| DZ1314603 | Microsoft Defender XDR | Some users may be unable to use unused OAuth app policies in App Governance |
|---|
| Status | serviceDegradation |
|---|---|
| Classification | advisory |
| User Impact | Users may be unable to use unused OAuth app policies in App Governance. |
| Last Updated | 08/26/2026 11:43:32 |
| Start Time | 05/18/2026 10:54:07 |
| End Time | |
| Latest Message | Title: Some users may be unable to use unused OAuth app policies in App Governance
User impact: Users may be unable to use unused OAuth app policies in App Governance. More info: Affected users may notice policy evaluation has been temporarily suspended, meaning alerts won’t be generated and governance actions won’t be executed. Existing policy configurations remain unchanged and will resume once normal operation is restored. Current status: We’re continuing to evaluate the conditions required to safely resume unused OAuth app policy evaluation. While the underlying issue causing inaccurate Last Used Date data has been addressed, we’re still assessing the timing and approach for re-enabling affected policies. Applications that generated activity after the remediation was deployed, should now display accurate Last Used Date information. For some previously affected applications where sufficient historical data wasn’t available to reliably reconstruct activity history, the Last Used Date may display as “Not Available” until new activity is detected. Scope of impact: Your organization is affected by this event, and any users with unused OAuth app policies configured in App Governance may be impacted. This section may be updated as the investigation progresses. Root cause: A pre-existing code issue within the service, related to how “last used” data is calculated, was triggered under specific conditions, which is resulting in data inconsistencies. Next update by: Friday, September 4, 2026, at 1:00 PM UTC |