Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderM365 ReportPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderM365 ReportPortfolio

Connect

© 2026 M365 Message Center. Created with ❤ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC1304287

Microsoft Exchange Online: Upcoming secure-by-default changes for Exchange APIs

Plan for Change

Message ID

MC1304287
View in Admin Center

Services

Exchange Online

Summary

Starting June 2026, Microsoft will update the default user consent policy for Microsoft Graph to require admin consent for additional Exchange-related permissions. Users cannot grant consent for these unless apps are approved in the Mail client policy. Existing consents and custom policies remain unaffected.

Details

Introduction

As part of the Microsoft Secure Future Initiative (SFI), and in alignment with the Secure by Default principle, we’re updating the Microsoft‑managed default user consent policy for Microsoft Graph. This change increases administrator control over third‑party application access to Exchange data and aligns default consent behavior with industry best practices for protecting email and related content.

When this will happen

General Availability (Worldwide): We will begin rolling out in early June 2026 and expect to complete by early July 2026.

How this affects your organization

Who is affected

  • Microsoft 365 tenants using the Microsoft‑managed default user consent policy
  • Admins managing Exchange Online and Microsoft Graph app access
  • Organizations that allow third‑party applications to access Exchange data via delegated permissions

What will happen

  • The following Microsoft Graph delegated permissions will be added to the Microsoft recommended user consent policy:
    • Contacts.ReadWrite
      • Contacts.Read.Shared
      • People.Read
      • Tasks.ReadWrite.Shared
        • Tasks.ReadWrite
          • Tasks.Read.Shared
            • Tasks.Read
              • Contacts.ReadWrite.Shared

              • These changes will be reflected as an update to the Microsoft‑managed default user consent policy.
              • With this change, any organization using the Microsoft‑managed user consent policy will require admin consent for these additional permissions to access Exchange mail data. Learn more about Graph permissions.
              • By default, admin consent will be required for third‑party apps requesting these permissions to access Exchange data.
              • Users will no longer be able to grant consent for these permissions unless the app is included in the Mail client policy.
              • The Mail client policy will continue to allow users to consent to approved, popular mail applications for the permissions included in the recommended user consent policy.
              • Existing approved apps and existing user consents are not impacted and will continue to work.
              • Tenants using custom user consent policies are not affected.
              • No additional licensing is required.

              What you can do to prepare

              • Review third‑party apps that access Exchange data using Microsoft Graph.
                • Review permissions granted to enterprise applications
              • Create granular app consent policies in advance for apps you want users to continue using without interruption.
                • Manage app consent policies
                • Configure how users consent to applications
              • Configure the admin consent workflow so users can request approval for apps that now require admin consent. 
                • Configure admin consent workflow
              • Notify helpdesk staff, security teams, and app owners about the upcoming change.
              • Update internal documentation to reflect the new default consent behavior.

              Learn more: 

              • Configure how users consent to applications | Enterprise applications | Microsoft Entra ID | Microsoft Entra | Microsoft Learn
              • Configure the admin consent workflow | Enterprise applications | Microsoft Entra ID | Microsoft Entra | Microsoft Learn
              • Manage app consent policies | Enterprise applications | Microsoft Entra ID | Microsoft Entra | Microsoft Learn
              • Microsoft Graph permissions reference | Microsoft Graph | Microsoft Learn
              • Microsoft Secure Future Initiative (SFI)
              • Review permissions granted to enterprise applications | Enterprise applications | Microsoft Entra ID | Microsoft Entra | Microsoft Learn

              Compliance considerations

              QuestionAnswer
              Does the change alter how existing customer data is processed, stored, or accessed?Yes. Access to Exchange data via delegated Microsoft Graph permissions will require admin approval for the additional permissions listed in this message when using the Microsoft‑managed default user consent policy. Existing approved access is not affected.
              Does the change include an admin control, and can it be managed through Entra ID?Yes. Admins can manage access using Microsoft Graph app consent policies and the admin consent workflow in Microsoft Entra ID.

              Timeline

              Published
              May 8, 2026
              Message published to Message Center
              Updated
              May 8, 2026
              Message content updated
              End Date
              Aug 1, 2026
              Message timeline ends

              Tags

              #New feature#User impact#Admin impact

              Category

              Plan for Change

              Related Messages

              Similar updates

              MC1303717

              Default compose font: Administrators can allow users to change the default font in Outlook for iOS and Android

              May 7, 2026
              MC1301802

              Change Optics report for Exchange Online begins public preview

              May 5, 2026
              MC1294524

              Microsoft Exchange Online: Dynamic distribution groups will populate membership faster on creation and modification

              Apr 28, 2026
              MC1272552

              Workweek view for Outlook on iOS and iPad

              Apr 6, 2026
              MC1269216

              Outlook for Android and iOS: Support for shareable links beautification and permissions in meeting description

              Apr 3, 2026