| MC1163922 | Upcoming Secure by Default Settings Changes for Exchange and Teams APIs |
|---|
| Classification | planForChange | ||||
|---|---|---|---|---|---|
| Last Updated | 10/02/2025 02:05:11 | ||||
| Start Time | 10/02/2025 02:02:35 | ||||
| End Time | 01/05/2026 08:00:00 | ||||
| Message Content |
As part of the Microsoft Secure Future Initiative (SFI) and in alignment with the “Secure by Default” principle, we are updating the Microsoft-managed default consent policy in Microsoft 365 Graph to align with Microsoft’s ongoing security improvements, help you to meet industry best practices, and harden your tenant’s security posture. These changes enable admins to better control third-party app access for Exchange and Teams content. This is the next step in a broader effort to evaluate and evolve Microsoft 365 defaults through the lens of SFI. This update follows our recent SharePoint and OneDrive changes that blocked legacy protocols and required admin consent for third-party apps accessing files and sites. The Exchange and Teams updates are a continuation of this same approach. admin consent for third-party apps accessing files and sites. The Exchange and Teams updates are a continuation of this same approach. [When this will happen:]
These changes will begin rolling out by end of October 2025 and are expected to be completed by late-November 2025. [How this affects your organization:]
The following settings will be updated:
To preserve end-user experience, some Exchange email clients are exempted from this change. Administrators can review and modify as noted below. These changes will be reflected as an update to the Microsoft-managed default consent policy. With this change, any organization using the Microsoft-managed user consent policy will require admin consent for Mail, Teams Chat and Meetings functionality across various protocols. Learn more about Graph permissions.
[What you can do to prepare:]
We recommend the following actions:
Additional considerations:
Does the change alter how existing customer data is processed and stored?
Does the change alter how existing customer data is accessed?
What is the impact on existing applications?
|