Updates from: 11/03/2022 02:19:56
Category Microsoft Docs article Related commit history on GitHub Change details
admin About Admin Roles https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/add-users/about-admin-roles.md
Because admins have access to sensitive data and files, we recommend that you fo
| Recommendation | Why is this important? | | :- | :- |
-| Have 2 to 4 global admins | Because only another global admin can reset a global admin's password, we recommend that you have at least 2 global admins in your organization in case of account lockout. But the global admin has almost unlimited access to your org's settings and most of the data, so we also recommend that you don't have more than 4 global admins because that's a security threat. |
+| Have 2 to 4 Global Admins | Global Admins have almost unlimited access to your organization's settings and most of its data. We recommend you limit the number of Global Admins as much as possible. A Global Admin may inadvertently lock their account and require a password reset. Either another Global Admin or a Privileged Authentication Admin can reset a Global Admin's password. Therefore, we recommend you have at least either one more Global Admin or a Privileged Authentication Admin in the event a Global Admin locks their account. |
| Assign the *least permissive* role | Assigning the *least permissive* role means giving admins only the access they need to get the job done. For example, if you want someone to reset employee passwords you shouldn't assign the unlimited global admin role, you should assign a limited admin role, like Password admin or Helpdesk admin. This will help keep your data secure. | | Require multi-factor authentication for admins | It's actually a good idea to require MFA for all of your users, but admins should definitely be required to use MFA to sign in. MFA makes users enter a second method of identification to verify they're who they say they are. Admins can have access to much of customer and employee data and if you require MFA, even if the admin's password gets compromised, the password is useless without the second form of identification. <br><br>When you turn on MFA, the next time the user signs in, they'll need to provide an alternate email address and phone number for account recovery. <br> [Set up multi-factor authentication](../security-and-compliance/set-up-multi-factor-authentication.md) |
admin Add Users https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/add-users/add-users.md
If you're seeing this page in the admin center, you're on the **admin simplified
4. Add the email address of the user in the **Up to 5 email addresses...** text box. This will make sure the new user gets the information they need to sign into Microsoft 365 services. 5. Select **Add user** and **Download sign-in info** if you want to save this info.
-## Add multiple users at the same time
+## Add multiple users at the same time in dashboard view
-You can use any of the following methods to add multiple users at the same time:
+1. Go to **Users** > **Active users**, and select **Add multiple users**.
+2. On the **Add list of user** page, choose whether to add user's one at a time or use a spreadsheet to add your new users.
+
+ :::image type="content" source="../../media/upload-csv-file.png" alt-text="Screenshot: Options to add users one at a time or use a CSV file.":::
+
+- Select **I'd like to upload a CSV with user information**. Download the example CSV file and make sure your spreadsheet includes the exact same column headings as the sample CSV file (User Name, First Name, and so on). If you use the sample CSV file, open it in an editing tool, like Microsoft Excel, and consider leaving all the data in row 1 alone, and only entering data in rows 2 and below. Your spreadsheet also needs to include values for the user name (like bob@contoso.com) and a display name (like Bob Kelly) for each user. When you're done entering your user's information, select **Browse** and navigate to the location of your CSV file and select **Open**.
+
+3. Choose **Next**.
+
+4. On the **Licenses** page, select the licenses you want to assign your users and choose **Next**.
+
+5. Review your selections and choose **Add users**.
+
+You can also use any of the following methods to add multiple users at the same time:
-- **Use a spreadsheet to add people in bulk.** See [Add several users at the same time](../../enterprise/add-several-users-at-the-same-time.md). - **Automate adding accounts and assigning licenses.** See [Create user accounts with Microsoft 365 PowerShell](../../enterprise/create-user-accounts-with-microsoft-365-powershell.md). Choose this method if you're already familiar with using Windows PowerShell cmdlets. - **Using ActiveDirectory?** [Set up directory synchronization for Microsoft 365](../../enterprise/set-up-directory-synchronization.md). Use the Azure AD Connect tool to replicate Active Directory user accounts (and other Active Directory objects) in Microsoft 365. The sync only adds the user accounts. You must assign licenses to the synced users before they can use email and other Office apps. - **Migrating from Exchange?** See [Ways to migrate multiple email accounts to Office 365](/Exchange/mailbox-migration/mailbox-migration). When you migrate multiple mailboxes to Microsoft 365 by using either cutover, staged, or a hybrid Exchange method, you automatically add users as part of the migration. The migration only adds the user accounts. You must assign licenses to the users before they can use email and other Office apps. If you don't assign a license to a user, their mailbox is disabled after a grace period of 30 days. Learn how to [assign licenses to users](../manage/assign-licenses-to-users.md) in the Microsoft 365 admin center.
If you're a global or user management admin of a Microsoft 365 for business subs
When you create, edit, or delete a custom user view, the changes are shown in the **Filter** list that all admins in your company see when they go to the **Users** page. > [!TIP]
-> Standard user views are displayed by default in the **Filters** drop-down list. The standard filters include **All users**, **Licensed users**, **Guest users**, **Sign-in allowed**, **Sign-in blocked**, **Unlicensed users**, **Users with errors**, **Billing admins**, **Global admins**, **Helpdesk admins**, **Service admins**, and **User management admins**. You can't edit or delete standard views.
+> Standard user views are displayed by default in the **Filters** drop-down list. The standard filters include **All users**, **Licensed users**, **Guest users**, **Sign-in allowed**, **Sign-in blocked**, **Unlicensed users**, **Users with errors**, **Billing admins**, **Global admins**, **Helpdesk admins**, **Service admins**, and **User management admins**. You can't edit or delete standard views.
-A few things to note about standard views:
+A few things to note about standard views:
- Some standard views display an unsorted list if there are more than 2,000 users in the list. To locate specific users in this list, use the search box. - If you didn't purchase Microsoft 365 from Microsoft, **Billing admins** don't appear in the standard views list. For more information, see [Assigning admin roles](assign-admin-roles.md).
You can also filter by additional user profile details used in your organization
- **Unlicensed users** Select this box to find all the users who haven't been assigned a license. The results for this view can also include users who have an Exchange mailbox but don't have a license. To track those users specifically, use the filter **Unlicensed users with Exchange mailboxes or archives**. The results for this view can also include users who have an Exchange archive, but don't have a license. -- **Unlicensed users with Exchange mailboxes or archives** Select this box to show user accounts that were created in Exchange Online and have an Exchange mailbox, but weren't assigned an Microsoft 365 license. The results of this filter include users who have or who were assigned an Exchange archive.
+- **Unlicensed users with Exchange mailboxes or archives** Select this box to show user accounts that were created in Exchange Online and have an Exchange mailbox, but weren't assigned a Microsoft 365 license. The results of this filter include users who have or who were assigned an Exchange archive.
> [!NOTE] > The **Unlicensed users with Exchange mailboxes** filter works when:
You can also filter by additional user profile details used in your organization
4. A new mailbox that has been created on-premise with a New-RemoteMailbox cmdlet is provisioned for the user. > [!TIP]
-> If you create a custom view that returns more than 2,000 users, the resulting user list isn't sorted. In this case, use the search box to find users or edit your custom view to refine your search.
+> If you create a custom view that returns more than 2,000 users, the resulting user list isn't sorted. In this case, use the search box to find users or edit your custom view to refine your search.
### Create a custom user view
You can also filter by additional user profile details used in your organization
1. In the admin center, go to **Users** \> <a href="https://go.microsoft.com/fwlink/p/?linkid=850628" target="_blank">Active users</a>. 2. On the **Active users** page, select **Filter**, select the filter you want to change, and then select **Edit filter**.
admin Plan Your Setup https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/setup/plan-your-setup.md
This article is for people who have subscribed to a Microsoft 365 for business p
Before moving your organization to Microsoft 365, there are requirements you need to meet, info you need to have on hand, and decisions you have to make.
+## Choosing the right business subscription
+
+When signing up for Microsoft 365 Business Standard, Microsoft 365 Business Basic, Microsoft Apps for Business or the trial versions, you have 2 options for how to get started. Evaluate three key factors to choose which best meets your needs:
+
+- Which apps and services do you want to use straight away?
+
+- How much technical skill do you have?
+
+- Do you need Microsoft to act as a processor for your data?
+
+The table below outlines each choice.
+
+|&nbsp;|**Option 1** ΓÇô Sign in with Outlook, Hotmail, Yahoo, Gmail or other email account |**Option 2** ΓÇô Add a business domain and create a new business email account |
+||||
+|Available apps and services|Use Word for the web, Excel for the web, PowerPoint for the web, Teams for the web and Access for the web. OneDrive and SharePoint desktop app are included. This set of apps is best for very small businesses who don't need branded email immediately, or who already use branded email from a different provider and do not intend to switch to use Microsoft Exchange. You'll use Outlook with your existing email account (be it outlook.com, Hotmail, Yahoo, Gmail or other).|Use Word for the web, Excel for the web, PowerPoint for the web, Teams for the web and Access for the web. OneDrive and SharePoint desktop app are included. Microsoft 365 Business Basic with Option 2 also lets you access a wide range of additional
+|Required knowledge|Let's you get started without technical know-how.|Requires you to buy a domain, or to own a domain. You may need technical knowledge to prove ownership of the domain.|
+|Data handling|Available under the Supplement to the [Microsoft Services Agreement](https://go.microsoft.com/fwlink/p/?linkid=2180702) and is best for businesses that want some remote work and collaboration tools and are comfortable with Microsoft acting as controller for your data under the [Microsoft Privacy Statement](https://go.microsoft.com/fwlink/?LinkId=521839). Subscribers to services using this option will not have access to an individual's user content or data until a domain is attached. Subscribers should evaluate data ownership and intellectual property rights considerations based on their needs. For example, if you are working collaboratively with other users on a document stored in their account, they may choose to make those documents inaccessible to you. As such, you should evaluate data ownership and intellectual property rights considerations accordingly. Separately, users may choose not to transfer documents in their Simplified Sign-Up account to your Domain Account subscription, even after you invite them to do so. This means their documents may also not be accessible to you even if you add a domain account later|Available under the [Microsoft Online Subscription Agreement](https://go.microsoft.com/fwlink/p/?linkid=2180430) and is best for businesses that need Microsoft to act as a processor for their data under Microsoft's [Data Protection Addendum](https://go.microsoft.com/fwlink/p/?linkid=2180314) and need our full suite of remote work and collaboration tools. Subscribers who are in regulated industries or seek more control, both over the use of the services by your employees and over processing of related data by Microsoft, should choose Option 2 and attach a domain and sign up under the Domain Account enterprise-level agreement.|
+
+Use these three factors to determine which of the two options is best for your business needs. For more info see:
+
+- [Sign up for a Microsoft 365 Business Standard subscription](../simplified-signup/signup-business-standard.md)
+
+- [Sign up for Microsoft 365 Business Basic](signup-business-basic.md)
+
+- [Sign up for Microsoft 365 Apps for business](signup--apps-business.md)
+ ## Overview of Microsoft 365 for business setup Check out this video and others on our [YouTube channel](https://go.microsoft.com/fwlink/?linkid=2197910).
bookings Set Scheduling Policies https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/bookings/set-scheduling-policies.md
This table explains the various scheduling policies available on the booking pag
| Policy | Explanation | ||| | Time increments | Determines the intervals between appointments. You can set your time increments from 5 minutes to 4 hours. You can also set your own customized time increments. An interval of 15 minutes, for example, means a customer could schedule a 60-minute appointment at 8:00, 8:15, 8:30, and so on. Conversely, a 60-minute interval means that appointments are only available on the hour. (To set service durations, see [Define your service offerings](define-service-offerings.md).) |
-| Lead time in hours | You build your staffing plan based on the appointments that are scheduled so it's important to know in advance how many customers are coming in for service on any particular day. The lead time policy enables you to specify the number of hours in advance that customers must book or cancel an appointment. |
+| Lead time in hours | You build your staffing plan based on the appointments that are scheduled so it's important to know in advance how many customers are coming in for service on any particular day. The lead time policy enables you to specify the number of hours in advance that customers must book or cancel an appointment. The minimum lead time is based on regular hours and not business hours.|
| Maximum days in advance | If you want to limit how far in advance customers can book appointments, then this is the setting for you! You can set the maximum for 365 days or more. | | Notify when a booking is created or changed | Select this option when you want to receive an email anytime a customer books an appointment or changes an existing one. The email will go to the mailbox specified on the Business information page. See [Enter your business information](enter-business-information.md) for details. |
compliance Create A Custom Sensitive Information Type https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/compliance/create-a-custom-sensitive-information-type.md
There are two ways to create a new sensitive information type:
- Your organization must have a subscription, such as Office 365 Enterprise, that includes Microsoft Purview Data Loss Prevention (DLP). See [Messaging Policy and Compliance ServiceDescription](/office365/servicedescriptions/exchange-online-protection-service-description/messaging-policy-and-compliance-servicedesc). -- Your organization must have a subscription, such as Office 365 Enterprise, that includes data loss prevention (DLP). See [Messaging Policy and Compliance ServiceDescription](/office365/servicedescriptions/exchange-online-protection-service-description/messaging-policy-and-compliance-servicedesc).- > [!IMPORTANT] > Microsoft Customer Service & Support can't assist with creating custom classifications or regular expression patterns. Support engineers can provide limited support for the feature, such as, providing sample regular expression patterns for testing purposes, or assisting with troubleshooting an existing regular expression pattern that's not triggering as expected, but can't provide assurances that any custom content-matching development will fulfill your requirements or obligations.
compliance Exchange Online Secures Email Secrets https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/compliance/exchange-online-secures-email-secrets.md
Title: "How Exchange Online secures your email secrets" f1.keywords: - NOCSH--- Previously updated : 07/01/2019+++ Last updated : 10/31/2022 audience: ITPro ms.localizationpriority: medium search.appverid: - MET150 - purview-compliance
-description: "In addition to the Office 365 Trust Center that provides Security, Privacy, and Compliance Information for Microsoft 365, you might want to know how Microsoft helps protect secrets you store in its datacenters. We use a technology called Distributed Key Manager (DKM)."
+description: "In addition to the Microsoft Trust Center that provides Security, Privacy, and Compliance Information for Microsoft 365, learn how Microsoft helps protect secrets you store in its datacenters. "
# How Exchange Online secures your email secrets
This article describes how Microsoft secures your email secrets in its datacente
[!INCLUDE [purview-preview](../includes/purview-preview.md)]
-## How do we secure secret information provided by you?
+## How we secure secret information provided by you
-In addition to the Office 365 Trust Center that provides [Security, Privacy, and Compliance Information for Office 365](./get-started-with-service-trust-portal.md), you might want to know how Microsoft helps protects secrets you provide in its datacenters. We use a technology called Distributed Key Manager (DKM).
+In addition to the Office 365 Trust Center that provides [Security, Privacy, and Compliance Information for Office 365](./get-started-with-service-trust-portal.md), we use a technology called Distributed Key Manager (DKM).
-[Distributed Key Manager](office-365-bitlocker-and-distributed-key-manager-for-encryption.md) (DKM) is a client-side functionality that uses a set of secret keys to encrypt and decrypt information. Only members of a specific security group in Active Directory Domain Services can access those keys in order to decrypt the data that is encrypted by DKM. In Exchange Online, only certain service accounts under which the Exchange processes run are part of that security group. As part of standard operating procedure in the datacenter, no human is given credentials that are part of this security group and therefore no human has access to the keys that can decrypt these secrets.
+[Distributed Key Manager](office-365-bitlocker-and-distributed-key-manager-for-encryption.md) (DKM) is a client-side technology that uses a set of secret keys to encrypt and decrypt information. Only members of a specific security group in Active Directory Domain Services can access those keys in order to decrypt the data that is encrypted by DKM. In Exchange Online, only certain service accounts under which the Exchange processes run are part of that security group. No human is given credentials that are part of this security group and therefore no human has access to the keys that can decrypt these secrets.
-For debugging, troubleshooting, or auditing purposes, a datacenter administrator must request elevated access to gain temporary credentials that are part of the security group. This process requires multiple levels of legal approval. If access is granted, all activity is logged and audited. In addition access is only granted for a set interval of time after which it automatically expires.
+For debugging, troubleshooting, or auditing purposes, a datacenter administrator must request elevated access to gain temporary credentials that are part of the security group. This process requires multiple levels of legal approval. If access is granted, all activity is logged and audited. Access is only granted for a set interval of time after which it automatically expires.
-For extra protection, DKM technology includes automated key rollover and archiving. This also ensures that you can continue to access your older content without having to rely on the same key indefinitely.
+For extra protection, DKM technology includes automated key rollover and archiving. Automated rollover and archiving ensure that you can continue to access your older content without having to rely on the same key indefinitely.
-## Where does Exchange Online make use of DKM?
+## Where Exchange Online uses DKM
Microsoft uses [Distributed Key Manager](office-365-bitlocker-and-distributed-key-manager-for-encryption.md) to encrypt your secrets in Exchange Online datacenters. For example: - Email account credentials for connected accounts. Connected accounts are third-party accounts such as Hotmail, Gmail, and Yahoo! mail accounts. -- Customer key. If you are using [Service encryption with Customer Key](customer-key-overview.md), you'll use [Azure Key Vault](/azure/key-vault/key-vault-whatis) to safeguard your secrets.
+- Customer Key. If you're using [Service encryption with Microsoft Purview Customer Key](customer-key-overview.md), you'll use [Azure Key Vault](/azure/key-vault/key-vault-whatis) to safeguard your secrets.
-## Related topics
+## Related articles
[Encryption in Office 365](encryption.md) [Technical reference details about encryption](technical-reference-details-about-encryption.md)
-[Service assurance in the Security &amp; Compliance Center](./service-assurance.md)
+[Service assurance in the Microsoft Purview compliance portal](./service-assurance.md)
compliance Service Assurance https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/compliance/service-assurance.md
Title: "Service assurance in the Security & Compliance Center"
+ Title: "Service assurance in the Microsoft Purview compliance portal"
f1.keywords: - NOCSH Previously updated : 6/29/2018 Last updated : 10/31/2022 audience: Admin
search.appverid:
- BCS160 - MET150 ms.assetid: 47e8b964-4b09-44f7-a2d7-b8a06e8e389c
-description: "Download third-party audits, find out how Microsoft keeps customer data safe, and know how you can comply with ISO, HIPAA, FINRA, and FedRAMP when you use Office 365."
+description: "Download third-party audits, learn how to comply with ISO, HIPAA, FINRA, and FedRAMP, and how Microsoft keeps customer data safe when you use Office 365."
-# Service assurance in the Security & Compliance Center
+# Service assurance in the Microsoft Purview compliance portal
-Use Service assurance in the Security & Compliance Center to access documents that describe a variety of topics, including:
+Use Service assurance in the Microsoft Purview compliance portal to access documents that describe various topics, including:
-- Microsoft security practices for customer data that is stored in Office 365.
-
-- Independent third-party audit reports of Office 365.
-
-- Implementation and testing details for security, privacy, and compliance controls that Office 365 uses to protect your data.
-
+- Microsoft security practices for customer data that is stored in Office 365.
+
+- Independent third-party audit reports of Office 365.
+
+- Implementation and testing details for security, privacy, and compliance controls that Office 365 uses to protect your data.
+ You can also find out how Office 365 can help customers comply with standards, laws, and regulations across industries, such as the: -- International Organization for Standardization (ISO) 27001 and 27018
-
+- International Organization for Standardization (ISO) 27001 and 27018
+ - Health Insurance Portability and Accountability Act of 1996 (HIPAA)
-
+ - Federal Risk and Authorization Management Program (FedRAMP)
-
+ [!INCLUDE [purview-preview](../includes/purview-preview.md)] ## Who can access Office 365 Service assurance, and how?
- **New customers, and customers evaluating Microsoft online services** can access Service assurance which is included with Office 365 Enterprise E3 and E5 plans (both trial and paid subscriptions). If you don't have one of these plans and want to try Service assurance, you can [sign-up for a trial of Office 365 Enterprise E5](https://go.microsoft.com/fwlink/p/?LinkID=698279).
+ **New customers, and customers evaluating Microsoft online services** can access Service assurance, which is included with Office 365 Enterprise E3 and E5 plans (both trial and paid subscriptions). If you don't have one of these plans and want to try Service assurance, you can [sign-up for a trial of Office 365 Enterprise E5](https://go.microsoft.com/fwlink/p/?LinkID=698279).
**O365 Subscription Members** can access the Service assurance section in the Office 365 Protection Center by default. Service assurance provides reports and documents that describe Microsoft's security practices for customer data that's stored in Office 365. It also provides independent third-party audit reports on Office 365.
-
+ ## Choose your industry and regional settings
-<a name="Chooseyourindustryregional"> </a>
When you access Service assurance for the first time, the first step is to configure your industry and regional settings. You can change these settings at any time. Configuring these settings enables Service assurance to provide you with content that is most relevant to your organization. To configure your industry and region settings:
-1. After you access Service assurance, select **Settings** and the Region and industry settings page displays as shown in the following screenshot.
-
- ![Shows the Protection center settings page.](../media/101716e8-9c0a-4839-a2c0-f6aacf64eb9d.png)
+1. After you access Service assurance, select **Settings**. The Region and industry settings page displays as shown in the following screenshot.
+
+ ![Screenshot that shows the Protection center settings page.](../media/101716e8-9c0a-4839-a2c0-f6aacf64eb9d.png)
-2. On the **Settings** page, select the down arrow next to **Region** and check the appropriate regions for your organization.
-
-3. Select the down arrow next to **Industry** and check the appropriate industries for your organization.
-
+2. On the **Settings** page, select the down arrow next to **Region** and check the appropriate regions for your organization.
+
+3. Select the down arrow next to **Industry** and check the appropriate industries for your organization.
+ 4. Once you have selected regions and industries, select **Save**.
-
+ ## Find, review, and download compliance and trust content
-<a name="Chooseyourindustryregional"> </a>
+
+Service assurance reports and documents are available to download for at least twelve months after publishing or until a new version of the document becomes available.
To review and download content, select an option from the navigation pane: -- **Compliance reports** to view independent audits and assessments of Office 365 and other Microsoft cloud services as shown in the following screen shot.
-
+- **Compliance reports** to view independent audits and assessments of Office 365 and other Microsoft cloud services as shown in the following screenshot.
+ ![Shows the Service assurance page: Service Compliance Reports.](../media/149f2181-a558-4963-85e5-8d5ebc7cdac8.png) -- **Trust documents** to view information about how Microsoft operates Office 365 as shown in the following screen shot.
-
+- **Trust documents** to view information about how Microsoft operates Office 365 as shown in the following screenshot.
+ ![Shows the Service assurance page: Trust documents provided by Microsoft.](../media/5dd4e89a-25a2-45e7-8d6c-a5c5b9237327.png) -- **Audited controls** to view information about how Office 365 controls meet security, compliance, and privacy requirements, as shown in the following screen shot.
-
+- **Audited controls** to view information about how Office 365 controls meet security, compliance, and privacy requirements, as shown in the following screenshot.
+ ![Shows the Service assurance audited controls screen.](../media/4baf252b-603d-45e0-af12-32616154df65.png)
-Select the report you want to download, and select **Save** to download it to your computer. For Audited controls, select the report you want and then select **Download**. The table below describes the reports you can find on each Service assurance page.
-
-> [!NOTE]
-> Service assurance reports and documents are available to download for at least twelve months after publishing or until a new version of the document becomes available.
+Select the report you want to download, and select **Save** to download it to your computer. For Audited controls, select the report you want and then select **Download**. The following table describes the reports you can find on each Service assurance page.
|**Service assurance page**|**Content available**|**Description**| |:--|:--|:--| |Compliance reports <br/> | FedRamp <br/> GRC Assessment <br/> ISO <br/> SOC/SSAE <br/> |Use service compliance reports to review audit assessments performed by third-party independent auditors of Office 365 Service Delivery Operations. <br/> | |Trust documents <br/> | FAQ and White Papers <br/> Risk Management Reports <br/> |Use white papers, FAQs, end-of-year reports and other Microsoft Confidential resources that are made available to you under non-disclosure agreement for your review / risk assessments. <br/> | |Audited controls <br/> |Global standards and regulations that Office 365 has implemented. <br/> | Help with risk-assessment when you're evaluating, onboarding, or using Office 365 services. Find out: <br/> <br/>- How Office 365 controls meet security, compliance, and privacy requirements. <br/>- About testing of controls in Office 365, results of these tests, and when they were completed. <br/> |
-
-Depending on your specific set-up, options included in your view might have some differences.
-
+
+Depending on your specific setup, options included in your view might have some differences.
+ ## Get help with Service assurance
-<a name="addother"> </a>
[Contact support for business products - Admin Help](../admin/get-help-support.md). ## Frequently Asked Questions
-<a name="addother"> </a>
- **Why am I getting an error saying that documents from Service assurance are corrupted?**
+**Why am I getting an error saying that documents from Service assurance are corrupted?**
Most Service assurance documents are in PDF format. Choose **Save** to save these files to, and then open them up from, your local computer.
enterprise Additional Office365 Ip Addresses And Urls https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/enterprise/additional-office365-ip-addresses-and-urls.md
Apart from DNS, these instances are all optional for most customers unless you n
|20|**[Azure AD Connect](/azure/active-directory/hybrid/)** with 21 ViaNet in China to sync on-premises user accounts to Azure AD.|\*.digicert.com:80 <BR> \*.entrust.net:80 <BR> \*.chinacloudapi.cn:443 <br> secure.aadcdn.partner.microsoftonline-p.cn:443 <br> \*.partner.microsoftonline.cn:443 <p> Also see [Troubleshoot ingress with Azure AD connectivity issues](https://docs.azure.cn/zh-cn/active-directory/hybrid/tshoot-connect-connectivity).|Outbound server-only traffic| |21|**Microsoft Stream** (needs the Azure AD user token). <br> Office 365 Worldwide (including GCC)|\*.cloudapp.net <br> \*.api.microsoftstream.com <br> \*.notification.api.microsoftstream.com <br> amp.azure.net <br> api.microsoftstream.com <br> az416426.vo.msecnd.net <br> s0.assets-yammer.com <br> vortex.data.microsoft.com <br> web.microsoftstream.com <br> TCP port 443|Inbound server traffic| |22|Use **MFA server** for multi-factor authentication requests, both new installations of the server and setting it up with Active Directory Domain Services (AD DS).|See [Getting started with the Azure AD multi-factor authentication Server](/azure/active-directory/authentication/howto-mfaserver-deploy#plan-your-deployment).|Outbound server-only traffic|
-|23|**Microsoft Graph Change Notifications** <p> Developers can use [change notifications](/graph/webhooks?context=graph%2fapi%2f1.0&view=graph-rest-1.0&preserve-view=true) to subscribe to events in the Microsoft Graph.|Public Cloud: 52.159.23.209, 52.159.17.84, 52.147.213.251, 52.147.213.181, 13.85.192.59, 13.85.192.123, 20.9.36.45, 20.9.35.166, 20.96.21.67, 20.69.245.215, 137.135.11.161, 137.135.11.116, 52.159.107.50, 52.159.107.4, 52.229.38.131, 52.183.67.212, 52.142.114.29, 52.142.115.31, 51.124.75.43, 51.124.73.177, 20.44.210.83, 20.44.210.146, 40.80.232.177, 40.80.232.118, 20.48.12.75, 20.48.11.201, 104.215.13.23, 104.215.6.169, 52.148.24.136, 52.148.27.39, 40.76.162.99, 40.76.162.42, 40.74.203.28, 40.74.203.27, 20.9.37.73, 20.9.37.76, 20.96.21.98, 20.96.21.115, 137.135.11.222, 137.135.11.250, 52.159.109.205, 52.159.102.72, 52.151.30.78, 52.191.173.85, 51.104.159.213, 51.104.159.181, 51.138.90.7, 51.138.90.52, 52.148.115.48, 52.148.114.238, 40.80.233.14, 40.80.239.196, 20.48.14.35, 20.48.15.147, 104.215.18.55, 104.215.12.254, 20.199.102.157, 20.199.102.73, 13.87.81.123, 13.87.81.35, 20.111.9.46, 20.111.9.77, 13.87.81.133, 13.87.81.141 <p> Microsoft Cloud for US Government: 52.244.33.45, 52.244.35.174, 52.243.157.104, 52.243.157.105, 52.182.25.254, 52.182.25.110, 52.181.25.67, 52.181.25.66, 52.244.111.156, 52.244.111.170, 52.243.147.249, 52.243.148.19, 52.182.32.51, 52.182.32.143, 52.181.24.199, 52.181.24.220 <p> Microsoft Cloud China operated by 21Vianet: 42.159.72.35, 42.159.72.47, 42.159.180.55, 42.159.180.56, 40.125.138.23, 40.125.136.69, 40.72.155.199, 40.72.155.216 <br> TCP port 443 <p> Note: Developers can specify different ports when creating the subscriptions.|Inbound server traffic|
+|23|**Microsoft Graph Change Notifications** <p> Developers can use [change notifications](/graph/webhooks?context=graph%2fapi%2f1.0&view=graph-rest-1.0&preserve-view=true) to subscribe to events in the Microsoft Graph.|Public Cloud: 52.159.23.209, 52.159.17.84, 52.147.213.251, 52.147.213.181, 13.85.192.59, 13.85.192.123, 20.9.36.45, 20.9.35.166, 20.96.21.67, 20.69.245.215, 137.135.11.161, 137.135.11.116, 52.159.107.50, 52.159.107.4, 20.98.68.182, 20.98.68.57, 52.142.114.29, 52.142.115.31, 51.124.75.43, 51.124.73.177, 20.44.210.83, 20.44.210.146, 40.80.232.177, 40.80.232.118, 20.48.12.75, 20.48.11.201, 104.215.13.23, 104.215.6.169, 52.148.24.136, 52.148.27.39, 40.76.162.99, 40.76.162.42, 40.74.203.28, 40.74.203.27, 20.9.37.73, 20.9.37.76, 20.96.21.98, 20.96.21.115, 137.135.11.222, 137.135.11.250, 52.159.109.205, 52.159.102.72, 20.98.68.203, 20.98.68.218, 51.104.159.213, 51.104.159.181, 51.138.90.7, 51.138.90.52, 52.148.115.48, 52.148.114.238, 40.80.233.14, 40.80.239.196, 20.48.14.35, 20.48.15.147, 104.215.18.55, 104.215.12.254, 20.199.102.157, 20.199.102.73, 13.87.81.123, 13.87.81.35, 20.111.9.46, 20.111.9.77, 13.87.81.133, 13.87.81.141 <p> Microsoft Cloud for US Government: 52.244.33.45, 52.244.35.174, 52.243.157.104, 52.243.157.105, 52.182.25.254, 52.182.25.110, 52.181.25.67, 52.181.25.66, 52.244.111.156, 52.244.111.170, 52.243.147.249, 52.243.148.19, 52.182.32.51, 52.182.32.143, 52.181.24.199, 52.181.24.220 <p> Microsoft Cloud China operated by 21Vianet: 42.159.72.35, 42.159.72.47, 42.159.180.55, 42.159.180.56, 40.125.138.23, 40.125.136.69, 40.72.155.199, 40.72.155.216 <br> TCP port 443 <p> Note: Developers can specify different ports when creating the subscriptions.|Inbound server traffic|
|24|**Network Connection Status Indicator**<p>Used by Windows 10 and 11 to determine if the computer is connected to the internet (does not apply to non-Windows clients). When this URL cannot be reached, Windows will assume it is not connected to the Internet and M365 Apps for Enterprise will not try to verify activation status, causing connections to Exchange and other services to fail.|www.msftconnecttest.com <br> 13.107.4.52<p>Also see [Manage connection endpoints for Windows 11 Enterprise](/windows/privacy/manage-windows-11-endpoints) and [Manage connection endpoints for Windows 10 Enterprise, version 21H2](/windows/privacy/manage-windows-21h2-endpoints).|Outbound server-only traffic| |25|**Teams Notifications on Mobile Devices**<p>Used by Android and Apple mobile devices to receive push notifications to the Teams client for incoming calls and other Teams services. When these ports are blocked, all push notifications to mobile devices will fail.|For specific ports, see [FCM ports and your firewall in the Google Firebase documentation](https://firebase.google.com/docs/cloud-messaging/concept-options#messaging-ports-and-your-firewall) and [If your Apple devices aren't getting Apple push notifications](https://support.apple.com/en-us/HT203609).|Outbound server-only traffic|
enterprise Assign Licenses To User Accounts With Microsoft 365 Powershell https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/enterprise/assign-licenses-to-user-accounts-with-microsoft-365-powershell.md
Set-MgUserLicense -UserId "belinda@litwareinc.com" -AddLicenses $addLicenses -Re
This example updates a user with **SPE_E5** (Microsoft 365 E5) and turns off the Sway and Forms service plans while leaving the user's existing disabled plans in their current state: ```powershell
-$userLicense = Get-MgUserLicenseDetail -UserId "belinda@fdoau.onmicrosoft.com"
+$userLicense = Get-MgUserLicenseDetail -UserId "belinda@litwareinc.com"
$userDisabledPlans = $userLicense.ServicePlans | ` Where ProvisioningStatus -eq "Disabled" | ` Select -ExpandProperty ServicePlanId
$addLicenses = @(
} )
-Set-MgUserLicense -UserId "belinda@litwareinc.onmicrosoft.com" -AddLicenses $addLicenses -RemoveLicenses @()
+Set-MgUserLicense -UserId "belinda@litwareinc.com" -AddLicenses $addLicenses -RemoveLicenses @()
``` ### Assign licenses to a user by copying the license assignment from another user
enterprise Cross Tenant Mailbox Migration https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/enterprise/cross-tenant-mailbox-migration.md
Test-MigrationServerAvailability -EndPoint "Migration endpoint for cross-tenant
### Move mailboxes back to the original source
-If a mailbox is required to move back to the original source tenant, the same set of steps and scripts will need to be run in both new source and new target tenants. The existing Organization Relationship object will be updated or appended, not recreated
+If a mailbox is required to move back to the original source tenant, the same set of steps and scripts will need to be run in both new source and new target tenants. The existing Organization Relationship object will be updated or appended, not recreated. The migration cannot happen both ways simultaneously.
## Prepare target user objects for migration
Migration batch submission is also supported from the new [Exchange admin center
Once the mailbox moves from source to target, you should ensure that the on-premises mail users, in both the source and target, are updated with the new targetAddress. In the examples, the targetDeliveryDomain used in the move is **contoso.onmicrosoft.com**. Update the mail users with this targetAddress.
+### Remove endpoints and organization relationships after migration
+
+Use the Remove-MigrationEndpoint(/powershell/module/exchange/remove-migrationendpoint) cmdlet to remove existing migration endpoints for source or destination servers after the migration is complete.
+
+Use the Remove-OrganizationRelationship (/exchange/sharing/organization-relationships/remove-an-organization-relationship#use-exchange-online-powershell-to-remove-an-organization-relationship) cmdlet to remove existing oraganization relationships for source or destination servers after the migration is complete.
+ ## Frequently asked questions ### Do we need to update RemoteMailboxes in source on-premises after the move?
enterprise Data Move Faq https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/enterprise/data-move-faq.md
- Title: "Data move general FAQ"--- Previously updated : 05/31/2022---- MET150-- NOCSH---- scotvorg
-description: Find answers to frequently asked questions (FAQs) about moving core data to a new Office 365 datacenter geo.
---
-# Data move general FAQ
-
-Here are answers to general questions about moving core customer data at rest to a new datacenter geo.
-
-### What customers are eligible to request a move?
-<details><summary>Click to expand</summary>
-
-Existing Microsoft 365 commercial customers who selected a country eligible for the new datacenter geo will be able to request a move. The program exists only for tenants with an eligible country code assigned to the Microsoft 365 tenant to migrate core customer data at rest for eligible workloads to the corresponding Microsoft 365 datacenter geo. See [How to request your data move](request-your-data-move.md) to confirm country eligibility.
-
-</details>
-
-### How do we define Core Customer Data?
-<details><summary>Click to expand</summary>
-
-Core customer data is a term that refers to a subset of customer data defined in the [Microsoft Online Services Terms](https://aka.ms/ost):
--- Exchange Online mailbox content (email body, calendar entries, and the content of email attachments)-- SharePoint Online site content and the files stored within that site-- Files uploaded to OneDrive for Business-
-</details>
-
-### What is in scope for Teams migration?
-<details><summary>Click to expand</summary>
-
-In addition to Exchange Online, SharePoint Online, and OneDrive for Business; Microsoft will migrate Teams data to the local datacenter.
--- Teams chat messages, including private messages and channel messages.-- Teams images used in chats.-
-Teams files are stored in SharePoint Online and Teams chat files are stored in OneDrive for Business. Voicemail, calendar, and contacts are stored in Exchange Online. In many cases, Exchange Online, SharePoint Online, and OneDrive for Business are already used by the customer in the local datacenter geo and are also part of the Microsoft 365 migration program for eligible customer countries.
-
-</details>
-
-### At what point is my migration complete so that my tenant's core customer data is being stored at rest in my new geo?
-<details><summary>Click to expand</summary>
-
-Due to shared dependencies between Exchange Online and SharePoint Online/OneDrive for Business, any migration cannot be considered
-completed until both services are migrated. Exchange Online and SharePoint Online/OneDrive for Business often migrate at separate times and independently from one another. Customer tenant admins receive confirmation in Message Center when each service migration is completed and can view the data location card in the Admin Center at any time to confirm the core customer data at rest location for
-each service.
-
-</details>
-
-### How do you make sure my customer data is safe during the move and that I won't experience downtime?
-<details><summary>Click to expand</summary>
-
-Data moves are a back-end service operation with minimal impact to end users. Features that can be impacted are listed in [During and after your data move](during-and-after-your-data-move.md). We adhere to the [Microsoft Online Services Service Level Agreement (SLA)](https://go.microsoft.com/fwlink/p/?LinkId=523897) for availability so there is nothing that customers need to prepare for or to monitor during the move.
-
-All Microsoft 365 services run the same versions in the datacenters, so you can be assured of consistent functionality. Your service is fully supported throughout the process.
-
-</details>
-
-### What is the impact of having different services located in different geos?
-<details><summary>Click to expand</summary>
-
-Some of the Microsoft 365 services may be located in different geos for some existing customers and for customers that are in the middle of the move process. Our services run independently of each other and there is no impact on the user experience if this is the case. However, for data residency purposes, a tenant migration cannot be considered as complete until both Exchange Online and SharePoint Online/OneDrive for Business are migrated to the same datacenter geo.
-
-</details>
-
-### Where is my core customer data located?
-<details><summary>Click to expand</summary>
-
-Customer tenant admins can view the data location card in the Admin Center at any time to confirm the core customer data at rest location for each service, specifically for their tenant. We also publish the location of datacenter geos, datacenters, and location of Office 365 customer data on the [Microsoft 365 interactive datacenter maps](https://office.com/datamaps) as a reference for the current default core customer data at rest locations for new tenants. You can verify the location of your customer data at rest via the Data Location section under your Organization Profile in the Microsoft 365 admin center.
-
-</details>
-
-### When will I be able to request a move?
-<details><summary>Click to expand</summary>
-
-Please refer to the [How to request your data move](request-your-data-move.md) page for supported timeframes for your datacenter geo.
-
-</details>
-
-### How can I request to be moved?
-<details><summary>Click to expand</summary>
-
-Eligible customers will see a page in their [Microsoft 365 admin center](https://admin.microsoft.com/). Please see [How to request your data move](request-your-data-move.md) for instructions on how to request a move.
-
-</details>
-
-### Can I change my selection after requesting a move?
-<details><summary>Click to expand</summary>
-
-It is not possible for us to remove you from the process after you submit your request.
-
-</details>
-
-### What happens if I do not request a move before the deadline?
-<details><summary>Click to expand</summary>
-
-We cannot accept requests for migration after the open enrollment period.
-
-</details>
-
-### What if I want to move my data in order to get better network performance?
-<details><summary>Click to expand</summary>
-
-Physical proximity to a Microsoft 365 datacenter is not a guarantee for a better networking performance. There are many factors and components that affect the network performance between the end user and the Microsoft 365 service. For more information about this and performance tuning, see [Network planning and performance tuning for Microsoft 365](network-planning-and-performance.md).
-
-</details>
-
-### Do all the services move their data on the same day?
-<details><summary>Click to expand</summary>
-
-Each service moves independently and will likely move their data at different times.
-
-</details>
-
-### Can I choose when I want my data to be moved?
-<details><summary>Click to expand</summary>
-
-Customers are not able to select a specific date, they cannot delay their move, and we cannot share a specific date or timeframe for the moves.
-
-</details>
-
-### Can you share when my data will be moved?
-<details><summary>Click to expand</summary>
-
-Data moves are a back-end operation with minimal impact to end users. The complexity, precision, and scale at which we need to perform data moves within a globally operated and automated environment prohibit us from sharing when a data move is expected to complete for your tenant or any other single tenant. Customers will receive one confirmation in Message Center per participating service when its data move has completed.
-
-</details>
-
-### What happens if users access services while the data is being moved?
-<details><summary>Click to expand</summary>
-
-See [During and after your data move](during-and-after-your-data-move.md) for a complete list of features that may be limited during portions of the data move for each service.
-
-</details>
-
-### How do I know the move is complete?
-<details><summary>Click to expand</summary>
-
-Watch the Microsoft 365 Message Center for confirmation that the move of each service's data is complete. When each service's data is moved, we'll post a completion notice so you'll get three completion notices: one each for Exchange Online, SharePoint Online, and Skype for Business Online. You can also verify the location of your customer data at rest via the Data Location section under your Organization Profile in the Microsoft 365 admin center.
-
-</details>
-
-### I am a Microsoft 365 customer in one of the new datacenter geos, but when I signed up, I selected a different country. How can I be moved to the new datacenter geo?
-<details><summary>Click to expand</summary>
-
-It is not possible to change the signup country associated with your tenant. Instead, you need to create a new Microsoft 365 tenant with a new subscription and manually move your users and data to the new tenant.
-
-</details>
-
-### What happens if we are in process of email data migration to Microsoft 365 during the Exchange Online move?
-<details><summary>Click to expand</summary>
-
-This is a very common scenario and is fully supported. Cloud migration between datacenter geos does not interfere with any on-premises to cloud mailbox migrations.
-
-</details>
-
-### Can I pilot some users?
-<details><summary>Click to expand</summary>
-
-You can create a separate trial tenant to test connectivity, but the trial tenant can't be combined in any way with your existing tenant.
-
-</details>
-
-### I don't want to wait for Microsoft to move my data. Can I just create a new tenant and move myself?
-<details><summary>Click to expand</summary>
-
-Yes, however the process will not be as seamless as if Microsoft were to perform the data move.
-
-If you create a new tenant after the new datacenter geo is available, the new tenant will be hosted in the new geo. This new tenant is completely separate from your previous tenant and you would be responsible for moving all user mailboxes, site content, domain names, and any other data. Note that you can't move the tenant name from one tenant to another. We recommend that you wait for the move program provided by Microsoft as we'll take care of moving all settings, data, and subscriptions for your users.
-
-</details>
-
-### My customer data has already been moved to a new datacenter geo. Can I move back?
-<details><summary>Click to expand</summary>
-
-No, this is not possible. Customers who have been moved to new geo datacenters cannot be moved back. As a customer in any geo, you will experience the same quality of service, performance, and security controls as you did before. [Microsoft 365 Multi Geo](https://aka.ms/multi-geo) is available to some customers as an add-on and lets a single tenant create multiple satellite geos and move user data to those geos with data residency commitments.
-
-</details>
-
-### Will Microsoft 365 tenants hosted in the new datacenters be available to users outside of the country?
-<details><summary>Click to expand</summary>
-
-Yes. Microsoft maintains a large global network with public Internet connections in more than 130 locations in 35 countries around the world with peering agreements with more than 2,700 Internet Service Providers (ISPs). Users will be able to access the datacenters from wherever they are on the Internet.
-
-</details>
-
-### My tenant has configured the Multi Geo add-on. Can I still enroll in my tenant in the Microsoft 365 Move Program? to change my default geo and move any user not in a satellite region to the new default geo?
-<details><summary>Click to expand</summary>
-
-Yes, your tenant is eligible to enroll but there are significant considerations as tenant-level move is not fully supported for customers that have configured [Multi-Geo](https://aka.ms/multi-geo).
-
-SharePoint Online and OneDrive for Business cannot migrate to the new datacenter geo at the tenant level through this program. The customer administrator can configure OneDrive for Business shares to move to any available region using Multi-Geo, but the default location for the tenant cannot be changed once Multi-Geo has been configured for a tenant.
-
-For customers that opt-in for migration - we will move all Exchange Online mailboxes from your current default geo to your new local datacenter geo and update the default Exchange Online region. We will not move any EXO mailboxes configured in Multi Geo satellite regions to continue to respect satellite region data residency as you"ve intended. Teams chat service tenant migrations for customers with a Multi Geo configuration behave similarly to Exchange Online.
-
-</details>
-
-### I have public folders deployed in my tenant. What will be the impact on public folder access during or after the move?
-<details><summary>Click to expand</summary>
-
-There is no impact to end users accessing public folders during or after the move of public folders. However, the public folders may not be available for administration in the Exchange Admin Center tool till all public folder mailboxes are moved in same region. Please check [this article](https://aka.ms/pfxrf) for more details.
-
-</details>
-
-### Related topics
-
-[Moving core data to new Microsoft 365 datacenter geos](moving-data-to-new-datacenter-geos.md)
-
-[How to request your data move](request-your-data-move.md)
-
-[Microsoft 365 Multi Geo](https://aka.ms/multi-geo)
-
-[Microsoft 365 interactive datacenter map](https://office.com/datamaps)
-
-[Microsoft 365 Support](../admin/get-help-support.md)
-
-[New datacenter geos for Microsoft Dynamics CRM Online](/power-platform/admin/new-datacenter-regions)
-
-[Azure services by region](https://azure.microsoft.com/regions/)
enterprise During And After Your Data Move https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/enterprise/during-and-after-your-data-move.md
- Title: "During and after your data move"--- Previously updated : 06/02/2022----- scotvorg-- SPO_Content-- MET150-- NOCSH
-description: "Data moves are back-end operations that occur when Microsoft moves services and associated data for your tenant to a new datacenter geo."
----
-# During and after your data move
-
-Data moves are a back-end operation with minimal impact to end users. No action is required while Microsoft moves each service and associated data for your tenant to a new datacenter geo. Data transfer and validation occur in the background in advance with minimal impact to users.
-
-> [!NOTE]
-> Moves occur at different times for each service. As a result, you'll see the described reduced functionality for each service at a different time.
-
-Watch the Microsoft 365 Message Center for confirmation when moves for each of Exchange Online, SharePoint Online, and Teams chat service complete. As shown in the table below, it can take up to 24 months after the end of the enrollment period to complete core customer data at rest moves to the new datacenter geo.
-
-| Customers with signup country in | All moves completed by |
-|:--|:--|
-|Australia, New Zealand, Fiji <br/> |July 1, 2022 <br/> |
-|Japan <br/> |July 1, 2022 <br/> |
-|India <br/> |July 1, 2022 <br/> |
-|Canada <br/> |July 1, 2022 <br/> |
-|South Korea <br/> |July 1, 2022 <br/> |
-|United Kingdom <br/> |July 1, 2022 <br/> |
-|France <br/> |July 1, 2022 <br/> |
-|United Arab Emirates <br/> |July 1, 2022 <br/> |
-|South Africa <br/> |July 1, 2022 <br/> |
-|Switzerland, Liechtenstein <br/> |July 1, 2022 <br/> |
-|Norway <br/> |November 1, 2022 <br/> |
-|Germany <br/> |May 1, 2023 <br/> |
-|Brazil <br/> |June 1, 2023 <br/> |
-|Sweden <br/> |June 1, 2024 <br/> |
-|Qatar <br/> |March 1, 2025 <br/> |
-
-## Exchange Online
-
-Because it takes time to move each user to the new datacenter geo for a single tenant, some users will still be in the old datacenter geo during the move, while others will be in the new datacenter geo. This means that some features that involve accessing multiple mailboxes may not fully work during a period of the move process, which can last weeks. These features are described in the following sections.
-
-### Open "Shared Folder" in Outlook Web Access
-
-Some users open a shared mail folder from another mailbox (that the user has read or write permissions to) in Outlook Web Access using the "Shared Folder" feature. The following table describes how access to shared folders works during a mailbox move. Please note that users with full permissions to a shared mailbox can open the mailbox by using Outlook Web Access during the move.
-
-| Configuration | Description |
-|:--|:--|
-|User has mailbox folder permission to another mailbox <br/> |Potentially limited. <br/> If User A and Mailbox B aren't in the same geo during the tenant move, User A can't open Mailbox B's folder in Outlook Web Access if User A only has permission to a specific folder in Mailbox B. <br/> To add a shared folder, right-click the user name in the left navigation panel and select **Add shared folder**. <br/> |
-|User with full mailbox permission to another mailbox <br/> |Fully supported. <br/> If User A has "Full Access" permission to Mailbox B, then User A can click the shared folder in the left navigation panel in Outlook Web Access to open a window showing Mailbox B. A user can open a shared mailbox using Outlook Web Access during the move without any adverse impact. The limitation only applies to folder-level sharing in a mailbox. |
-
-## SharePoint Online
-
-When SharePoint Online is moved, data for the following services is also moved:
-
-- OneDrive for Business--- Microsoft 365 Video services--- Office in a browser--- Microsoft 365 Apps for enterprise--- Visio Pro for Microsoft 365-
-After we've completed moving your SharePoint Online data, you might see some of the following effects.
-
-### Microsoft 365 Video Services
--- The data move for video takes longer than the moves for the rest of your content in SharePoint Online.--- After the SharePoint Online content is moved, there will be a time frame when videos aren't able to be played.--- We're removing the trans-coded copies from the previous datacenter and transcoding them again in the new datacenter.-
-### Search
-
-In the course of moving your SharePoint Online data, we migrate your search index and search settings to a new location. Until we've **completed** the move of your SharePoint Online data, we continue to serve your users from the index in the original location. In the new location, search automatically starts crawling your content after we've completed moving your SharePoint Online data. From this point and onwards we serve your users from the migrated index. Changes to your content that occurred after the migration aren't included in the migrated index until crawling picks them up. Most customers don't notice that results are less fresh right after we've completed moving their SharePoint Online data, but some customers might experience reduced freshness in the first 24-48 hours.
-
-The following search features are affected:
-
-- Search results and Search Web Parts: Results don't include changes that occurred after the migration until crawling picks them up. --- Delve: Delve doesn't include changes that occurred after the migration until crawling picks them up.--- Popularity and Search Reports for the site: Counts for Excel reports in the new location only include migrated counts and counts from usage reports that have run after we completed moving your SharePoint Online data. Any counts from the interim period are lost and can't be recovered. This period is typically a couple of days. Some customers might experience shorter or longer losses.--- Video Portal: View counts and statistics for the Video Portal depend on the statistics for Excel Reports, so view counts and statistics for the Video Portal are lost for the same time period as for the Excel reports.--- eDiscovery: Items that changed during the migration aren't shown until crawling picks up the changes.--- Data Loss Protection (DLP): Policies aren't enforced on items that change until crawling picks up the changes.-
-As part of the migration, the default region will change and all new content will be stored at rest in the new default region. Existing content will move in the background with no impact to you for up to 90 days after the first change to the SharePoint Online data location in the admin center.
-
-## Microsoft Teams
-
-### Files tab
-
-After the migration is complete the Files tab may take additional time (up to 7 seconds) to fully load when the user first attempts to use it.
-
-### Read-only period
-
-Teams chat services moves each thread individually. The thread is locked in a read-only state during the move, which lasts a few seconds per thread. Threads remain accessible during the migration.
-
-## Skype for Business
-
-Skype for Business moves are no longer available. [Skype for Business Online will be retired](/lifecycle/announcements/skype-for-business-online-retirement) on July 31, 2021. After that time, the service will no longer be accessible.
-
-## Related topics
-
-[How to request your data move](request-your-data-move.md)
-
-[Data move general FAQ](data-move-faq.md)
-
-[New datacenter geos for Microsoft Dynamics CRM Online](/power-platform/admin/new-datacenter-regions)
-
-[Azure services by region](https://azure.microsoft.com/regions/)
enterprise External Domain Name System Records https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/enterprise/external-domain-name-system-records.md
Email customers who are using Exchange Federation will also need the additional
|**TXT** <br/> **(Exchange federation)**|Used for Exchange federation for hybrid deployment.|**TXT record 1:** For example, contoso.com and associated custom-generated, domain-proof hash text (for example, Y96nu89138789315669824) <br/> **TXT record 2:** For example, exchangedelegation.contoso.com and associated custom-generated, domain-proof hash text (for example, Y3259071352452626169)| |**CNAME** <br/> **(Exchange federation)**|Helps Outlook clients to easily connect to the Exchange Online service by using the Autodiscover service when your company is using Exchange federation. Autodiscover automatically finds the correct Exchange Server host and configures Outlook for your users.|**Alias:** For example, Autodiscover.service.contoso.com <br/> **Target:** autodiscover.outlook.com|
-## External DNS records required for Teams and Skype for Business Online
+## External DNS records required for Teams
<a name="BKMK_ReqdCore"> </a> There are specific steps to take when you use [Office 365 URLs and IP address ranges](urls-and-ip-address-ranges.md) to make sure your network is configured correctly.
These DNS records apply to Teams, Skype for Business Online or both as indicated
|DNS record|Purpose|Value to use| ||||
-|**SRV** <br/> **(Teams and Skype for Business Online)**|Allows your Office 365 domain to share instant messaging (IM) features with external clients by enabling SIP federation.|**Service:** sipfederationtls <br/> **Protocol:** TCP <br/> **Priority:** 100 <br/> **Weight:** 1 <br/> **Port:** 5061 <br/> **Target:** sipfed.online.lync.com <br/> **Note:** If the firewall or proxy server blocks SRV lookups on an external DNS, you should add this record to the internal DNS record. |
-|**SRV** <br/> **(Teams and Skype for Business Online)**|Required by both Teams and Skype for Business Online to communicate between Skype for Business on-premises, Teams and Skype for Business cross-cloud (e.g., between Office 365 @ _sipfed.online.lync.com_ and Office 365 operated by 21Vianet @ _sipfed.online.partner.lync.cn_ or US government clouds).<br/>Required in both Teams-only and hybrid mode. In Teams-only mode it points to online edge servers (e.g. _sipfed.online.lync.com_) while in hybrid mode it points to on-premises edge servers (e.g. _sipfed.\<domain>_).|**Service:** sipfederationtls <br/> **Protocol:** TCP <br/> **Priority:** 100 <br/> **Weight:** 1 <br/> **Port:** 5061 <br/> **Target:** _sipfederationtls.tcp.\<domain> <br/> **Note:** If the firewall or proxy server blocks SRV lookups on an external DNS, you should add this record to the internal DNS record. |
-|**SRV** <br/> **(Teams and Skype for Business Online)**|Required by Skype for Business Windows Desktop client and Skype for Business phones for sign-in. It may be needed by Teams-only tenants that use Skype for Business Online phones for Teams and must point to online edge servers (e.g. _sip.online.lync.com_). <br/>It is needed by hybrid tenants to support their Windows Desktop clients and phones that sign in to on-premises deployments (e.g. _sip.\<domain>_).|**Target:** _sip._tls.\<domain>|
-|**CNAME** <br/> **(Teams and Skype for Business Online)**|Required by the Skype for Business desktop client for Windows, Mac, and web clients as well as Skype Meeting Application (SMA) to sign in. <br/>Also used by PowerShell cmdlets that still use Skype for Business Online infrastructure for management. Therefore, it is also needed for both Teams-only and hybrid tenants.|**Target:** lyncdiscover.\<domain>|
-|**SRV** <br/> **(Skype for Business Online)**|Required by Skype for Business to coordinate the flow of information between Lync clients.|**Service:** sip <br/> **Protocol:** TLS <br/> **Priority:** 100 <br/> **Weight:** 1 <br/> **Port:** 443 <br/> **Target:** sipdir.online.lync.com|
-|**CNAME** <br/> **(Skype for Business Online)**|Required by the Lync desktop client to locate the Skype for Business Online service and sign in.|**Alias:** sip <br/> **Target:** sipdir.online.lync.com|
-|**CNAME** <br/> **(Skype for Business Online)**|Required by the Lync mobile client to help find the Skype for Business Online service and sign in.|**Alias:** lyncdiscover <br/> **Target:** webdir.online.lync.com|
+|**SRV** <br/> **(Teams)**|Allows your Office 365 domain to share instant messaging (IM) features with external clients by enabling SIP federation.|**Service:** sipfederationtls <br/> **Protocol:** TCP <br/> **Priority:** 100 <br/> **Weight:** 1 <br/> **Port:** 5061 <br/> **Target:** sipfed.online.lync.com <br/> **Note:** If the firewall or proxy server blocks SRV lookups on an external DNS, you should add this record to the internal DNS record. |
+|**SRV** <br/> **(Teams)**| It may be needed by Teams-only tenants that use Skype for Business Online phones for Teams and must point to online edge servers (such as _sip.online.lync.com_). <br/>It is needed by hybrid tenants to support their Windows Desktop clients and phones that sign in to on-premises deployments (such as _sip.\<domain>_).|**Target:** _sip._tls.\<domain>|
+|**CNAME** <br/> **(Teams)**|Required for PowerShell cmdlets that still use Skype for Business Online infrastructure for management. Therefore, it is also needed for Teams-only tenants.|**Target:** lyncdiscover.\<domain>|
+ ## External DNS records required for Office 365 Single Sign-On <a name="BKMK_ReqdCore"> </a>
enterprise M365 Dr Commitments https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/enterprise/m365-dr-commitments.md
>[!NOTE] >If you have purchased a Multi-Geo subscription, then Microsoft will store certain customer data at rest in more than one Geography based on your configuration even if you have purchased the Microsoft 365 Advanced Data Residency add-on ("ADR").
-Microsoft makes commitments to store certain customer data at rest in the applicable _Local Region Geography_ or _Expanded Local Region Geography_ for [eligible customers](advanced-data-residency.md#eligibility) that purchase ADR. The commitments are specified below.
+Microsoft makes commitments to store certain customer data at rest in the applicable _Local Region Geography_ for [eligible customers](advanced-data-residency.md#eligibility) that purchase ADR. The commitments are specified below.
## Exchange Online
-The following customer data will be stored at rest in the _Local Region Geography_ or _Expanded Local Region Geography_:
+The following customer data will be stored at rest in the _Local Region Geography_:
-- Exchange Online mailbox content, (e-mail body, calendar entries, and the content of e-mail attachments stored in the related _Local Region Geography_ or _Expanded Local Region Geography_.
+- Exchange Online mailbox content, (e-mail body, calendar entries, and the content of e-mail attachments stored in the related _Local Region Geography_.
## SharePoint Online/OneDrive for Business
-The following customer data will be stored at rest in the _Local Region Geography_ or _Expanded Local Region Geography_:
+The following customer data will be stored at rest in the _Local Region Geography_:
- SharePoint Online site content and the files stored within that site, and files uploaded to OneDrive for Business. ## Microsoft Teams
-The following customer data will be stored at rest in the _Local Region Geography_ or _Expanded Local Region Geography_:
+The following customer data will be stored at rest in the _Local Region Geography_:
- Microsoft Teams chat messages (including private messages, channel messages, meeting messages and images used in chats), and, for customers using Microsoft Stream (on SharePoint), meeting recordings. ## Microsoft Defender for Office P1
-The following customer data will be stored at rest in the _Local Region Geography_ or _Expanded Local Region Geography_:
+The following customer data will be stored at rest in the _Local Region Geography_:
- MDO P1 does not store any customer data within its service.-- Exchange Online Protection (EOP). The following customer data will be stored at rest in the _Local Region Geography_ or _Expanded Local Region Geography_: Service configuration data and policies, quarantined email and attachments, junk email, grading analysis, block lists (url, tenant, user), spam domains, reports, and alerts
+- Exchange Online Protection (EOP). The following customer data will be stored at rest in the _Local Region Geography_: Service configuration data and policies, quarantined email and attachments, junk email, grading analysis, block lists (url, tenant, user), spam domains, reports, and alerts
## Office for the Web
-The following customer data will be stored at rest in the _Local Region Geography_ or _Expanded Local Region Geography_:
+The following customer data will be stored at rest in the _Local Region Geography_:
-- Office for the Web stores files on a storage host which has its applicable promises to _Local Region Geography_/_Expanded Local Geography_.
+- Office for the Web stores files on a storage host which has its applicable promises to _Local Region Geography_.
## Viva Connections
-The following customer data will be stored in the _Local Region Geography_ or _Expanded Local Region Geography_:
+The following customer data will be stored in the _Local Region Geography_:
-- Viva Connections Dashboard and Feed can have content sourced from SharePoint Online, Exchange Online and Microsoft Teams. All customer data sourced from these services covered by data residency commitments will be stored in the _Local Region Geography_ or _Expanded Local Region Geography_. Please refer to [Exchange Online](m365-dr-workload-exo.md), [SharePoint Online](m365-dr-workload-spo.md) and [Microsoft Teams](m365-dr-workload-teams.md) workload data residency pages for more details.
+- Viva Connections Dashboard and Feed can have content sourced from SharePoint Online, Exchange Online and Microsoft Teams. All customer data sourced from these services covered by data residency commitments will be stored in the _Local Region Geography_. Please refer to [Exchange Online](m365-dr-workload-exo.md), [SharePoint Online](m365-dr-workload-spo.md) and [Microsoft Teams](m365-dr-workload-teams.md) workload data residency pages for more details.
## Viva Topics
-The following customer data will be stored at rest in the _Local Region Geography_ or _Expanded Local Region Geography_:
+The following customer data will be stored at rest in the _Local Region Geography_:
-- All the topics and customer data snippets discovered are stored within the relevant _Geographies_ in Exchange Online Substrate (site or arbitration mailboxes, and Substrate). All topic customer data is partitioned based on which _Local Region Geography_ or _Expanded Local Region Geography_ the data came from within your tenant.
+- All the topics and customer data snippets discovered are stored within the relevant _Geographies_ in Exchange Online Substrate (site or arbitration mailboxes, and Substrate). All topic customer data is partitioned based on which _Local Region Geography_ the data came from within your tenant.
- Machine Learning ("ML") models are trained on public web data, and as such do not contain any customer data from your tenant. In the future it's possible we will use customer data to improve accuracy of the ML models, in which case the data handling of ML models will follow the same policies as any other customer content (including data residency, retention, access control, sensitivity)-- Topic highlighting is computed dynamically when the SharePoint Online page is rendered by running a language model against the content of the page and linking it with the knowledge base of Topics. The Topics data is sourced from the Substrate in the _Local Region Geography_ or _Expanded Local Region Geography_.-- The administration configuration data is stored within the _Local Region Geography_ or _Expanded Local Region Geography_.
+- Topic highlighting is computed dynamically when the SharePoint Online page is rendered by running a language model against the content of the page and linking it with the knowledge base of Topics. The Topics data is sourced from the Substrate in the _Local Region Geography_.
+- The administration configuration data is stored within the _Local Region Geography_.
## Purview Audit (Standard)
-The following customer data will be stored at rest in the _Local Region Geography_ or _Expanded Local Region Geography_:
+The following customer data will be stored at rest in the _Local Region Geography_:
- Service configuration data, audited Activities, audit Records, and audit log query permissions. ## Purview Audit (Premium)
-The following customer data will be stored at rest in the _Local Region Geography_ or _Expanded Local Region Geography_:
+The following customer data will be stored at rest in the _Local Region Geography_:
- In addition to the customer data stored as part of Purview Audit (Standard), configuration and Customer Data related to high-value crucial events. ## Data lifecycle management - Data Retention
-The following customer data will be stored at rest in the _Local Region Geography_ or _Expanded Local Region Geography_:
+The following customer data will be stored at rest in the _Local Region Geography_:
- Retention policy settings, retention label definitions - Customer Data stored in original locations for the following
The following customer data will be stored at rest in the _Local Region Geograph
## Data lifecycle management - Records Management
-The following customer data will be stored at rest in the _Local Region Geography_ or _Expanded Local Region Geography_:
+The following customer data will be stored at rest in the _Local Region Geography_:
- Record retention label definitions, file plan definitions, event-based retention policy settings, disposition review records and records of deletion ## Information Protection - Sensitivity labels
-The following customer data will be stored at rest in the _Local Region Geography_ or _Expanded Local Region Geography_:
+The following customer data will be stored at rest in the _Local Region Geography_:
- Label configuration - Labels definition
The following customer data will be stored at rest in the _Local Region Geograph
## Information Protection - Data Loss Prevention (DLP)
-The following customer data will be stored at rest in the _Local Region Geography_ or _Expanded Local Region Geography_:
+The following customer data will be stored at rest in the _Local Region Geography_:
- DLP admin configuration, DLP policies in Compliance Center, DLP monitored activities, violation history, Activity Explorer and Microsoft 365 unified audit logs, quarantine storage, DLP Alerts and DLP Alert management dashboard. ## Information Protection - Office Message Encryption
-The following customer data will be stored at rest in the _Local Region Geography_ or _Expanded Local Region Geography_:
+The following customer data will be stored at rest in the _Local Region Geography_:
- Encryption policies, admin settings and encrypted messages. ## Insider Risk Management - Information Barriers
-The following customer data will be stored at rest in the _Local Region Geography_ or _Expanded Local Region Geography_:
+The following customer data will be stored at rest in the _Local Region Geography_:
- Policy settings, risk indicators and admin settings.
enterprise M365 Dr Legacy Move Program https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/enterprise/m365-dr-legacy-move-program.md
Here are answers to general questions about moving applicable customer data at
### What customers are eligible to request a move? <details><summary>Click to expand</summary>
-Existing Microsoft 365 commercial customers who selected a country eligible for the new datacenter geo will be able to request a move. The program exists only for _Tenants_ with an eligible country code assigned to the Microsoft 365 _Tenant_ to migrate applicable customer data at rest for eligible workloads to the corresponding Microsoft 365 datacenter geo. See [How to request your data move](request-your-data-move.md) to confirm country eligibility.
+Existing Microsoft 365 commercial customers who selected a country eligible for the new datacenter geo will be able to request a move. The program exists only for _Tenants_ with an eligible country code assigned to the Microsoft 365 _Tenant_ to migrate applicable customer data at rest for eligible workloads to the corresponding Microsoft 365 datacenter geo. For more information, see [Microsoft 365 Multi-Geo availability](microsoft-365-multi-geo.md#microsoft-365-multi-geo-availability) to confirm country eligibility.
</details>
each service.
### How do you make sure my customer data is safe during the move and that I won't experience downtime? <details><summary>Click to expand</summary>
-Data moves are a back-end service operation with minimal impact to end users. Features that can be impacted are listed in [During and after your data move](during-and-after-your-data-move.md). We adhere to the [Microsoft Online Services Service Level Agreement (SLA)](https://go.microsoft.com/fwlink/p/?LinkId=523897) for availability so there is nothing that customers need to prepare for or to monitor during the move.
+Data moves are a back-end service operation with minimal impact to end users. Features that can be impacted are listed in [User experience in a Multi-Geo environment](multi-geo-user-experience.md). We adhere to the [Microsoft Online Services Service Level Agreement (SLA)](https://go.microsoft.com/fwlink/p/?LinkId=523897) for availability so there is nothing that customers need to prepare for or to monitor during the move.
All Microsoft 365 services run the same versions in the datacenters, so you can be assured of consistent functionality. Your service is fully supported throughout the process.
Some of the Microsoft 365 services may be located in different geos for some exi
### Where is my applicable customer data located? <details><summary>Click to expand</summary>
-Customer _Tenant_ admins can view the data location card in the Admin Center at any time to confirm the applicable customer data at rest location for each service, specifically for their _Tenant_. We also publish the location of datacenter geos, datacenters, and location of Office 365 customer data on the [Microsoft 365 interactive datacenter maps](https://office.com/datamaps) as a reference for the current default applicable customer data at rest locations for new _Tenant_. You can verify the location of your customer data at rest via the Data Location section under your Organization Profile in the Microsoft 365 admin center.
+Customer _Tenant_ admins can view the data location card in the Admin Center at any time to confirm the applicable customer data at rest location for each service, specifically for their _Tenant_. We also publish the location of datacenter geos, datacenters, and location of Microsoft 365 customer data in [Where your Microsoft 365 customer data is stored](https://office.com/datamaps) as a reference for the current default applicable customer data at rest locations for new _Tenant_. You can verify the location of your customer data at rest via the Data Location section under your Organization Profile in the Microsoft 365 admin center.
</details> ### When will I be able to request a move? <details><summary>Click to expand</summary>
-Please refer to the [How to request your data move](request-your-data-move.md) page for supported timeframes for your datacenter geo.
+Please refer to the [Data Residency Legacy Move Program](m365-dr-legacy-move-program.md) page for supported timeframes for your datacenter geo.
</details> ### How can I request to be moved? <details><summary>Click to expand</summary>
-Eligible customers will see a page in their [Microsoft 365 admin center](https://admin.microsoft.com/). Please see [How to request your data move](request-your-data-move.md) for instructions on how to request a move.
+Eligible customers will see a page in their [Microsoft 365 admin center](https://admin.microsoft.com/). Please see [Data Residency Legacy Move Program](m365-dr-legacy-move-program.md) for instructions on how to request a move.
</details>
Data moves are a back-end operation with minimal impact to end users. The comple
### What happens if users access services while the data is being moved? <details><summary>Click to expand</summary>
-See [During and after your data move](during-and-after-your-data-move.md) for a complete list of features that may be limited during portions of the data move for each service.
+See [User experience in a Multi-Geo environment](multi-geo-user-experience.md) for a complete list of features that may be limited during portions of the data move for each service.
</details>
enterprise Modern Desktop Deployment And Management Lab https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/enterprise/modern-desktop-deployment-and-management-lab.md
The Windows and Office 365 deployment lab kits are designed to help you plan, te
|Windows 10 Lab|Windows 11 Lab| ||| |[Windows 10 lab environment](https://download.microsoft.com/download/b/7/6/b7696d5b-940e-4af6-ba8b-32cfa3532e6e/Windows10_21H2_2022-10-19.zip)|[Windows 11 lab environment](https://download.microsoft.com/download/a/1/0/a10d1f67-b499-4c2f-8db1-79d29cd98b05/Windows11_21H1_2022-10-18.zip)|
-|[Windows 10 lab guides](https://download.microsoft.com/download/b/d/4/bd4f430b-8cd1-4a07-97b1-c32100fce7ae/Win_10_21H2_lab_guides.zip)|[Windows 11 lab guides](https://download.microsoft.com/download/a/1/0/a10d1f67-b499-4c2f-8db1-79d29cd98b05/Win11_Lab_Guides_10.18.zip)|
+|[Windows 10 lab guides](https://download.microsoft.com/download/5/c/e/5cee2d36-da83-45b5-8ce5-5c478c343620/Win10_21H2_guides.zip)|[Windows 11 lab guides](https://download.microsoft.com/download/a/1/0/a10d1f67-b499-4c2f-8db1-79d29cd98b05/Win11_Lab_Guides_10.18.zip)|
## A complete lab environment
enterprise Moving Data To New Datacenter Geos https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/enterprise/moving-data-to-new-datacenter-geos.md
- Title: "Moving core data to new Microsoft 365 datacenter geos"--- Previously updated : 09/23/2022---- MET150-- NOCSH
-description: Learn about new Office 365 datacenter geos and how to use the data residency option to request a move of your core data to a new geo.
----
-# Moving core data to new Microsoft 365 datacenter geos
-
-We continue to open new datacenter geos for Microsoft 365 services. These new datacenter geos add capacity and compute resources to support our ongoing customer demand and usage growth. Additionally, the new datacenter geos offer in-geo data residency for core customer data.
-
-Core customer data is a term that refers to a subset of customer data including:
--- Exchange Online mailbox content (email body, calendar entries, and the content of email attachments)-- SharePoint Online site content and the files stored within that site-- Files uploaded to OneDrive for Business-- Teams chat messages, including private messages, channel messages, and images used in chats
-
-Existing customers that have their core customer data stored in an already existing datacenter geo are not impacted by the launch of a new datacenter geo. We introduce no unique capabilities, features or compliance certifications with the new datacenter geo. As a customer in any of those two geos, you will experience the same quality of service, performance and security controls as you did before. We offer existing customers listed in the table below an option to request early migration of their organization's core customer data at rest to their new datacenter geo.
-
-| Customers with tenant signup country in | Previous datacenter geo | New datacenter geo | Geo available since |
-|:--|:--|:--|:--|
-|**Japan**| Asia/Pacific | Japan | December 2014 |
-|**Australia, New Zealand, Fiji**| Asia/Pacific | Australia | March 2015 |
-|**India**| Asia/Pacific | India | October 2015 |
-|**Canada**| United States | Canada | May 2016 |
-|**United Kingdom**| European Union | United Kingdom | September 2016 |
-|**South Korea**| Asia/Pacific | South Korea | April 2017 |
-|**France**| European Union | France | March 2018 |
-|**United Arab Emirates**| European Union | United Arab Emirates | June 2019 |
-|**South Africa**| European Union | South Africa | July 2019 |
-|**Switzerland, Liechtenstein**| European Union | Switzerland | December 2019 |
-|**Germany**| European Union | Germany | December 2019 |
-|**Norway**| European Union | Norway | April 2020 |
-|**Brazil**| Americas | Brazil | November 2020 |
-|**Sweden**| European Union | Sweden | November 2021 |
-|**Qatar**| European Union | Qatar | August 2022 |
-
-As of October 1, 2020 customers with an Office 365 Education subscription included in the tenant are not eligible for migration.
-
-A complete list of all datacenter geos, datacenters, and the location of customer data at rest is available as part of the [interactive datacenter maps](https://office.com/datamaps).
-
-## Data residency option
-
-We provide a data residency option to eligible Microsoft 365 customers who are covered by the datacenter geos listed in the table above. With this option, eligible customers with data residency requirements can request migration of their organization's core customer data at rest to their new datacenter geo. Microsoft will offer a committed deadline to all eligible customers who request migration during the enrollment window. Review the [How to request your data move](request-your-data-move.md) page for more details about the open enrollment window for your datacenter geo and the steps to enroll into the program. Data moves can take up to 24 months after the request period ends to complete.
-
-We introduce no unique capabilities, features or compliance certifications with the new datacenter geo.
-
-The complexity, precision and scale at which we need to perform data moves within a globally operated and automated environment prohibit us from sharing when a data move is expected to complete for your tenant or any other single tenant. Customers will receive one confirmation in Message Center per participating service when its data move has completed.
-
-Data moves are a back-end service operation with minimal impact to end-users. Features that can be impacted are listed on the [During and after your data move](during-and-after-your-data-move.md) page. We adhere to the [Microsoft Online Services Service Level Agreement (SLA)](https://go.microsoft.com/fwlink/p/?LinkId=523897) for availability so there is nothing that customers need to prepare for or to monitor during the move. Notification of any service maintenance is done if needed.
-
-Data moves to the new datacenter geo are completed at no additional cost to the customer.
-
-During the migration process, Microsoft temporarily copies your address book data into Microsoft global resources where it is encrypted and only used to support business continuity and disaster recovery operations (BCDR). After Microsoft has completed the mailbox data moves, Microsoft deletes that temporary data from the global resources. Microsoft continues to invest in global and regional resources on a regular basis. In calendar year 2023, Microsoft plans to utilize regional resources for BCDR purposes during the migration process.
-
-## Related topics
-
-[How to request your data move](request-your-data-move.md)
-
-[Data move general FAQ](data-move-faq.md)
-
-[New datacenter geos for Microsoft Dynamics CRM Online](/power-platform/admin/new-datacenter-regions)
-
-[Azure services by region](https://azure.microsoft.com/regions/)
-
-[Teams experience in a Microsoft 365 Multi-Geo-enabled tenancy](/microsoftteams/teams-experience-o365odb-spo-multi-geo)
enterprise Request Your Data Move https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/enterprise/request-your-data-move.md
- Title: "How to request your data move"--- Previously updated : 06/02/2022---- MET150-- NOCSH
-description: Existing Office 365 customers must submit a request before the deadline for their country to have their Microsoft 365 services data moved to their new geo.
-----
-# How to request your data move
-
-> [!NOTE]
-> The information on this page only applies to customers who had existing Microsoft 365 tenants before the new datacenters in their datacenter geo opened. Migration eligibility also depends on the specific service provisioning date. The tenant creation date may not always be the single date that matters.
-
-Eligible Microsoft 365 customers may request migration for their entire organization's core customer data at rest. The program supports requests for each country in the time period described in the table and from customers with an eligible signup country associated with their Microsoft 365 tenant.
-
-## When can I request a move?
-
-| Customers with signup country in | Request period begins | Request deadline |
-|:--|:--|:--|
-|Japan | |Request period closed |
-|Australia, New Zealand, Fiji | |Request period closed |
-|India | |Request period closed |
-|Canada | |Request period closed |
-|United Kingdom | |Request period closed |
-|South Korea | |Request period closed |
-|France | |Request period closed |
-|United Arab Emirates | |Request period closed |
-|South Africa | |Request period closed |
-|Switzerland, Liechtenstein | |Request period closed |
-|Norway | |Request period closed |
-|Germany | |Request period closed |
-|Brazil | |Request period closed |
-|Sweden | |Request period closed |
-|Qatar |August 30, 2022 |February 28, 2023 |
-
-## How to request a move
-
-Eligible customers will see a page in the Microsoft 365 admin center, which will allow them to request to have their core customer data moved to their new datacenter region.
-
-To access the page in the Microsoft 365 admin center, in the navigation pane on the left, expand **Settings**, and then click **Org Settings**.
-Select the tab **Organization profile**, then select the option **Data residency**.
-
-You will not see this section if your tenant is not eligible for the Microsoft 365 Move Program. If your organization has data residency requirements and you need to request migration, mark the checkbox and then **Save**.
-
-![Datacenter opt-in action screen.](../media/dataresidencyflyoutae.jpg)
-
-The text in the **Data residency** will section change to indicate **Your organization has requested to move its data** to the appropriate country and date. You'll also have a confirmation message in your message center. This confirms that you have successfully requested a move.
-
-## What happens after requesting a move?
-
-After requesting a move, we will plan to move your core customer data at rest for eligible Microsoft 365 services as quickly as our operational constraints allow. Due to the unpredictable nature of many of the constraints, we cannot share a specific date or timeframe for the moves. Customer tenant administrators will see a notification in Message Center after the move for each service has completed.
-
-Moves may take up to 24 months from the request deadline for your country to complete.
-
-## Microsoft Teams
-
-As of January 2020, customers in eligible Office 365 countries can opt-in for migration of Microsoft Teams chat service data. Customers that previously opted-in for a Data Residency move will also have Teams move to their local datacenter geo. No additional action is required by these customers.
-
-## Related topics
-
-[Moving core data to new Office 365 datacenter geos](moving-data-to-new-datacenter-geos.md)
-
-[Data move general FAQ](data-move-faq.md)
-
-[New datacenter geos for Microsoft Dynamics CRM Online](/power-platform/admin/new-datacenter-regions)
-
-[Azure services by region](https://azure.microsoft.com/regions/)
frontline Virtual Appointments Toolkit https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/virtual-appointments-toolkit.md
Download and [customize](#customize-your-infographic) one of these infographics
| Graphic | Description and links | | :- | -: |
-| [![Image of the financial services infographic](media/vv-finserv-thumbnail.png)](//download.microsoft.com/download/8/5/7/85784cd8-6945-4fcc-a3c3-972bd88d3fef/VirtualVisit_Financial_Infographic.pdf) | Customizable infographic for your financial services organization <br> [Download as a PDF](//download.microsoft.com/download/8/5/7/85784cd8-6945-4fcc-a3c3-972bd88d3fef/VirtualVisit_Financial_Infographic.pdf) <br> [Download as a PowerPoint](//download.microsoft.com/download/8/5/7/85784cd8-6945-4fcc-a3c3-972bd88d3fef/VirtualVisit_Financial_Infographic.pptx)
-| [![Image of the retail infographic](media/vv-retail-thumbnail.png)](//download.microsoft.com/download/a/b/5/ab5c07d9-cf7a-47b3-ba54-05a8a0a2a1bd/VirtualVisit_Retail_Infographic.pdf) | Customizable infographic for your retail organization <br> [Download as a PDF](//download.microsoft.com/download/a/b/5/ab5c07d9-cf7a-47b3-ba54-05a8a0a2a1bd/VirtualVisit_Retail_Infographic.pdf) <br> [Download as a PowerPoint](//download.microsoft.com/download/a/b/5/ab5c07d9-cf7a-47b3-ba54-05a8a0a2a1bd/VirtualVisit_Retail_Infographic.pptx) |
-| [![Image of the healthcare infographic](media/vv-healthcare-thumbnail.png)](//download.microsoft.com/download/4/d/3/4d3d9c53-0304-4aea-a56a-60a16402c58f/VirtualVisit_Healthcare_Infographic.pdf) | Customizable infographic for your healthcare organization <br> [Download as a PDF](//download.microsoft.com/download/4/d/3/4d3d9c53-0304-4aea-a56a-60a16402c58f/VirtualVisit_Healthcare_Infographic.pdf) <br> [Download as a PowerPoint](//download.microsoft.com/download/4/d/3/4d3d9c53-0304-4aea-a56a-60a16402c58f/VirtualVisit_Healthcare_Infographic.pptx) |
-| [![Image of the non-industry-specific infographic.](media/va-generic-thumb.png)](//download.microsoft.com/download/c/6/9/c69d3f29-a8f5-462b-a645-79119beab406/VirtualVisit_Generic_Infographic.pdf) | Customizable infographic not specific to a particular industry <br> [Download as a PDF](//download.microsoft.com/download/c/6/9/c69d3f29-a8f5-462b-a645-79119beab406/VirtualVisit_Generic_Infographic.pdf) <br> [Download as a PowerPoint](//download.microsoft.com/download/c/6/9/c69d3f29-a8f5-462b-a645-79119beab406/VirtualVisit_Generic_Infographic.pptx) |
+|![Image of the financial services infographic](media/vv-finserv-thumbnail.png)| Customizable infographic for your financial services organization <br> [Download as a PDF](https://go.microsoft.com/fwlink/?linkid=2214189) <br> [Download as a PowerPoint](https://go.microsoft.com/fwlink/?linkid=2214285)
+|![Image of the retail infographic](media/vv-retail-thumbnail.png)| Customizable infographic for your retail organization <br> [Download as a PDF](https://go.microsoft.com/fwlink/?linkid=2214355) <br> [Download as a PowerPoint](https://go.microsoft.com/fwlink/?linkid=2214283) |
+|![Image of the healthcare infographic](media/vv-healthcare-thumbnail.png)| Customizable infographic for your healthcare organization <br> [Download as a PDF](https://go.microsoft.com/fwlink/?linkid=2214356) <br> [Download as a PowerPoint](https://go.microsoft.com/fwlink/?linkid=2214357) |
+|![Image of the non-industry-specific infographic.](media/va-generic-thumb.png)| Customizable infographic not specific to a particular industry <br> [Download as a PDF](https://go.microsoft.com/fwlink/?linkid=2214284) <br> [Download as a PowerPoint](https://go.microsoft.com/fwlink/?linkid=2214282) |
### Customize your infographic
Download and [customize](#customize-your-infographic) one of these infographics
1. Healthcare 2. Financial services 3. Retail
- 1. Any industry
+ 4. Any industry
2. Customize the infographic in PowerPoint. 1. Use your organization's colors and preferred fonts.
security Linux Whatsnew https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/defender-endpoint/linux-whatsnew.md
This article is updated frequently to let you know what's new in the latest rele
- [What's new in Defender for Endpoint on macOS](mac-whatsnew.md) - [What's new in Defender for Endpoint on iOS](ios-whatsnew.md)
+<details>
+ <summary>Nov-2022 (Build: 101.85.27 | Release version: 30.122092.18527.0)</summary>
+
+&ensp;Released: **November 02, 2022**<br/>
+&ensp;Published: **November 02, 2022**<br/>
+&ensp;Build: **101.85.27**<br/>
+&ensp;Release version: **30.122092.18527.0**<br/>
+&ensp;Engine version: **1.1.19500.2**<br/>
+&ensp;Signature version: **1.371.1369.0**<br/>
+
+**What's new**
+
+- There are mutiple fixes and new changes in this release
+ -V2 engine is default with this release and V1 engine bits are completely removed for enhanced security.
+ -Now you can set the temp path for scanning of archive files. Use oemTemporaryPath - via managed config / wdavcfg if you donΓÇÖt want engine to use /tmp for scratch work.
+ - V2 support configuration path for AV definitions. (mdatp definition set path)
+ - Removed external packages dependencies from MDE package. Removed dependencies are libatomic1, libselinux, libseccomp, libfuse, and libuuid
+ - In case crash collection is disabled by configuration, crash monitoring process will not be launched.
+ - Performance fixes to optimally use system events for AV capabilities.
+ - Stability improvement in case of mdatp restart and loading of epsext issues.
+ - Other fixes
+
+**Known issues**
+
+- When upgrading from mdatp version 101.75.43 or 101.78.13, you might encounter a kernel hang. Run the following commands before attempting to upgrade to version 101.85.21. More information about the underlying issue can be found at [System hang due to blocked tasks in fanotify code](https://access.redhat.com/solutions/2838901)
+
+This should prevent the issue from occurring.
+
+Use your package manager to uninstall the 101.75.43 or 101.78.13 mdatp version.
+
+```bash
+sudo apt remove mdatp
+sudo apt-get install mdatp
+```
+
+After executing the above, use your package manager to perform the upgrade.
+
+As an alternative to the above, you can follow the instructions to [uninstall](/microsoft-365/security/defender-endpoint/linux-resources#uninstall), then [install](/microsoft-365/security/defender-endpoint/linux-install-manually#application-installation) the latest version of the package.
+
+</details>
+ <details> <summary>Sep-2022 (Build: 101.80.97 | Release version: 30.122072.18097.0)</summary>
security Create Safe Sender Lists In Office 365 https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/office-365-security/create-safe-sender-lists-in-office-365.md
The available safe sender lists are described in the following list in order fro
1. Allow entries for domains and email addresses (including spoofed senders) in the Tenant Allow/Block List. 2. Mail flow rules (also known as transport rules).
-3. Outlook Safe Senders (the Safe Senders list that's stored in each mailbox).
+3. Outlook Safe Senders (the Safe Senders list that's stored in each mailbox that affects only that mailbox).
4. IP Allow List (connection filtering) 5. Allowed sender lists or allowed domain lists (anti-spam policies)
The following example assumes you need email from contoso.com to skip spam filte
> [!CAUTION] > This method creates a high risk of attackers successfully delivering email to the Inbox that would otherwise be filtered; however, if a message from an entry in the user's Safe Senders or Safe Domains lists is determined to be malware or high confidence phishing, the message will be filtered.
-Instead of an organizational setting, users or admins can add the sender email addresses to the Safe Senders list in the mailbox. For instructions, see [Configure junk email settings on Exchange Online mailboxes in Office 365](configure-junk-email-settings-on-exo-mailboxes.md).
+Instead of an organizational setting, users or admins can add the sender email addresses to the Safe Senders list in the mailbox. For instructions, see [Configure junk email settings on Exchange Online mailboxes in Office 365](configure-junk-email-settings-on-exo-mailboxes.md). Safe Senders list entries in the mailbox affect that mailbox only.
This method is not desirable in most situations since senders will bypass parts of the filtering stack. Although you trust the sender, the sender can still be compromised and send malicious content. You should let our filters check every message and then [report the false positive/negative to Microsoft](report-junk-email-messages-to-microsoft.md) if we got it wrong. Bypassing the filtering stack also interferes with [zero-hour auto purge (ZAP)](zero-hour-auto-purge.md).
security Enable The Report Message Add In https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/office-365-security/enable-the-report-message-add-in.md
If you're a global administrator or an Exchange Online administrator, and Exchan
- Organizations that have a URL filtering or security solution (such as a proxy and/or firewall) in place, must have ipagave.azurewebsites.net and outlook.office.com endpoints allowed to be reached on HTTPS protocol.
+- Currently, reporting messages in shared mailboxes or other mailboxes by a delegate using the add-ins is not supported. Messages are not sent to the [custom mailbox](user-submission.md) or to Microsoft. Built-in reporting in Outlook on the web sends messages reported by a delegate to the custom mailbox and/or to Microsoft.
+ > [!IMPORTANT] > To view messages reported to Microsoft on the **User reported messages** tab at <https://security.microsoft.com/reportsubmission>, don't turn off the built-in reporting experience.
security Manage Tenant Allow Block List https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/office-365-security/manage-tenant-allow-block-list.md
Use the Submissions portal (also known as *admin submission*) at <https://securi
- Email messages from these senders are marked as *high confidence spam* (SCL = 9). What happens to the messages is determined by the [anti-spam policy](configure-your-spam-filter-policies.md) that detected the message for the recipient. In the default anti-spam policy and new custom policies, messages that are marked as high confidence spam are delivered to the Junk Email folder by default. In Standard and Strict [preset security policies](preset-security-policies.md), high confidence spam messages are quarantined. - Users in the organization can't send email to these blocked domains and addresses. They'll receive the following non-delivery report (also known as an NDR or bounce message): `5.7.1 Your message can't be delivered because one or more recipients are blocked by your organization's tenant allow/block list policy.` The entire message is blocked to all recipients if email is sent to any of the entries in the list.
+ > [!NOTE]
+ > To block only spam from a specific sender, add the email address or domain to the block list in [anti-spam policies](configure-your-spam-filter-policies.md). To block all email from the sender, use **Domains and email addresses** in the Tenant Allow/Block List.
+ - **Files**: Email messages that contain these blocked files are blocked as *malware*. - **URLs**: Email messages that contain these blocked URLs are blocked as *high confidence phishing*. Messages containing the blocked URLs are quarantined.
test-base Testbase For M365 Product Terms Changehistory https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/test-base/testbase-for-m365-product-terms-changehistory.md
+
+ Title: 'Test Base for Microsoft 365 Product Terms Change History'
+description: How to Test Base for Microsoft 365 Product Terms Change History
+search.appverid: MET150
+++
+audience: Software-Vendor
+ Last updated : 10/26/2022+
+ms.localizationpriority: medium
+++
+f1.keywords: NOCSH
++
+# Test Base for Microsoft 365 Product Terms Change History
+
+Version 1.0
+
+- Created on Nov 2nd, 2021.
+
+Version 1.1
+
+- Changes made on Feb 28th, 2022.
+
+Version 1.2
+
+- Changes made on Oct 28th, 2022.
+
+- Added Personal Data used for Communication
+
+- Refined No Personal Data Processing Required for Testing
test-base Testbase For M365 Product Terms https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/test-base/testbase-for-m365-product-terms.md
+
+ Title: 'Test Base for Microsoft 365 Product Terms'
+description: How to Test Base for Microsoft 365 Product Terms
+search.appverid: MET150
+++
+audience: Software-Vendor
+ Last updated : 10/26/2022+
+ms.localizationpriority: medium
+++
+f1.keywords: NOCSH
++
+# Test Base for Microsoft 365
+
+The agreement that Customer has entered into with Microsoft for use of Azure services, including the [Product Terms](https://www.microsoft.com/licensing/terms) (the ΓÇ£AgreementΓÇ¥), applies to CustomerΓÇÖs use of Test Base for Microsoft 365. Additionally, the terms in this document (the ΓÇ£Service-Specific TermsΓÇ¥) apply to Test Base for Microsoft 365 and these terms control over any conflicting provisions in the Agreement.
+
+For the purposes of these Service-Specific Terms, ΓÇ£ServicesΓÇ¥ means Test Base for Microsoft 365, ΓÇ£Provided TechnologyΓÇ¥ means the technology provided by Customer to Microsoft through the Services, and ΓÇ£TestingΓÇ¥ means installing, accessing, or using the Provided Technology to evaluate its compatibility and performance with Microsoft hardware, software products and services. Testing may include compatibility testing, smoke testing, API analysis, functional testing, regression testing, performance testing, black box testing, or failure analysis (which involves the use of process monitoring and kernel debugging tools to determine the root cause of issues). Testing may also include the collection of data, including but not be limited to, diagnostic, analytical, security, basic health and quality, app insights and Windows reliability and Performance Monitor (ΓÇ£perfmonΓÇ¥) data.
+
+### Privacy Notice
+
+Microsoft will handle Provided Technology and data resulting from Testing in accordance with the Microsoft Privacy Statement at [aka.ms/privacy](https://privacy.microsoft.com/privacystatement). Please note that the [Data Protection Addendum terms](https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA) do not apply.
+
+### No Personal Data Processing Required for Testing
+
+Test Base for Microsoft 365 does not require any personal data to perform the Testing. Customers shall not provide any personal data to Microsoft in connection with the Test Base process (for example, when uploading the application package binaries.)
+
+### Personal Data used for Communication
+
+If Customers choose to, they may enter an email address that will be used to notify them of newly generated Test Base test results. Customer data will be deleted by Test Base no later than 30 days after the Customer account is terminated.
+
+### License grant to Microsoft
+
+Customer grants to Microsoft a nonexclusive, nontransferable, limited, royalty-free license during the Term: (1) to use the Provided Technology for evaluation and Testing in the Services; and (2) to reproduce a reasonable number of copies of the Provided Technology for back-up purposes.
+
+The license granted in these Service-Specific Terms will control if it conflicts with any license terms that accompany the Provided Technology.
+
+The license in these Service-Specific Terms does not grant Microsoft any development, marketing, or distribution rights to the Provided Technology, nor does it grant Microsoft a license to any intellectual property of Customer or any third party, other than the express license to Provided Technology set forth above.
+
+Microsoft will not modify, decompile, disassemble or otherwise reverse engineer the Provided Technology except as authorized by this agreement. Microsoft will not remove any proprietary marks or confidentiality notices that appear on the Provided Technology as provided to Microsoft.
+
+### Testing and Remediating Issues
+
+Testing. Customer will provide the Provided Technology to Microsoft for Testing without cost or expense to Microsoft. Microsoft, in its sole discretion, may conduct Testing on the Provided Technology through the Services. Upon completion of Testing, Microsoft will share the test results with Customer, including applicable log files if Testing reveals application compatibility or performance issues with the Provided Technology.
+
+Use of Test Results. Either Microsoft or Customer may use the test results to fix issues and/or improve its hardware, software products, and services without restriction of any kind.
+
+Remediating Issues. In the event the Testing identifies application compatibility or performance issues, the parties may discuss a remediation plan to address those issues. Neither party is responsible for interacting with the other partyΓÇÖs customers or end users regarding remediation of issues that are identified as a result of Testing. Customer will not make any representations to end users or others regarding Testing results or suggesting that Microsoft endorses the Provided Technology (unless the parties have expressly agreed otherwise in a separate agreement).
+
+### Provided Technology Warranties
+
+Customer continuously represents and warrants that Provided Technology it provides to Microsoft through the Services will not: (1) to the best of CustomerΓÇÖs knowledge, infringe any third-party patent, copyright, trademark, trade secret, or other proprietary right, or (2) exfiltrate any Microsoft technology or information from the Services.
+
+Customer will indemnify, defend, and hold Microsoft and its affiliates, successors, officers, directors and employees harmless from any and all third party claims (including attorneys' fees) arising out of or related to a breach of these warranties.