SHD / MC Checker

[serviceDegradation] DZ1314603 | Microsoft Defender XDR | Some users may be unable to use unused OAuth app policies in App Governance



DZ1314603 | Microsoft Defender XDR | Some users may be unable to use unused OAuth app policies in App Governance

Status serviceDegradation
Classification advisory
User Impact Users may be unable to use unused OAuth app policies in App Governance.
Last Updated 07/10/2026 11:48:18
Start Time 05/18/2026 10:54:07
End Time
Latest Message Title: Some users may be unable to use unused OAuth app policies in App Governance

User impact: Users may be unable to use unused OAuth app policies in App Governance.

More info: Affected users may notice policy evaluation has been temporarily suspended, meaning alerts won’t be generated and governance actions won’t be executed. Existing policy configurations remain unchanged and will resume once normal operation is restored.

Current status: Our efforts to deploy the secondary fix are taking longer than expected as the fix only applies to new app activity occurring after that deployment date. Apps that were affected prior to the fix may require a separate backfill process which we’re working to verify the best possible remediation path.

Scope of impact: Your organization is affected by this event, and any users with unused OAuth app policies configured in App Governance may be impacted.

Estimated time to resolve: Friday, July 31, 2026

Root cause: A pre-existing code issue within the service, related to how “last used” data is calculated, was triggered under specific conditions, which is resulting in data inconsistencies.

Next update by: Friday, July 31, 2026, at 12:30 PM UTC