SHD / MC Checker

[serviceDegradation] DZ1314603 | Microsoft Defender XDR | Some users may be unable to use unused OAuth app policies in App Governance



DZ1314603 | Microsoft Defender XDR | Some users may be unable to use unused OAuth app policies in App Governance

Status serviceDegradation
Classification advisory
User Impact Users may be unable to use unused OAuth app policies in App Governance.
Last Updated 08/14/2026 11:35:26
Start Time 05/18/2026 10:54:07
End Time
Latest Message Title: Some users may be unable to use unused OAuth app policies in App Governance

User impact: Users may be unable to use unused OAuth app policies in App Governance.

More info: Affected users may notice policy evaluation has been temporarily suspended, meaning alerts won’t be generated and governance actions won’t be executed. Existing policy configurations remain unchanged and will resume once normal operation is restored.

Current status: We’re progressing with our efforts to validate the effectiveness of the deployed fix. We’ve observed some applications affected by the original issue haven’t generated new activity since the remediation was implemented, and we’re assessing what additional mitigation steps may be required to fully address impact.

Scope of impact: Your organization is affected by this event, and any users with unused OAuth app policies configured in App Governance may be impacted. This section may be updated as the investigation progresses.

Root cause: A pre-existing code issue within the service, related to how “last used” data is calculated, was triggered under specific conditions, which is resulting in data inconsistencies.

Next update by: Wednesday, August 26, 2026, at 1:00 PM UTC