| DZ1314603 | Microsoft Defender XDR | Some users may be unable to use unused OAuth app policies in App Governance |
|---|
| Status | serviceDegradation |
|---|---|
| Classification | advisory |
| User Impact | Users may be unable to use unused OAuth app policies in App Governance. |
| Last Updated | 09/04/2026 12:45:14 |
| Start Time | 05/18/2026 10:54:07 |
| End Time | |
| Latest Message | Title: Some users may be unable to use unused OAuth app policies in App Governance
User impact: Users may be unable to use unused OAuth app policies in App Governance. More info: Affected users may notice policy evaluation has been temporarily suspended, meaning alerts won’t be generated and governance actions won’t be executed. Existing policy configurations remain unchanged and will resume once normal operation is restored. Current status: The previously identified issue with the application Last Used Date signal has been remediated, and affected data has been corrected where possible. As an additional precaution, automated App Governance policies that rely on Last Used Date for app disablement will continue to remain disabled for some more time while we complete enhancements designed to further improve the accuracy and consistency of this signal. During this period, impacted users can continue to review and disable unused applications manually using Last Used Date. We will provide further updates once these enhancements are complete and the related policies are ready to be safely re-enabled. Scope of impact: Your organization is affected by this event, and any users with unused OAuth app policies configured in App Governance may be impacted. This section may be updated as the investigation progresses. Root cause: A pre-existing code issue within the service, related to how “last used” data is calculated, was triggered under specific conditions, which is resulting in data inconsistencies. Next update by: Monday, October 5, 2026, at 1:00 PM UTC |