using-copilot.png and b/microsoft-365/media/ai-using-copilot.png differ diff --git a/microsoft-365/media/content-understanding/agreements-expiration-date-added.png b/microsoft-365/media/content-understanding/agreements-expiration-date-added.png new file mode 100644 index 00000000000..caab9509ee4 Binary files /dev/null and b/microsoft-365/media/content-understanding/agreements-expiration-date-added.png differ diff --git a/microsoft-365/media/content-understanding/agreements-expired-agreement-notification.png b/microsoft-365/media/content-understanding/agreements-expired-agreement-notification.png new file mode 100644 index 00000000000..69e71be0207 Binary files /dev/null and b/microsoft-365/media/content-understanding/agreements-expired-agreement-notification.png differ diff --git a/microsoft-365/media/content-understanding/agreements-generate-documents-expiration-date.png b/microsoft-365/media/content-understanding/agreements-generate-documents-expiration-date.png new file mode 100644 index 00000000000..31f43f57077 Binary files /dev/null and b/microsoft-365/media/content-understanding/agreements-generate-documents-expiration-date.png differ diff --git a/microsoft-365/media/content-understanding/agreements-setup-field-expiration-date.png b/microsoft-365/media/content-understanding/agreements-setup-field-expiration-date.png new file mode 100644 index 00000000000..75229c81270 Binary files /dev/null and b/microsoft-365/media/content-understanding/agreements-setup-field-expiration-date.png differ diff --git a/microsoft-365/media/content-understanding/backup-choose-selection-method-exchange.png b/microsoft-365/media/content-understanding/backup-choose-selection-method-exchange.png new file mode 100644 index 00000000000..601a76ed206 Binary files /dev/null and b/microsoft-365/media/content-understanding/backup-choose-selection-method-exchange.png differ diff --git a/microsoft-365/media/content-understanding/backup-choose-selection-method-onedrive.png b/microsoft-365/media/content-understanding/backup-choose-selection-method-onedrive.png new file mode 100644 index 00000000000..ab44c0e5143 Binary files /dev/null and b/microsoft-365/media/content-understanding/backup-choose-selection-method-onedrive.png differ diff --git a/microsoft-365/media/content-understanding/backup-overview-page-onedrive.png b/microsoft-365/media/content-understanding/backup-overview-page-onedrive.png index 4d676922e60..a38930c2901 100644 Binary files a/microsoft-365/media/content-understanding/backup-overview-page-onedrive.png and b/microsoft-365/media/content-understanding/backup-overview-page-onedrive.png differ diff --git a/microsoft-365/media/content-understanding/backup-policy-created-onedrive.png b/microsoft-365/media/content-understanding/backup-policy-created-onedrive.png index 37327ee66a1..4b774e50aa0 100644 Binary files a/microsoft-365/media/content-understanding/backup-policy-created-onedrive.png and b/microsoft-365/media/content-understanding/backup-policy-created-onedrive.png differ diff --git a/microsoft-365/media/content-understanding/backup-setup-backup-page-onedrive.png b/microsoft-365/media/content-understanding/backup-setup-backup-page-onedrive.png index 7459d943fe8..23874d88077 100644 Binary files a/microsoft-365/media/content-understanding/backup-setup-backup-page-onedrive.png and b/microsoft-365/media/content-understanding/backup-setup-backup-page-onedrive.png differ diff --git a/microsoft-365/media/content-understanding/esignature-notification-processing.png b/microsoft-365/media/content-understanding/esignature-notification-processing.png new file mode 100644 index 00000000000..9370b7bd9eb Binary files /dev/null and b/microsoft-365/media/content-understanding/esignature-notification-processing.png differ diff --git a/microsoft-365/media/content-understanding/esignature-notification-review-sign.png b/microsoft-365/media/content-understanding/esignature-notification-review-sign.png new file mode 100644 index 00000000000..9cc56b0b5ce Binary files /dev/null and b/microsoft-365/media/content-understanding/esignature-notification-review-sign.png differ diff --git a/microsoft-365/media/content-understanding/esignature-notification-send-second-request.png b/microsoft-365/media/content-understanding/esignature-notification-send-second-request.png new file mode 100644 index 00000000000..fc70bac3063 Binary files /dev/null and b/microsoft-365/media/content-understanding/esignature-notification-send-second-request.png differ diff --git a/microsoft-365/media/content-understanding/esignature-notification-two-requests-sent.png b/microsoft-365/media/content-understanding/esignature-notification-two-requests-sent.png new file mode 100644 index 00000000000..2a2ba2fb8ed Binary files /dev/null and b/microsoft-365/media/content-understanding/esignature-notification-two-requests-sent.png differ diff --git a/microsoft-365/media/enable-dev-analytics/enable-dev-analytics-flyout.png b/microsoft-365/media/enable-dev-analytics/enable-dev-analytics-flyout.png new file mode 100644 index 00000000000..7c98c0cbfcc Binary files /dev/null and b/microsoft-365/media/enable-dev-analytics/enable-dev-analytics-flyout.png differ diff --git a/microsoft-365/media/enable-dev-analytics/enable-dev-analytics.png b/microsoft-365/media/enable-dev-analytics/enable-dev-analytics.png new file mode 100644 index 00000000000..ec58a31ee45 Binary files /dev/null and b/microsoft-365/media/enable-dev-analytics/enable-dev-analytics.png differ diff --git a/microsoft-365/media/m365-backup/backup-choose-selection-method-exchange.png b/microsoft-365/media/m365-backup/backup-choose-selection-method-exchange.png index f182b0c066c..05cde8418f4 100644 Binary files a/microsoft-365/media/m365-backup/backup-choose-selection-method-exchange.png and b/microsoft-365/media/m365-backup/backup-choose-selection-method-exchange.png differ diff --git a/microsoft-365/media/m365-backup/backup-choose-selection-method-onedrive.png b/microsoft-365/media/m365-backup/backup-choose-selection-method-onedrive.png index 1e5a0169f92..60d8a7c3795 100644 Binary files a/microsoft-365/media/m365-backup/backup-choose-selection-method-onedrive.png and b/microsoft-365/media/m365-backup/backup-choose-selection-method-onedrive.png differ diff --git a/microsoft-365/media/m365-backup/backup-exchange-add-mailbox.png b/microsoft-365/media/m365-backup/backup-exchange-add-mailbox.png index 82997e00b96..6c53297de75 100644 Binary files a/microsoft-365/media/m365-backup/backup-exchange-add-mailbox.png and b/microsoft-365/media/m365-backup/backup-exchange-add-mailbox.png differ diff --git a/microsoft-365/media/m365-backup/backup-overview-page-exchange.png b/microsoft-365/media/m365-backup/backup-overview-page-exchange.png index e97c5f2b339..4eeb873833e 100644 Binary files a/microsoft-365/media/m365-backup/backup-overview-page-exchange.png and b/microsoft-365/media/m365-backup/backup-overview-page-exchange.png differ diff --git a/microsoft-365/media/m365-backup/backup-overview-page-onedrive.png b/microsoft-365/media/m365-backup/backup-overview-page-onedrive.png index 4d676922e60..de28658f681 100644 Binary files a/microsoft-365/media/m365-backup/backup-overview-page-onedrive.png and b/microsoft-365/media/m365-backup/backup-overview-page-onedrive.png differ diff --git a/microsoft-365/media/m365-backup/backup-policy-add-account.png b/microsoft-365/media/m365-backup/backup-policy-add-account.png index 7203e684b17..dd0e4e124b8 100644 Binary files a/microsoft-365/media/m365-backup/backup-policy-add-account.png and b/microsoft-365/media/m365-backup/backup-policy-add-account.png differ diff --git a/microsoft-365/media/m365-backup/backup-policy-created-exchange.png b/microsoft-365/media/m365-backup/backup-policy-created-exchange.png index 9696787b44c..2ca1f779995 100644 Binary files a/microsoft-365/media/m365-backup/backup-policy-created-exchange.png and b/microsoft-365/media/m365-backup/backup-policy-created-exchange.png differ diff --git a/microsoft-365/media/m365-backup/backup-policy-created-onedrive.png b/microsoft-365/media/m365-backup/backup-policy-created-onedrive.png index 37327ee66a1..1ba30797af2 100644 Binary files a/microsoft-365/media/m365-backup/backup-policy-created-onedrive.png and b/microsoft-365/media/m365-backup/backup-policy-created-onedrive.png differ diff --git a/microsoft-365/media/m365-backup/backup-policy-remove-account.png b/microsoft-365/media/m365-backup/backup-policy-remove-account.png index 9bf205ac52f..574e8d1d81a 100644 Binary files a/microsoft-365/media/m365-backup/backup-policy-remove-account.png and b/microsoft-365/media/m365-backup/backup-policy-remove-account.png differ diff --git a/microsoft-365/media/m365-backup/backup-policy-remove-mailbox.png b/microsoft-365/media/m365-backup/backup-policy-remove-mailbox.png index 3504c690b5a..be33c12765c 100644 Binary files a/microsoft-365/media/m365-backup/backup-policy-remove-mailbox.png and b/microsoft-365/media/m365-backup/backup-policy-remove-mailbox.png differ diff --git a/microsoft-365/media/m365-backup/backup-policy-updated-account.png b/microsoft-365/media/m365-backup/backup-policy-updated-account.png index 80199f5a617..e12c4c16b8d 100644 Binary files a/microsoft-365/media/m365-backup/backup-policy-updated-account.png and b/microsoft-365/media/m365-backup/backup-policy-updated-account.png differ diff --git a/microsoft-365/media/m365-backup/backup-policy-updated-mailbox.png b/microsoft-365/media/m365-backup/backup-policy-updated-mailbox.png index 500530434be..573dcf96dfd 100644 Binary files a/microsoft-365/media/m365-backup/backup-policy-updated-mailbox.png and b/microsoft-365/media/m365-backup/backup-policy-updated-mailbox.png differ diff --git a/microsoft-365/media/m365-backup/backup-setup-backup-page-exchange.png b/microsoft-365/media/m365-backup/backup-setup-backup-page-exchange.png index d122e78d41b..dc68ff98713 100644 Binary files a/microsoft-365/media/m365-backup/backup-setup-backup-page-exchange.png and b/microsoft-365/media/m365-backup/backup-setup-backup-page-exchange.png differ diff --git a/microsoft-365/media/m365-backup/backup-setup-backup-page-onedrive.png b/microsoft-365/media/m365-backup/backup-setup-backup-page-onedrive.png index 7459d943fe8..4228b120cf2 100644 Binary files a/microsoft-365/media/m365-backup/backup-setup-backup-page-onedrive.png and b/microsoft-365/media/m365-backup/backup-setup-backup-page-onedrive.png differ diff --git a/microsoft-365/media/solutions-architecture-center/m365-zero-trust-deployment-plan-thumb.png b/microsoft-365/media/solutions-architecture-center/m365-zero-trust-deployment-plan-thumb.png index 62aa83b7c8d..3c00b74ebe9 100644 Binary files a/microsoft-365/media/solutions-architecture-center/m365-zero-trust-deployment-plan-thumb.png and b/microsoft-365/media/solutions-architecture-center/m365-zero-trust-deployment-plan-thumb.png differ diff --git a/microsoft-365/media/zero-trust/ai-hub-sensitive-interactions-report.png b/microsoft-365/media/zero-trust/ai-hub-sensitive-interactions-report.png new file mode 100644 index 00000000000..546cc518e27 Binary files /dev/null and b/microsoft-365/media/zero-trust/ai-hub-sensitive-interactions-report.png differ diff --git a/microsoft-365/media/zero-trust/identity-access-enterprise-tier.svg b/microsoft-365/media/zero-trust/identity-access-enterprise-tier.svg index b80e3fcc328..f098dfda559 100644 --- a/microsoft-365/media/zero-trust/identity-access-enterprise-tier.svg +++ b/microsoft-365/media/zero-trust/identity-access-enterprise-tier.svg @@ -2,769 +2,694 @@ - Zero Trust deployment plan with Microsoft 365 + xmlns:v="http://schemas.microsoft.com/visio/2003/SVGExtensions/" width="17.0278in" height="8.65278in" + viewBox="0 0 1226 623" xml:space="preserve" color-interpolation-filters="sRGB" class="st32"> + + + + + Page-1 - - - - Sheet.1494 + + + + + + Sheet.1972 - + - + - - Sheet.1495 + + Sheet.2006 - + - + - - Arrow 1 - gray.1496 + + Sheet.1885 - + - + - - Devices.32 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + Sheet.1680 + + + + - - Monitor / TV.33 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + Arrow 1 - gray.3208 + + + + + - - Sheet.1497 + + Sheet.1683 Microsoft Entra Conditional Access policies - + - - - Microsoft Entra Conditional Access + + Microsoft Entra Conditional Access policies - - Sheet.1498 + + Sheet.1684 Protection level - + - - - - Protection level - - Sheet.1499 + + + + Protection level + + Sheet.1685 Starting point - + - - - Starting point - - Sheet.1500 - Specialized security (only if needed for specific data sets o... + + + Starting point + + Sheet.1687 + Device type - + - - - Specialized security(only if needed for specific data sets or users) - - Sheet.1501 - Device type - - - - - - - Device type - - - Sheet.1502 - Zero Trust identity and device access policies - - - - - - - Zero Trust identity and device access policies - - - Sheet.1503 + + + Device type + + Sheet.1690 Intune device compliance policy - + - - - Intune device compliance policy - - Sheet.1504 + + + Intune device compliance policy + + Sheet.1691 Intune app protection policies - + - - - Intune app + + Intune app protection policies - - Arrow 1 - gray.1505 + + Arrow 1 - gray.3217 - + - + + - - Monitor / TV.34 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Sheet.1506 - PCs + + Arrow 1 - gray.3220 - + - - - - PCs - - Devices.35 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + - - Sheet.1507 - Phones and tablets + + Sheet.1697 + Define compliance policies (one for each platform) + + + + + + + + + + Define compliance policies (one for each platform). + + Sheet.1700 + + + + + + + + Sheet.1708 + Require compliant PCs and mobile devices This policy enforces... - + - - - - Phones and tablets - - Arrow 1 - gray.1508 + + + + + + + Require compliant PCs and mobile devices.Enforces Intune management for PCs and mobile devices. + + Sheet.1710 + Block clients that don’t support modern authentication Client... - + - + + + + + + + Block clients that don’t support modern authentication.Clients that dont use modern authentication can bypass Conditional Access policies. + + Sheet.1711 + + + + + - - Devices.36 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + Phone Tablet Blue.1838 + + Sheet.1839 + + + + Sheet.1840 + + - - Monitor / TV.37 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + Desktop Tower Blue.1841 + + Sheet.1842 + + + + Sheet.1843 + + - - - Sheet.1509 - Define compliance policies (one for each platform) - - - - - - - Define compliance policies (one for each platform) - - - - Sheet.1510 - High risk users must change password This policy forces users... - - - - - - - High risk users must change passwordThis policy forces users to change their password when signing in if high risk activity is detected for their account. - - - Sheet.1511 - - - - + + + + + Phone Tablet Blue.1829 + + Sheet.1830 + + + + Sheet.1831 + + - - - Sheet.1512 - Apply Level 2 APP data protection - - - - - - - Apply Level 2 APP data protection - - - - Sheet.1513 - Apply Level 3 APP data protection - - - - - - - Apply Level 3 APP data protection - - - - Sheet.1514 - Apply Level 2 App Protection Policies (APP) data protection (... - - - - - - - Apply Level 2 App Protection Policies (APP) data protection (one for each platform) - - - - Sheet.1515 - Require compliant PCs and mobile devices This policy enforces... + + + + + Desktop Tower Blue.1832 + + Sheet.1833 + + + + Sheet.1834 + + + + + Sheet.1704 + Apply Level 3 APP data protection + + + + + + + + + + Apply Level 3 APP data protection. + + Sheet.1721 + Require MFA always This is also available for all Microsoft 365 ... + + + + + + + + + + Require MFA always.Available for all Microsoft 365 Enterprise plans. + + Sheet.1732 + Require approved apps + + + + + + + + + + Require approved apps. + + Sheet.1706 + Apply Level 2 App Protection Policies (APP) data protection (... + + + + + + + + + + Apply Level 2 App Protection Policies (APP) data protection.(one for each platform) + + Sheet.1715 + Require approved apps This policy enforces mobile app protect... + + + + + + + + + + Require approved apps.Enforces app protection for mobile devices. + + Sheet.1702 + Apply Level 2 APP data protection + + + + + + + + + + Apply Level 2 APP data protection. + + Sheet.1713 + Require approved apps + + + + + + + + + + Require approved apps. + + Sheet.1694 + Phones and tablets + + + + + + + Mobile devices + + + + + Phone Tablet Blue + + Sheet.1807 + + + + Sheet.1808 + + + + + Sheet.1693 + PCs + + + + + + + PCs + + + + + Desktop Tower Blue + + Sheet.1811 + + + + Sheet.1812 + + + + + Sheet.1727 + PCs include devices running the Windows or macOS platforms + + + + + + + PCs running on Windows or macOS platforms. + + Sheet.1728 + Phones and tablets include devices running the iOS, iPadOS, o... + + + + + + + Mobile devices running on iOS, iPadOS, or Android platforms. + + Sheet.1730 + Requires Microsoft 365 E5, Microsoft 365 E3 with the E5 Ident... + + + + + + + Requires one of the following subscriptions:Microsoft 365 E5Microsoft 365 E3 with the E5 Identity add-onMicrosoft 365 with EMS E5Individual Microsoft Entra ID P2 licenses + + + + + Sheet.2000 + + Sheet.1719 + Require multifactor authentication (MFA) when sign-in risk is... - + - - - - Require compliant PCs and mobile devicesThis policy enforces Intune management for PCs, phones, and tablets. - - - - Sheet.1516 - Block clients that don’t support modern authentication Client... + + + + + + + Require multifactor authentication (MFA) when sign-in risk is Medium or High. + + + + + + Sheet.2001 + + Sheet.1717 + Require MFA when sign-in risk is low, medium, or high - + - - - - Block clients that don’t support modern authentication Clients that do not use modern authentication can bypass Conditional Access policies. - - - Sheet.1517 - - - - + + + + + + + Require MFA when sign-in risk is Low, Medium, or High. - - - Sheet.1518 - Require approved apps + + + + + Sheet.2002 + + Sheet.1699 + High-risk users must change password This policy forces users... - + - - - - Require approved apps - - - - Sheet.1519 - Require approved apps This policy enforces mobile app protect... + + + + + + + High-risk users must change password.Forces users to change their password when signing in if high-risk activity is detected for their account. + + + + + + Sheet.2004 + + Sheet.1725 + Enterprise (Recommended for Zero Trust) - + - - - - Require approved appsThis policy enforces mobile app protection for phones & tablets. - - - - Sheet.1520 - Require MFA when sign-in risk is low, medium, or high + + + + Enterprise + + Sheet.1878 + Enterprise (Recommended for Zero Trust) - + - - - - Require MFA when sign-in risk is low, medium, or high - - - - Sheet.1521 - Require multi-factor authentication (MFA) when sign-in risk i... + + + + (Recommended forZero Trust) + + + + + + Sheet.2005 + + Sheet.1686 + Specialized security (only if needed for specific data sets o... - + - - - - Require multi-factor authentication (MFA) when sign-in risk is medium or high - - - - Sheet.1522 - Require MFA always This is also available for all Office 365 ... + + + + Specialized security + + Sheet.1877 + Specialized security (only if needed for specific data sets o... - + - - - - Require MFA alwaysThis is also available for all Office 365 Enterprise plans. - - - Sheet.1523 - - - - + + + + (only if needed for specific data sets or users) - - Sheet.1524 + + Sheet.1966 - + - + - - Sheet.1525 + + Sheet.1967 - + - + - - Sheet.1526 - Enterprise (Recommended for Zero Trust) + + Sheet.1968 - - - - - - Enterprise(Recommended for Zero Trust) - - Sheet.1527 - March 2024 - - - - - - - March 2024 - - Sheet.1528 - PCs include devices running the Windows or macOS platforms - - + - - - - PCs include devices running the Windows or macOS platforms - - Sheet.1529 - Phones and tablets include devices running the iOS, iPadOS, o... - - - - - - - Phones and tablets include devices running the iOS, iPadOS, or Android platforms - - Sheet.1530 + + + + Sheet.1969 - + - + - - Sheet.1531 - Requires Microsoft 365 E5, Microsoft 365 E3 with the E5 Ident... + + Sheet.1971 - + - - - - Requires Microsoft 365 E5, Microsoft 365 E3 with the E5 Identity add-on, Office 365 with EMS E5, or individual - - - Sheet.1532 - Require approved apps - - - - - - - Require approved apps - - - Sheet.1533 - - - - + diff --git a/microsoft-365/media/zero-trust/identity-access-starting-point-tier.svg b/microsoft-365/media/zero-trust/identity-access-starting-point-tier.svg index dc705894231..375854dfe42 100644 --- a/microsoft-365/media/zero-trust/identity-access-starting-point-tier.svg +++ b/microsoft-365/media/zero-trust/identity-access-starting-point-tier.svg @@ -2,769 +2,694 @@ - Zero Trust deployment plan with Microsoft 365 + xmlns:v="http://schemas.microsoft.com/visio/2003/SVGExtensions/" width="17.0278in" height="8.65278in" + viewBox="0 0 1226 623" xml:space="preserve" color-interpolation-filters="sRGB" class="st32"> + + + + + Page-1 - - - - Sheet.1455 + + + + + + Sheet.1972 - + - + - - Sheet.1456 + + Sheet.2006 - + - + - - Arrow 1 - gray.3208 + + Sheet.1885 - + - + - - Devices.5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + Sheet.1680 + + + + - - Monitor / TV.6 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + Arrow 1 - gray.3208 + + + + + - - Sheet.1458 + + Sheet.1683 Microsoft Entra Conditional Access policies - + - - - Microsoft Entra Conditional Access + + Microsoft Entra Conditional Access policies - - Sheet.1459 + + Sheet.1684 Protection level - + - - - - Protection level - - Sheet.1460 + + + + Protection level + + Sheet.1685 Starting point - + - - - Starting point - - Sheet.1461 - Specialized security (only if needed for specific data sets o... + + + Starting point + + Sheet.1687 + Device type - + - - - Specialized security(only if needed for specific data sets or users) - - Sheet.1462 - Device type - - - - - - - Device type - - - Sheet.1463 - Zero Trust identity and device access policies - - - - - - - Zero Trust identity and device access policies - - - Sheet.1464 + + + Device type + + Sheet.1690 Intune device compliance policy - + - - - Intune device compliance policy - - Sheet.1465 + + + Intune device compliance policy + + Sheet.1691 Intune app protection policies - + - - - Intune app + + Intune app protection policies - + Arrow 1 - gray.3217 - + - - - - Monitor / TV.9 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + - - Sheet.1467 - PCs + + Arrow 1 - gray.3220 - + - - - - PCs - - Devices.10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + Sheet.1697 + Define compliance policies (one for each platform) + + + + + + + + + + Define compliance policies (one for each platform). + + Sheet.1700 + + + + + + + + Sheet.1708 + Require compliant PCs and mobile devices This policy enforces... + + + + + + + + + + Require compliant PCs and mobile devices.Enforces Intune management for PCs and mobile devices. + + Sheet.1710 + Block clients that don’t support modern authentication Client... + + + + + + + + + + Block clients that don’t support modern authentication.Clients that dont use modern authentication can bypass Conditional Access policies. + + Sheet.1711 + + + + + + + + + + + Phone Tablet Blue.1838 + + Sheet.1839 + + + + Sheet.1840 + + + + + + + + Desktop Tower Blue.1841 + + Sheet.1842 + + + + Sheet.1843 + + + + + + + + Phone Tablet Blue.1829 + + Sheet.1830 + + + + Sheet.1831 + + - - Sheet.1468 + + + + + Desktop Tower Blue.1832 + + Sheet.1833 + + + + Sheet.1834 + + + + + Sheet.1704 + Apply Level 3 APP data protection + + + + + + + + + + Apply Level 3 APP data protection. + + Sheet.1721 + Require MFA always This is also available for all Microsoft 365 ... + + + + + + + + + + Require MFA always.Available for all Microsoft 365 Enterprise plans. + + Sheet.1732 + Require approved apps + + + + + + + + + + Require approved apps. + + Sheet.1706 + Apply Level 2 App Protection Policies (APP) data protection (... + + + + + + + + + + Apply Level 2 App Protection Policies (APP) data protection.(one for each platform) + + Sheet.1715 + Require approved apps This policy enforces mobile app protect... + + + + + + + + + + Require approved apps.Enforces app protection for mobile devices. + + Sheet.1702 + Apply Level 2 APP data protection + + + + + + + + + + Apply Level 2 APP data protection. + + Sheet.1713 + Require approved apps + + + + + + + + + + Require approved apps. + + Sheet.1694 Phones and tablets - + - - - - Phones and tablets - - Arrow 1 - gray.3220 + + + + Mobile devices + + + + + Phone Tablet Blue + + Sheet.1807 + + + + Sheet.1808 + + + + + Sheet.1693 + PCs - + - - - - Devices.11 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Monitor / TV.12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + PCs + + + + + Desktop Tower Blue + + Sheet.1811 + + + + Sheet.1812 + + - - - Sheet.1470 - Define compliance policies (one for each platform) - - - - - - - Define compliance policies (one for each platform) - - - - Sheet.1471 - High risk users must change password This policy forces users... + + Sheet.1727 + PCs include devices running the Windows or macOS platforms + + + + + + + PCs running on Windows or macOS platforms. + + Sheet.1728 + Phones and tablets include devices running the iOS, iPadOS, o... + + + + + + + Mobile devices running on iOS, iPadOS, or Android platforms. + + Sheet.1730 + Requires Microsoft 365 E5, Microsoft 365 E3 with the E5 Ident... + + + + + + + Requires one of the following subscriptions:Microsoft 365 E5Microsoft 365 E3 with the E5 Identity add-onMicrosoft 365 with EMS E5Individual Microsoft Entra ID P2 licenses + + + + + Sheet.2000 + + Sheet.1719 + Require multifactor authentication (MFA) when sign-in risk is... - + - - - - High risk users must change passwordThis policy forces users to change their password when signing in if high risk activity is detected for their account. - - - Sheet.1472 - - - - + + + + + + + Require multifactor authentication (MFA) when sign-in risk is Medium or High. - - - Sheet.1473 - Apply Level 2 APP data protection - - - - - - - Apply Level 2 APP data protection - - - - Sheet.1474 - Apply Level 3 APP data protection - - - - - - - Apply Level 3 APP data protection - - - - Sheet.1475 - Apply Level 2 App Protection Policies (APP) data protection (... - - - - - - - Apply Level 2 App Protection Policies (APP) data protection (one for each platform) - - - - Sheet.1476 - Require compliant PCs and mobile devices This policy enforces... - - - - - - - Require compliant PCs and mobile devicesThis policy enforces Intune management for PCs, phones, and tablets. - - - - Sheet.1477 - Block clients that don’t support modern authentication Client... + + + + + Sheet.2001 + + Sheet.1717 + Require MFA when sign-in risk is low, medium, or high - + - - - - Block clients that don’t support modern authentication Clients that do not use modern authentication can bypass Conditional Access policies. - - - Sheet.1478 - - - - + + + + + + + Require MFA when sign-in risk is Low, Medium, or High. - - - Sheet.1479 - Require approved apps + + + + + Sheet.2002 + + Sheet.1699 + High-risk users must change password This policy forces users... - + - - - - Require approved apps - - - - Sheet.1480 - Require approved apps This policy enforces mobile app protect... + + + + + + + High-risk users must change password.Forces users to change their password when signing in if high-risk activity is detected for their account. + + + + + + Sheet.2004 + + Sheet.1725 + Enterprise (Recommended for Zero Trust) - + - - - - Require approved appsThis policy enforces mobile app protection for phones & tablets. - - - - Sheet.1481 - Require MFA when sign-in risk is low, medium, or high + + + + Enterprise + + Sheet.1878 + Enterprise (Recommended for Zero Trust) - + - - - - Require MFA when sign-in risk is low, medium, or high - - - - Sheet.1482 - Require multi-factor authentication (MFA) when sign-in risk i... + + + + (Recommended forZero Trust) + + + + + + Sheet.2005 + + Sheet.1686 + Specialized security (only if needed for specific data sets o... - + - - - - Require multi-factor authentication (MFA) when sign-in risk is medium or high - - - - Sheet.1483 - Require MFA always This is also available for all Office 365 ... + + + + Specialized security + + Sheet.1877 + Specialized security (only if needed for specific data sets o... - + - - - - Require MFA alwaysThis is also available for all Office 365 Enterprise plans. - - - Sheet.1484 - - - - + + + + (only if needed for specific data sets or users) - - Sheet.1485 + + Sheet.1966 - + - + - - Sheet.1486 + + Sheet.1967 - + - + - - Sheet.1487 - Enterprise (Recommended for Zero Trust) - - - - - - - Enterprise(Recommended for Zero Trust) - - Sheet.1488 - March 2024 - - - - - - - March 2024 - - Sheet.1489 - PCs include devices running the Windows or macOS platforms + + Sheet.1968 - + - - - - PCs include devices running the Windows or macOS platforms - - Sheet.1490 - Phones and tablets include devices running the iOS, iPadOS, o... - - - - - - - Phones and tablets include devices running the iOS, iPadOS, or Android platforms - - Sheet.1491 + + + + Sheet.1969 - + - + - - Sheet.1492 - Requires Microsoft 365 E5, Microsoft 365 E3 with the E5 Ident... + + Sheet.1971 - + - - - - Requires Microsoft 365 E5, Microsoft 365 E3 with the E5 Identity add-on, Office 365 with EMS E5, or individual - - - Sheet.1493 - Require approved apps - - - - - - - Require approved apps - - - Sheet.1534 - - - - + diff --git a/microsoft-365/media/zero-trust/m365-zero-trust-architecture-defender.svg b/microsoft-365/media/zero-trust/m365-zero-trust-architecture-defender.svg new file mode 100644 index 00000000000..180b298b730 --- /dev/null +++ b/microsoft-365/media/zero-trust/m365-zero-trust-architecture-defender.svg @@ -0,0 +1,1576 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + Page-1 + + + + + + + + + Sheet.1698 + + + + + + + Sheet.2601 + + + + + + + Sheet.2602 + Strong authentication + + + + + + + Strong authentication + + Sheet.2603 + Device compliance + + + + + + + Device compliance + + Sheet.2604 + Risk assessment + + + + + + + Risk assessment + + Sheet.2605 + Traffic filtering & segmentation + + + + + + + Traffic filtering & segmentation + + Sheet.2606 + + + + + + + Sheet.2607 + Telemetry/analytics/assessment + + + + + + + Telemetry/analytics/assessment + + Sheet.2608 + JIT & Version Control + + + + + + + JIT & Version Control + + Dynamic connector.1162 + + + + + + + Sheet.2610 + + + + + + + Sheet.2611 + + + + + + + Sheet.2612 + Corporate + + + + + + + Corporate + + Sheet.2613 + Personal + + + + + + + Personal + + + + + Sheet.2614 + + Sheet.2615 + + + + + + + Sheet.2746 + + + + + + + + Sheet.2616 + Endpoints + + + + + + + Endpoints + + Sheet.2617 + + + + + + + Sheet.2618 + + + + + + + Sheet.2619 + Human + + + + + + + Human + + Sheet.2620 + Non-human + + + + + + + Non-human + + + + + Sheet.2621 + + Sheet.2622 + + + + + + + Sheet.2744 + + + + + + + + Sheet.2623 + Identities + + + + + + + Identities + + Sheet.2624 + + + + + + + Sheet.2625 + + + + + + + Sheet.2626 + Evaluation + + + + + + + Evaluation + + Sheet.2627 + Enforcement + + + + + + + Enforcement + + + + + Sheet.2628 + + Sheet.2629 + + + + + + + Sheet.2751 + + + + + + + + Sheet.2630 + Zero Trust Policies + + + + + + + Zero Trust Policies + + Sheet.2631 + + + + + + + Sheet.2632 + + + + + + + Sheet.2633 + + + + + + + Sheet.2634 + + + + + + + Sheet.2635 + Governance + + + + + + + Governance + + Sheet.2636 + Compliance + + + + + + + Compliance + + Sheet.2637 + Security Posture Assessment + + + + + + + Security Posture Assessment + + Sheet.2638 + Productivity Optimization + + + + + + + Productivity Optimization + + + + + Sheet.2639 + + Sheet.2640 + + + + + + + Sheet.2747 + + + + + + + + Sheet.2641 + Policy Optimization + + + + + + + Policy Optimization + + Sheet.2642 + + + + + + + Sheet.2643 + + + + + + + Sheet.2644 + Public + + + + + + + Public + + Sheet.2645 + + + + + + + Sheet.2646 + + + + + + + Sheet.2647 + Serverless + + + + + + + Serverless + + Sheet.2648 + Containers + + + + + + + Containers + + + + + Sheet.2649 + + Sheet.2650 + + + + + + + Sheet.2753 + + + + + + + + Sheet.2651 + Infrastructure + + + + + + + Infrastructure + + Sheet.2652 + + + + + + + Sheet.2653 + IaaS + + + + + + + IaaS + + Sheet.2654 + + + + + + + Sheet.2655 + Paas + + + + + + + Paas + + Sheet.2656 + + + + + + + Sheet.2657 + Internal Sites + + + + + + + Internal Sites + + Sheet.2658 + + + + + + + Sheet.2659 + + + + + + + Sheet.2660 + + + + + + + Sheet.2661 + + + + + + + Sheet.2662 + + + + + + + Sheet.2663 + + + + + + + Sheet.2664 + + + + + + + Sheet.2665 + Emails & documents + + + + + + + Emails & documents + + Sheet.2666 + Structured data + + + + + + + Structured data + + + + + Sheet.2667 + + Sheet.2668 + + + + + + + Sheet.2755 + + + + + + + + Dynamic connector.1267 + + + + + + + Sheet.2669 + Data + + + + + + + Data + + Sheet.2670 + + + + + + + Sheet.2671 + + + + + + + Sheet.2672 + SaaS + + + + + + + SaaS + + Sheet.2673 + On-premises + + + + + + + On-premises + + + + + Sheet.2674 + + Sheet.2675 + + + + + + + Sheet.2754 + + + + + + + + Dynamic connector.1259 + + + + + + + Sheet.2676 + Apps + + + + + + + Apps + + Sheet.2677 + + + + + + + Sheet.2678 + + + + + + + Sheet.2679 + + + + + + + Sheet.2680 + + + + + + + Sheet.2681 + Continuous Assessment + + + + + + + Continuous Assessment + + Sheet.2682 + Threat Intelligence + + + + + + + Threat Intelligence + + Sheet.2683 + Forensics + + + + + + + Forensics + + Sheet.2684 + Response Automation + + + + + + + Response Automation + + + + + Sheet.2685 + + Sheet.2686 + + + + + + + Sheet.2752 + + + + + + + + Sheet.2687 + Threat Protection + + + + + + + Threat Protection + + Sheet.2688 + Request enhancement + + + + + + + Request enhancement + + + + + Sheet.2689 + + Sheet.2690 + + + + Sheet.2691 + + + + + Dynamic connector.1260 + + + + + + + Sheet.2692 + Adaptive Access + + + + + + + Adaptive Access + + Sheet.2693 + + + + + + + Dynamic connector.1261 + + + + + + + Sheet.2694 + Classify, label, encrypt + + + + + + + Classify, label, encrypt + + Sheet.2695 + + + + + + + Dynamic connector.1280 + + + + + + + Dynamic connector.1262 + + + + + + + Sheet.2696 + Runtime control + + + + + + + Runtime control + + Sheet.2697 + + + + + + + Dynamic connector.1263 + + + + + + + Dynamic connector.1264 + + + + + + + Dynamic connector.1265 + + + + + + + Dynamic connector.1266 + + + + + + + Dynamic connector.1268 + + + + + + + Dynamic connector.1269 + + + + + + + Dynamic connector.1270 + + + + + + + Dynamic connector.1271 + + + + + + + Dynamic connector.1272 + + + + + + + Dynamic connector.1273 + + + + + + + Dynamic connector.1274 + + + + + + + Dynamic connector.1275 + + + + + + + Dynamic connector.1276 + + + + + + + Dynamic connector.1277 + + + + + + + Dynamic connector.1278 + + + + + + + Dynamic connector.1279 + + + + + + + Sheet.2720 + + + + + + + + + + Sheet.2721 + + Sheet.2722 + + + + + Sheet.2723 + + + + + + + + + + Sheet.2724 + + Sheet.2725 + + + + + Sheet.2726 + + + + + + + + + + Sheet.2727 + + Sheet.2728 + + + + + Sheet.2729 + + + + + + + + + + Sheet.2730 + + Sheet.2731 + + + + + Sheet.2732 + + + + + + + + + + Sheet.2733 + + Sheet.2734 + + + + + Sheet.2735 + Private + + + + + + + Private + + + + + Sheet.2736 + + Sheet.2738 + + + + + + + Sheet.2750 + + + + + + + + Sheet.2739 + Network + + + + + + + Network + + Sheet.1682 + AI + + + + + + + AI + + Sheet.1683 + + + + + + + Sheet.1684 + + + + + + + Sheet.1685 + + + + + + + Sheet.1686 + Management Azure subscription + + + + + + + Defender for Office 365 + + Sheet.1687 + Management Azure subscription + + + + + + + Defender for Cloud Apps + + Sheet.1688 + Management Azure subscription + + + + + + + Defender for identity· AD DS servers· AD FS servers + + Sheet.1689 + Management Azure subscription + + + + + + + Pilot and deploy Microsoft Defender XDR + + Sheet.1690 + + + + + + + Sheet.1691 + Management Azure subscription + + + + + + + Defender for Endpoint + + Sheet.1692 + Management Azure subscription + + + + + + + Entra ID Protection + + Sheet.1693 + + + + + + + Sheet.1694 + + + + + + + Sheet.1695 + + + + + + + Sheet.1696 + + + + + + + Sheet.1697 + + + + + + + diff --git a/microsoft-365/media/zero-trust/m365-zero-trust-deployment-swim-lanes.svg b/microsoft-365/media/zero-trust/m365-zero-trust-deployment-swim-lanes.svg new file mode 100644 index 00000000000..59d84d52fa1 --- /dev/null +++ b/microsoft-365/media/zero-trust/m365-zero-trust-deployment-swim-lanes.svg @@ -0,0 +1,1271 @@ + + + + + + + + + + + + + + + + + + Page-1 + + + + + + + + + + Sheet.1213 + + + + + + + Sheet.1124 + Secure remote and hybrid work + + + + + + + Secure remote and hybrid work + + Sheet.1125 + Prevent or reduce business damage from a breach + + + + + + + Prevent or reduce business damage from a breach + + Sheet.1126 + Identify and protect sensitive business data + + + + + + + Identify and protect sensitive business data + + Sheet.1127 + Secure AI apps and data + + + + + + + Secure AI apps and data + + + Rectangle.1061 + Configure cloud identity and/or cloud provisioning: Cloud onl... + + + + + + + + + + + Configure cloud identity and/or cloud provisioning:· Cloud only· Hybrid with Password Hash Synchronization (PHS) + + + + Rectangle.1063 + Configure Starting point Zero Trust identity and device acces... + + + + + + + + + + + Configure Starting point Zero Trust identity and device access policies Turn on Multi-Factor Authentication (MFA) and configure Intune app protection policies that don’t require managing devices + + + Rectangle.1065 + Add SaaS apps to Microsoft Entra and include these in the sco... + + + + + + + + + + + Add SaaS apps to Microsoft Entra and include these in the scope of MFA policies + + + Rectangle.1067 + Enroll devices into management + + + + + + + + + + + Enroll devices into management + + + + Rectangle.1069 + Configure compliance policies To be sure devices meet minimum... + + + + + + + + + + + Configure compliance policiesTo be sure devices meet minimum requirements + + + + Rectangle.1071 + Configure Enterprise (recommended) Zero Trust identity and de... + + + + + + + + + + + Configure Enterprise (recommended) Zero Trust identity and device access policies Require healthy and compliant devices + + + + Rectangle.1073 + Deploy Intune configuration profiles to harden devices agains... + + + + + + + + + + + Deploy Intune configuration profiles to harden devices against threats + + + + Rectangle.1075 + Pilot and deploy Microsoft Defender XDR + + + + + + + + + + + Pilot and deploy Microsoft Defender XDR + + + + Rectangle.1076 + Defender for Identity + + + + + + + + + + + Defender for Identity + + + + Rectangle.1077 + Defender for Office 365 + + + + + + + + + + + Defender for Office 365 + + + + Rectangle.1080 + Monitor device risk and compliance of devices to security bas... + + + + + + + + + + + Monitor device risk and compliance of devices to security baselines + + + Rectangle.1081 + Create Defender for Cloud Apps policies to protect access and... + + + + + + + + + + + Create Defenderfor Cloud Apps policies to protect access and use of SaaS apps + + Sheet.1140 + + + + + + + Sheet.1141 + + + + + + + Sheet.1142 + + + + + + + Sheet.1143 + + + + + + + Sheet.1144 + + + + + + + Rectangle.1088 + + + + + + + + Rectangle.1089 + + + + + + + + Sheet.1147 + Security operations + + + + + + + Security operations + + Sheet.1148 + Identity + + + + + + + Identity + + Rectangle.1092 + + + + + + + + Rectangle.1093 + + + + + + + + Sheet.1151 + Information protection & governance + + + + + + + Information protection & governance + + Sheet.1152 + Devices + + + + + + + Devices + + + Rectangle.1096 + Deploy global secure access — Security Service Edge (SSE) + + + + + + + + + + + Deploy global secure access — Security Service Edge (SSE) + + + + Rectangle.1097 + Configure employee and guest access and approval (entitlements) + + + + + + + + + + + Configure employee and guest access and approval (entitlements) + + + + Rectangle.1099 + Review employee and guest access and approval (entitlements) ... + + + + + + + + + + + Review employee and guest access and approval (entitlements) and remove unused access permissions + + + + Rectangle.1103 + Discover and identify sensitive business data with Data Secur... + + + + + + + + + + + Discover and identify sensitive business data with Data Security Posture Management (DSPM) + + + + Rectangle.1105 + Address files with the highest sensitivity + + + + + + + + + + + Address files with the highest sensitivity + + + + Rectangle.1106 + Use DSPM to learn about and correct gaps in policy coverage f... + + + + + + + + + + + Use DSPM to learn about and correct gaps in policy coverage for sensitivity labels and DLP policies + + + + Rectangle.1107 + Set up secure Teams for sharing data internally and externall... + + + + + + + + + + + Set up secure Teams for sharing data internally and externally with business partners + + + Sheet.1160 + + + + + + + + Rectangle.1111 + Add encryption and access controls to labels + + + + + + + + + + + Add encryption and access controls to labels + + + + Rectangle.1112 + Introduce automatic & recommended labeling + + + + + + + + + + + Introduce automatic & recommended labeling + + + + Rectangle.1113 + Extend DLP policies across Microsoft 365 services + + + + + + + + + + + Extend DLP policies across Microsoft 365 services + + + + Rectangle.1114 + Implement key insider risk management policies + + + + + + + + + + + Implement key insider risk management policies + + + + Rectangle.1115 + Extend labels and protection to data in SaaS apps, including ... + + + + + + + + + + + Extend labels and protection to data in SaaS apps, including DLP + + + + Rectangle.1116 + Extend DLP policies to Windows and MacOS devices + + + + + + + + + + + Extend DLP policies to Windows and MacOS devices + + + Sheet.1167 + + + + + + + + Rectangle.1118 + Begin investigating and responding to threats + + + + + + + + + + + Begin investigating and responding to threats + + + Sheet.1169 + Meet regulatory and compliance requirements + + + + + + + Meet regulatory and compliance requirements + + Sheet.1170 + + + + + + + Sheet.1171 + + + + + + + + Rectangle.1172 + Gain visibility into AI usage with Data Security Posture Mana... + + + + + + + + + + + Gain visibility into AI usage with Data Security Posture Management (DSPM) for AI + + + + Rectangle.1129 + Apply SharePoint oversharing controls + + + + + + + + + + + Apply SharePoint oversharing controls + + + + Rectangle.1130 + Apply the Insider Risk Management ‘Risky AI usage’ policy tem... + + + + + + + + + + + Apply the Insider Risk Management Risky AI usage’ policy template + + + Sheet.1175 + + + + + + + + Rectangle.1125 + Discover, sanction, and block AI apps with Microsoft Defender... + + + + + + + + + + + Discover, sanction, and block AI apps with Microsoft Defender for Cloud Apps + + + + Rectangle.1108 + Discover non-sanctioned SaaS apps + + + + + + + + + + + Discover non-sanctioned SaaS apps + + + Sheet.1178 + + + + + + + + Rectangle.1134 + Identify regulatory requirements + + + + + + + + + + + Identify regulatory requirements + + + + Rectangle.1135 + Use Compliance Manager to assess compliance and plan remediat... + + + + + + + + + + + Use Compliance Manager to assess compliance and plan remediation for identified gaps + + + + Rectangle.1136 + Review current guidance for regulations that apply to your or... + + + + + + + + + + + Review current guidance for regulations that apply to your organization + + + + Rectangle.1137 + Use content explorer to identify regulated data + + + + + + + + + + + Use content explorer to identify regulated data + + + + Rectangle.1139 + Implement DLP policies for compliance + + + + + + + + + + + Implement DLP policies for compliance + + + + Rectangle.1140 + Implement communication compliance policies + + + + + + + + + + + Implement communication compliance policies + + + + Rectangle.1141 + Extend data lifecycle management policies with automation + + + + + + + + + + + Extend data lifecycle management policies with automation + + + + Rectangle.1142 + Implement container labeling, automatic and mandatory labelin... + + + + + + + + + + + Implement container labeling, automatic and mandatory labeling, and stricter DLP policies + + + + Rectangle.1143 + Use Compliance Manager to identify and remediate remaining ga... + + + + + + + + + + + Use Compliance Manager to identify and remediate remaining gaps and meet the requirements of new or updated regulations + + + Sheet.1188 + + + + + + + + Rectangle.1145 + For Communication Compliance, ensure AI apps are connected by... + + + + + + + + + + + For Communication Compliance, ensure AI apps are connected by Microsoft Entra or Microsoft Purview Data Map connectors + + + + Rectangle.1138 + Apply retention policies and sensitivity labels + + + + + + + + + + + Apply retention policies and sensitivity labels + + + Sheet.1191 + + + + + + + + Rectangle.1078 + Defender for Endpoint + + + + + + + + + + + Defender for Endpoint + + + + Rectangle.1079 + Defender for Cloud Apps + + + + + + + + + + + Defender forCloud Apps + + + + Rectangle.1132 + Ensure AI apps are included in identity and device access pol... + + + + + + + + + + + Ensure AI apps are included in identity and device access policies apply the policies to All resources” instead of individual apps. + + + Sheet.1195 + + + + + + + Rectangle.1152 + + + + + + + + Sheet.1197 + Regulatory compliance + + + + + + + Regulatory compliance + + + Rectangle.1155 + Use DSPM for AI to find gaps in your policy coverage for sens... + + + + + + + + + + + Use DSPM for AI to find gaps in your policy coverage for sensitivity labels and DLP policies + + + + Rectangle.1169 + Review data assessments in DSPM for AI to learn about gaps in... + + + + + + + + + + + Review data assessments in DSPM for AI to learn about gaps in oversharing + + + + Rectangle.1171 + Start with sensitivity labels and DLP policies + + + + + + + + + + + Start with sensitivity labels and DLP policies + + + diff --git a/microsoft-365/media/zero-trust/security-for-ai-m365-composite.svg b/microsoft-365/media/zero-trust/security-for-ai-m365-composite.svg new file mode 100644 index 00000000000..1b777fed348 --- /dev/null +++ b/microsoft-365/media/zero-trust/security-for-ai-m365-composite.svg @@ -0,0 +1,711 @@ + + + + + + + + + + + + + + + + + + Page-1 + + + + + Sheet.1000 + + + + + + + Sheet.1001 + + + + + + + Rectangle.1264 + Microsoft Defender for Cloud Apps + + + + + + + + + + + SaaS AI apps + + Rectangle.1265 + Microsoft Defender for Identity + + + + + + + + + + + Copilot Studio + + Rectangle.1266 + Microsoft Defender for Endpoint + + + + + + + + + + + AI apps in Azure + + Rectangle.1267 + Microsoft Defender for Office 365 + + + + + + + + + + + Microsoft 365 + + Rectangle.1268 + + + + + + + + Rectangle.1269 + Microsoft Defender XDR + + + + + + + + AI you use + + Rectangle.1270 + Microsoft Defender for Endpoint + + + + + + + + + + + Other providers + + Sheet.1009 + Microsoft Sentinel workspace + + + + + + + CopilotsCopilot agentsCopilot Chat + + Sheet.1010 + Microsoft Sentinel workspace + + + + + + + OpenAIAmazon Web ServicesGoogle Cloud PlatformOthers . . . + + Rectangle.1273 + + + + + + + + Rectangle.1274 + Microsoft Defender XDR + + + + + + + + AI you build + + Sheet.1013 + Management Azure subscription + + + + + + + Microsoft 365 capabilities for protecting and governing AI + + Add to cloud blue.223 + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Add to cloud blue.224 + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Add to cloud blue.225 + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Rectangle.1282 + eDiscovery + + + + + + + + + + + eDiscovery + + Rectangle.1284 + Data Lifecycle Management + + + + + + + + + + + Data Lifecycle Management + + Rectangle.1287 + Audit logs for Copilot and AI activities + + + + + + + + + + + Audit logs for Copilot and AI activities + + Rectangle.1286 + Compliance Manager — Assessments for AI regulations + + + + + + + + + + + Compliance Manager — Assessments for AI regulations + + Sheet.1021 + + + + + + + Sheet.1022 + Management Azure subscription + + + + + + + Threat protection + + Rectangle.1263 + + + + + + + + + + + Sheet.1025 + Management Azure subscription + + + + + + + Microsoft Defender + + Sheet.1026 + Management Azure subscription + + + + + + + Defender for Cloud Apps + + Sheet.1027 + Management Azure subscription + + + + + + + Discover, sanction, & block AI apps + + Sheet.1031 + Management Azure subscription + + + + + + + Govern + + Sheet.1032 + Management Azure subscription + + + + + + + Microsoft Purview + + Rectangle.1283 + Communication Compliance — AI apps connected by Microsoft Ent... + + + + + + + + + + + Communication Compliance — AI apps connected by Microsoft Entra or Microsoft Purview Data Map connectors + + Sheet.1034 + Management Azure subscription + + + + + + + Priva Privacy Assesments + + Add to cloud blue.220 + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Sheet.1095 + + Sheet.1085 + + + + + + + Rectangle.1086 + Insider Risk Management (IRM) — Risky AI usage policy template + + + + + + + + + + + Insider Risk Management (IRM) — Risky AI usage policy template + + Sheet.1087 + Management Azure subscription + + + + + + + Microsoft Purview + + Sheet.1088 + Management Azure subscription + + + + + + + SharePoint Online + + Rectangle.1089 + SharePoint oversharing controls + + + + + + + + + + + SharePoint oversharing controls + + Sheet.1090 + Management Azure subscription + + + + + + + Data protection + + Rectangle.1091 + Data Security Posture Management (DSPM) for AI + + + + + + + + + + + Data Security Posture Management (DSPM) for AI + + Rectangle.1092 + Coming soon + + + + + + + + + + + Coming soon + + Rectangle.1093 + Sensitivity labels and DLP policies + + + + + + + + + + + Sensitivity labels and DLP policies + + Rectangle.1363 + Adaptive Protection + + + + + + + + + + + Adaptive Protection + + + diff --git a/microsoft-365/media/zero-trust/zero-trust-architecture.svg b/microsoft-365/media/zero-trust/zero-trust-architecture.svg new file mode 100644 index 00000000000..257f68d9a2c --- /dev/null +++ b/microsoft-365/media/zero-trust/zero-trust-architecture.svg @@ -0,0 +1,1444 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + Page-1 + + + + + + + + + Sheet.2601 + + + + + + + Sheet.2602 + Strong authentication + + + + + + + Strong authentication + + Sheet.2603 + Device compliance + + + + + + + Device compliance + + Sheet.2604 + Risk assessment + + + + + + + Risk assessment + + Sheet.2605 + Traffic filtering & segmentation + + + + + + + Traffic filtering & segmentation + + Sheet.2606 + + + + + + + Sheet.2607 + Telemetry/analytics/assessment + + + + + + + Telemetry/analytics/assessment + + Sheet.2608 + JIT & Version Control + + + + + + + JIT & Version Control + + Dynamic connector.1162 + + + + + + + Sheet.2610 + + + + + + + Sheet.2611 + + + + + + + Sheet.2612 + Corporate + + + + + + + Corporate + + Sheet.2613 + Personal + + + + + + + Personal + + + + + Sheet.2614 + + Sheet.2615 + + + + + + + Sheet.2746 + + + + + + + + Sheet.2616 + Endpoints + + + + + + + Endpoints + + Sheet.2617 + + + + + + + Sheet.2618 + + + + + + + Sheet.2619 + Human + + + + + + + Human + + Sheet.2620 + Non-human + + + + + + + Non-human + + + + + Sheet.2621 + + Sheet.2622 + + + + + + + Sheet.2744 + + + + + + + + Sheet.2623 + Identities + + + + + + + Identities + + Sheet.2624 + + + + + + + Sheet.2625 + + + + + + + Sheet.2626 + Evaluation + + + + + + + Evaluation + + Sheet.2627 + Enforcement + + + + + + + Enforcement + + + + + Sheet.2628 + + Sheet.2629 + + + + + + + Sheet.2751 + + + + + + + + Sheet.2630 + Zero Trust Policies + + + + + + + Zero Trust Policies + + Sheet.2631 + + + + + + + Sheet.2632 + + + + + + + Sheet.2633 + + + + + + + Sheet.2634 + + + + + + + Sheet.2635 + Governance + + + + + + + Governance + + Sheet.2636 + Compliance + + + + + + + Compliance + + Sheet.2637 + Security Posture Assessment + + + + + + + Security Posture Assessment + + Sheet.2638 + Productivity Optimization + + + + + + + Productivity Optimization + + + + + Sheet.2639 + + Sheet.2640 + + + + + + + Sheet.2747 + + + + + + + + Sheet.2641 + Policy Optimization + + + + + + + Policy Optimization + + Sheet.2642 + + + + + + + Sheet.2643 + + + + + + + Sheet.2644 + Public + + + + + + + Public + + Sheet.2645 + + + + + + + Sheet.2646 + + + + + + + Sheet.2647 + Serverless + + + + + + + Serverless + + Sheet.2648 + Containers + + + + + + + Containers + + + + + Sheet.2649 + + Sheet.2650 + + + + + + + Sheet.2753 + + + + + + + + Sheet.2651 + Infrastructure + + + + + + + Infrastructure + + Sheet.2652 + + + + + + + Sheet.2653 + IaaS + + + + + + + IaaS + + Sheet.2654 + + + + + + + Sheet.2655 + Paas + + + + + + + Paas + + Sheet.2656 + + + + + + + Sheet.2657 + Internal Sites + + + + + + + Internal Sites + + Sheet.2658 + + + + + + + Sheet.2659 + + + + + + + Sheet.2660 + + + + + + + Sheet.2661 + + + + + + + Sheet.2662 + + + + + + + Sheet.2663 + + + + + + + Sheet.2664 + + + + + + + Sheet.2665 + Emails & documents + + + + + + + Emails & documents + + Sheet.2666 + Structured data + + + + + + + Structured data + + + + + Sheet.2667 + + Sheet.2668 + + + + + + + Sheet.2755 + + + + + + + + Dynamic connector.1267 + + + + + + + Sheet.2669 + Data + + + + + + + Data + + Sheet.2670 + + + + + + + Sheet.2671 + + + + + + + Sheet.2672 + SaaS + + + + + + + SaaS + + Sheet.2673 + On-premises + + + + + + + On-premises + + + + + Sheet.2674 + + Sheet.2675 + + + + + + + Sheet.2754 + + + + + + + + Dynamic connector.1259 + + + + + + + Sheet.2676 + Apps + + + + + + + Apps + + Sheet.2677 + + + + + + + Sheet.2678 + + + + + + + Sheet.2679 + + + + + + + Sheet.2680 + + + + + + + Sheet.2681 + Continuous Assessment + + + + + + + Continuous Assessment + + Sheet.2682 + Threat Intelligence + + + + + + + Threat Intelligence + + Sheet.2683 + Forensics + + + + + + + Forensics + + Sheet.2684 + Response Automation + + + + + + + Response Automation + + + + + Sheet.2685 + + Sheet.2686 + + + + + + + Sheet.2752 + + + + + + + + Sheet.2687 + Threat Protection + + + + + + + Threat Protection + + Sheet.2688 + Request enhancement + + + + + + + Request enhancement + + + + + Sheet.2689 + + Sheet.2690 + + + + Sheet.2691 + + + + + Dynamic connector.1260 + + + + + + + Sheet.2692 + Adaptive Access + + + + + + + Adaptive Access + + Sheet.2693 + + + + + + + Dynamic connector.1261 + + + + + + + Sheet.2694 + Classify, label, encrypt + + + + + + + Classify, label, encrypt + + Sheet.2695 + + + + + + + Dynamic connector.1280 + + + + + + + Dynamic connector.1262 + + + + + + + Sheet.2696 + Runtime control + + + + + + + Runtime control + + Sheet.2697 + + + + + + + Dynamic connector.1263 + + + + + + + Dynamic connector.1264 + + + + + + + Dynamic connector.1265 + + + + + + + Dynamic connector.1266 + + + + + + + Dynamic connector.1268 + + + + + + + Dynamic connector.1269 + + + + + + + Dynamic connector.1270 + + + + + + + Dynamic connector.1271 + + + + + + + Dynamic connector.1272 + + + + + + + Dynamic connector.1273 + + + + + + + Dynamic connector.1274 + + + + + + + Dynamic connector.1275 + + + + + + + Dynamic connector.1276 + + + + + + + Dynamic connector.1277 + + + + + + + Dynamic connector.1278 + + + + + + + Dynamic connector.1279 + + + + + + + Sheet.2720 + + + + + + + + + + Sheet.2721 + + Sheet.2722 + + + + + Sheet.2723 + + + + + + + + + + Sheet.2724 + + Sheet.2725 + + + + + Sheet.2726 + + + + + + + + + + Sheet.2727 + + Sheet.2728 + + + + + Sheet.2729 + + + + + + + + + + Sheet.2730 + + Sheet.2731 + + + + + Sheet.2732 + + + + + + + + + + Sheet.2733 + + Sheet.2734 + + + + + Sheet.2735 + Private + + + + + + + Private + + + + + Sheet.2736 + + Sheet.2738 + + + + + + + Sheet.2750 + + + + + + + + Sheet.2739 + Network + + + + + + + Network + + Sheet.1682 + AI + + + + + + + AI + + Sheet.1683 + + + + + + + diff --git a/microsoft-365/security/microsoft-365-zero-trust.md b/microsoft-365/security/microsoft-365-zero-trust.md index c45e833f835..455735b7053 100644 --- a/microsoft-365/security/microsoft-365-zero-trust.md +++ b/microsoft-365/security/microsoft-365-zero-trust.md @@ -20,26 +20,36 @@ ms.collection: - zerotrust-solution - highpri - tier1 -ms.date: 04/09/2024 +ms.date: 04/14/2025 --- # Zero Trust deployment plan with Microsoft 365 -This article provides a deployment plan for building **Zero Trust** security with Microsoft 365. Zero Trust is a new security model that assumes breach and verifies each request as though it originated from an uncontrolled network. Regardless of where the request originates or what resource it accesses, the Zero Trust model teaches us to "never trust, always verify." +This article provides a deployment plan for building **Zero Trust** security with Microsoft 365. Zero Trust is a security model that assumes breach and verifies each request as though it originated from an uncontrolled network. Regardless of where the request originates or what resource it accesses, the Zero Trust model teaches us to "never trust, always verify." Use this article together with this poster. | Item | Description | |:-----|:-----| -|[![Illustration of the Microsoft 365 Zero Trust deployment plan.](../media/solutions-architecture-center/m365-zero-trust-deployment-plan-thumb.png)](https://download.microsoft.com/download/f/d/b/fdb6ab0c-34bb-4cb8-84e6-5de8f13298da/m365-zero-trust-deployment-plan.pdf)
    [PDF](https://download.microsoft.com/download/f/d/b/fdb6ab0c-34bb-4cb8-84e6-5de8f13298da/m365-zero-trust-deployment-plan.pdf) \| [Visio](https://download.microsoft.com/download/f/d/b/fdb6ab0c-34bb-4cb8-84e6-5de8f13298da/m365-zero-trust-deployment-plan.vsdx)
    Updated March 2024 | **Related solution guides**
    • [Deploy your identity infrastructure for Microsoft 365](/microsoft-365/enterprise/deploy-identity-solution-overview)
    • [Recommended identity and device access configurations](../security/office-365-security/zero-trust-identity-device-access-policies-overview.md)
    • [Manage devices with Intune](../solutions/manage-devices-with-intune-overview.md)
    • [Evaluate and pilot Microsoft Defender XDR](../security/defender/eval-overview.md)
    • [Deploy an information protection solution with Microsoft Purview](../compliance/information-protection-solution.md)
    • [Deploy information protection for data privacy regulations with Microsoft 365](../solutions/information-protection-deploy.md)
    +|[![Illustration of the Microsoft 365 Zero Trust deployment plan.](../media/solutions-architecture-center/m365-zero-trust-deployment-plan-thumb.png)](https://download.microsoft.com/download/f/d/b/fdb6ab0c-34bb-4cb8-84e6-5de8f13298da/m365-zero-trust-deployment-plan.pdf)
    [PDF](https://download.microsoft.com/download/f/d/b/fdb6ab0c-34bb-4cb8-84e6-5de8f13298da/m365-zero-trust-deployment-plan.pdf) \| [Visio](https://download.microsoft.com/download/f/d/b/fdb6ab0c-34bb-4cb8-84e6-5de8f13298da/m365-zero-trust-deployment-plan.vsdx)
    Updated April 2025 | **Related solution guides**
    • [Deploy your identity infrastructure for Microsoft 365](/microsoft-365/enterprise/deploy-identity-solution-overview)
    • [Recommended identity and device access configurations](../security/office-365-security/zero-trust-identity-device-access-policies-overview.md)
    • [Manage devices with Intune](../solutions/manage-devices-with-intune-overview.md)
    • [Pilot and deploy Microsoft Defender XDR](../security/defender/eval-overview.md)
    • [Deploy an information protection solution with Microsoft Purview](../compliance/information-protection-solution.md)
    • [Discover, protect, and govern AI apps and data](/security/security-for-ai/)
    • [Manage data privacy regulations with Microsoft 365](../solutions/data-privacy-protection.md)
    -## Zero Trust security architecture +## Zero Trust principles and architecture + +Zero Trust is a security strategy. It isn't a product or a service, but an approach in designing and implementing the following set of security principles. + +|Principle|Description| +|---|---| +|Verify explicitly|Always authenticate and authorize based on all available data points.| +|Use least privilege access|Limit user access with Just-In-Time and Just-Enough-Access (JIT/JEA), risk-based adaptive policies, and data protection.| +|Assume breach|Minimize blast radius and segment access. Verify end-to-end encryption and use analytics to get visibility, drive threat detection, and improve defenses.| + +The guidance in this article helps you apply these principles by implementing capabilities with Microsoft 365. A Zero Trust approach extends throughout the entire digital estate and serves as an integrated security philosophy and end-to-end strategy. This illustration provides a representation of the primary elements that contribute to Zero Trust. -:::image type="content" source="../media/zero-trust/zero-trust-architecture.png" alt-text="The Zero Trust security architecture" lightbox="../media/zero-trust/zero-trust-architecture.png"::: +:::image type="content" source="../media/zero-trust/zero-trust-architecture.svg" alt-text="The Zero Trust security architecture" lightbox="../media/zero-trust/zero-trust-architecture.png"::: In the illustration: @@ -49,100 +59,117 @@ In the illustration: For more information about Zero Trust, see Microsoft's [_**Zero Trust Guidance Center**_](/security/zero-trust). - + ## Deploying Zero Trust for Microsoft 365 Microsoft 365 is built intentionally with many security and information protection capabilities to help you build Zero Trust into your environment. Many of the capabilities can be extended to protect access to other SaaS apps your organization uses and the data within these apps. -This illustration represents the work of deploying Zero Trust capabilities. This work is broken into units of work that can be configured together, starting from the bottom and working to the top to ensure that prerequisite work is complete. +This illustration represents the work of deploying Zero Trust capabilities. This work is aligned to Zero Trust business scenarios in the [Zero Trust adoption framework](/security/zero-trust/adopt/zero-trust-adoption-overview). -:::image type="content" source="../media/zero-trust/m365-zero-trust-deployment-stack.svg" alt-text="Diagram that shows the Microsoft 365 Zero Trust deployment stack." lightbox="../media/zero-trust/m365-zero-trust-deployment-stack.svg"::: +:::image type="content" source="../media/zero-trust/m365-zero-trust-deployment-swim-lanes.svg" alt-text="Diagram that shows the Microsoft 365 Zero Trust deployment plan across five swim lanes." lightbox="../media/zero-trust/m365-zero-trust-deployment-swim-lanes.svg"::: -In this illustration: +In this illustration the deployment work is categorized into five swim lanes: -- Zero Trust begins with a foundation of identity and device protection. -- Threat protection capabilities are built on top of this foundation to provide real-time monitoring and remediation of security threats. -- Information protection and governance provide sophisticated controls targeted at specific types of data to protect your most valuable information and to help you comply with compliance standards, including protecting personal information. +- **Secure remote and hybrid work** — This work builds a foundation of identity and device protection. +- **Prevent or reduce business damage from a breach** — Threat protection provides real-time monitoring and remediation of security threats. Defender for Cloud Apps provides discovery of SaaS apps, including AI apps, and allows you to extend data protection to these apps. +- **Identify and protect sensitive business data** — Data protection capabilities provide sophisticated controls targeted at specific types of data to protect your most valuable information. +- **Secure AI apps and data** — Rapidly protect your organization's use of AI apps and the data these interact with. +- **Meet regulatory and compliance requirements** — Understand and track your progress toward complying with regulations that affect your organization. -This article assumes you are using cloud identity. If you need guidance for this objective, see [**Deploy your identity infrastructure for Microsoft 365**](/microsoft-365/enterprise/deploy-identity-solution-overview). +This article assumes you're using cloud identity. If you need guidance for this objective, see [**Deploy your identity infrastructure for Microsoft 365**](/microsoft-365/enterprise/deploy-identity-solution-overview). > [!TIP] > When you understand the steps and the end-to-end deployment process, you can use the [Set up your Microsoft Zero Trust security model](https://go.microsoft.com/fwlink/?linkid=2224820) advanced deployment guide when signed in to the Microsoft 365 admin center. This guide steps you through applying Zero Trust principles for standard and advanced technology pillars. To step through the guide without signing in, go to the [Microsoft 365 Setup portal](https://go.microsoft.com/fwlink/?linkid=2222968). -## Step 1: Configure Zero Trust identity and device access protection: Starting-point policies -The first step is to build your Zero Trust foundation by configuring identity and device access protection. + +## Swim lane 1 — Secure remote and hybrid work +Securing remote and hybrid work involves configuring identity and device access protection. These protections contribute to the Zero Trust principle **verify explicitly**. + +Accomplish the work of securing remote and hybrid work in three phases. + +#### Phase 1 — Implement starting-point identity and device access policies + +Microsoft recommends a comprehensive set of identity and device access policies for Zero Trust in this guide — [Zero Trust identity and device access configurations](/security/zero-trust/zero-trust-identity-device-access-policies-overview). + +In phase 1, start by implementing the starting-point tier. These policies don't require enrolling devices into management. + + + +:::image type="content" source="../media/zero-trust/identity-access-starting-point-tier.svg" alt-text="Diagram that shows the Zero Trust identity and access policies for the Starting-point tier" lightbox="../media/zero-trust/identity-access-starting-point-tier.svg"::: + Go to [**_Zero Trust identity and device access protection_**](office-365-security/zero-trust-identity-device-access-policies-overview.md) for detailed prescriptive guidance. This series of articles describes a set of identity and device access prerequisite configurations and a set of Microsoft Entra Conditional Access, Microsoft Intune, and other policies to secure access to Microsoft 365 for enterprise cloud apps and services, other SaaS services, and on-premises applications published with Microsoft Entra application proxy. |Includes|Prerequisites|Doesn't include| |---------|---------|---------| -|Recommended identity and device access policies for three levels of protection:
    • Starting point
    • Enterprise (recommended)
    • Specialized

    Additional recommendations for:
    • External users (guests)
    • Microsoft Teams
    • SharePoint Online
    • Microsoft Defender for Cloud Apps
    |Microsoft E3 or E5

    Microsoft Entra ID in either of these modes:
    • Cloud-only
    • Hybrid with password hash sync (PHS) authentication
    • Hybrid with pass-through authentication (PTA)
    • Federated
    |Device enrollment for policies that require managed devices. See [Step 2. Manage endpoints with Intune](#step-2-manage-endpoints-with-intune) to enroll devices| - -Start by implementing the starting-point tier. These policies don't require enrolling devices into management. - -:::image type="content" source="../media/zero-trust/identity-access-starting-point-tier.svg" alt-text="Diagram that shows the Zero Trust identity and access policies for the Starting-point tier" lightbox="../media/zero-trust/identity-access-starting-point-tier.svg"::: +|Recommended identity and device access policies for three levels of protection:
    • Starting point
    • Enterprise (recommended)
    • Specialized

    Additional recommendations for:
    • External users (guests)
    • Microsoft Teams
    • SharePoint
    |Microsoft E3 or E5

    Microsoft Entra ID in either of these modes:
    • Cloud-only
    • Hybrid with password hash sync (PHS) authentication
    • Hybrid with pass-through authentication (PTA)
    • Federated
    |Device enrollment for policies that require managed devices. See [Manage devices with Intune](../solutions/manage-devices-with-intune-overview.md) to enroll devices.| -## Step 2: Manage endpoints with Intune +#### Phase 2 — Enroll devices into management with Intune Next, enroll your devices into management and begin protecting them with more sophisticated controls. + +See [**_Manage devices with Intune_**](../solutions/manage-devices-with-intune-overview.md) for detailed prescriptive guidance on enrolling devices into management. -|Includes|Prerequisites|Doesn't include| +|Includes |Prerequisites |Doesn't include | |---------|---------|---------| -|Enroll devices with Intune:
    • Corporate-owned devices
    • Autopilot/automated
    • enrollment

    Configure policies:
    • App Protection policies
    • Compliance policies
    • Device profile policies
    |Register endpoints with Microsoft Entra ID|Configuring information protection capabilities, including:
    • Sensitive information types
    • Labels
    • DLP policies

    For these capabilities, see [Step 5. Protect and govern sensitive data](#step-5-protect-and-govern-sensitive-data) (later in this article).| +|Enroll devices with Intune:
    • Corporate-owned devices
    • Autopilot/automated
    • enrollment

    Configure policies:
    • App Protection policies
    • Compliance policies
    • Device profile policies
    |Register endpoints with Microsoft Entra ID|Configuring information protection capabilities, including:
    • Sensitive information types
    • Labels
    • DLP policies

    For these capabilities, see [Swim lane 3 — Identify and protect sensitive business data](#swim-lane-3) (later in this article).| For more information, see [Zero Trust for Microsoft Intune](/mem/intune/fundamentals/zero-trust-with-microsoft-intune). -## Step 3: Add Zero Trust identity and device access protection: Enterprise policies +#### Phase 3 — Add Zero Trust identity and device access protection: Enterprise policies With devices enrolled into management, you can now implement the full set of recommended Zero Trust identity and device access policies, requiring compliant devices. + Return to [**_Common identity and device access policies_**](office-365-security/zero-trust-identity-device-access-policies-common.md) and add the policies in the Enterprise tier. :::image type="content" source="../media/zero-trust/identity-access-enterprise-tier.svg" alt-text="Diagram that shows the Zero Trust identity and access policies for the Enterprise (recommended) tier." lightbox="../media/zero-trust/identity-access-enterprise-tier.svg"::: - +Read more about how to secure remote and hybrid work in the **Zero Trust adoption framework** — [Secure remote and hybrid work](/security/zero-trust/adopt/secure-remote-hybrid-work). + + -## Step 4: Evaluate, pilot, and deploy Microsoft Defender XDR +## Swim lane 2 — Prevent or reduce business damage from a breach -Microsoft Defender XDR is an extended detection and response (XDR) solution that automatically collects, correlates, and analyzes signal, threat, and alert data from across your Microsoft 365 environment, including endpoint, email, applications, and identities. +Microsoft Defender XDR is an extended detection and response (XDR) solution that automatically collects, correlates, and analyzes signal, threat, and alert data from across your Microsoft 365 environment, including endpoint, email, applications, and identities. Additionally, Microsoft Defender for Cloud Apps helps organizations identify and manage access to SaaS apps, including GenAI apps. -:::image type="content" source="../media/zero-trust/m365-zero-trust-architecture-defender.png" alt-text="The process of adding Microsoft Defender XDR to the Zero Trust architecture" lightbox="../media/zero-trust/m365-zero-trust-architecture-defender.png"::: +Prevent or reduce business damage from a breach by piloting and deploying Microsoft Defender XDR. -Go to [**_Evaluate and pilot Microsoft Defender XDR_**](defender/eval-overview.md) for a methodical guide to piloting and deploying Microsoft Defender XDR components. +:::image type="content" source="../media/zero-trust/m365-zero-trust-architecture-defender.svg" alt-text="The process of adding Microsoft Defender XDR to the Zero Trust architecture" lightbox="../media/zero-trust/m365-zero-trust-architecture-defender.svg"::: + +Go to [**_Pilot and deploy Microsoft Defender XDR_**](defender/eval-overview.md) for a methodical guide to piloting and deploying Microsoft Defender XDR components. |Includes|Prerequisites|Doesn't include| |---------|---------|---------| -|Set up the evaluation and pilot environment for all components:
    • Defender for Identity
    • Defender for Office 365
    • Defender for Endpoint
    • Microsoft Defender for Cloud Apps

    Protect against threats

    Investigate and respond to threats|See the guidance to read about the architecture requirements for each component of Microsoft Defender XDR.| Microsoft Entra ID Protection isn't included in this solution guide. It's included in [Step 1. Configure Zero Trust identity and device access protection](#step-1-configure-zero-trust-identity-and-device-access-protection-starting-point-policies).| +|Set up the evaluation and pilot environment for all components:
    • [Defender for Identity](/defender-for-identity/zero-trust)
    • [Defender for Office 365](./office-365-security/zero-trust-with-microsoft-365-defender-office-365.md)
    • [Defender for Endpoint](./defender-endpoint/zero-trust-with-microsoft-defender-endpoint.md)
    • [Defender for Cloud Apps](/defender-cloud-apps/zero-trust)

    Protect against threats

    Investigate and respond to threats|See the guidance to read about the architecture requirements for each component of Microsoft Defender XDR.| Microsoft Entra ID Protection isn't included in this solution guide. It's included in [Swim lane 1 — Secure remote and hybrid work](#swim-lane-1).| -For more information, see these additional Zero Trust articles: +Read more about how to prevent or reduce business damage from a breach in the **Zero Trust adoption framework** — [Prevent or reduce business damage from a breach](/security/zero-trust/adopt/prevent-reduce-business-damage-breach). -- [Defender for Endpoint](./defender-endpoint/zero-trust-with-microsoft-defender-endpoint.md) -- [Defender for Office 365](./office-365-security/zero-trust-with-microsoft-365-defender-office-365.md) -- [Defender for Cloud Apps](/defender-cloud-apps/zero-trust) -- [Defender for Identity](/defender-for-identity/zero-trust) -## Step 5: Protect and govern sensitive data + +## Swim lane 3 — Identify and protect sensitive business data -Implement Microsoft Purview Information Protection to help you discover, classify, and protect sensitive information wherever it lives or travels. +Implement Microsoft Purview Information Protection to help you discover, classify, and protect sensitive information wherever it lives or travels. -Microsoft Purview Information Protection capabilities are included with Microsoft Purview and give you the tools to know your data, protect your data, and prevent data loss. +Microsoft Purview Information Protection capabilities are included with Microsoft Purview and give you the tools to know your data, protect your data, and prevent data loss. You can begin this work anytime. -:::image type="content" source="../media/zero-trust/m365-zero-trust-architecture-info-protect.png" alt-text="The Information protection capabilities protecting data through policy enforcement" lightbox="../media/zero-trust/m365-zero-trust-architecture-info-protect.png"::: + Microsoft Purview Information Protection provides a framework, process, and capabilities you can use to accomplish your specific business objectives. @@ -150,4 +177,70 @@ Microsoft Purview Information Protection provides a framework, process, and capa For more information on how to plan and deploy information protection, see [**_Deploy a Microsoft Purview Information Protection solution_**](../compliance/information-protection-solution.md). -If you're deploying information protection for data privacy regulations, this solution guide provides a recommended framework for the entire process: [**_Deploy information protection for data privacy regulations with Microsoft 365_**](../solutions/information-protection-deploy.md). +Read more about how to identify and protect sensitive business data in the **Zero Trust adoption framework** — [Identify and protect sensitive business data](/security/zero-trust/adopt/identify-protect-sensitive-business-data). + +## Swim lane 4 — Secure AI apps and data + +Microsoft 365 includes capabilities to help organizations rapidly secure AI apps and the data these use. + +Start by using Purview Data Security Posture Management (DSPM) for AI. This tool focuses on how AI is used in your organization, especially your sensitive data that interacts with AI tools. DSPM for AI provides deeper insights for Microsoft Copilots and third-party SaaS applications like ChatGPT Enterprise and Google Gemini. + +The following diagram shows one of the aggregated views into the impact of AI use on your data—Sensitive interactions per generative AI app. + +:::image type="content" source="../media/zero-trust/ai-hub-sensitive-interactions-report.png" alt-text="Sensitive interactions per generative AI app" lightbox="../media/zero-trust/ai-hub-sensitive-interactions-report.png"::: + +Use DSPM for AI to: +- Gain visibility into AI usage, including sensitive data. +- Review data assessments to learn about gaps in oversharing that can be mitigated with SharePoint oversharing controls. +- Find gaps in your policy coverage for sensitivity labels and data loss prevention (DLP) policies. + +Defender for Cloud Apps is another powerful tool to discover and govern SaaS GenAI apps and usage. Defender for Cloud Apps includes more than a thousand generative AI-related apps in the catalog, providing visibility into how generative AI apps are used in your organization and helping you manage them securely. + +In addition to these tools, Microsoft 365 provides a comprehensive set of capabilities for securing and governing AI. See [**Discover, protect, and govern AI apps and data**](/security/security-for-ai) to learn how to get started with these capabilities. + +:::image type="content" source="../media/zero-trust/security-for-ai-m365-composite.svg" alt-text="Microsoft 365 capabilities for protecting and governing AI" lightbox="../media/zero-trust/security-for-ai-m365-composite.svg"::: + +The following table lists the Microsoft 365 capabilities with links to more information in the [Security for AI library](/security/security-for-ai). + +|Capability|More information| +|---------|---------| +|SharePoint oversharing controls, including SharePoint Advanced Management| [Apply SharePoint oversharing controls](/security/security-for-ai/protect#step-1--apply-sharepoint-oversharing-controls) | +|DSPM for AI |[Gain visibility into AI usage with (DSPM) for AI](/security/security-for-ai/discover#step-1gain-visibility-into-ai-usage-with-data-security-posture-management-dspm-for-ai)
    [Protect data through DSPM for AI](/security/security-for-ai/protect#step-2--protect-data-through-dspm-for-ai)| +|Sensitivity labels and DLP policies | [Continue to identify gaps in sensitivity labels and DLP policies](/security/security-for-ai/protect#step-3continue-to-identify-gaps-in-sensitivity-labels-and-dlp-policies) | +|Insider Risk Management (IRM) — Risky AI usage policy template | [Apply the Risky AI template](/security/security-for-ai/protect#step-4apply-the-risky-ai-template-in-insider-risk-management-irm) | +|Adaptive protection | [Configure Adaptive Protection for Insider Risk Management](/security/security-for-ai/protect#step-5configure-adaptive-protection-for-insider-risk-management) | +|Defender for Cloud Apps | [Discover, sanction, and block AI apps](/security/security-for-ai/discover#step-2discover-sanction-and-block-ai-apps-with-microsoft-defender-for-cloud-apps)
    [Triage and protect use of AI apps](/security/security-for-ai/protect#step-1use-defender-for-cloud-apps-to-triage-and-protect-use-of-ai-apps)
    [Manage AI apps based on compliance risk](/security/security-for-ai/govern#step-2use-defender-for-cloud-apps) | +|Purview Compliance Manager | [Build and manage assessments for AI-related regulations](/security/security-for-ai/govern#step-1build-and-manage-assessments-in-microsoft-purview-compliance-manager) | +|Purview Communication Compliance | [Analyze prompts and responses entered into generative AI applications to help detect inappropriate or risky interactions or sharing of confidential information](/security/security-for-ai/govern#step-4configure-purview-communication-compliance) | +|Purview Data Lifecycle Management | [Proactively delete content you’re no longer required to keep to reduce the risk of data overexposure in AI tools](/security/security-for-ai/govern#step-5configure-purview-data-lifecycle-management) | +|eDiscovery | [Search for keywords in prompts and responses, manage the results within eDiscovery cases](/security/security-for-ai/govern#step-6use-ediscovery-together-with-audit-logs-for-microsoft-365-copilot) | +|Audit logs for Copilot and AI activities |[identify how, when, and where Copilot interactions occurred and which items were accessed, including any sensitivity labels on those items](/security/security-for-ai/govern#step-6use-ediscovery-together-with-audit-logs-for-microsoft-365-copilot) | +|Priva Privacy Assessments | [Initiate privacy impact assessments for AI apps you build](/security/security-for-ai/govern#step-7use-priva-privacy-assessments) | + +## Swim lane 5 — Meet regulatory and compliance requirements + +Regardless of the complexity of your organization’s IT environment or the size of your organization, new regulatory requirements that might affect your business are continually adding up. A Zero Trust approach often exceeds some types of requirements imposed by compliance regulations, for example, those controlling access to personal data. Organizations that have implemented a Zero Trust approach may find that they already meet some new conditions or can easily build upon their Zero Trust architecture to be compliant. + +Microsoft 365 includes capabilities to assist with regulatory compliance, including: +- Compliance Manager +- Content explorer +- Retention policies, sensitivity labels, and DLP policies +- Communication compliance +- Data lifecycle management +- Priva Privacy Risk Management + +Use the following resources to meet regulatory and compliance requirements. + +|Resource|More information| +|---------|---------| +| Zero Trust adoption framework — [Meet regulatory and compliance requirements](/security/zero-trust/adopt/meet-regulatory-compliance-requirements) |Describes a methodical approach your organization can follow, including defining strategy, planning, adopting, and governing. | +|[Govern AI apps and data for regulatory compliance](/security/security-for-ai/govern) |Addresses regulatory compliance for the emerging AI-related regulations, including specific capabilities that help.| +| [Manage data privacy and data protection with Microsoft Priva and Microsoft Purview](../solutions/data-privacy-protection.md)| Assess risks and take appropriate action to protect personal data in your organization's environment using Microsoft Priva and Microsoft Purview.| + +## Next steps + +Learn more about Zero Trust by visiting the [Zero Trust guidance center](/security/zero-trust). + + + + diff --git a/microsoft-365/solutions/apps-add-overview.md b/microsoft-365/solutions/apps-add-overview.md index 8ff841be822..6960361b67e 100644 --- a/microsoft-365/solutions/apps-add-overview.md +++ b/microsoft-365/solutions/apps-add-overview.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: solution-overview -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Add apps overview for Microsoft Intune. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-add-step-1.md b/microsoft-365/solutions/apps-add-step-1.md index fe8bde0b6d2..2614ca872f8 100644 --- a/microsoft-365/solutions/apps-add-step-1.md +++ b/microsoft-365/solutions/apps-add-step-1.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: how-to -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Step 1. Assess app requirements. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-add-step-2.md b/microsoft-365/solutions/apps-add-step-2.md index 0cbd6e53c92..c86f7b5a432 100644 --- a/microsoft-365/solutions/apps-add-step-2.md +++ b/microsoft-365/solutions/apps-add-step-2.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: how-to -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Step 2. Create and edit categories for apps. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-add-step-3.md b/microsoft-365/solutions/apps-add-step-3.md index 619bb7cb445..587bc118b20 100644 --- a/microsoft-365/solutions/apps-add-step-3.md +++ b/microsoft-365/solutions/apps-add-step-3.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: how-to -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Step 3. Purchase apps. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-add-step-4.md b/microsoft-365/solutions/apps-add-step-4.md index e75467c0dbf..31fe849b622 100644 --- a/microsoft-365/solutions/apps-add-step-4.md +++ b/microsoft-365/solutions/apps-add-step-4.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: how-to -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Step 4. Add apps to Intune. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-add-step-5.md b/microsoft-365/solutions/apps-add-step-5.md index 5d201b7d7e6..4535e6aa301 100644 --- a/microsoft-365/solutions/apps-add-step-5.md +++ b/microsoft-365/solutions/apps-add-step-5.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: how-to -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Step 5. Manage apps and licenses. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-assign-assignments.md b/microsoft-365/solutions/apps-assign-assignments.md index 571d4b9219b..849e2b0476d 100644 --- a/microsoft-365/solutions/apps-assign-assignments.md +++ b/microsoft-365/solutions/apps-assign-assignments.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: concept-article -ms.date: 09/12/2024 +ms.date: 04/21/2025 description: Understand app assignments using Microsoft Intune. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-assign-deployment.md b/microsoft-365/solutions/apps-assign-deployment.md index 600d9b8f6a1..3c28177f9f4 100644 --- a/microsoft-365/solutions/apps-assign-deployment.md +++ b/microsoft-365/solutions/apps-assign-deployment.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: concept-article -ms.date: 09/12/2024 +ms.date: 04/21/2025 description: Understand app deployment using Microsoft Intune. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-assign-management.md b/microsoft-365/solutions/apps-assign-management.md index 8f69ac5e3b4..66ce2ec6f83 100644 --- a/microsoft-365/solutions/apps-assign-management.md +++ b/microsoft-365/solutions/apps-assign-management.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: concept-article -ms.date: 09/12/2024 +ms.date: 04/21/2025 description: Understand app management using Microsoft Intune. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-assign-overview.md b/microsoft-365/solutions/apps-assign-overview.md index 37385ad58fa..309541f94f6 100644 --- a/microsoft-365/solutions/apps-assign-overview.md +++ b/microsoft-365/solutions/apps-assign-overview.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: install-set-up-deploy -ms.date: 09/12/2024 +ms.date: 04/21/2025 description: Assign and deploy apps using Microsoft Intune. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-assign-step-1.md b/microsoft-365/solutions/apps-assign-step-1.md index acad7c5d74a..f75fc427e4f 100644 --- a/microsoft-365/solutions/apps-assign-step-1.md +++ b/microsoft-365/solutions/apps-assign-step-1.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: how-to -ms.date: 09/12/2024 +ms.date: 04/21/2025 description: Step 1. Confirm users, devices, and groups. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-assign-step-2.md b/microsoft-365/solutions/apps-assign-step-2.md index 3eb2773e036..5095155b7d7 100644 --- a/microsoft-365/solutions/apps-assign-step-2.md +++ b/microsoft-365/solutions/apps-assign-step-2.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: how-to -ms.date: 09/12/2024 +ms.date: 04/21/2025 description: Step 2. Assign apps to groups. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-assign-step-3.md b/microsoft-365/solutions/apps-assign-step-3.md index b280f6404fb..b55cd2e5fa5 100644 --- a/microsoft-365/solutions/apps-assign-step-3.md +++ b/microsoft-365/solutions/apps-assign-step-3.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: how-to -ms.date: 09/12/2024 +ms.date: 04/21/2025 description: Step 3. Verify and monitor app assignments. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-assign-step-4.md b/microsoft-365/solutions/apps-assign-step-4.md index ab066e2e6ec..77557568ccf 100644 --- a/microsoft-365/solutions/apps-assign-step-4.md +++ b/microsoft-365/solutions/apps-assign-step-4.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: troubleshooting-general -ms.date: 09/12/2024 +ms.date: 04/21/2025 description: Step 4. Troubleshoot app deployment issues. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-assign-steps-overview.md b/microsoft-365/solutions/apps-assign-steps-overview.md index 2dfb1ef2488..945fd56e637 100644 --- a/microsoft-365/solutions/apps-assign-steps-overview.md +++ b/microsoft-365/solutions/apps-assign-steps-overview.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: article -ms.date: 09/12/2024 +ms.date: 04/21/2025 description: Assign managed apps to your organization using Microsoft Intune. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-config-overview.md b/microsoft-365/solutions/apps-config-overview.md index 7cab5211c4a..3e571308a3a 100644 --- a/microsoft-365/solutions/apps-config-overview.md +++ b/microsoft-365/solutions/apps-config-overview.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: how-to -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Configure apps using Microsoft Intune. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-config-step-1.md b/microsoft-365/solutions/apps-config-step-1.md index 15d48b36d42..921273c3d05 100644 --- a/microsoft-365/solutions/apps-config-step-1.md +++ b/microsoft-365/solutions/apps-config-step-1.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: how-to -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Step 1. Configure the Company Portal ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-config-step-2.md b/microsoft-365/solutions/apps-config-step-2.md index f2351df69a5..b2e19a00914 100644 --- a/microsoft-365/solutions/apps-config-step-2.md +++ b/microsoft-365/solutions/apps-config-step-2.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: how-to -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Step 2. Configure Microsoft Outlook. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-config-step-3.md b/microsoft-365/solutions/apps-config-step-3.md index 9c488ec467e..70a9145df60 100644 --- a/microsoft-365/solutions/apps-config-step-3.md +++ b/microsoft-365/solutions/apps-config-step-3.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: how-to -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Step 3. Configure Microsoft 365. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-config-step-4.md b/microsoft-365/solutions/apps-config-step-4.md index d728bc2098f..631055c4252 100644 --- a/microsoft-365/solutions/apps-config-step-4.md +++ b/microsoft-365/solutions/apps-config-step-4.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: how-to -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Step 4. Configure Microsoft Edge in Intune. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-config-step-5.md b/microsoft-365/solutions/apps-config-step-5.md index 6d50ecae30a..b6df1413ce2 100644 --- a/microsoft-365/solutions/apps-config-step-5.md +++ b/microsoft-365/solutions/apps-config-step-5.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: how-to -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Step 5. Configure Microsoft Teams in Intune. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-config-step-6.md b/microsoft-365/solutions/apps-config-step-6.md index ae37621d032..bd692162798 100644 --- a/microsoft-365/solutions/apps-config-step-6.md +++ b/microsoft-365/solutions/apps-config-step-6.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: how-to -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Step 6. Configure other apps in Intune. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-config-step-7.md b/microsoft-365/solutions/apps-config-step-7.md index 2ca01e923eb..9471ff5f4c0 100644 --- a/microsoft-365/solutions/apps-config-step-7.md +++ b/microsoft-365/solutions/apps-config-step-7.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: how-to -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Step 7. Verify app configuration. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-guide-overview.md b/microsoft-365/solutions/apps-guide-overview.md index a8f4c988e53..1fce4bd8e47 100644 --- a/microsoft-365/solutions/apps-guide-overview.md +++ b/microsoft-365/solutions/apps-guide-overview.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: article -ms.date: 05/17/2024 +ms.date: 04/21/2025 description: Purchase and add managed apps for your managed environment. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-license-manage.md b/microsoft-365/solutions/apps-license-manage.md index b1b02a8d20a..d8dc9af7a2b 100644 --- a/microsoft-365/solutions/apps-license-manage.md +++ b/microsoft-365/solutions/apps-license-manage.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: article -ms.date: 07/15/2024 +ms.date: 04/21/2025 description: Manage app licenses used in Intune. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-license-overview.md b/microsoft-365/solutions/apps-license-overview.md index ef5b2881f64..a734d6025e4 100644 --- a/microsoft-365/solutions/apps-license-overview.md +++ b/microsoft-365/solutions/apps-license-overview.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: concept-article -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Understand app licenses used in Intune. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-protect-access-requirements.md b/microsoft-365/solutions/apps-protect-access-requirements.md index dc6ece9b3c0..b136b11e478 100644 --- a/microsoft-365/solutions/apps-protect-access-requirements.md +++ b/microsoft-365/solutions/apps-protect-access-requirements.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: concept-article -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Understand app protection access requirements using Microsoft Intune. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-protect-conditional-launch.md b/microsoft-365/solutions/apps-protect-conditional-launch.md index 28b7da07445..5b604a91173 100644 --- a/microsoft-365/solutions/apps-protect-conditional-launch.md +++ b/microsoft-365/solutions/apps-protect-conditional-launch.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: concept-article -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Understand app protection conditional launch using Microsoft Intune. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-protect-data-protection.md b/microsoft-365/solutions/apps-protect-data-protection.md index 94b084b303c..7b93da454b2 100644 --- a/microsoft-365/solutions/apps-protect-data-protection.md +++ b/microsoft-365/solutions/apps-protect-data-protection.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: concept-article -ms.date: 07/10/2024 +ms.date: 04/21/2025 description: Understand app data protection using Microsoft Intune. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-protect-framework.md b/microsoft-365/solutions/apps-protect-framework.md index cbc5387828e..f5c36daf1a6 100644 --- a/microsoft-365/solutions/apps-protect-framework.md +++ b/microsoft-365/solutions/apps-protect-framework.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: how-to -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Use the app protection framework with Microsoft Intune. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-protect-health-checks.md b/microsoft-365/solutions/apps-protect-health-checks.md index 19ae640a854..36b254cdcef 100644 --- a/microsoft-365/solutions/apps-protect-health-checks.md +++ b/microsoft-365/solutions/apps-protect-health-checks.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: concept-article -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Understand app protection health checks using Microsoft Intune. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-protect-overview.md b/microsoft-365/solutions/apps-protect-overview.md index f85d4dd18c8..6a741aba924 100644 --- a/microsoft-365/solutions/apps-protect-overview.md +++ b/microsoft-365/solutions/apps-protect-overview.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: solution-overview -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Secure and protect apps using Microsoft Intune. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-protect-step-1.md b/microsoft-365/solutions/apps-protect-step-1.md index df87d34598d..11e765e6ad4 100644 --- a/microsoft-365/solutions/apps-protect-step-1.md +++ b/microsoft-365/solutions/apps-protect-step-1.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: how-to -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Step 1. Apply minimum data protection. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-protect-step-2.md b/microsoft-365/solutions/apps-protect-step-2.md index 58fe15705cb..d521863b47d 100644 --- a/microsoft-365/solutions/apps-protect-step-2.md +++ b/microsoft-365/solutions/apps-protect-step-2.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: how-to -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Step 2. Apply enhanced data protection ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-protect-step-3.md b/microsoft-365/solutions/apps-protect-step-3.md index fb3f512b67f..f409b66029a 100644 --- a/microsoft-365/solutions/apps-protect-step-3.md +++ b/microsoft-365/solutions/apps-protect-step-3.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: how-to -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Step 3. Apply high data protection ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-protect-step-4.md b/microsoft-365/solutions/apps-protect-step-4.md index 42782050eec..9946a4848a8 100644 --- a/microsoft-365/solutions/apps-protect-step-4.md +++ b/microsoft-365/solutions/apps-protect-step-4.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: how-to -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Step 4. Understand app protection delivery. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-protect-step-5.md b/microsoft-365/solutions/apps-protect-step-5.md index af4f290d3be..198ab3b1322 100644 --- a/microsoft-365/solutions/apps-protect-step-5.md +++ b/microsoft-365/solutions/apps-protect-step-5.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: how-to -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Step 5. Verify and monitor app protection ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-protect-step-6.md b/microsoft-365/solutions/apps-protect-step-6.md index e9c1e576627..6761ca4a09f 100644 --- a/microsoft-365/solutions/apps-protect-step-6.md +++ b/microsoft-365/solutions/apps-protect-step-6.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: how-to -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Step 6. Use app protection actions. ms.service: o365-solutions ms.localizationpriority: high @@ -17,30 +17,30 @@ keywords: # Step 6. Use app protection actions -In addition to applying conditional launch actions as part of your app protection policy, you can remove organizational or corporate app data by creating a device based wipe request or a user based wipe request. Applying this form of protection is done when either a member of your organization leaves, the devices is lost, or the device is stolen. This method only removes your organization data, not personal data on the device. +In addition to applying conditional launch actions as part of your app protection policy, you have more app protection actions. You can remove organizational or corporate app data by creating a device based wipe request or a user based wipe request. This form of protection is applied when either a member of your organization leaves, the devices is lost, or the device is stolen. This method only removes your organization data, not personal data on the device. ## Device based wipe -You can create a device based wipe request for an end-user. Sometimes end-users have multiple devices, such as a tablet and a phone. You can choose which device to wipe. In addition, you can see the state of the wipe request in Intune. For more information, see [Create a device based wipe request](/mem/intune/apps/apps-selective-wipe#create-a-device-based-wipe-request). +You can create a device based wipe request for an end-user. Sometimes end-users have multiple devices, such as a tablet and a phone. You can choose which device to wipe. In addition, you can see the state of the wipe request in Intune. For more information, see [Create a device based wipe request](/intune/intune-service/apps/apps-selective-wipe#create-a-device-based-wipe-request). ## User based wipe -You can also create a user based wipe request. This wipe request removes organizational data from all apps on all the user's devices that are managed by Intune. You can also see the state of the wipe request in Intune. For more information, see [Create a user based wipe request](/mem/intune/apps/apps-selective-wipe#create-a-user-based-wipe-request). +You can also create a user based wipe request. This wipe request removes organizational data from all managed apps on all the user's devices. You can also see the state of the wipe request in Intune. For more information, see [Create a user based wipe request](/intune/intune-service/apps/apps-selective-wipe#create-a-user-based-wipe-request). ## Additional actions In addition to the above actions, you can also do the following actions: -- [Monitor your wipe requests](/mem/intune/apps/apps-selective-wipe#monitor-your-wipe-requests) -- [Delete a device wipe request](/mem/intune/apps/apps-selective-wipe#delete-a-device-wipe-request) -- [Delete a user wipe request](/mem/intune/apps/apps-selective-wipe#delete-a-user-wipe-request) +- [Monitor your wipe requests](/intune/intune-service/apps/apps-selective-wipe#monitor-your-wipe-requests) +- [Delete a device wipe request](/intune/intune-service/apps/apps-selective-wipe#delete-a-device-wipe-request) +- [Delete a user wipe request](/intune/intune-service/apps/apps-selective-wipe#delete-a-user-wipe-request) ## After securing and protecting apps in Intune Once you have reviewed and completed the steps provided in this solution, you're ready to configure, protect, assign, and monitor the managed apps your organization uses. For more information about how to proceed, see the following articles: -- [App configuration policies for Microsoft Intune](/mem/intune/apps/app-configuration-policies-overview) -- [App protection policies overview](/mem/intune/apps/app-protection-policy) -- [Data protection framework using app protection policies](/mem/intune/apps/app-protection-framework) -- [Assign apps to groups with Microsoft Intune](/mem/intune/apps/apps-deploy) -- [Monitor app information and assignments with Microsoft Intune](/mem/intune/apps/apps-monitor) \ No newline at end of file +- [App configuration policies for Microsoft Intune](/intune/intune-service/apps/app-configuration-policies-overview) +- [App protection policies overview](/intune/intune-service/apps/app-protection-policy) +- [Data protection framework using app protection policies](/intune/intune-service/apps/app-protection-framework) +- [Assign apps to groups with Microsoft Intune](/intune/intune-service/apps/apps-deploy) +- [Monitor app information and assignments with Microsoft Intune](/intune/intune-service/apps/apps-monitor) \ No newline at end of file diff --git a/microsoft-365/solutions/apps-purchase-overview.md b/microsoft-365/solutions/apps-purchase-overview.md index 6a221cffff7..5d07edb3bee 100644 --- a/microsoft-365/solutions/apps-purchase-overview.md +++ b/microsoft-365/solutions/apps-purchase-overview.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: article -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Understand how to purchase apps for Intune. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-purchase-store.md b/microsoft-365/solutions/apps-purchase-store.md index 5a52d224431..d7a0a837385 100644 --- a/microsoft-365/solutions/apps-purchase-store.md +++ b/microsoft-365/solutions/apps-purchase-store.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: article -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Purchase store apps in Intune. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-purchase-volume.md b/microsoft-365/solutions/apps-purchase-volume.md index d8a57af6546..c6c9ec17d62 100644 --- a/microsoft-365/solutions/apps-purchase-volume.md +++ b/microsoft-365/solutions/apps-purchase-volume.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: how-to -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Purchase apps in-volume for Intune. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-type-built-in.md b/microsoft-365/solutions/apps-type-built-in.md index a18f23b291b..52b795684e4 100644 --- a/microsoft-365/solutions/apps-type-built-in.md +++ b/microsoft-365/solutions/apps-type-built-in.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: concept-article -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Understand built-in apps as they apply to a managed environment. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-type-lob.md b/microsoft-365/solutions/apps-type-lob.md index 16868081696..4520f9421f1 100644 --- a/microsoft-365/solutions/apps-type-lob.md +++ b/microsoft-365/solutions/apps-type-lob.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: concept-article -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Understand line-of-business apps as they apply to a managed environment. ms.service: o365-solutions ms.localizationpriority: high @@ -17,7 +17,7 @@ keywords: # Understand line-of-business apps for Intune -A line-of-business (LOB) app is an app that you add to Microsoft Intune from an app installation file. Line-of-business (LOB) apps are commonly referred to as custom apps and in-house apps because they're typically created by your organization. These apps support a specific purpose for your organization. To include LOB apps in your managed environment, you upload the app installation file to Intune and assign the app to devices or groups from Intune. Intune supports LOB apps for Android devices, iOS/iPadOS devices, Windows devices, and macOS devices. +A line-of-business (LOB) app is an app that you add to Microsoft Intune from an app installation file. Line-of-business (LOB) apps are commonly referred to as custom apps and in-house apps because these apps are typically created by your organization. These apps support a specific purpose for your organization. To include LOB apps in your managed environment, you upload the app installation file to Intune and assign the app to devices or groups from Intune. Intune supports LOB apps for Android devices, iOS/iPadOS devices, Windows devices, and macOS devices. When your organization initially creates an app for the members of your organization to use, they can include support for Intune app configuration policies and app protection policies. This support allows Intune to manage your LOB app. To add this support to your app, your organization must use either the [Intune App SDK](/mem/intune/developer/app-sdk) or the [Intune App Wrapping Tool](/mem/intune/developer/apps-prepare-mobile-application-management). @@ -38,7 +38,7 @@ LOB apps can be added to Intune by first selecting either **Line-of-business app :::image type="content" source="../media/purchase-add-managed-apps/purchase-add-managed-apps-09.png" alt-text="Intune app types" border="true" ::: -When you select **Line-of-business app**, you have the option to add your specific installation package file. Also, you can choose to use [Test Base](https://go.microsoft.com/fwlink/?linkid=2165798) to help you manage the performance of your LOB app. +When you select **Line-of-business app**, you can add your specific installation package file. Also, you can choose to use [Test Base](https://go.microsoft.com/fwlink/?linkid=2165798) to help you manage the performance of your LOB app. :::image type="content" source="../media/purchase-add-managed-apps/purchase-add-managed-apps-10.png" alt-text="Intune - Line-of-business app" border="true" ::: diff --git a/microsoft-365/solutions/apps-type-microsoft.md b/microsoft-365/solutions/apps-type-microsoft.md index 560b092004a..91000f7b087 100644 --- a/microsoft-365/solutions/apps-type-microsoft.md +++ b/microsoft-365/solutions/apps-type-microsoft.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: concept-article -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Understand Microsoft apps as they apply to a managed environment. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-type-overview.md b/microsoft-365/solutions/apps-type-overview.md index ab223494813..f351b13f3f8 100644 --- a/microsoft-365/solutions/apps-type-overview.md +++ b/microsoft-365/solutions/apps-type-overview.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: concept-article -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Understand the app types that are available for managed environments. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-type-store.md b/microsoft-365/solutions/apps-type-store.md index c50015b9dff..59513f2c8de 100644 --- a/microsoft-365/solutions/apps-type-store.md +++ b/microsoft-365/solutions/apps-type-store.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: concept-article -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Understand store apps as they apply to a managed environment. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/apps-type-web.md b/microsoft-365/solutions/apps-type-web.md index ccde0cc9d93..1f63566e35f 100644 --- a/microsoft-365/solutions/apps-type-web.md +++ b/microsoft-365/solutions/apps-type-web.md @@ -5,7 +5,7 @@ author: erikre manager: dougeby audience: ITPro ms.topic: concept-article -ms.date: 03/29/2024 +ms.date: 04/21/2025 description: Understand web apps as they apply to a managed environment. ms.service: o365-solutions ms.localizationpriority: high diff --git a/microsoft-365/solutions/best-practices-anonymous-sharing.md b/microsoft-365/solutions/best-practices-anonymous-sharing.md index ace4e6d2d35..3e2026fab83 100644 --- a/microsoft-365/solutions/best-practices-anonymous-sharing.md +++ b/microsoft-365/solutions/best-practices-anonymous-sharing.md @@ -110,7 +110,7 @@ You can use [Microsoft Purview Data Loss Prevention (DLP)](/purview/dlp-learn-ab To create a DLP rule: -1. In the [Microsoft Purview admin center](https://compliance.microsoft.com/), expand **Data loss prevention**, and select **Policies**. +1. In the [Microsoft Purview portal](https://purview.microsoft.com/), expand **Data loss prevention**, and select **Policies**. 1. Select **Create policy**. 1. Choose **Custom**, select **Custom policy,** and then select **Next**. 1. Type a name for the policy and select **Next**. @@ -137,11 +137,11 @@ You can also use the *Safe Documents* feature to scan opened Office documents in ## Add copyright information to your files -If you use sensitivity labels in the Microsoft Purview admin center, you can configure *content marking* in your labels to add a watermark or a header or footer automatically to your organization's Office documents. In this way, you can make sure that shared files contain copyright or other ownership information. +If you use sensitivity labels in the Microsoft Purview portal, you can configure *content marking* in your labels to add a watermark or a header or footer automatically to your organization's Office documents. In this way, you can make sure that shared files contain copyright or other ownership information. To add a footer to a labeled file -1. Open the [Microsoft Purview admin center](https://compliance.microsoft.com). +1. Open the [Microsoft Purview portal](https://purview.microsoft.com). 1. In the left navigation, under **Solutions**, expand **Information protection** and select **Labels**. 1. Select the label where you want to add content marking, and then select **Edit label**. 1. Select **Next** to reach the **Choose protection settings for labeled items** page, and then select **Apply content marking**. Select **Next** diff --git a/microsoft-365/solutions/configure-teams-highly-sensitive-protection.md b/microsoft-365/solutions/configure-teams-highly-sensitive-protection.md index d773557b579..c3760f82fa0 100644 --- a/microsoft-365/solutions/configure-teams-highly-sensitive-protection.md +++ b/microsoft-365/solutions/configure-teams-highly-sensitive-protection.md @@ -107,7 +107,7 @@ If you already have sensitivity labels deployed in your organization, consider h Once you have enabled sensitivity labels for Teams, the next step is to create the label. To create a sensitivity label -1. Open the [Microsoft Purview compliance portal](https://compliance.microsoft.com). +1. Open the [Microsoft Purview portal](https://purview.microsoft.com). 1. Under **Solutions**, expand **Information protection**. 1. Select **Create a label**. 1. Give the label a name. We suggest **Highly sensitive**, but you can choose a different name if that one is already in use. @@ -133,7 +133,7 @@ To create a sensitivity label 1. On the **Auto-labeling for schematized data assets** page, select **Next**. 1. Select **Create label**, and then select **Done**. -Once you've created the label, you need to publish it to the users who will use it. For sensitive protection, we make the label available to all users. You publish the label in the Microsoft Purview compliance portal, on the **Label policies** page under **Information protection**. If you have an existing policy that applies to all users, add this label to that policy. If you need to create a new policy, see [Publish sensitivity labels by creating a label policy](../compliance/create-sensitivity-labels.md#publish-sensitivity-labels-by-creating-a-label-policy). +Once you've created the label, you need to publish it to the users who will use it. For sensitive protection, we make the label available to all users. You publish the label in the Microsoft Purview portal, on the **Label policies** page under **Information protection**. If you have an existing policy that applies to all users, add this label to that policy. If you need to create a new policy, see [Publish sensitivity labels by creating a label policy](../compliance/create-sensitivity-labels.md#publish-sensitivity-labels-by-creating-a-label-policy). ## Teams settings diff --git a/microsoft-365/solutions/configure-teams-sensitive-protection.md b/microsoft-365/solutions/configure-teams-sensitive-protection.md index 3c2389beba2..fc464b45b32 100644 --- a/microsoft-365/solutions/configure-teams-sensitive-protection.md +++ b/microsoft-365/solutions/configure-teams-sensitive-protection.md @@ -64,7 +64,7 @@ If you already have sensitivity labels deployed in your organization, consider h Once you have enabled sensitivity labels for Teams, the next step is to create the label. To create a sensitivity label -1. Open the [Microsoft Purview compliance portal](https://compliance.microsoft.com). +1. Open the [Microsoft Purview portal](https://purview.microsoft.com). 1. Under **Solutions**, expand **Information protection**. 1. Select **Create a label**. 1. Give the label a name. We suggest **Sensitive**, but you can choose a different name if that one is already in use. @@ -85,7 +85,7 @@ To create a sensitivity label 1. On the **Auto-labeling for schematized data assets** page, select **Next**. 1. Select **Create label**, and then select **Done**. -Once you've created the label, you need to publish it to the users who will use it. For sensitive protection, we make the label available to all users. You publish the label in the Microsoft Purview compliance portal, on the **Label policies** page under **Information protection**. If you have an existing policy that applies to all users, add this label to that policy. If you need to create a new policy, see [Publish sensitivity labels by creating a label policy](../compliance/create-sensitivity-labels.md#publish-sensitivity-labels-by-creating-a-label-policy). +Once you've created the label, you need to publish it to the users who will use it. For sensitive protection, we make the label available to all users. You publish the label in the Microsoft Purview portal, on the **Label policies** page under **Information protection**. If you have an existing policy that applies to all users, add this label to that policy. If you need to create a new policy, see [Publish sensitivity labels by creating a label policy](../compliance/create-sensitivity-labels.md#publish-sensitivity-labels-by-creating-a-label-policy). ## Teams settings diff --git a/microsoft-365/solutions/create-secure-guest-sharing-environment.md b/microsoft-365/solutions/create-secure-guest-sharing-environment.md index f8af931b4e6..44ed2ec0f5d 100644 --- a/microsoft-365/solutions/create-secure-guest-sharing-environment.md +++ b/microsoft-365/solutions/create-secure-guest-sharing-environment.md @@ -213,13 +213,13 @@ To configure a guest session timeout policy ## Create a sensitive information type for a highly sensitive project -Sensitive information types are predefined strings that can be used in policy workflows to enforce compliance requirements. The Microsoft Purview compliance portal comes with over one hundred sensitive information types, including driver's license numbers, credit card numbers, bank account numbers, etc. +Sensitive information types are predefined strings that can be used in policy workflows to enforce compliance requirements. The Microsoft Purview portal comes with over one hundred sensitive information types, including driver's license numbers, credit card numbers, bank account numbers, etc. You can create custom sensitive information types to help manage content specific to your organization. In this example, we create a custom sensitive information type for a highly sensitive project. We can then use this sensitive information type to automatically apply a sensitivity label. To create a sensitive information type -1. In the [Microsoft Purview compliance portal](https://compliance.microsoft.com), in the left navigation, expand **Data classification**, and then select **Classifiers**. +1. In the [Microsoft Purview portal](https://purview.microsoft.com), in the left navigation, expand **Data classification**, and then select **Classifiers**. 1. select the **Sensitive info types** tab. 1. Select **Create sensitive info type**. 1. For **Name** and **Description**, type **Project Saturn**, and then select **Next**. @@ -240,7 +240,7 @@ If you're using sensitivity labels in your organization, you can automatically a To create an auto-labeling policy -1. Open the [Microsoft Purview admin center](https://compliance.microsoft.com). +1. Open the [Microsoft Purview portal](https://purview.microsoft.com). 1. In the left navigation, expand **Information protection**, and select **Auto-labeling**. 1. Select **Create auto-labeling policy**. 1. On the **Choose info you want this label applied to** page, choose **Custom** and then select **Custom policy**. @@ -274,7 +274,7 @@ You can use [Microsoft Purview Data Loss Prevention (DLP)](/purview/dlp-learn-ab To create a DLP rule -1. Open the [Microsoft Purview admin center](https://compliance.microsoft.com). +1. Open the [Microsoft Purview portal](https://purview.microsoft.com). 1. In the left navigation, expand **Data loss prevention**, and select **Policies**. 1. Select **Create policy**. 1. Choose **Custom** and then **Custom policy**. diff --git a/microsoft-365/solutions/empower-people-to-work-remotely-security-compliance.md b/microsoft-365/solutions/empower-people-to-work-remotely-security-compliance.md index 3837c0be45e..f423ddd5aba 100644 --- a/microsoft-365/solutions/empower-people-to-work-remotely-security-compliance.md +++ b/microsoft-365/solutions/empower-people-to-work-remotely-security-compliance.md @@ -71,7 +71,7 @@ Comply with internal policies or regulatory requirements with these compliance f |Data retention labels and policies|Implement information governance controls, such as how long to keep data and requirements on the storage of personal data on customers, to comply with your organization's policies or data regulations.|Microsoft 365 E3 or E5| |Microsoft Purview Message Encryption|Send and receive encrypted email messages between people inside and outside your organization that contains regulated data, such as personal data on customers.|Microsoft 365 E3 or E5| |Compliance Manager|Manage regulatory compliance activities related to Microsoft cloud services with this workflow-based risk assessment tool in the Microsoft Service Trust Portal.|Microsoft 365 E3 or E5| -|Compliance Manager|See an overall score of your current compliance configuration and recommendations for improving it in the Microsoft Purview compliance portal.|Microsoft 365 E3 or E5| +|Compliance Manager|See an overall score of your current compliance configuration and recommendations for improving it in the Microsoft Purview portal.|Microsoft 365 E3 or E5| |Communication Compliance|Detect, capture, and take remediation actions for inappropriate messages in your organization.|Microsoft 365 E5 or Microsoft 365 E3 with the Compliance or Insider Risk Management add-ons| |Insider Risk Management|Detect, investigate, and act on malicious and inadvertent risks in your organization. Microsoft 365 can detect these kinds of risks even when a worker is using an unmanaged device.|Microsoft 365 E5 or Microsoft 365 E3 with the Compliance or Insider Risk Management add-ons| |||| diff --git a/microsoft-365/solutions/identity-design-principles.md b/microsoft-365/solutions/identity-design-principles.md index 2529a9f72c7..bd0ca604eac 100644 --- a/microsoft-365/solutions/identity-design-principles.md +++ b/microsoft-365/solutions/identity-design-principles.md @@ -223,17 +223,17 @@ Sometimes scenarios call for adding an external user to a role (see the previous -### Microsoft Defender XDR and Microsoft 365 Purview compliance portals +### Microsoft Defender XDR and Microsoft Purview portals -**Email & Collaboration roles** in the [Microsoft Defender portal](../security/office-365-security/mdo-portal-permissions.md) and ***Role groups for Microsoft Purview solutions** in the [Microsoft 365 Purview compliance portal](../compliance/microsoft-365-compliance-center-permissions.md) are a collection of "role groups", which are separate and distinct from Microsoft Entra roles. This can be confusing because some of these role groups have the same name as Microsoft Entra roles (for example, Security Reader), yet they can have different membership. I prefer the use of Microsoft Entra roles. Each role group consists of one or more "roles" (see what I mean about reusing the same word?) and have members from Microsoft Entra ID, which are email enabled objects. Also, you can create a role group with the same name as a role, which might or might not contain that role (avoid this confusion). +**Email & Collaboration roles** in the [Microsoft Defender portal](../security/office-365-security/mdo-portal-permissions.md) and ***Role groups for Microsoft Purview solutions** in the [Microsoft Purview portal](../compliance/microsoft-365-compliance-center-permissions.md) are a collection of "role groups", which are separate and distinct from Microsoft Entra roles. This can be confusing because some of these role groups have the same name as Microsoft Entra roles (for example, Security Reader), yet they can have different membership. I prefer the use of Microsoft Entra roles. Each role group consists of one or more "roles" (see what I mean about reusing the same word?) and have members from Microsoft Entra ID, which are email enabled objects. Also, you can create a role group with the same name as a role, which might or might not contain that role (avoid this confusion). -In a sense, these permissions are an evolution of the Exchange role groups model. However, Exchange Online has its own [role group management](/exchange/permissions-exo) interface. Some role groups in Exchange Online are locked and managed from Microsoft Entra ID or the Microsoft Defender XDR and Microsoft 365 Purview compliance portals, but others might have the same or similar names and are managed in Exchange Online (adding to the confusion). I recommend you avoid using the Exchange Online user interface unless you need scopes for Exchange management. +In a sense, these permissions are an evolution of the Exchange role groups model. However, Exchange Online has its own [role group management](/exchange/permissions-exo) interface. Some role groups in Exchange Online are locked and managed from Microsoft Entra ID or the Microsoft Defender XDR and Microsoft Purview portals, but others might have the same or similar names and are managed in Exchange Online (adding to the confusion). I recommend you avoid using the Exchange Online user interface unless you need scopes for Exchange management. You can't create custom roles. Roles are defined by services created by Microsoft and continue to grow as new services are introduced. This behavior is similar in concept to [roles defined by applications](/azure/active-directory/develop/howto-add-app-roles-in-azure-ad-apps) in Microsoft Entra ID. When new services are enabled, often new role groups need to be created in order to grant or delegate access to these (for example, [insider risk management](../compliance/insider-risk-management-configure.md). These role groups also require direct membership and can't contain Microsoft Entra groups. Unfortunately, today these role groups aren't supported by Microsoft Entra PIM. Like Microsoft Entra roles, I tend to recommend management of these role groups through APIs or a partner governance product like Saviynt, or others. -Microsoft Defender portal and Microsoft 365 Purview compliance portal roles span Microsoft 365 and you can't scope these role groups to a subset of the environment (like you can with administrative units in Microsoft Entra ID). Many customers ask how they can subdelegate. For example, "create a DLP policy only for EU users." Today, if you have rights to a specific function in the Microsoft Defender XDR and Microsoft 365 Purview compliance portals, you have rights to everything covered by this function in the tenant. However, many policies have capabilities to target a subset of the environment (for example, "make these [labels](../compliance/create-sensitivity-labels.md#publish-sensitivity-labels-by-creating-a-label-policy) available only to these users"). Proper governance and communication are a key component to avoid conflicts. Some customers choose to implement a "configuration as code" approach to address subdelegation in the Microsoft Defender XDR and Microsoft 365 Purview compliance portals. Some specific services support subdelegation (see the next section). +Microsoft Defender portal and Microsoft Purview portal roles span Microsoft 365 and you can't scope these role groups to a subset of the environment (like you can with administrative units in Microsoft Entra ID). Many customers ask how they can subdelegate. For example, "create a DLP policy only for EU users." Today, if you have rights to a specific function in the Microsoft Defender XDR and Microsoft Purview portals, you have rights to everything covered by this function in the tenant. However, many policies have capabilities to target a subset of the environment (for example, "make these [labels](../compliance/create-sensitivity-labels.md#publish-sensitivity-labels-by-creating-a-label-policy) available only to these users"). Proper governance and communication are a key component to avoid conflicts. Some customers choose to implement a "configuration as code" approach to address subdelegation in the Microsoft Defender XDR and Microsoft Purview portals. Some specific services support subdelegation (see the next section). ### Service Specific diff --git a/microsoft-365/solutions/microsoft-365-groups-expiration-policy.md b/microsoft-365/solutions/microsoft-365-groups-expiration-policy.md index ba77843a562..9ec8618725f 100644 --- a/microsoft-365/solutions/microsoft-365-groups-expiration-policy.md +++ b/microsoft-365/solutions/microsoft-365-groups-expiration-policy.md @@ -73,7 +73,7 @@ Note that currently you can't have different policies for different groups. ## How expiry works with the retention policy -If you have set up a retention policy for groups in the Microsoft Purview compliance portal, the expiration policy works seamlessly with retention policy. When a group expires, the group's mailbox conversations and files in the group site are retained in the retention container for the specific number of days defined in the retention policy. Users won't see the group, or its content, after expiration however. +If you have set up a retention policy for groups in the Microsoft Purview portal, the expiration policy works seamlessly with retention policy. When a group expires, the group's mailbox conversations and files in the group site are retained in the retention container for the specific number of days defined in the retention policy. Users won't see the group, or its content, after expiration however. ## How and when a group owner learns if their groups are going to expire diff --git a/microsoft-365/solutions/tenant-management-tenants.md b/microsoft-365/solutions/tenant-management-tenants.md index 724724de702..5d48244e0aa 100644 --- a/microsoft-365/solutions/tenant-management-tenants.md +++ b/microsoft-365/solutions/tenant-management-tenants.md @@ -144,7 +144,7 @@ On an ongoing basis, you might need to: - Add a new tenant. - Add new products to a tenant with an initial number of licenses. -- Change the set of licenses for a product in a tenant to adjust for changing staff requirements. +- Change the set of licenses for a product in a tenant to adjust for changing staff requirements. For more information, see [Buy or remove Microsoft 365 licenses for a subscription](/microsoft-365/commerce/licenses/buy-licenses). - Move your core data from a tenant to a new datacenter geo location. - Add Multi-Geo for data residency requirements. - Set up inter-tenant collaboration. diff --git a/microsoft-365/syntex/adoption-getstarted.md b/microsoft-365/syntex/adoption-getstarted.md index e0a0e69d62d..fa8199e1ff0 100644 --- a/microsoft-365/syntex/adoption-getstarted.md +++ b/microsoft-365/syntex/adoption-getstarted.md @@ -3,7 +3,7 @@ title: Get started driving adoption of Microsoft Syntex ms.author: chucked author: chuckedmonson manager: jtremper -ms.date: 09/09/2024 +ms.date: 03/09/2025 audience: admin ms.topic: get-started ms.service: microsoft-syntex diff --git a/microsoft-365/syntex/adoption-scenarios.md b/microsoft-365/syntex/adoption-scenarios.md index 55f083a5513..a00908f524b 100644 --- a/microsoft-365/syntex/adoption-scenarios.md +++ b/microsoft-365/syntex/adoption-scenarios.md @@ -101,7 +101,7 @@ When you automate this scenario, you can feel secure that: Most organizations have large repositories of legal documents, policies, contracts, HR documents, and governance guidelines. Mine these data stores to extract valuable information such as: projects, sectors, themes, people, geographical areas, and so on. -For example, an HR director needs to quickly access all HR documents – including resumes, HR policies, and other forms. And they want to quickly identify necessary information from resumes and other HR-related documents without manually sifting through the documents. They’re looking for a solution that allows them to quickly find the information they need without having to manually look through thousands of resumes, HR policies, and other documentation that may be spread across several sites. +For example, an HR director needs to quickly access all HR documents – including resumes, HR policies, and other forms. And they want to quickly identify necessary information from resumes and other HR-related documents without manually sifting through the documents. They’re looking for a solution that allows them to quickly find the information they need without having to manually look through thousands of resumes, HR policies, and other documentation that might be spread across several sites. When you automate this scenario, you can: diff --git a/microsoft-365/syntex/apply-a-retention-label-to-a-model.md b/microsoft-365/syntex/apply-a-retention-label-to-a-model.md index 039dd06a5b6..65bfd08c0ce 100644 --- a/microsoft-365/syntex/apply-a-retention-label-to-a-model.md +++ b/microsoft-365/syntex/apply-a-retention-label-to-a-model.md @@ -38,7 +38,7 @@ You can apply a pre-existing retention label to your model through your model se ## Add a retention label to an unstructured document processing model or a prebuilt model > [!Important] -> For retention labels to be available to apply to your unstructured document processing or prebuilt models, they need to be [created](../compliance/file-plan-manager.md#create-retention-labels) and [published](../compliance/create-apply-retention-labels.md#how-to-publish-retention-labels) in the Microsoft Purview compliance portal. +> For retention labels to be available to apply to your unstructured document processing or prebuilt models, they need to be [created](../compliance/file-plan-manager.md#create-retention-labels) and [published](../compliance/create-apply-retention-labels.md#how-to-publish-retention-labels) in the Microsoft Purview portal. 1. From the model home page, select **Model settings**. @@ -80,7 +80,7 @@ For example, all *Insurance notice* documents that your model identifies will al ## Add a retention label to a structured or freeform document processing model > [!Important] -> For retention labels to be available to apply to your structured or freeform document processing models, they need to be [created](../compliance/file-plan-manager.md#create-retention-labels) and [published](../compliance/create-apply-retention-labels.md#how-to-publish-retention-labels) in the Microsoft Purview compliance portal. +> For retention labels to be available to apply to your structured or freeform document processing models, they need to be [created](../compliance/file-plan-manager.md#create-retention-labels) and [published](../compliance/create-apply-retention-labels.md#how-to-publish-retention-labels) in the Microsoft Purview portal. You can either apply a retention label to a structured or freeform document processing model when you're creating a model, or apply it to an existing model. diff --git a/microsoft-365/syntex/apply-a-sensitivity-label-to-a-model.md b/microsoft-365/syntex/apply-a-sensitivity-label-to-a-model.md index 09c71acdd65..92a46cb36a2 100644 --- a/microsoft-365/syntex/apply-a-sensitivity-label-to-a-model.md +++ b/microsoft-365/syntex/apply-a-sensitivity-label-to-a-model.md @@ -27,7 +27,7 @@ Sensitivity labels let you apply encryption to the documents that your models id You can apply a pre-existing sensitivity label to your model through your model settings on your model's home page. The label must already be published to be available for selection from model settings. Labels apply to Office files for Word (.docx), PowerPoint (.pptx), and Excel (.xlsx). > [!Important] -> For sensitivity labels to be available to apply to your models, they need to be [created and published in the Microsoft Purview compliance portal](../admin/security-and-compliance/set-up-compliance.md). +> For sensitivity labels to be available to apply to your models, they need to be [created and published in the Microsoft Purview portal](../admin/security-and-compliance/set-up-compliance.md). ## Add a sensitivity label to a model diff --git a/microsoft-365/syntex/difference-between-document-understanding-and-form-processing-model.md b/microsoft-365/syntex/difference-between-document-understanding-and-form-processing-model.md index 438168401d1..b07f67daeec 100644 --- a/microsoft-365/syntex/difference-between-document-understanding-and-form-processing-model.md +++ b/microsoft-365/syntex/difference-between-document-understanding-and-form-processing-model.md @@ -4,7 +4,7 @@ ms.author: chucked author: chuckedmonson manager: jtremper ms.reviewer: lauris -ms.date: 10/29/2024 +ms.date: 03/29/2025 audience: admin ms.topic: product-comparison ms.service: microsoft-syntex diff --git a/microsoft-365/syntex/esignature-overview.md b/microsoft-365/syntex/esignature-overview.md index a55633d7ee0..4e07d1d2651 100644 --- a/microsoft-365/syntex/esignature-overview.md +++ b/microsoft-365/syntex/esignature-overview.md @@ -4,7 +4,7 @@ ms.author: chucked author: chuckedmonson manager: jtremper ms.reviewer: amcdonnell -ms.date: 01/16/2025 +ms.date: 04/23/2025 audience: enabler ms.topic: concept-article ms.service: microsoft-syntex @@ -46,6 +46,21 @@ Before you can use SharePoint eSignature, you must first link your Azure subscri SharePoint eSignature enables binding agreements between parties. External parties are allowed guests access to SharePoint via Microsoft Entra ID in order to electronically sign a document. Certain external sharing settings must be enabled at a tenant and site level to allow this access. For more information, see [Set up SharePoint eSignature for external recipients](esignature-setup.md#external-recipients). Consider whether this meets your compliance and security requirements when enabling eSignature. +### Purview integration + +SharePoint eSignature enables logging of eSignature activities in the Purview Audit log. Activities can be viewed by opening the audit log and searching for *eSignature* in the **Activities - operation names** field. The activities logged are: + +- Request was created +- Request was sent +- Request was canceled +- Request was declined +- Request has expired +- Request was completed +- Document was viewed by recipient +- Document was signed by the recipient +- Signed document link was sent to the recipient +- Signed document was downloaded by recipient + ## Using other signature providers SharePoint eSignature is now integrated with other electronic signature providers, such as Adobe Acrobat Sign and DocuSign. You can initiate requests using these other providers from PDF documents in SharePoint, while ensuring the secure and automatic storage of signed documents in Microsoft 365. Other electronic signature providers will be added in the future. diff --git a/microsoft-365/syntex/esignature-review-sign-requests.md b/microsoft-365/syntex/esignature-review-sign-requests.md index db352f8ea30..63c3c891255 100644 --- a/microsoft-365/syntex/esignature-review-sign-requests.md +++ b/microsoft-365/syntex/esignature-review-sign-requests.md @@ -4,7 +4,7 @@ ms.author: chucked author: chuckedmonson manager: jtremper ms.reviewer: amcdonnell -ms.date: 09/10/2024 +ms.date: 04/10/2025 audience: enabler ms.topic: how-to ms.service: microsoft-syntex diff --git a/microsoft-365/syntex/esignature-send-requests.md b/microsoft-365/syntex/esignature-send-requests.md index be2a66935e4..85b6e23f6f0 100644 --- a/microsoft-365/syntex/esignature-send-requests.md +++ b/microsoft-365/syntex/esignature-send-requests.md @@ -4,7 +4,7 @@ ms.author: chucked author: chuckedmonson manager: jtremper ms.reviewer: amcdonnell -ms.date: 09/10/2024 +ms.date: 04/10/2025 audience: enabler ms.topic: how-to ms.service: microsoft-syntex @@ -45,6 +45,32 @@ Use the following steps to start the SharePoint eSignature process. You must be Once sent, the status of the request is set to **In progress**. An email notification is sent to the creator and the recipients. If **Recipients must sign in order** is toggled on, recipients will be able to add their signature in the order specified, otherwise they can add their signature in any order. + + #### Track and manage other provider requests Managing ongoing eSignature requests for other providers is done on the provider website or through the Approvals app in Microsoft Teams. You'll also be notified by email from the provider throughout the signing process. diff --git a/microsoft-365/syntex/esignature-setup.md b/microsoft-365/syntex/esignature-setup.md index e0a2e6bd0a0..2c0d19924ce 100644 --- a/microsoft-365/syntex/esignature-setup.md +++ b/microsoft-365/syntex/esignature-setup.md @@ -24,6 +24,14 @@ description: Learn how to set up and manage sites in SharePoint eSignature. SharePoint eSignature is a pay-as-you-go service that is set up in the Microsoft 365 admin center. Before you begin, determine whether this feature is appropriate for your needs by reading the [Before you begin section](esignature-overview.md#before-you-begin). +## SharePoint eSignature admin checklist + +- Review prerequisites +- Set up SharePoint eSignature +- Add other signature providers +- Manage sites +- Enable new external guests or default to existing guests only + ## Prerequisites ### Licensing @@ -91,7 +99,7 @@ To specify the sites where users can use eSignature, follow these steps. ### Microsoft Entra B2B -Microsoft Entra B2B provides authentication and management of new guests. External signers or recipients are considered as guests within your tenant. To be able to send requests to new signers outside your organization, you need to enable [Microsoft Entra B2B integration for SharePoint and OneDrive](/sharepoint/sharepoint-azureb2b-integration). Consider whether this meets your compliance and security requirements when enabling eSignature. +Microsoft Entra B2B provides authentication and management of **new guests**. External signers or recipients are considered as guests within your tenant. To be able to send requests to **new signers** outside your organization, you need to enable [Microsoft Entra B2B integration for SharePoint and OneDrive](/sharepoint/sharepoint-azureb2b-integration). Consider whether this meets your compliance and security requirements when enabling eSignature. If a guest is deleted from the tenant while the request is ongoing, they can no longer access the request document or the final signed document. In such cases, you need to resend the eSignature request. Before deleting a guest, ensure they aren't involved in any ongoing requests. This setting doesn't affect your existing Azure Active Directory guests. diff --git a/microsoft-365/syntex/esignature-troubleshoot.md b/microsoft-365/syntex/esignature-troubleshoot.md index b0fe80ae6c2..84554e35a83 100644 --- a/microsoft-365/syntex/esignature-troubleshoot.md +++ b/microsoft-365/syntex/esignature-troubleshoot.md @@ -4,7 +4,7 @@ ms.author: chucked author: chuckedmonson manager: jtremper ms.reviewer: amcdonnell -ms.date: 10/11/2024 +ms.date: 04/24/2025 audience: enabler ms.topic: troubleshooting-general ms.service: microsoft-syntex @@ -21,18 +21,18 @@ description: Learn how to troubleshoot issues with sending, receiving, or viewin ## Unable to create a request -If you aren't able to create a signature request, check the PDF viewer settings, the collaboration settings, or the access policies. Refer to the [setup page](/microsoft-365/syntex/esignature-setup) to ensure the correct settings are done. Also, check that the PDF you're attempting to sign isn't already electronically signed using SharePoint eSignature or any other electronic signature provider. +If you can't create a signature request, ensure you have edit rights to the folder containing the document and that the PDF is under 10 MB. If the document is stored in a private group, the signers must be members of the private group to receive the request. You can also check the PDF viewer settings, the collaboration settings, or the access policies. Refer to [Admin setup](esignature-setup.md) to ensure the correct settings are done. Also, check that the PDF you're attempting to sign isn't already electronically signed using SharePoint eSignature or any other electronic signature provider. > [!NOTE] -> New eSignature requests can't be started from documents that have been previously signed. You need to choose another document to create the request. +> New eSignature requests can't be started from documents that were previously signed. You need to choose another document to create the request. ### Default program for PDF viewing -The PDF viewer is opened by selecting a PDF file from a SharePoint library. The ability to use the **Get signatures** option won't be available if the PDF is viewed in any other way, for example, in Microsoft Edge or Adobe Reader. +The PDF viewer is opened by selecting a PDF file from a SharePoint library. The ability to use the **Get signatures** option isn't available if the PDF is viewed in any other way, for example, in Microsoft Edge or Adobe Reader. ### Collaboration settings -SharePoint eSignature is an extension of SharePoint document storage and management service. Existing access, sharing, and data loss prevention policies that are already applied at the tenant level, SharePoint site and library level, or folder and file level might affect whether a request can be started from a document in SharePoint and who it can be sent to. Some of the scenarios that might affect the signature request process are: +SharePoint eSignature is an extension of SharePoint document storage and management service. Existing access, sharing, and data loss prevention policies at the tenant, SharePoint site, library, folder, or file level might affect whether a request can be started from a document in SharePoint and who it can be sent to. Some of the scenarios that might affect the signature request process are: - If encryption is applied (for example, sensitivity labeling applied to the file), the ability to view the document wouldn't be available from SharePoint and therefore can't start a Signature request from there. Read more about [sensitivity labels](/purview/sensitivity-labels). @@ -48,9 +48,11 @@ Connect-SPOService -Url "https://yourtenant.sharepoint.com" Get-SPOSite -Limit All | Select-Object Url, SharingCapability ~~~ -### Conditional access policies +### Unable to send a request to an external recipient -Certain [conditional access](/entra/identity/conditional-access/overview) policies might determine whether an external recipient (signers outside of your organization or Microsoft 365 tenant) is able sign a document. When this happens, the external signers might not be able to access the document for signing. In some other cases, they might be able to access the document for signing but the signing operation is unsuccessful. One common way to resolve this is to contact your IT admin who will be able to add the SharePoint eSignature app to the list of approved apps via the Microsoft Entra admin center. +Your IT admin might not have configured Microsoft Entra B2B to allow new external guests. Review the [External recipients](esignature-setup.md#external-recipients) section in [Admin setup](esignature-setup.md) to determine if this meets your compliance and security requirements when enabling eSignature. + +Certain [conditional access](/entra/identity/conditional-access/overview) policies might determine whether an external recipient (signers outside of your organization or Microsoft 365 tenant) is able sign a document. When this happens, the external signers might not be able to access the document for signing. In some other cases, they might be able to access the document for signing but the signing operation is unsuccessful. One common way to resolve this is to contact your IT admin who can add the SharePoint eSignature app to the list of approved apps via the Microsoft Entra admin center. In some cases, the admin might need to add the SharePoint eSignature app (formally called Microsoft eSign service) to the **Excluded Apps** list in the **Conditional Access policy** > **Target resources** section so that the policy doesn't apply to the SharePoint eSignature app. The admin can verify the changes using the WhatIf tool with the policy. @@ -60,15 +62,15 @@ When you initiate a signature request from a document for another provider, such ## Unable to find the request emails -If you were sent an eSignature request and can't find it in your email inbox, you should check your spam or junk folder. It's also good practice to mark the sender as non-spam so that future emails from the same sender go directly into your inbox. +If you can't find an eSignature request in your email inbox, check your spam or junk folder. It's also good practice to mark the sender as safe so that future emails from the same sender go directly into your inbox. ## Unable to sign a document as an external recipient -When you receive a document for signing from someone outside of your organization, you might be able to access and read the document but the signing operation fails when you attempt to sign it. Other times, you might not be able to access and read the document. If you're experiencing any issues with signing a document sent from someone outside your organization, contact the sender who will be able to resolve the issue. +When you receive a document for signing from someone outside of your organization, you might be able to access and read the document but the signing operation fails when you attempt to sign it. Other times, you might not be able to access and read the document. If you're experiencing any issues with signing a document sent from someone outside your organization, contact the sender who can resolve the issue. ## Unable to access a signed document -Before a signature request is sent and at the completion of the request, certain checks are done to ensure that the sender has the permissions to write to the document and the originating folder because the final signed document is saved in this folder. If the sender loses access to this folder at any point before signing is complete, they might not be able to access the signed document permanently. In this scenario, the sender is provided temporary access of 30 days to the signed document through the completion email. To access the folder and document, the sender should ensure that they have read permission to the originating folder or request access from the owner. +Before sending a signature request and upon its completion, checks are performed to ensure the sender has permission to write to the document and the originating folder, as the final signed document will be saved in this folder. If the sender loses access to this folder at any point before signing is complete, they might not be able to access the signed document permanently. In this scenario, the sender is provided temporary access of 30 days to the signed document through the completion email. To access the folder and document, the sender should ensure that they have read permission to the originating folder or request access from the owner. Additionally, the eSignature service might not be able to save a copy of the signed document to the originating folder if the folder was accidentally deleted before the signature request was completed. diff --git a/microsoft-365/syntex/explanation-types-overview.md b/microsoft-365/syntex/explanation-types-overview.md index ebbc90920a7..0ee64908f64 100644 --- a/microsoft-365/syntex/explanation-types-overview.md +++ b/microsoft-365/syntex/explanation-types-overview.md @@ -4,7 +4,7 @@ ms.author: chucked author: chuckedmonson manager: jtremper ms.reviewer: ssquires -ms.date: 09/09/2024 +ms.date: 04/09/2025 audience: admin ms.topic: article ms.service: microsoft-syntex @@ -215,7 +215,7 @@ You can choose the following options for this setting: When training a classifier, there a few things to keep in mind that will produce more predictable results: - The more documents you train with, the more accurate the classifier will be. When possible, use more than five good documents and use more than one bad document. If the libraries you're working with have several different document types in it, several of each type lead to more predictable results. -- Labeling the document plays an important role in the training process. They're used together with explanations to train the model. You might see some anomalies when training a classifier with documents that don't have much content in them. The explanation might not match anything in the document but since it was labeled as a "good" document you may see it be a match during training. +- Labeling the document plays an important role in the training process. They're used together with explanations to train the model. You might see some anomalies when training a classifier with documents that don't have much content in them. The explanation might not match anything in the document but since it was labeled as a "good" document you might see it be a match during training. - When creating explanations, it uses OR logic in combination with the label to determine if it's a match. Regular expression that uses AND logic might be more predictable. Here's a sample regular expression to use on real documents as your training them. Note the text highlighted in red is the phrase or phrases you would be looking for.
    (?=.*network provider)(?=.*participating providers).*
    diff --git a/microsoft-365/syntex/image-tagging.md b/microsoft-365/syntex/image-tagging.md index e00612f9c54..26be20a9de0 100644 --- a/microsoft-365/syntex/image-tagging.md +++ b/microsoft-365/syntex/image-tagging.md @@ -65,7 +65,7 @@ Users with permissions to the image file can see and edit the tags in the file i If you turn tagging off, images will no longer be automatically tagged. Existing tags won't be removed. > [!NOTE] -> System generated tags may change with updates to the image or our tag technology. +> System generated tags might change with updates to the image or our tag technology. ## Configure image tagging diff --git a/microsoft-365/syntex/model-types-overview.md b/microsoft-365/syntex/model-types-overview.md index 0a6a94f2720..8b58c724ca9 100644 --- a/microsoft-365/syntex/model-types-overview.md +++ b/microsoft-365/syntex/model-types-overview.md @@ -4,7 +4,7 @@ ms.author: chucked author: chuckedmonson manager: jtremper ms.reviewer: ssquires -ms.date: 11/19/2024 +ms.date: 02/19/2025 audience: admin ms.topic: concept-article ms.custom: intro-overview diff --git a/microsoft-365/syntex/model-usage-analytics.md b/microsoft-365/syntex/model-usage-analytics.md index c2335145710..b959fdff206 100644 --- a/microsoft-365/syntex/model-usage-analytics.md +++ b/microsoft-365/syntex/model-usage-analytics.md @@ -50,7 +50,7 @@ Regarding model usage analytics, note that: The **Classification by model** pie chart displays which models have classified the most files. It shows each published model as a percentage of the total files processed by all published models on the content center. -Each model also shows the **Completeness Rate**, the percentage of uploaded files that were successfully analyzed by the model. A low completeness rate may mean that there are issues with either the model or the files that are being analyzed. +Each model also shows the **Completeness Rate**, the percentage of uploaded files that were successfully analyzed by the model. A low completeness rate might mean that there are issues with either the model or the files that are being analyzed. ## Classification by library diff --git a/microsoft-365/syntex/ocr.md b/microsoft-365/syntex/ocr.md index 4e90465c63e..ad2c5ce9c91 100644 --- a/microsoft-365/syntex/ocr.md +++ b/microsoft-365/syntex/ocr.md @@ -40,7 +40,7 @@ After an [Azure subscription is linked to Microsoft Syntex](syntex-azure-billing ### Set up data loss prevention policies using OCR -The compliance admin for your organization can also [configure the OCR settings for your tenant](../compliance/ocr-learn-about.md?#phase-3-configure-your-ocr-settings) for [data loss prevention policies](../compliance/dlp-learn-about-dlp.md) in the Microsoft Purview compliance portal. +The compliance admin for your organization can also [configure the OCR settings for your tenant](../compliance/ocr-learn-about.md?#phase-3-configure-your-ocr-settings) for [data loss prevention policies](../compliance/dlp-learn-about-dlp.md) in the Microsoft Purview portal. The compliance admin can specify which SharePoint sites to include for data loss prevention. If there are different sites specified for Syntex and data loss prevention, the maximum number of sites will be enabled for OCR. You won't be charged twice for processing. diff --git a/microsoft-365/syntex/promo-syntex.md b/microsoft-365/syntex/promo-syntex.md index 2fa6a55b46b..d5ef7c2158c 100644 --- a/microsoft-365/syntex/promo-syntex.md +++ b/microsoft-365/syntex/promo-syntex.md @@ -4,7 +4,7 @@ ms.author: chucked author: chuckedmonson manager: jtremper ms.reviewer: lauris; jaeccles -ms.date: 10/11/2024 +ms.date: 01/11/2025 audience: admin ms.topic: how-to ms.service: microsoft-syntex diff --git a/microsoft-365/syntex/push-content-type-to-hub.md b/microsoft-365/syntex/push-content-type-to-hub.md index c2054046b12..d2032273759 100644 --- a/microsoft-365/syntex/push-content-type-to-hub.md +++ b/microsoft-365/syntex/push-content-type-to-hub.md @@ -3,7 +3,7 @@ title: Push content types to a hub ms.author: chucked author: chuckedmonson ms.reviewer: ssquires -ms.date: 10/14/2024 +ms.date: 04/14/2025 manager: jtremper audience: admin ms.topic: how-to diff --git a/microsoft-365/syntex/skos-format-reference.md b/microsoft-365/syntex/skos-format-reference.md index a1ccfdd2920..98d95f8649d 100644 --- a/microsoft-365/syntex/skos-format-reference.md +++ b/microsoft-365/syntex/skos-format-reference.md @@ -4,7 +4,7 @@ ms.author: chucked author: chuckedmonson manager: jtremper ms.reviewer: ssquires -ms.date: 10/14/2024 +ms.date: 03/14/2025 audience: admin ms.topic: reference ms.service: microsoft-syntex @@ -131,7 +131,7 @@ Use this property to map a [Term](/dotnet/api/microsoft.sharepoint.client.taxono ## Required labels -Your organization may want to do careful planning before you start to use managed metadata. The amount of planning that you must do depends on how formal your taxonomy is. It also depends on how much control that you want to impose on metadata. At each level of the hierarchy, you need to configure required labels for a Term or TermSet. +Your organization might want to do careful planning before you start to use managed metadata. The amount of planning that you must do depends on how formal your taxonomy is. It also depends on how much control that you want to impose on metadata. At each level of the hierarchy, you need to configure required labels for a Term or TermSet. A Term can have one or more labels in the default language, and zero or more labels in the nondefault language. If the term has labels in a language, one of the labels must be the default label. diff --git a/microsoft-365/syntex/solutions/agreements-analyze-sections.md b/microsoft-365/syntex/solutions/agreements-analyze-sections.md index 6ed29e35c85..c79f1d469a2 100644 --- a/microsoft-365/syntex/solutions/agreements-analyze-sections.md +++ b/microsoft-365/syntex/solutions/agreements-analyze-sections.md @@ -4,7 +4,7 @@ ms.author: chucked author: chuckedmonson manager: jtremper ms.reviewer: ssathyamoort, neilh, shrganguly -ms.date: 10/22/2024 +ms.date: 03/22/2025 audience: admin ms.topic: how-to ms.service: microsoft-syntex diff --git a/microsoft-365/syntex/solutions/agreements-attachments.md b/microsoft-365/syntex/solutions/agreements-attachments.md index 8edf80efef1..c6e19597123 100644 --- a/microsoft-365/syntex/solutions/agreements-attachments.md +++ b/microsoft-365/syntex/solutions/agreements-attachments.md @@ -32,9 +32,9 @@ To add an attachment, follow these steps: 2. From the **Agreements** tab, select the agreement to which you wish to add an attachment. -3. With the agreement viewer panel now open, select **Attachments** in the upper right of the panel. +3. With the agreement viewer panel now open, select **Attachments** from the **Details** dropdown. -4. From the **Attachments** panel, select **Add attachment** to open the file picker. +4. From the **Attachments** panel, select **Add attachments** to open the file picker. 5. Browse to the location of the attachment, and then choose one or more files to attach to the agreement. @@ -46,6 +46,7 @@ To add an attachment, follow these steps: > The supported file types for attachments are Adobe .pdf, Microsoft Office files including Word, Excel and PowerPoint, and email files in Outlook or Gmail format. Attempting to add unsupported files results in an error.

    > When you add a file to an attachment, only one instance of the same file can be attached. Duplicates generate a warning.

    > Attachments added to an agreement have the same access permissions as the agreement to which they're attached. +> Attachments can be added to an agreement in any state, before or after they have been signed. ## View or open an attachment @@ -59,6 +60,7 @@ To view the attached files from with in the Agreements teams app, follow these s ![A screenshot of the agreement viewer page.](../../media/content-understanding/agreements-attachments.png) + 4. From the **Attachments** panel, select the attachment you want to view and it loads in the viewer. 5. With the attachment file visible in the viewer you can return to the original agreement using the breadcrumb in the upper left, the **Return to agreement** button in the lower left, or you can clear the attachment from the attachments list. diff --git a/microsoft-365/syntex/solutions/agreements-create-agreement.md b/microsoft-365/syntex/solutions/agreements-create-agreement.md index 42fe4d11d24..9da7ce3d734 100644 --- a/microsoft-365/syntex/solutions/agreements-create-agreement.md +++ b/microsoft-365/syntex/solutions/agreements-create-agreement.md @@ -4,7 +4,7 @@ ms.author: chucked author: chuckedmonson manager: jtremper ms.reviewer: ssathyamoort -ms.date: 12/19/2024 +ms.date: 03/19/2025 audience: admin ms.topic: how-to ms.service: microsoft-syntex diff --git a/microsoft-365/syntex/solutions/agreements-create-template.md b/microsoft-365/syntex/solutions/agreements-create-template.md index aaabb8cbb8b..7353efa6f73 100644 --- a/microsoft-365/syntex/solutions/agreements-create-template.md +++ b/microsoft-365/syntex/solutions/agreements-create-template.md @@ -82,8 +82,8 @@ There are a few standard fields that come with SharePoint Agreements AI. These f - **First party** – The first party on the agreement. - **Second party** – The second party on the agreement. -- **Effective date** –The date on which the agreement comes into effect. -- **Expiration date** – The date on which the agreement expires. +- **Effective date** – The date on which the agreement comes into effect. +- **Expiration date** – The date on which the [agreement expires](agreements-expirations.md). - **Expiration type** – This type can either be single date, where the agreement expires on a specific date, or evergreen, where the agreement never expires. To add fields to a template, follow these steps: diff --git a/microsoft-365/syntex/solutions/agreements-expirations.md b/microsoft-365/syntex/solutions/agreements-expirations.md new file mode 100644 index 00000000000..45ea71b742d --- /dev/null +++ b/microsoft-365/syntex/solutions/agreements-expirations.md @@ -0,0 +1,81 @@ +--- +title: Manage expirations of agreements in SharePoint Agreements +ms.author: chucked +author: chuckedmonson +manager: jtremper +ms.reviewer: vbarla +ms.date: 04/10/2025 +audience: admin +ms.topic: conceptual +ms.service: microsoft-syntex +ms.subservice: syntex-content-intelligence +search.appverid: +ms.collection: + - enabler-strategic + - m365initiative-syntex +ms.localizationpriority: medium +ROBOTS: NOINDEX, NOFOLLOW +description: Learn about the expiration process for agreements in the SharePoint Agreements solution. +--- + +# Manage expirations of agreements in SharePoint Agreements + +It's essential to monitor the expiration dates of agreements to ensure they're renewed on time and to prevent any lapses. The Agreements solution offers timely notifications to agreement owners, prompting them to take the necessary actions before the agreements expire. + +## Expiration date field + +The **Expiration date** is a standard field that records when an agreement is set to expire. Template creators should include this field in any template designed for agreements that have an expiration date. To add this field, template creators need to search for *expiration date* in the **Set up fields** panel and then add it to the template. + +![A screenshot of the Set up fields panel showing the expiration date has been added.](../../media/content-understanding/agreements-setup-field-expiration-date.png) + +The agreements generated using the template should have the **Expiration date** field filled in with the appropriate value by agreement creators. Only when this field value is filled, the reports, notifications, and status changes take effect on corresponding expiration dates. + +![A screenshot of the Generate documents panel showing the expiration date has been added.](../../media/content-understanding/agreements-generate-documents-expiration-date.png) + +To ensure that imported agreements follow the expiration flow, make sure that the **Expiration date** field is filled in the agreement's details screen when importing signed agreements. + +![A screenshot of an agreement showing an expiration date is added.](../../media/content-understanding/agreements-expiration-date-added.png) + +Once an agreement generated from the solution is signed and executed, or an imported agreement is successfully added after reviewing and confirming its details, the expiration date can no longer be added or updated. + +If the **Expiration date** isn't included in the agreement, it's treated as an evergreen agreement. + +## Expiration notifications + +When the **Expiration date** field is filled in the agreement, the following actions occur: + +**Two months before the expiration date:** + +- A reminder notification is sent to the [default recipients](#default-recipients-of-notifications), indicating the specific date the agreement will expire. + +- This notification is sent weekly for the two months leading up to the expiration date. + +**On the expiration date:** + +- A notification is sent to the [default recipients](#default-recipients-of-notifications), informing them that the agreement has expired. + +- The status of the agreement is updated to **Expired**. + + ![A screenshot of a notification sent to inform recipients than an agreement is expired.](../../media/content-understanding/agreements-expired-agreement-notification.png) + +### Default recipients of notifications + +For agreements generated using the solution, the recipient is the agreement author or creator. For imported agreements, the recipient is the uploader of the agreement. + +#### Considerations for managing notifications + +- To ensure the expiration notification is sent to a specific person or group other than the default recipient, include the **Owner** field in the template and designate the appropriate recipients during the agreement authoring stage. + +- For the agreements in **Draft** status, the expiration notifications and status change aren't triggered. + +- If an agreement's Word document is under the status of **Published**, **Reviewed**, or **Approved**, and is downloaded, signed, and converted into a PDF using a non-Microsoft electronic signature service, the following occurs: + + - The PDF is imported into the Agreements solution with the status **Active**, while the Word document remains in its original status. + + - As a result, two different expiration notifications are sent: one for the Word document and one for the PDF. + + +
    + +> [!div class="nextstepaction"] +> [See the complete list of help documentation.](agreements-overview.md#help-documentation) diff --git a/microsoft-365/syntex/solutions/agreements-faq.md b/microsoft-365/syntex/solutions/agreements-faq.md index 8db6dc7da86..4df04eb5daa 100644 --- a/microsoft-365/syntex/solutions/agreements-faq.md +++ b/microsoft-365/syntex/solutions/agreements-faq.md @@ -4,7 +4,7 @@ ms.author: chucked author: chuckedmonson manager: jtremper ms.reviewer: ssathyamoort, neilh, shrganguly, rammenon -ms.date: 10/30/2024 +ms.date: 03/30/2025 audience: admin ms.topic: faq ms.service: microsoft-syntex diff --git a/microsoft-365/syntex/solutions/agreements-import-agreement.md b/microsoft-365/syntex/solutions/agreements-import-agreement.md index c1542ae00f6..9296abce12f 100644 --- a/microsoft-365/syntex/solutions/agreements-import-agreement.md +++ b/microsoft-365/syntex/solutions/agreements-import-agreement.md @@ -59,7 +59,7 @@ To import agreements, follow these steps: 8. For files that are ready to confirm, you can either preview the file by clicking on the file, or select the file and confirm the values with the Confirm button on the action bar. You can confirm multiple files in the ready to confirm status at once. -9. For files that are in *Action needed* status, select the file to preview the file and provide values for mandatory fields. Once all mandatory fields are set, you can confirm the file. +9. For files that are in **Action needed** status, select the file to preview the file and provide values for mandatory fields. Once all mandatory fields are set, you can confirm the file. > [!NOTE] > The values in the fields can't be changed later. diff --git a/microsoft-365/syntex/solutions/agreements-key-concepts.md b/microsoft-365/syntex/solutions/agreements-key-concepts.md index 2d13b11398b..dc900eb6dc7 100644 --- a/microsoft-365/syntex/solutions/agreements-key-concepts.md +++ b/microsoft-365/syntex/solutions/agreements-key-concepts.md @@ -4,7 +4,7 @@ ms.author: chucked author: chuckedmonson manager: jtremper ms.reviewer: rammenon -ms.date: 10/22/2024 +ms.date: 03/22/2025 audience: admin ms.topic: concept-article ms.service: microsoft-syntex diff --git a/microsoft-365/syntex/solutions/agreements-license-requirements.md b/microsoft-365/syntex/solutions/agreements-license-requirements.md index 1c1743e9a36..8f968f531a9 100644 --- a/microsoft-365/syntex/solutions/agreements-license-requirements.md +++ b/microsoft-365/syntex/solutions/agreements-license-requirements.md @@ -4,7 +4,7 @@ ms.author: chucked author: chuckedmonson manager: jtremper ms.reviewer: ssathyamoort, neilh -ms.date: 10/22/2024 +ms.date: 03/22/2025 audience: admin ms.topic: article ms.service: microsoft-syntex diff --git a/microsoft-365/syntex/solutions/agreements-manage-sections.md b/microsoft-365/syntex/solutions/agreements-manage-sections.md index 8f874393590..9fbd287250a 100644 --- a/microsoft-365/syntex/solutions/agreements-manage-sections.md +++ b/microsoft-365/syntex/solutions/agreements-manage-sections.md @@ -4,7 +4,7 @@ ms.author: chucked author: chuckedmonson manager: jtremper ms.reviewer: ssathyamoort -ms.date: 10/22/2024 +ms.date: 03/22/2025 audience: admin ms.topic: how-to ms.service: microsoft-syntex diff --git a/microsoft-365/syntex/solutions/agreements-notifications.md b/microsoft-365/syntex/solutions/agreements-notifications.md index 75b8b1a062e..2167d6c371a 100644 --- a/microsoft-365/syntex/solutions/agreements-notifications.md +++ b/microsoft-365/syntex/solutions/agreements-notifications.md @@ -4,7 +4,7 @@ ms.author: chucked author: chuckedmonson manager: jtremper ms.reviewer: ssathyamoort -ms.date: 10/22/2024 +ms.date: 03/22/2025 audience: admin ms.topic: article ms.service: microsoft-syntex diff --git a/microsoft-365/syntex/solutions/agreements-overview.md b/microsoft-365/syntex/solutions/agreements-overview.md index a323a9e0811..3352177ec37 100644 --- a/microsoft-365/syntex/solutions/agreements-overview.md +++ b/microsoft-365/syntex/solutions/agreements-overview.md @@ -4,7 +4,7 @@ ms.author: chucked author: chuckedmonson manager: jtremper ms.reviewer: ssathyamoort -ms.date: 03/12/2025 +ms.date: 04/02/2025 audience: admin ms.topic: article ms.service: microsoft-syntex @@ -54,6 +54,7 @@ With SharePoint Agreements, you can: |[Get users ready](agreements-user-prereqs.md) |Get users ready to use all of the solution features. | |[Organize and import your existing agreements](agreements-import-agreement.md) |Add existing agreements by uploading signed documents. | |[Create a template](agreements-create-template.md) |Create and publish templates, set up fields and sections, configure workflows, and more. | +|[Manage expirations](agreements-expirations.md) |Manage and plan for the expiration dates in agreements. | |[Update a template](agreements-update-template.md) |Find and edit existing templates, and publish updates to a template. | |[Manage sections in a template](agreements-manage-sections.md) |Publish a new section, insert a section into a template, edit a section, and configure section settings. | |[Create an agreement](agreements-create-agreement.md) |Create an agreement from a template in Microsoft Teams and in Microsoft Word. | diff --git a/microsoft-365/syntex/solutions/agreements-reports.md b/microsoft-365/syntex/solutions/agreements-reports.md index 1daba40db10..0b6017e5f22 100644 --- a/microsoft-365/syntex/solutions/agreements-reports.md +++ b/microsoft-365/syntex/solutions/agreements-reports.md @@ -4,7 +4,7 @@ ms.author: chucked author: chuckedmonson manager: jtremper ms.reviewer: ssathyamoort -ms.date: 10/22/2024 +ms.date: 03/22/2025 audience: admin ms.topic: article ms.service: microsoft-syntex diff --git a/microsoft-365/syntex/solutions/agreements-setup.md b/microsoft-365/syntex/solutions/agreements-setup.md index b85b78e7b6d..445f77eecb5 100644 --- a/microsoft-365/syntex/solutions/agreements-setup.md +++ b/microsoft-365/syntex/solutions/agreements-setup.md @@ -4,7 +4,7 @@ ms.author: chucked author: chuckedmonson manager: jtremper ms.reviewer: ssathyamoort, rk-menon -ms.date: 10/22/2024 +ms.date: 03/22/2025 audience: admin ms.topic: install-set-up-deploy ms.service: microsoft-syntex diff --git a/microsoft-365/syntex/solutions/agreements-update-template.md b/microsoft-365/syntex/solutions/agreements-update-template.md index bbfe79afebf..01d6d2dda54 100644 --- a/microsoft-365/syntex/solutions/agreements-update-template.md +++ b/microsoft-365/syntex/solutions/agreements-update-template.md @@ -4,7 +4,7 @@ ms.author: chucked author: chuckedmonson manager: jtremper ms.reviewer: ssathyamoort -ms.date: 10/22/2024 +ms.date: 03/22/2025 audience: admin ms.topic: how-to ms.service: microsoft-syntex diff --git a/microsoft-365/syntex/solutions/agreements-user-prereqs.md b/microsoft-365/syntex/solutions/agreements-user-prereqs.md index d432dedf27c..aef4fd492b9 100644 --- a/microsoft-365/syntex/solutions/agreements-user-prereqs.md +++ b/microsoft-365/syntex/solutions/agreements-user-prereqs.md @@ -4,7 +4,7 @@ ms.author: chucked author: chuckedmonson manager: jtremper ms.reviewer: ssathyamoort, neilh -ms.date: 10/22/2024 +ms.date: 03/22/2025 audience: admin ms.topic: article ms.service: microsoft-syntex diff --git a/microsoft-365/syntex/syntex-pay-as-you-go-services.md b/microsoft-365/syntex/syntex-pay-as-you-go-services.md index d1e3a5e1c56..72ff296e159 100644 --- a/microsoft-365/syntex/syntex-pay-as-you-go-services.md +++ b/microsoft-365/syntex/syntex-pay-as-you-go-services.md @@ -47,7 +47,7 @@ The following tables describe each meter, its pricing, and how it measures usage |Service|What's counted?|What's billed? (USD)| |:----|:--------------|:-------------| -|**[Microsoft 365 Archive](/microsoft-365/archive/archive-overview)** |The number of gigabytes (GB) of data archived. (This meter is only charged when archived storage plus active storage in SharePoint exceeds a tenant’s included or licensed allocated SharePoint storage capacity limit.)
    Reactivation of archived data after seven days.

    **NOTE**: Education organizations are billed at $0.02/GB/month for the data archived. This meter is only charged when archived storage in SharePoint plus active pooled storage usage exceeds a tenant’s pooled storage capacity limit. For more information, see [Education offering](../archive/archive-education-offering.md). |$0.05/GB/month (shows on invoice as $0.00167/GB/day)

    $0.60/GB| +|**[Microsoft 365 Archive](/microsoft-365/archive/archive-overview)** |The number of gigabytes (GB) of data archived. (This meter is only charged when archived storage plus active storage in SharePoint exceeds a tenant’s included or licensed allocated SharePoint storage capacity limit.)
    **For OneDrive only**, the number of GBs of archived data reactivated.

    **NOTE**: Education organizations are billed at $0.02/GB/month for the data archived. This meter is only charged when archived storage in SharePoint plus active pooled storage usage exceeds a tenant’s pooled storage capacity limit. For more information, see [Education offering](../archive/archive-education-offering.md). |$0.05/GB/month (shows on invoice as $0.00167/GB/day)

    $0.60/GB| |**[Microsoft 365 Backup](/microsoft-365/backup/backup-overview)** |The number of gigabytes (GB) of data backed up. |$0.15/GB/month (shows on invoice as $0.005/GB/day)| ## Video services diff --git a/microsoft-365/syntex/term-store-analytics.md b/microsoft-365/syntex/term-store-analytics.md index b8d1cbb40c7..62f974dd0a3 100644 --- a/microsoft-365/syntex/term-store-analytics.md +++ b/microsoft-365/syntex/term-store-analytics.md @@ -4,7 +4,7 @@ ms.author: chucked author: chuckedmonson manager: jtremper ms.reviewer: ssquires -ms.date: 10/15/2024 +ms.date: 03/15/2025 audience: admin ms.topic: article ms.service: microsoft-syntex diff --git a/microsoft-365/syntex/use-content-center-site.md b/microsoft-365/syntex/use-content-center-site.md index baced8f60e7..176bac56419 100644 --- a/microsoft-365/syntex/use-content-center-site.md +++ b/microsoft-365/syntex/use-content-center-site.md @@ -5,7 +5,7 @@ author: chuckedmonson manager: jtremper audience: admin ms.reviewer: ssquires -ms.date: 09/16/2024 +ms.date: 02/16/2025 ms.topic: how-to ms.service: microsoft-syntex search.appverid: diff --git a/microsoft-365/topics/changes-coming-to-topics.md b/microsoft-365/topics/changes-coming-to-topics.md index c837dd0fcb5..83c086899dc 100644 --- a/microsoft-365/topics/changes-coming-to-topics.md +++ b/microsoft-365/topics/changes-coming-to-topics.md @@ -1,5 +1,5 @@ --- -ms.date: 02/20/2024 +ms.date: 04/18/2025 title: Changes coming to Topics ms.author: daisyfeller author: daisyfell @@ -19,9 +19,9 @@ description: Learn about changes coming to Topics. # Changes coming to Topics -## Viva Topics to be retired on February 22, 2025 +## Viva Topics has been retired as of February 22, 2025 -Viva Topics will be retired on February 22, 2025 and Microsoft won't invest in new feature development for Viva Topics going forward from February 22, 2024. +Viva Topics has been retired as of February 22, 2025. With the generational shift in AI technology underway, we're now focusing our strategy and efforts on building new AI-powered knowledge management experiences in [Microsoft Copilot](https://www.microsoft.com/microsoft-365/enterprise/copilot-for-microsoft-365) and other parts of Microsoft 365. To help customers plan, please see [new guidance on the Managing Knowledge page](https://aka.ms/M365KnowledgeManagement) on the Microsoft 365 Adoption Center. diff --git a/microsoft-365/topics/topics-changes-faq.md b/microsoft-365/topics/topics-changes-faq.md index 59fa25b03f1..c1b7823090b 100644 --- a/microsoft-365/topics/topics-changes-faq.md +++ b/microsoft-365/topics/topics-changes-faq.md @@ -1,5 +1,5 @@ --- -ms.date: 02/20/2024 +ms.date: 04/18/2025 title: Frequently asked questions about changes coming to Topics ms.author: daisyfeller author: daisyfell diff --git a/microsoft-365/whiteboard/gdpr-requests.md b/microsoft-365/whiteboard/gdpr-requests.md index 10840666249..10a63df25df 100644 --- a/microsoft-365/whiteboard/gdpr-requests.md +++ b/microsoft-365/whiteboard/gdpr-requests.md @@ -10,7 +10,9 @@ ms.topic: how-to ms.custom: ms.service: whiteboard search.appverid: MET150 -ms.collection: essentials-privacy +ms.collection: +- essentials-privacy +- essentials-compliance ms.localizationpriority: medium description: Learn how to export, transfer, or delete personal information from Microsoft Whiteboard. --- diff --git a/microsoft-365/whiteboard/manage-sharing-organizations.md b/microsoft-365/whiteboard/manage-sharing-organizations.md index b23a9d05168..7e2347f7f0b 100644 --- a/microsoft-365/whiteboard/manage-sharing-organizations.md +++ b/microsoft-365/whiteboard/manage-sharing-organizations.md @@ -23,7 +23,7 @@ The sharing experience differs based on whether you're in a Teams meeting, if yo When you share a whiteboard in a Teams meeting, Whiteboard creates a sharing link. This link is accessible by anyone within the organization. The whiteboard is also shared with any in-tenant users in the meeting. Whiteboards are shared using company-shareable links, regardless of the default setting. Support for the default sharing link type is planned. -During a Teams meeting, external and shared device accounts (typically used in Surface Hubs and Teams Rooms devices) have more capability for temporary +During a Teams meeting, external and shared device accounts (typically used in Surface Hubs and Teams Rooms devices) have more capabilities for temporary collaboration. Users can temporarily view and collaborate on whiteboards that are shared in a meeting, in a similar way to PowerPoint Live sharing. In this case, Whiteboard provides temporary viewing and collaboration on the whiteboard during the Teams meeting only. A share link isn't created and Whiteboard doesn't grant access to the file. @@ -44,41 +44,41 @@ To enable this behavior, follow these steps: Set-SPOTenant -AllowAnonymousMeetingParticipantsToAccessWhiteboards On ``` -4. Ensure that the Teams meeting setting **Anonymous users can interact with apps in meetings** is enabled. If you've disabled it, any anonymous users (as opposed to guests or federated users) won't have access to the whiteboard during the meeting. +4. Ensure that the Teams meeting setting **Anonymous users can interact with apps in meetings** is enabled. If the setting is disabled, any anonymous users (as opposed to guests or federated users) don't have access to the whiteboard during the meeting. This setting applies only to whiteboards and replaces the previously shared settings: **OneDriveLoopSharingCapability** and **CoreLoopSharingCapability**. Those settings are no longer applicable and can be disregarded. > [!NOTE] -> By default, the Teams meeting setting **Anonymous users can interact with apps in meetings** is enabled. If you have disabled it, any anonymous user (as opposed to guests or federated users) won't have access to the whiteboard during the meeting. +> By default, the Teams meeting setting **Anonymous users can interact with apps in meetings** is enabled. If the setting is disabled, any anonymous user (as opposed to guests or federated users) doesn't have access to the whiteboard during the meeting. > [!NOTE] > If you would like shared device accounts to have access to Whiteboard in Teams meetings but not anonymous users, you can disable **Anonymous users can interact with apps in meetings** while having **AllowAnonymousMeetingParticipantsToAccessWhiteboards** enabled. > [!NOTE] -> Even when **AllowAnonymousMeetingParticipantsToAccessWhiteboards** is enabled, Teams channel meetings have a limitation that anonymous users *cannot* see the whiteboard share. +> Even when **AllowAnonymousMeetingParticipantsToAccessWhiteboards** is enabled, Teams channel meetings have a limitation that anonymous users *can't* see the whiteboard share. These changes should take approximately 60 minutes to apply across your tenancy. |Scenario|Storage and ownership|Sharing settings|Sharing experience| |---|---|---|---| -|Start the whiteboard from a desktop or mobile device|Storage: OneDrive for Business

    Owner: User who creates the whiteboard|Enabled|In-tenant users: Can create, view, and collaborate

    External users: Can view and collaborate during the meeting only (the button to share a whiteboard won't appear for external users)

    Shared device accounts: Can view and collaborate during the meeting only| +|Start the whiteboard from a desktop or mobile device|Storage: OneDrive for Business

    Owner: User who creates the whiteboard|Enabled|In-tenant users: Can create, view, and collaborate

    External users: Can view and collaborate during the meeting only (the button to share a whiteboard doesn't appear for external users)

    Shared device accounts: Can view and collaborate during the meeting only| |Start the whiteboard from a desktop or mobile device|Storage: OneDrive for Business

    Owner: User who creates the whiteboard|Disabled|In-tenant users: Can initiate, view, and collaborate

    External users: Can't view or collaborate

    Shared device accounts: Can't view or collaborate| -|Start the whiteboard from a Surface Hub or Microsoft Teams Rooms|Storage: Azure (Whiteboard files will be moved to OneDrive for Business in the future)

    Owner: Meeting participant|Not applicable|In-tenant users: Can initiate, view, and collaborate

    External users: Can view and collaborate during the meeting only

    Shared device accounts: Can initiate, view, and collaborate during the meeting only| +|Start the whiteboard from a Microsoft Teams Rooms device|Storage: Temporary local storage. A local whiteboard will be removed if it isn't saved

    Owner: None (unless a non-MTR in-tenant user joins the meeting, which saves the whiteboard to their OneDrive for Business)
    [Learn more](/microsoftteams/rooms/whiteboard-rooms)|Not applicable|In-tenant users: Can initiate, view, and collaborate

    External users: Can view and collaborate during the meeting only

    Shared device accounts: Can initiate, view, and collaborate. A participant not joining through a Teams Rooms device must join for the Whiteboard to become collaborative. Whiteboard collaboration between only two Teams Rooms isn't supported.| > [!NOTE] -> If a Whiteboard is stored in OneDrive and already attached to a meeting, it cannot be initiated on a Surface Hub or Microsoft Teams Rooms device. An authenticated user on another device will need to do so. We plan to enable this functionality in a future release. +> If a Whiteboard is stored in OneDrive and already attached to a meeting, it can't be initiated on a Surface Hub or Microsoft Teams Rooms device. An authenticated user on another device must do so. We plan to enable this functionality in a future release. ## Share in Teams calls During a one-on-one or group call, you might start sharing a Whiteboard. Similar limitations apply to who can share a Whiteboard regarding scenarios where users from different organizations are involved in a call. -When all members of the call are from the same organization, any person can start and access the Whiteboard. For calls involving users from different organizations, only some users can access the Whiteboard sharing button. During a one-on-one call, only the original user who created a conversation or call (the first person to send a message or call another user, whichever occurs first) between the two users can access the Whiteboard sharing button from the drop-down share tray button. +When all members of the call are from the same organization, any person can start and access the Whiteboard. For calls involving users from different organizations, only some users can access the Whiteboard sharing button. During a one-on-one call, only the original user who created the conversation or call between the two users can access the Whiteboard sharing button from the drop-down share tray button. The _original user_ is the first person to send a message or call another user, whichever occurs first. -This cannot be changed after two users have started a conversation. Deleting the chat involving the two users will not restart the chat, therefore, this will not reset who created or started the chat. Having the other user call will also not change who can share the Whiteboard, even if a Whiteboard has not been shared yet. The purpose of this limitation is to prevent out-of-organization user access to a Whiteboard unless sharing starts from an in-organization user. +Permission to share the Whiteboard can't be changed after two users start a conversation. Deleting the chat that involves the two users doesn't restart the chat and doesn't reset who created or started the chat. Having the other user call also doesn't change who can share the Whiteboard, even if a Whiteboard hasn't been shared yet. The purpose of this limitation is to prevent access to a Whiteboard by an out-of-organization user unless sharing starts from an in-organization user. ## Add as a tab in Teams channels and chats -When you add a whiteboard as a tab in a Teams channel or chat, Whiteboard will create a sharing link that's accessible by anyone in the organization. +When you add a whiteboard as a tab in a Teams channel or chat, Whiteboard creates a sharing link that's accessible by anyone in the organization. |Scenario|Storage and ownership|Sharing settings|Sharing experience| |---|---|---|---| @@ -91,8 +91,8 @@ When you share whiteboards from the web, desktop, or mobile clients, you can cho |Scenario|Storage and ownership|Sharing settings|Sharing experience| |---|---|---|---| |Create the whiteboard from a desktop or mobile device|Storage: OneDrive for Business

    Owner: User who creates the whiteboard|Not applicable (only applies to meetings)|In-tenant users: Can share within their organization

    External users: Sharing with external users isn't supported at this time| -|Create the whiteboard from a Surface Hub|Storage: Local

    Owner: None (Unless user sign ins to save and share the board, which saves to OneDrive for Business. Easy share will be added back in the future.|Not applicable (only applies to meetings)|In-tenant users: User must sign in to save and share the board (Easy share will be added in the future)

    External users: Sharing with external users isn't supported at this time outside of a Teams meeting| -|Create the whiteboard from Microsoft Teams Rooms|Not yet supported|Not applicable (only applies to meetings)|Not yet supported| +|Create the whiteboard from a Surface Hub running [Windows 10 Team edition](/surface-hub/surface-hub-3-faq)|Storage: Local

    Owner: None (Unless user sign ins to save and share the board, which saves to OneDrive for Business)|Not applicable (only applies to meetings)|In-tenant users: User must sign in to save and share the board

    External users: Sharing with external users isn't supported at this time outside of a Teams meeting| +|Create the whiteboard from Microsoft Teams Rooms|Storage: Temporary local storage. A local whiteboard will be removed if it isn't saved

    Owner: None (unless the Whiteboard is escalated to start a meeting or Save and a non-MTR in-tenant user joins the meeting, at which point the whiteboard is saved to their OneDrive for Business)|Not applicable (only applies to meetings)|In-tenant users: Can initiate and view, as well as collaborate if the Whiteboard is escalated to start a meeting or Save

    External users: Can view and collaborate during the meeting only if the Whiteboard is escalated to start a meeting or Save

    Shared device accounts: Can initiate and view, as well as collaborate (as long as the Whiteboard is escalated to start a meeting or Save, and a non-Teams Rooms participant has joined, thereby causing the Whiteboard to be saved to the OneDrive for Business and thereby become collaborative)| ## See also @@ -102,4 +102,4 @@ When you share whiteboards from the web, desktop, or mobile clients, you can cho [Network requirements for Microsoft Defender of Cloud Apps](/defender-cloud-apps/network-requirements) -[Deploy Whiteboard on Windows](deploy-on-windows-organizations.md) +[Deploy Whiteboard on Windows](deploy-on-windows-organizations.md) \ No newline at end of file diff --git a/microsoft-365/whiteboard/manage-whiteboard-access-organizations.md b/microsoft-365/whiteboard/manage-whiteboard-access-organizations.md index e343033b006..f9f04dba842 100644 --- a/microsoft-365/whiteboard/manage-whiteboard-access-organizations.md +++ b/microsoft-365/whiteboard/manage-whiteboard-access-organizations.md @@ -10,7 +10,9 @@ ms.topic: how-to ms.custom: ms.service: whiteboard search.appverid: MET150 -ms.collection: essentials-manage +ms.collection: +- essentials-manage +- essentials-security ms.localizationpriority: medium description: Learn how to set up Microsoft Whiteboard for your organization in the Microsoft 365 admin center. ---