Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

© 2026 M365 Message Center. Created with ❤️ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC1036568

Updates to App Governance Pre-Defined Policies in Defender for Cloud Apps

Plan for Change

Message ID

MC1036568
View in Admin Center

Services

Microsoft Defender XDR

Summary

Microsoft Defender for Cloud Apps will disable three pre-defined policies by default to improve alert accuracy. The rollout starts mid-May 2025 (worldwide) and early June 2025 (GCC, GCC High). Users can re-enable these policies if desired. No immediate action is required. More details are available in the documentation.

Details

Updated May 29, 2025: We have updated the timeline below. Thank you for your patience.

Microsoft Defender for Cloud Apps is continuously working to ensure that our out-of-the-box (OOTB) threat protection capabilities within App Governance are as accurate and effective as possible.

As part of this effort, we will be disabling by default three specific pre-defined policies that have been found to mostly trigger on legitimate activities, rather than alerting on malicious ones. This change is aimed at improving the overall accuracy of our alerts by relying on more accurate sources that provide a comprehensive view of potential attacks, rather than focusing on isolated anomalous activities.

If you prefer to continue receiving these alerts, the option to re-enable them remains available.

When this will happen:

General Availability (Worldwide): We will begin rolling out mid-May (previously late April) and expect to complete by late May 2025.

General Availability (GCC, GCC High): We will begin rolling out early June 2025 (previously late May) and expect to complete by mid-June 2025 (previously late May).

How this will affect your organization:

These specific pre-defined policies within App Governance will be switched off for all customers by default. The policies being disabled are:

  • Increase in data usage by an overprivileged or highly privileged app
  • Unusual activity from an app with priority account consent
  • Access to sensitive data

This change will reduce the number of alerts triggered by legitimate activities, allowing you to focus on more accurate and relevant security notifications. The remaining policies and our advanced threat detection engines, which are always enabled and running behind the scenes, will continue to provide robust protection by correlating multiple pieces of evidence to identify potential attacks with higher confidence.

If you have made any changes to customize the existing pre-defined policy template, they will not be disabled as part of this change.

If for any reason you prefer to continue receiving these alerts, you can re-enable the policies via the policy management interface. Additionally, we provide tools for customers to create custom policies tailored to their specific needs. For more details, please refer to the relevant documentation.

For more details, please refer to the relevant documentation: Get started with app policies

What you need to do to prepare:

No immediate action is required. However, if you wish to re-enable any of the disabled policies, you can do so through the policy management interface. This will allow you to utilize the full functionality of the policies as you have been up to this point.

Timeline

📅
Published
Mar 19, 2025
Message published to Message Center
✏️
Updated
May 29, 2025
Message content updated
🏁
End Date
Jul 21, 2025
Message timeline ends

Tags

#Updated message#Feature update#Admin impact

Category

📋Plan for Change

Related Messages

Similar updates

MC1042926

Microsoft Defender for Office 365: Platform migration for enhanced data storage and performance

Mar 28, 2025
MC1023484

Microsoft Defender for Identity: New recommendations for Microsoft Secure Score

Mar 5, 2025
MC1057719

MDE Mobile: Open Wi-Fi and Certificate Detections will be logged as Events

Apr 18, 2025
MC1052160●

Microsoft Defender XDR services: Changes to the IdentityInfo table in Advanced Hunting

Apr 10, 2025
MC992217

Microsoft Defender: Changes to Defender for Cloud Apps alerts

Jan 30, 2025