Updates from: 03/25/2023 02:22:23
Category Microsoft Docs article Related commit history on GitHub Change details
admin About Guest Users https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/add-users/about-guest-users.md
In addition to Microsoft Teams and SharePoint, Microsoft 365 also supports guest
- Microsoft 365 groups - [Manage guest access in Microsoft 365 groups](../create-groups/manage-guest-access-in-groups.md). - Yammer - [Work with external groups in Yammer networks not aligned to native mode](/yammer/work-with-external-users/create-and-manage-external-groups).
-For Microsoft Office applications like Microsoft Word and Excel, guest access is controlled by the location of the output file, for example, Microsoft SharePoint, Teams, and OneDrive.
+For Microsoft 365 apps like Microsoft Word and Excel, guest access is controlled by the location of the output file, for example, Microsoft SharePoint, Teams, and OneDrive.
## Next steps: Add guests in Azure Active Directory
admin Add New Employee https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/add-users/add-new-employee.md
search.appverid:
- MET150 - MOE150 ms.assetid: 9cdfa29d-7681-4af2-a79d-3e72e7ab9778
-description: "Admins can learn how to add new employees to Microsoft 365 for business and give them access to email, Skype, and Office apps."
+description: "Admins can learn how to add new employees to Microsoft 365 for business and give them access to email, Skype, and Microsoft 365 apps."
# Add a new employee to Microsoft 365 This article helps you onboard a new employee to Microsoft 365 for business. We assume you're an Admin and you've already [completed Microsoft 365 set up](../setup/setup.md), and now you have someone new joining your company.
-You're in the right place if your new employee needs Microsoft 365, and you're using a [Microsoft 365 plan](https://products.office.com/business/compare-office-365-for-business-plans) that lets you install Office apps like Word and Excel on a computer.
+You're in the right place if your new employee needs Microsoft 365, and you're using a [Microsoft 365 plan]( https://www.microsoft.com/microsoft-365/buy/compare-all-microsoft-365-products?rtc=1) that lets you install Microsoft 365 apps like Word and Excel on a computer.
**Not an admin?** [Learn your way around Microsoft 365](https://support.microsoft.com/office/396b8d9e-e118-42d0-8a0d-87d1f2f055fb) helps business and home users with set up.
- **No Office apps in your plan?** Follow the steps below, but skip the sections for installing apps. Use the [Online versions of Office](https://support.microsoft.com/office/91a4ec74-67fe-4a84-a268-f6bdf3da1804) instead.
+ **No Microsoft 365 apps in your plan?** Follow the steps below, but skip the sections for installing apps. Instead, use the [Get started at Microsoft365.com](https://support.microsoft.com/office/91a4ec74-67fe-4a84-a268-f6bdf3da1804).
Here's a quick overview:
And here's a quick reference to help get them started:
|**Task**|**Find the details**| |:--|:--|
-|Sign in to Office <br/> |Go to [https://www.office.com](https://www.office.com), select **Sign in**, and then enter your user ID and password. <br/> |
-|Install Office apps onto your computer. <br/><br/> |When you sign in, the home page has a link to download and install apps like Word and Outlook. Select **Install Office**. For instructions, see [How to install Office](https://support.microsoft.com/office/4414eaaf-0478-48be-9c42-23adc4716658). <br/> |
-|Set up your email in Outlook 2016 . <br/> |Once Office apps are installed on your computer, set up your email. For instructions, see [How to set up Outlook](https://support.microsoft.com/office/6e27792a-9267-4aa4-8bb6-c84ef146101b). <br/> |
+|Sign in to Microsoft 365 <br/> |Go to [https://www.microsoft365.com](https://www.microsoft365.com), select **Sign in**, and then enter your user ID and password. <br/> |
+|Install Microsoft 365 apps onto your computer. <br/><br/> |When you sign in, the home page has a link to download and install apps like Word and Outlook. Select **Install Microsoft 365**. For instructions, see [Download and install or reinstall Microsoft 365 or Office 2021 on a PC or Mac"](https://support.microsoft.com/office/4414eaaf-0478-48be-9c42-23adc4716658). <br/> |
+|Set up your email in Outlook 2016 . <br/> |Once Microsoft 365 apps are installed on your computer, set up your email. For instructions, see [How to set up Outlook](https://support.microsoft.com/office/6e27792a-9267-4aa4-8bb6-c84ef146101b). <br/> |
|Set up Skype for Business so you can connect with co-workers or business partners in your company or around the world. You can start conversations with IM, voice, or video calls. <br/> |[Install Skype for Business on your computer](https://support.microsoft.com/office/8a0d4da8-9d58-44f9-9759-5c8f340cb3fb). <br/> <br/>To learn how to use Skype for Business, [watch a video.](https://support.microsoft.com/office/3a21eca4-434d-41f1-ab06-3d4a268573b7) <br/> <br/>Have you set up Skype for Business so your employees can contact people external to your business who are using the free Skype app? If not, tell your new employee so they know what to expect when using Skype for Business. <br/> | |Install apps on your mobile device if you want to get email or use Skype for Business on your phone. <br/> |If you want to set up the Outlook mobile app so you can get email via your phone. For instructions, see [iOS](https://support.microsoft.com/office/b2de2161-cc1d-49ef-9ef9-81acd1c8e234), [Android](https://support.microsoft.com/office/886db551-8dfa-4fd5-b835-f8e532091872), [Windows Phone](https://support.microsoft.com/office/181a112a-be92-49ca-ade5-399264b3d417) <br/> <br/>If you want to use Skype for Business on your mobile device, download and install the mobile app. For instructions, see [iOS](https://support.microsoft.com/office/3239c8a3-cf55-4ff0-a967-5de51911c049#OS_Type=iOS), [Android](https://support.microsoft.com/office/4d1b7dfa-5b0b-4868-bae5-25947fb99e6e#OS_Type=Android), [Windows Phone](https://support.microsoft.com/office/4d1b7dfa-5b0b-4868-bae5-25947fb99e6e#OS_Type=Windows_Phone) <br/> | |Complete the OneDrive for Business training to help you learn how to store and organize your documents, presentations, and spreadsheets in the cloud. <br/> |Keep your business-related documents in the cloud by using OneDrive for Business. You can always get to your content, even if you're signed in to Microsoft 365 on a different computer. [Watch a video to learn how to use your OneDrive for Business](https://support.microsoft.com/office/b30da4eb-ddd2-44b6-943b-e6fbfc6b8dde) <br/><br/> **Training:** [OneDrive for Business training](https://support.microsoft.com/office/1f608184-b7e6-43ca-8753-2ff679203132) (Select OneDrive for Business). <br/> |
admin Add Users https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/add-users/add-users.md
If you're seeing this page in the admin center, you're on the **admin simplified
You can also use any of the following methods to add multiple users at the same time: - **Automate adding accounts and assigning licenses.** See [Create user accounts with Microsoft 365 PowerShell](../../enterprise/create-user-accounts-with-microsoft-365-powershell.md). Choose this method if you're already familiar with using Windows PowerShell cmdlets.-- **Using ActiveDirectory?** [Set up directory synchronization for Microsoft 365](../../enterprise/set-up-directory-synchronization.md). Use the Azure AD Connect tool to replicate Active Directory user accounts (and other Active Directory objects) in Microsoft 365. The sync only adds the user accounts. You must assign licenses to the synced users before they can use email and other Office apps.-- **Migrating from Exchange?** See [Ways to migrate multiple email accounts to Office 365](/Exchange/mailbox-migration/mailbox-migration). When you migrate multiple mailboxes to Microsoft 365 by using either cutover, staged, or a hybrid Exchange method, you automatically add users as part of the migration. The migration only adds the user accounts. You must assign licenses to the users before they can use email and other Office apps. If you don't assign a license to a user, their mailbox is disabled after a grace period of 30 days. Learn how to [assign licenses to users](../manage/assign-licenses-to-users.md) in the Microsoft 365 admin center.
+- **Using ActiveDirectory?** [Set up directory synchronization for Microsoft 365](../../enterprise/set-up-directory-synchronization.md). Use the Azure AD Connect tool to replicate Active Directory user accounts (and other Active Directory objects) in Microsoft 365. The sync only adds the user accounts. You must assign licenses to the synced users before they can use email and other Microsoft 365 apps.
+- **Migrating from Exchange?** See [Ways to migrate multiple email accounts to Microsoft 365](/Exchange/mailbox-migration/mailbox-migration). When you migrate multiple mailboxes to Microsoft 365 by using either cutover, staged, or a hybrid Exchange method, you automatically add users as part of the migration. The migration only adds the user accounts. You must assign licenses to the users before they can use email and other Microsoft 365 apps. If you don't assign a license to a user, their mailbox is disabled after a grace period of 30 days. Learn how to [assign licenses to users](../manage/assign-licenses-to-users.md) in the Microsoft 365 admin center.
## Create, edit, or delete custom user views
You can also filter by additional user profile details used in your organization
## Next steps
-After you add a user, you get an email notification from Microsoft. The email contains the person's user ID and password so they can sign in to Microsoft 365. Use your normal process for communicating new passwords. Share the [Employee quickstart guide](https://support.microsoft.com/office/7f34c318-e772-46a5-8c0a-ab86661542d1) with your new users to set up things, like how to [download and install Office apps on a PC or Mac](https://support.microsoft.com/office/4414eaaf-0478-48be-9c42-23adc4716658) and how to [set up Office apps and email on a mobile device](https://support.microsoft.com/office/7dabb6cb-0046-40b6-81fe-767e0b1f014f).
+After you add a user, you get an email notification from Microsoft. The email contains the person's user ID and password so they can sign in to Microsoft 365. Use your normal process for communicating new passwords. Share the [Employee quickstart guide](https://support.microsoft.com/office/7f34c318-e772-46a5-8c0a-ab86661542d1) with your new users to set up things, like how to [Download and install or reinstall Microsoft 365 or Office 2021 on a PC or Mac](https://support.microsoft.com/office/4414eaaf-0478-48be-9c42-23adc4716658) and how to [Set up Microsoft 365 apps and email on a mobile device](https://support.microsoft.com/office/7dabb6cb-0046-40b6-81fe-767e0b1f014f).
## Related content
admin Delete A User https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/add-users/delete-a-user.md
Before you begin, think about what you want to do with the user's email and OneD
|Product licenses <br/> |You can remove the license from the user and remove it from your subscriptions to stop paying for that license. If you select this option, the license will be removed automatically from your subscriptions. <br/><br/> **You can't remove the license** if you bought it through a Partner or volume licensing. If you're paying for an annual plan or if you're in the middle of a billing cycle, you won't be able to remove the license from your subscription until your commitment is completed. <br/> | |OneDrive content <br/> |If the user saved their files to OneDrive, you can give another user access to these files. <br/><br/> You'll need to move the files you want to keep within the retention period that is set for OneDrive files. **By default, the retention period is 30 days.** If you don't move the files within the retention period after deleting the user, the OneDrive for the deleted user is moved to the site collection recycle bin, where it is kept for 93 days. During this time, users will no longer be able to access any shared content in the OneDrive. To restore the OneDrive, you need to use PowerShell. For info, see [Restore a deleted OneDrive](/onedrive/restore-deleted-onedrive).<br/><br/> To increase the number of days that you retain OneDrive files for deleted accounts, see [Set the OneDrive retention for deleted users](/onedrive/set-retention). <br/><br/> **Important!** If the deleted user used a personal computer to download files from SharePoint and OneDrive, there's no way for you to wipe those files they stored on their computer. They will continue to have access to any files that were synced from OneDrive. | |Email <br/> | Giving another user access to the deleted user's email will convert the deleted user's mailbox to a shared mailbox. The new mailbox owner can then access the mailbox and monitor for new email. You'll also have the following options: <br/> <br/>Change the display name - We recommend changing the display name so that it will be easy to identify the shared mailbox in the **Active users** list. <br/> <br/> Turn on automatic replies - We've already written a polite automatic reply for you. You can send different automatic replies to people within your organization and people from outside your organization. <br/> <br/> [Remove any existing calendar permissions](/powershell/module/exchange/remove-mailboxfolderpermission?view=exchange-ps) using PowerShell. <br/> <br/> Clean up aliases - Aliases are additional email addresses for users. Some organizations don't use them, so if you don't have any you don't need to do anything else here. If the user does have aliases, we recommend removing them so that you can reuse those email addresses. Otherwise, you can't reuse those email addresses until the retention period for deleted mailboxes has passed. By default, a deleted mailbox is recoverable for 30 days. For more information, see [Delete or restore user mailboxes in Exchange Online](/exchange/recipients-in-exchange-online/delete-or-restore-mailboxes#delete-a-user-mailbox). <br/> |
-|Active Directory <br/> |If your business uses **Active Directory** that is synchronizing with Azure AD, you need to delete the user account from Active Directory. You can't do it through Office 365. For instructions, see [Delete a User Account](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc753730(v=ws.11)). <br/> |
+|Active Directory <br/> |If your business uses **Active Directory** that is synchronizing with Azure AD, you need to delete the user account from Active Directory. You can't do it through Microsoft 365. For instructions, see [Delete a User Account](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc753730(v=ws.11)). <br/> |
### Get started
Since the guided experience walks through the steps to delete a user, here's how
2. Select the user that you want to delete, and then select **Delete user**.
-## User management admin: Delete one or more users from Office 365
+## User management admin: Delete one or more users from Microsoft 365
> [!IMPORTANT] > Don't delete a user's account if you've [converted it to a shared mailbox](../email/convert-user-mailbox-to-shared-mailbox.md) or if you've set up email forwarding on the account. Those functions still need the account. A shared mailbox doesn't require a license. If you've converted the account to a shared mailbox you can [Stop paying for the license](#stop-paying-for-the-license). If you've set up email forwarding on the account, you can't remove the license. Doing so will stop email forwarding and deactivate the mailbox.
Here are the most common issues people encounter when deleting a user:
[Restore a user](restore-user.md) (article)\ [Permanently delete a mailbox](/exchange/permanently-delete-a-mailbox-exchange-2013-help) (article)\
-[Remove a former employee from Office 365](remove-former-employee.md) (article)\
-[Add a new employee to Office 365](add-new-employee.md) (article)\
-[Delete a User Account](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc753730(v=ws.11)): Use these instructions if your business uses **Active Directory** that is synchronizing with Azure AD. You can't do it through Office 365. (article)
+[Remove a former employee from Microsoft 365](remove-former-employee.md) (article)\
+[Add a new employee to Microsoft 365](add-new-employee.md) (article)\
+[Delete a User Account](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc753730(v=ws.11)): Use these instructions if your business uses **Active Directory** that is synchronizing with Azure AD. You can't do it through Microsoft 365. (article)
admin Remove Former Employee Step 3 https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/add-users/remove-former-employee-step-3.md
description: "Use the Exchange admin center to wipe and block a former employee'
# Step 3 - Wipe and block a former employee's mobile device
-If your former employee had an organization phone, you can use the <a href="https://go.microsoft.com/fwlink/p/?linkid=2059104" target="_blank">Exchange admin center</a> to wipe and block that device so that all organization data is removed from the device and it can no longer connect to Office 365. If your organization uses Basic Mobility and Security to manage mobile devices, you can wipe and block those devices using Basic Mobility and Security.
+If your former employee had an organization phone, you can use the <a href="https://go.microsoft.com/fwlink/p/?linkid=2059104" target="_blank">Exchange admin center</a> to wipe and block that device so that all organization data is removed from the device and it can no longer connect to Microsoft 365. If your organization uses Basic Mobility and Security to manage mobile devices, you can wipe and block those devices using Basic Mobility and Security.
## Wipe mobile device using the Exchange admin center
admin Remove Former Employee Step 6 https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/add-users/remove-former-employee-step-6.md
For more information about managing user licenses for Microsoft 365 for business
## How the deleted employee account affects Skype for Business
-When you remove a user's license from Office 365, the PSTN calling number associated with the user will be released. You can assign it to another user.
+When you remove a user's license from Microsoft 365, the PSTN calling number associated with the user will be released. You can assign it to another user.
If the user belongs to a queue group, they will no longer be a viable target of the call queue agents. So, we recommend also removing the user from the groups associated with the call queue.
admin Remove Former Employee Step 7 https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/add-users/remove-former-employee-step-7.md
If you found this video helpful, check out the [complete training series for sma
## Does your organization use Active Directory?
-If your organization synchronizes user accounts to Microsoft 365 from a local Active Directory environment, you must delete and restore those user accounts in your local Active Directory service. You can't delete or restore them in Office 365.
+If your organization synchronizes user accounts to Microsoft 365 from a local Active Directory environment, you must delete and restore those user accounts in your local Active Directory service. You can't delete or restore them in Microsoft 365.
To learn how to delete and restore user account in Active Directory, see [Delete a User Account](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc753730(v=ws.11)).
admin Reset Passwords https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/add-users/reset-passwords.md
If you found this video helpful, check out the [complete training series for sma
## Let users reset their own passwords
-We strongly recommend that you set up self-service password reset. This way you don't have to manually reset passwords for your users. Less work for you! To learn how, see [Let users reset their own passwords in Office 365](let-users-reset-passwords.md).
+We strongly recommend that you set up self-service password reset. This way you don't have to manually reset passwords for your users. Less work for you! To learn how, see [Let users reset their own passwords in Microsoft 365](let-users-reset-passwords.md).
## Resend user password
Check out this great blog post by Vasil Michev, Microsoft MVP: [Force password c
## I don't have a Microsoft 365 for business subscription
-Try this article: [I forgot the username or password for the account I use with Office.](https://support.microsoft.com/office/eba0b4a2-c0ae-472c-99f6-bc63ee2425a8?wt.mc_id=SCL_reset-passwords_AdmHlp)
+Try this article: [I forgot the username or password for the account I use with Microsoft 365.](https://support.microsoft.com/office/eba0b4a2-c0ae-472c-99f6-bc63ee2425a8?wt.mc_id=SCL_reset-passwords_AdmHlp)
## Related content
admin Restore User https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/add-users/restore-user.md
Here are a couple of tips:
- Make sure licenses are available to assign to the account. -- If your business uses Active Directory, for instructions on restoring a user account, see [How to troubleshoot deleted user accounts in Office 365](/office365/troubleshoot/active-directory/restore-deleted-user-accounts).
-
+- If your business uses Active Directory, for instructions on restoring a user account, see [How to restore deleted user accounts in Microsoft 365, Azure, and Intune](/microsoft-365/troubleshoot/active-directory/restore-deleted-user-accounts).
+ ## Restore one or more user accounts You must be a Microsoft 365 global admin or user management admin to do these steps.
admin Admin Center Overview https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/admin-overview/admin-center-overview.md
Here are the features and settings you'll find in the left-hand navigation of th
|**Resources**|Create and manage resources, like a SharePoint site collection. Learn how to [create site collections](/sharepoint/create-site-collection).| |**Billing**|View, purchase, or cancel subscriptions for your organization. View past billing statements or view the number of assigned licenses to individual users. Learn how to [manage billing](../../commerce/index.yml).| |**Support**|View existing service requests or create new ones. Learn more in [Contact support for business products - Admin Help](../../business-video/get-help-support.md).|
-|**Settings**|Manage global settings for apps like email, sites, and the Office suite. Change your password policy and expiration date. Add and update domain names like contoso.com. Change your organization profile and release preferences. And choose whether partners can access your admin center.|
-|**Setup**|Manage existing domains, turn on and manage multi-factor authentication, manage admin access, migrate user mailboxes to Office 365, manage feature updates, and help users install their Office apps.|
-|**Reports**|See at a glance how your organization is using Microsoft 365 with detailed reports on email use, Office activations, and more. Learn how to use the new [activity reports](../activity-reports/activity-reports.md).|
+|**Settings**|Manage global settings for apps like email, sites, and Microsoft 365. Change your password policy and expiration date. Add and update domain names like contoso.com. Change your organization profile and release preferences. And choose whether partners can access your admin center.|
+|**Setup**|Manage existing domains, turn on and manage multi-factor authentication, manage admin access, migrate user mailboxes to Microsoft 365, manage feature updates, and help users install their Microsoft 365 apps.|
+|**Reports**|See at a glance how your organization is using Microsoft 365 with detailed reports on email use, Microsoft 365 activations, and more. Learn how to use the new [activity reports](../activity-reports/activity-reports.md).|
|**Health**|View health at a glance. You can also check out more details and the health history. See [How to check service health](../../enterprise/view-service-health.md) and [How to check Windows release health](/windows/deployment/update/check-release-health) for more information. <p> Use Message center to keep track of upcoming changes to features and services. We post announcements there with information that helps you plan for change and understand how it may affect users. Get more details in [Message center](../manage/message-center.md).| |**Admin centers**|Open separate admin centers for Exchange, Skype for Business, SharePoint, Yammer, and Azure AD. Each admin center includes all available settings for that service. <p> For example, in the Exchange admin center, set up and manage email, calendars, distribution groups, and more. In the SharePoint admin center, create and manage site collections, site settings, and OneDrive for Business. In the Skype for Business admin center, set up instant messaging notifications, dial-in conferencing, and online presence. <p> Learn more about the [Exchange admin center](/exchange/exchange-admin-center) and [SharePoint Admin Center](/sharepoint/sharepoint-online). <p> **Note:** The admin centers available to you depend on your plan and region.|
Check out this video and others on our [YouTube channel](https://go.microsoft.co
With the <a href="https://go.microsoft.com/fwlink/p/?linkid=2024339" target="_blank">Microsoft 365 admin center</a>, you can reset passwords, view your invoice, add or remove users, and much more all in one place.
-Sign in to Office.com with your work account, and select the app launcher.
+Sign in to Microsoft365.com with your work account, and select the app launcher.
If you have permission to access the admin center, you'll see **Admin** in the list. Select it.
Don't see your questions answered here? Go to the **Feedback** section at the bo
### Which Microsoft 365 plans are available to trial or buy?
-Microsoft 365 is a complete, intelligent solution that includes Office 365, Windows 10, and Enterprise Mobility + Security that empowers everyone to be creative and work together, securely. The following Microsoft 365 subscriptions are available in the admin center for you to try or buy now:
+Microsoft 365 is a complete, intelligent solution that includes Microsoft 365, Windows 10, and Enterprise Mobility + Security that empowers everyone to be creative and work together, securely. The following Microsoft 365 subscriptions are available in the admin center for you to try or buy now:
- Microsoft 365 for business - Microsoft 365 Enterprise E3
admin Sign Up For Office 365 https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/admin-overview/sign-up-for-office-365.md
search.appverid: - MET150
-description: "Understand what you need to know about the latest versions of the Office programs before you go through the sign-up process for Office 365."
+description: "Understand what you need to know about the latest versions of the Microsoft 365 apps before you go through the sign-up process for Microsoft 365."
Last updated 03/17/2021
Check out all of our small business content on [Small business help & learning](
Check out [Microsoft 365 small business help](https://go.microsoft.com/fwlink/?linkid=2197659) on YouTube.
-Sign up for Microsoft 365 for business so that your team can begin using the latest versions of Word, Excel, PowerPoint, and other Office programs.
+Sign up for Microsoft 365 for business so that your team can begin using the latest versions of Word, Excel, PowerPoint, and other Microsoft 365 apps.
::: moniker range="o365-21vianet"
admin What Is Microsoft 365 For Business https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/admin-overview/what-is-microsoft-365-for-business.md
Microsoft 365 for business provides the following plans to select from to help y
|Plan|Description| |||
-|[Microsoft 365 Apps for Business](https://www.microsoft.com/microsoft-365/business/microsoft-365-apps-for-business)|<ul><li>Get desktop versions of Office apps: Outlook, Word, Excel, PowerPoint, OneNote (plus Access and Publisher for PC only).</li><li>Store and share files with 1 TB of OneDrive cloud storage per user.</li><li>Use one license to cover fully installed Office apps on five mobile devices, five tablets, and five PCs or Macs per user.</li><li>Automatically update your apps with new features and capabilities every month.</li><li>Get help anytime with around-the-clock phone and web support from Microsoft.</li></ul>|
-|[Microsoft 365 Business Basic](https://www.microsoft.com/microsoft-365/business/microsoft-365-business-basic)|<ul><li>Host email with a 50 GB mailbox and custom email domain address.</li><li>Create a hub for teamwork to connect people using Microsoft Teams.</li><li>Use Office apps for the web, including Outlook, Word, Excel, PowerPoint, and OneNote.</li><li>Store and share files with 1 TB of OneDrive cloud storage per user.</li><li>Facilitate online meetings and video conferencing for up to 300 users.</li><li>Get help anytime with around-the-clock phone and web support from Microsoft.</li></ul>|
-|[Microsoft 365 Business Standard](https://www.microsoft.com/microsoft-365/business/microsoft-365-business-standard)|<ul><li>Get desktop versions of Office apps, including Outlook, Word, Excel, PowerPoint, and OneNote (plus Access and Publisher for PC only).</li><li>Host email with a 50 GB mailbox and custom email domain.</li><li>Create a hub for teamwork to connect people using Microsoft Teams.</li><li>Store and share files with 1 TB of OneDrive cloud storage per user.</li><li>Use one license to cover fully installed Office apps on five mobile devices, five tablets, and five PCs or Macs per user.</li><li>Get help anytime with around-the-clock phone and web support from Microsoft.</li></ul>|
+|[Microsoft 365 Apps for Business](https://www.microsoft.com/microsoft-365/business/microsoft-365-apps-for-business)|<ul><li>Get desktop versions of Microsoft 365 apps: Outlook, Word, Excel, PowerPoint, OneNote (plus Access and Publisher for PC only).</li><li>Store and share files with 1 TB of OneDrive cloud storage per user.</li><li>Use one license to cover fully installed Microsoft 365 apps on five mobile devices, five tablets, and five PCs or Macs per user.</li><li>Automatically update your Microsoft 365 apps with new features and capabilities every month.</li><li>Get help anytime with around-the-clock phone and web support from Microsoft.</li></ul>|
+|[Microsoft 365 Business Basic](https://www.microsoft.com/microsoft-365/business/microsoft-365-business-basic)|<ul><li>Host email with a 50 GB mailbox and custom email domain address.</li><li>Create a hub for teamwork to connect people using Microsoft Teams.</li><li>Use Microsoft 365 apps for the web, including Outlook, Word, Excel, PowerPoint, and OneNote.</li><li>Store and share files with 1 TB of OneDrive cloud storage per user.</li><li>Facilitate online meetings and video conferencing for up to 300 users.</li><li>Get help anytime with around-the-clock phone and web support from Microsoft.</li></ul>|
+|[Microsoft 365 Business Standard](https://www.microsoft.com/microsoft-365/business/microsoft-365-business-standard)|<ul><li>Get desktop versions of Microsoft 365 apps, including Outlook, Word, Excel, PowerPoint, and OneNote (plus Access and Publisher for PC only).</li><li>Host email with a 50 GB mailbox and custom email domain.</li><li>Create a hub for teamwork to connect people using Microsoft Teams.</li><li>Store and share files with 1 TB of OneDrive cloud storage per user.</li><li>Use one license to cover fully installed Microsoft 365 apps on five mobile devices, five tablets, and five PCs or Macs per user.</li><li>Get help anytime with around-the-clock phone and web support from Microsoft.</li></ul>|
|[Microsoft 365 Business Premium](https://www.microsoft.com/microsoft-365/business/microsoft-365-business-premium)|<ul><li>Stay up to date with the latest versions of Word, Excel, PowerPoint, and more.</li><li>Connect with customers and coworkers using Outlook, Exchange, and Microsoft Teams.</li><li>Manage your files from anywhere with 1 TB of cloud storage on OneDrive per user.</li><li>Defend your business against advanced cyberthreats with sophisticated phishing and ransomware protection.</li><li>Control access to sensitive information using encryption to help keep data from being accidentally shared.</li><li>Secure devices that connect to your data and help keep iOS, Android, Windows, and MacOS devices safe and up to date.</li></ul>| ### Need help with choosing a plan?
admin Content Collaboration https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/adoption/content-collaboration.md
Types considered for this information include Word, Excel, PowerPoint, OneNote,
They're defined as follows:</br> **Readers:** People who access or download online files in OneDrive or SharePoint.</br> **Creators:** People who create, modify, upload, sync, check in, copy, or move online OneDrive or SharePoint files.</br>
- **Collaborators:** People who collaborate with online files by using OneDrive or SharePoint. Two people are collaborators if one of them reads or edits an online Office app or PDF after the other person has created or modified it, within a 28-day window.
+ **Collaborators:** People who collaborate with online files by using OneDrive or SharePoint. Two people are collaborators if one of them reads or edits an online Microsoft 365 app or PDF after the other person has created or modified it, within a 28-day window.
> [!NOTE] > The files considered in the visualization are Word, Excel, PowerPoint, OneNote, or PDF files that are online and saved to OneDrive or SharePoint.
The trend visualizations chart shows the trend-line of the primary insight key m
### Scoring framework
-The content collaboration score for your organization measures at an aggregate (organization) level whether people are consistently reading, creating, or collaborating on online Office files such as Word, Excel, PowerPoint, OneNote, or PDFs, or in OneDrive or SharePoint.
+The content collaboration score for your organization measures at an aggregate (organization) level whether people are consistently reading, creating, or collaborating on online Microsoft 365 files such as Word, Excel, PowerPoint, OneNote, or PDFs, or in OneDrive or SharePoint.
Scores are not provided at the individual user level.
We also provide you with information that helps you gain visibility into how you
:::image type="content" source="../../media/sharepointonedrivefiles.jpg" alt-text="Chart that shows number of people who create files in OneDrive or SharePoint.":::
-1. **Header:** Highlights the percentage of people active on Microsoft 365 Office applications who create files on OneDrive or SharePoint.
+1. **Header:** Highlights the percentage of people active on Microsoft 365 apps who create files on OneDrive or SharePoint.
2. **Body:** Provides information about the value of content creation in OneDrive and SharePoint.
-3. **Visualization:** The breakdown in the visualization represents the extent to which people who are using Microsoft Office apps to create files in OneDrive and SharePoint, as follows:
- - **OneDrive:** The blue (colored) portion of the bar and the fraction on the bar represent the percentage of people active on Office applications creating content on OneDrive as follows:
- - Numerator: The number of people who create, modify, upload, sync, check in, copy, or move online Office files in OneDrive within the last 28 days.</br>
+3. **Visualization:** The breakdown in the visualization represents the extent to which people who are using Microsoft 365 apps to create files in OneDrive and SharePoint, as follows:
+ - **OneDrive:** The blue (colored) portion of the bar and the fraction on the bar represent the percentage of people active on Microsoft 365 apps creating content on OneDrive as follows:
+ - Numerator: The number of people who create, modify, upload, sync, check in, copy, or move online Microsoft 365 files in OneDrive within the last 28 days.</br>
- Denominator: The number of people who have access to OneDrive or SharePoint and access office files within the last 28 days.
- - **SharePoint:** The blue (colored) portion of the bar and the fraction on the bar represent the percentage of people who are active on Office applications and create content on SharePoint as:</br>
- - Numerator: The number of people who create, modify, upload, sync, check in, copy, or move online Office files (Microsoft Word, Excel, PowerPoint, or OneNote files) on SharePoint within the last 28 days. </br>
- - Denominator: The number of people who have access to OneDrive or SharePoint and have accessed Office files within the last 28 days.
+ - **SharePoint:** The blue (colored) portion of the bar and the fraction on the bar represent the percentage of people who are active in Microsoft 365 apps and create content on SharePoint as:</br>
+ - Numerator: The number of people who create, modify, upload, sync, check in, copy, or move online Microsoft 365 files (Microsoft Word, Excel, PowerPoint, or OneNote files) on SharePoint within the last 28 days. </br>
+ - Denominator: The number of people who have access to OneDrive or SharePoint and have accessed Microsoft 365 files within the last 28 days.
4. **Link to resources:** Select this link to view help content.
admin Organizational Messages https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/adoption/organizational-messages.md
Once messages have been created, you'll see the reporting in the table under the
A: For any given message, not every user **in its selected audience** (selected as message recipients) will receive the message. This is expected behavior because the message delivery depends on other factors that affect a message's reach, including: -- **User behavior**: some delivery channels require the user to go to a specific location/app to have a chance to see the message (for example, an Office desktop app call-out message can only be delivered to a user who opens the Office desktop app).
+- **User behavior**: some delivery channels require the user to go to a specific location/app to have a chance to see the message (for example, a Microsoft 365 app call-out message can only be delivered to a user who opens the Microsoft 365 app).
- **System protections to prevent over-messaging and user dissatisfaction**: some communication channels have message frequency limits if too many messages are live at a given time (for example, a Teaching call-out won't appear more than twice to each user).
admin Restore Deleted Group https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/create-groups/restore-deleted-group.md
If you are a global administrator or a groups administrator, you can restore a d
## Got questions about Microsoft 365 Groups?
-Visit the [Microsoft Tech Community](https://techcommunity.microsoft.com/t5/Office-365-Groups/ct-p/Office365Groups) to post questions and participate in conversations about Microsoft 365 groups.
+Visit the [Microsoft Tech Community](https://techcommunity.microsoft.com/t5/microsoft-365-groups/bd-p/Microsoft365Groups) to post questions and participate in conversations about Microsoft 365 groups.
## Related content
admin Create A Shared Mailbox https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/email/create-a-shared-mailbox.md
But what if an admin simply resets the password of the shared mailbox user accou
4. In the **Block this user?** pane, select **Block the user from signing in**, and then select **Save changes**.
-For instructions on how to block sign-in for accounts using Azure AD PowerShell (including many accounts at the same time), see [Block user accounts with Office 365 PowerShell](../../enterprise/block-user-accounts-with-microsoft-365-powershell.md).
+For instructions on how to block sign-in for accounts using Azure AD PowerShell (including many accounts at the same time), see [Block Microsoft 365 user accounts with PowerShell](../../enterprise/block-user-accounts-with-microsoft-365-powershell.md).
## Add the shared mailbox to Outlook
admin Dns Basics https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/get-help-with-domains/dns-basics.md
Domain names are used in URLs and email addresses, and they have different level
Why use a third-level domain? You might want to have different domain names for marketing or a blog. For example, blog.contoso.com. You typically add a second-level domain, like contoso.com, to use with Microsoft but you can also use third-level domains if you like.
-Learn more about what you can do with domains for each type of offering in the [Microsoft 365 and Office 365 platform service description](/office365/servicedescriptions/office-365-platform-service-description/domains).
+Learn more about what you can do with domains for each type of offering in the [Microsoft 365 feature descriptions](/microsoft-365/admin/m365-feature-descriptions?tabs=Domains).
## Understand DNS record types
Why might your domain's zone file be somewhere besides at your domain registrar?
Adding a custom domain, like fourthcoffee.com, to Microsoft 365 lets you use a shorter, more familiar email address and userID with the service. You're [given a domain to use](../setup/domains-faq.yml) when you sign up for a Microsoft 365 account, but it includes "onmicrosoft.com." Many people prefer to add their organization or business domain if they plan to use Microsoft 365 for email. > [!NOTE]
-> If you just want to download and use Microsoft apps, like Outlook or Word, you don't need to add a domain: [Install Office on your PC or Mac](https://support.microsoft.com/office/4414eaaf-0478-48be-9c42-23adc4716658).
+> If you just want to download and use Microsoft 365 apps, like Outlook or Word, you don't need to add a domain: [Download and install or reinstall Microsoft 365 or Office 2021 on a PC or Mac](https://support.microsoft.com/office/4414eaaf-0478-48be-9c42-23adc4716658).
You can use your domain name in Microsoft 365 with your email, public website, and instant messaging address.
admin Remove A Domain https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/get-help-with-domains/remove-a-domain.md
For example, change the MX record at your DNS host. Email sent to your domain st
- Before you update the MX record, let your users know the date you plan to switch their email, and the new email provider you plan to use. Also, if your users want to move their existing Microsoft email to the new provider, they must take extra steps. -- On the day you change the MX record, make sure to [save your data](/microsoft-365/commerce/subscriptions/cancel-your-subscription#save-your-data) and [uninstall Office if needed](/microsoft-365/commerce/subscriptions/cancel-your-subscription#uninstall-office-optional).
+- On the day you change the MX record, make sure to [save your data](/microsoft-365/commerce/subscriptions/cancel-your-subscription#save-your-data) and [uninstall Microsoft 365 if needed](/microsoft-365/commerce/subscriptions/cancel-your-subscription#uninstall-office-optional).
#### Update your domain MX and other DNS records (if you're using a custom domain)
admin Assign Licenses To Users https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/manage/assign-licenses-to-users.md
You can invite guest users to collaborate with your organization in the Azure Ac
## Next steps
-If your users don't yet have the Office apps installed, you can share the [Employee quick start guide](https://support.microsoft.com/office/7f34c318-e772-46a5-8c0a-ab86661542d1) with your users to set up things, like [how to download and install Microsoft 365 or Office 2019 on a PC or Mac](https://support.microsoft.com/office/4414eaaf-0478-48be-9c42-23adc4716658) and [how to set up Office apps and email on a mobile device](https://support.microsoft.com/office/7dabb6cb-0046-40b6-81fe-767e0b1f014f).
+If your users don't yet have the Microsoft 365 apps installed, you can share the [Employee quick start guide](https://support.microsoft.com/office/7f34c318-e772-46a5-8c0a-ab86661542d1) with your users to set up things, like [Download and install or reinstall Microsoft 365 or Office 2021 on a PC or Mac](https://support.microsoft.com/office/4414eaaf-0478-48be-9c42-23adc4716658) and [Set up Microsoft 365 apps and email on a mobile device](https://support.microsoft.com/office/7dabb6cb-0046-40b6-81fe-767e0b1f014f).
## Related content
admin Change Address Contact And More https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/manage/change-address-contact-and-more.md
An explanation of each field is provided below.
||| |Name <br/> | The name entered here is what users will see on the following pages: <br/> Sign-in page: If your users have set up other Microsoft accounts with their business or school email address, they may see the organization name on the sign-in page. This helps them distinguish between their work or school account and their other accounts, so they can identify which one to use when they sign in. <br/> Organization profile link and page: The link to your organization's profile displays the organization name. <br/> Yammer navigation: In Yammer, the left navigation uses the organization name as the name of the home Yammer network. <br/> OneDrive sync client: The organization name is shown in File Explorer on Windows and Finder on Mac, the file paths, the OneDrive activity center, the tooltip of the OneDrive cloud icon, and the OneDrive settings window. Currently, updating the organization name does not update it for configured clients. <br/> MS Teams: Organization Switcher in Teams displays the organization Name <br/> | |Address, City, State/Province, Postal code <br/> | The address entered here is what you will see on your bill, under Sold To: The Sold To address on your bill is the same as your organization address on your profile page (see [Understand your bill or invoice for Microsoft 365 for business](../../commerce/billing-and-payments/understand-your-invoice2.md). <br/> |
-|Country or region <br/> | This is the country or region where the company is headquartered. The selected country or region determines which services are available to you, the taxes and billing currency for your country or region, and the location of the data center closest to you (see [Microsoft Office license restrictions](https://office.microsoft.com/redir/FX103037529)).<br/>NOTE: Once selected, the country or region cannot be changed. If you want to change the selection, you'll have to cancel your subscription and sign up again. For help with this process, [contact support](../../business-video/get-help-support.md). |
+|Country or region <br/> | This is the country or region where the company is headquartered. The selected country or region determines which services are available to you, the taxes and billing currency for your country or region, and the location of the data center closest to you (see [About license restrictions](https://www.microsoft.com/microsoft-365/business/microsoft-office-license-restrictions)).<br/>NOTE: Once selected, the country or region cannot be changed. If you want to change the selection, you'll have to cancel your subscription and sign up again. For help with this process, [contact support](../get-help-support.md). |
|Phone <br/> | This is the primary number for your company. It's usually the number of your company headquarters. <br/> | |Technical contact <br/> |This is the email address for the primary technical person who administers your Microsoft 365 subscription. This is the person who will receive communications about Microsoft 365 service status. <br/> | |Preferred language <br/> |The preferred language determines the language for all communications that are sent from Microsoft to your organization. When you sign up, this setting determines the language used by SharePoint Online, which your users see on your team site. If you change the language preference setting after you sign up, all future communications are sent in the most recent language selected. <br/> NOTE: The language used by SharePoint Online can't be changed. |
admin Health Dashboard Overview https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/manage/health-dashboard-overview.md
At the bottom of the dashboard, youΓÇÖll see recommendations on what you can do
- **Turn on multi-factor authentication**: See a summary of how many accounts are currently enabled for multi-factor authentication (MFA), and a link to the MFA setup wizard. -- **Turn on monthly updates for Office**: See whether your organization's Office update frequency is set so that you receive updates more than once every six months.
+- **Turn on monthly updates for Microsoft 365**: See whether your organization's Microsoft 365 update frequency is set so that you receive updates more than once every six months.
- **Share OneDrive training**: Encourage users to store files in OneDrive to help with recovery against ransomware or device failure. Send them a video overview to help them set up and use OneDrive.
admin Idle Session Timeout Web Apps https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/manage/idle-session-timeout-web-apps.md
When a user has been inactive in Microsoft 365 web apps for the time period you
- SharePoint Online (SPO)
- - Office.com and other start pages
+ - Microsoft365.com and other start pages
- - Office (Word, Excel, PowerPoint) on the web
+ - Microsoft 365 apps (Word, Excel, PowerPoint) on the web
- - Microsoft 365 Admin Center
+ - Microsoft 365 admin center
- Activity refers to any client-side user interaction happening in the context of the web app. For example, mouse clicks and keyboard presses.
If you're already using existing Outlook web app and SharePoint Online idle time
### What happens if I am inactive on an included Microsoft 365 web app, but active on a Microsoft web app or SaaS web app that doesn't have idle session timeout turned on?
-The following Microsoft 365 web apps are supported.
+The following Microsoft 365 apps are supported.
- Outlook Web App
The following Microsoft 365 web apps are supported.
- SharePoint Online (SPO) -- Office.com and other start pages
+- Microsoft365.com and other start pages
-- Office (Word, Excel, PowerPoint) on the web
+- Microsoft 365 apps (Word, Excel, PowerPoint) on the web
-- Microsoft 365 Admin Center
+- Microsoft 365 admin center
If you're working on a different web app with the same account, the activity in that web app won't be applied to the idle session timeout.
Delete the policy:
1. In the Microsoft 365 admin center, select **Org settings**, go to the **Security & Privacy** tab and select **Idle session timeout**.
-2. Uncheck **Turn on to set the period of inactivity for users to be signed off of Office web apps** and select **Save**.
+2. Uncheck **Turn on to set the period of inactivity for users to be signed off of Microsoft 365 apps** and select **Save**.
admin Manage Feedback Ms Org https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/manage/manage-feedback-ms-org.md
The table below represents which apps and services are currently connected to th
|**Intune Company Portal (Android)**|Yes|Yes|Yes|Yes| |**Microsoft Stream (Android, iOS)**|Yes|Yes|Yes|Yes| |**Microsoft Whiteboard**|Yes|Yes|Yes|Yes|
-|**Office.com**|Yes|Yes|Yes|Yes|
+|**Microsoft365.com**|Yes|Yes|Yes|Yes|
|**OneNote**|Yes|Yes|Yes|Yes| |**OneDrive**|[Some settings currently managed by other controls.](/onedrive/disable-contact-support-send-feedback)|||| |**Outlook (Web, iOS)**|Coming soon|Coming soon|Coming soon|Coming soon|
Your devices must be on a minimum build number to use these policies. See the ta
## Configure policies
-To configure these policy settings, you can use the Office cloud policy service. For more information, see [Overview of the Office cloud policy service](/deployoffice/overview-office-cloud-policy-service). You can search for "feedback" or "survey" within the Office cloud policy service UI to find the policy settings to configure them.
+To configure these policy settings, you can use the Cloud Policy service for Microsoft 365. For more information, see [Overview of the Cloud Policy service for Microsoft 365](/deployoffice/overview-office-cloud-policy-service). You can search for "feedback" or "survey" within the Cloud Policy service for Microsoft 365 UI to find the policy settings to configure them.
These policy settings are also available if you use Group Policy. To use these policy settings, download at least version 5146.1000 of the [Administrative Template files (ADMX/ADML)](https://www.microsoft.com/download/details.aspx?id=49030), released on March 22, 2021.
admin Manage Feedback Product Insights https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/manage/manage-feedback-product-insights.md
You can export raw data for further analysis using the Export to CSV functionali
You can filter by **Channels**, **Products**, **Platforms** and **Feedback Types**.
-**Channels** are a way for organizations to select how often they get feature updates for Office. Learn more at [Overview of update channels for Microsoft 365 Apps](/deployoffice/overview-update-channels). This filter allows you to filter down to feedback submitted from a user on a specific channel.
+**Channels** are a way for organizations to select how often they get feature updates for Microsoft 365. Learn more at [Overview of update channels for Microsoft 365 apps](/deployoffice/overview-update-channels). This filter allows you to filter down to feedback submitted from a user on a specific channel.
Feedback can be submitted on various **Platforms** like Android, iOS, Mac, and Windows. This filter allows you to filter feedback based on the platform it was submitted on.
admin Manage Industry News https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/manage/manage-industry-news.md
When your users sign in to Microsoft Edge (release 87 or higher) with a valid wo
1. In the Microsoft 365 admin center, go to **Settings** > **Org settings** > **Services** > [News](https://admin.microsoft.com/adminportal/home?#/Settings/Services/:/Settings/L1/BingNews). 2. In the **News** panel, click **Microsoft Edge new tab page**.
-3. Select **Allow Office 365 content on the new tab page**. When enabled, users can customize their new tab to show information from Office 365, including recommended and recent files, along with frequently used SharePoint sites and other information.
+3. Select **Allow Microsoft 365 content on the new tab page**. When enabled, users can customize their new tab to show information from Microsoft 365, including recommended and recent files, along with frequently used SharePoint sites and other information.
4. Select **Show company information and industry news on the new tab page**. News articles about your organization and industry appear for users that choose to see articles on their new tab. ## Related content
admin Manage Office Scripts Settings https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/manage/manage-office-scripts-settings.md
description: "Learn how to manage Office Scripts settings for users in your orga
- To manage Office Scripts settings, you must be a Global admin. For more information, see [About admin roles](../add-users/about-admin-roles.md). -- Ensure users in your organization have a valid license for a Microsoft 365 or Office 365 commercial or EDU plan that includes access to Office desktop apps, such as one of the following plans:
+- Ensure users in your organization have a valid license for a Microsoft 365 or Office 365 commercial or EDU plan that includes access to Microsoft 365 apps, such as one of the following plans:
- Microsoft 365 Business Standard - Microsoft 365 Apps for business
admin Pin Apps To App Launcher https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/manage/pin-apps-to-app-launcher.md
description: "As a global admin you can pin up to three apps to your users' app
# Pin apps to your users' app launcher
-You can use controls in the Azure Active Directory portal to pin up to three apps to Office.com and the app launcher for all the users in your organization. You can also organize groups of applications. Any app you add can later be unpinned by the user at any time. To pin an app for your users, you must be a Cloud application administrator, or Application administrator in Azure Active Directory, or a Global administrator in Microsoft 365. For more information about admin roles, see [Azure AD built-in roles](/azure/active-directory/roles/permissions-reference) and [admin roles in Microsoft 365](../add-users/about-admin-roles.md).
+You can use controls in the Azure Active Directory portal to pin up to three apps to Microsoft365.com and the app launcher for all the users in your organization. You can also organize groups of applications. Any app you add can later be unpinned by the user at any time. To pin an app for your users, you must be a Cloud application administrator, or Application administrator in Azure Active Directory, or a Global administrator in Microsoft 365. For more information about admin roles, see [Azure AD built-in roles](/azure/active-directory/roles/permissions-reference) and [admin roles in Microsoft 365](../add-users/about-admin-roles.md).
-For more information about the app launcher and Office.com, see [meet the app launcher](https://support.microsoft.com/office/79f12104-6fed-442f-96a0-eb089a3f476a) and [updates to office.com and the-Office 365 app launcher](https://techcommunity.microsoft.com/t5/office-365-blog/updates-to-office-com-and-the-office-365-app-launcher/ba-p/1150503) blog article.
+For more information about the app launcher and Microsoft365.com, see [meet the app launcher](https://support.microsoft.com/office/79f12104-6fed-442f-96a0-eb089a3f476a) and [updates to office.com and the-Office 365 app launcher](https://techcommunity.microsoft.com/t5/office-365-blog/updates-to-office-com-and-the-office-365-app-launcher/ba-p/1150503) blog article.
## Use the Azure Active Directory portal to pin apps
For more information about the app launcher and Office.com, see [meet the app la
1. Go to the Microsoft 365 admin center at <a href="https://go.microsoft.com/fwlink/p/?linkid=2024339" target="_blank">https://admin.microsoft.com</a>. 2. In the left nav, choose **Show all**, and under **Admin centers**, choose **Azure Active Directory**.
-3. In **Azure Active Directory**, choose **Enterprise applications** > **User settings**.
-4. In the **Office 365 Settings** section, choose **Add application**.
+3. In **Azure Active Directory**, choose **Enterprise applications** > **App launchers** > **Settings**.
+4. In the **Microsoft 365 settings** section, choose **Add application**.
5. Choose the applications you want to pin to the users' app launcher, and then choose **Add**. - ### Pin a custom app > [!NOTE]
admin Remove Licenses From Users https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/manage/remove-licenses-from-users.md
You can unassign licenses from users on either the **Active users** page, or on
## Before you begin - You must be a Global, License, User admin to unassign licenses. For more information, see [About Microsoft 365 admin roles](../add-users/about-admin-roles.md).-- You can [remove licenses from user accounts with Office 365 PowerShell](../../enterprise/remove-licenses-from-user-accounts-with-microsoft-365-powershell.md).
+- You can [remove licenses from user accounts with Microsoft 365 PowerShell](../../enterprise/remove-licenses-from-user-accounts-with-microsoft-365-powershell.md).
- You can also [delete user accounts](../add-users/delete-a-user.md) that were assigned a license to make their license available to other users. When you delete a user account, their license is immediately available to assign to someone else. - If you're a Cloud Solution Provider (CSP) and you bought products on behalf of a customer, you can't use the **Your products** page to assign or unassign licenses for certain products, like perpetual software. To assign or unassign licenses for those products, [use the Licenses page](#use-the-licenses-page-to-unassign-licenses).
When you use the **Active users** page to unassign licenses, you unassign produc
- When the license is removed, the user's mailbox is no longer searchable by using an eDiscovery tool such as Content Search or eDiscovery (Premium). For more information, see "Searching disconnected or de-licensed mailboxes" in [Content Search in Microsoft 365](../../compliance/ediscovery-content-search.md). - If you have an Enterprise subscription, like Office 365 Enterprise E3, Exchange Online lets you preserve the mailbox data of a deleted user account by using [inactive mailboxes](../../compliance/inactive-mailboxes-in-office-365.md). For more information, see [Create and manage inactive mailboxes in Exchange Online](../../compliance/create-and-manage-inactive-mailboxes.md). - To learn how to block a user's access to Microsoft 365 data after their license is removed, and how to get access to the data afterwards, see [Remove a former employee](../add-users/remove-former-employee.md).-- If you remove a user's license and they still have Office apps installed, they see [Unlicensed Product and activation errors in Office](https://support.microsoft.com/office/0d23d3c0-c19c-4b2f-9845-5344fedc4380) when they use Office apps.
+- If you remove a user's license and they still have Microsoft 365 apps installed, they see [Unlicensed Product and activation errors in Office](https://support.microsoft.com/office/0d23d3c0-c19c-4b2f-9845-5344fedc4380) when they use Microsoft 365 apps.
## Next steps
business-premium M365bp Mdb Whats New https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/business-premium/m365bp-mdb-whats-new.md
audience: Admin Previously updated : 03/23/2023 Last updated : 03/24/2023 ms.localizationpriority: medium
This article lists new features in the latest release of [Microsoft 365 Business
- **Monthly security summary report (preview) is added to Defender for Business** (preview). The new monthly security summary report shows how secure your organization is across identity, devices, information, and apps. You can view threats detected (and blocked) by Defender for Business together with your current status from Microsoft Secure Score. Recommendations to improve your security are also provided. See [Reports in Microsoft Defender for Business](../security/defender-business/mdb-reports.md). -- **Device exposure score is now visible in Microsoft 365 Lighthouse** (preview). Microsoft Cloud Solution Providers (CSPs) who are using [Microsoft 365 Lighthouse](../lighthouse/m365-lighthouse-overview.md) can now view and manage device exposure scores across customer tenants. These capabilities enable partners to discover which customers' devices are at risk because of vulnerabilities. See [Microsoft 365 Lighthouse and Microsoft Defender for Business](../security/defender-business/mdb-lighthouse-integration.md).
+- **Device exposure score is now visible in Microsoft 365 Lighthouse** (preview). Microsoft Cloud Solution Providers (CSPs) who are using [Microsoft 365 Lighthouse](../lighthouse/m365-lighthouse-overview.md) can now view and manage device exposure scores across customer tenants. These capabilities enable partners to discover which customers' devices are at risk because of vulnerabilities. See [Overview of the Vulnerability management page in Microsoft 365 Lighthouse](/microsoft-365/lighthouse/m365-lighthouse-vulnerability-management-page-overview).
## January 2023
This article lists new features in the latest release of [Microsoft 365 Business
## See also
-[What's new in Microsoft 365 Lighthouse](../lighthouse/m365-lighthouse-whats-new.md)
+[What's new in Microsoft 365 Lighthouse](../lighthouse/m365-lighthouse-whats-new.md)
commerce Close Your Account https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/commerce/close-your-account.md
Delete all users except for one global administrator. The global administrator c
If users are synchronized from on-premises, first turn off sync, then delete the users in the cloud directory by using the Azure portal or Azure PowerShell cmdlets.
-To delete users, see [User management admin: Delete one or more users](../admin/add-users/delete-a-user.md#user-management-admin-delete-one-or-more-users-from-office-365).
+To delete users, see [User management admin: Delete one or more users](../admin/add-users/delete-a-user.md#user-management-admin-delete-one-or-more-users-from-microsoft-365).
You can also use the [Remove-MsolUser](/powershell/module/msonline/remove-msoluser) PowerShell cmdlet to delete users in bulk.
compliance Apply Retention Labels Automatically https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/compliance/apply-retention-labels-automatically.md
f1.keywords:
Previously updated : 03/06/2023 Last updated : 03/24/2023 audience: Admin
Or, you can automatically apply retention labels to newly shared [cloud attachme
When you configure retention labels to auto-apply based on sensitive information, keywords or searchable properties, or trainable classifiers, use the following table to identify when retention labels can be automatically applied.
+SharePoint items that are in draft or that have never been published aren't supported for this scenario.
+ Exchange: |Condition|Items in transit (sent or received) |Existing items (data at rest)| |:--|:--|:--|
-|Sensitive info types - built-in| Yes | No |
-|Sensitive info types - custom| Yes | No |
+|Sensitive info types | Yes | No |
|Specific keywords or searchable properties| Yes |Yes | |Trainable classifiers| Yes | Yes (last six months only) |
SharePoint and OneDrive:
|Condition|New or modified items |Existing items | |:--|:--|:--|
-|Sensitive info types - built-in| Yes | Yes |
-|Sensitive info types - custom| Yes | No |
+|Sensitive info types | Yes | Yes <sup>\*</sup> |
|Specific keywords or searchable properties| Yes |Yes | |Trainable classifiers| Yes | Yes (last six months only) |
-Additionally, SharePoint items that are in draft or that have never been published aren't supported for this scenario.
+**Footnote:**
+
+<sup>\*</sup>
+Applies only to content that's already classified, which you can determine by using [content explorer](data-classification-content-explorer.md).
#### Auto-apply labels to content with specific types of sensitive information
compliance Customer Key Availability Key Roll https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/compliance/customer-key-availability-key-roll.md
Title: "Roll or rotate a Customer Key or an availability key"
Previously updated : 09/25/2019 Last updated : 03/24/2023 audience: ITPro
description: "Learn how to roll the customer root keys stored in Azure Key Vault
# Roll or rotate a Customer Key or an availability key > [!CAUTION]
-> Only roll an encryption key that you use with Customer Key when your security or compliance requirements dictate that you must roll the key. In addition, do not delete any keys that are or were associated with policies. When you roll your keys, there will be content encrypted with the previous keys. For example, while active mailboxes will be re-encrypted frequently, inactive, disconnected, and disabled mailboxes may still be encrypted with the previous keys. SharePoint Online performs backup of content for restore and recovery purposes, so there may still be archived content using older keys.
+> Only roll an encryption key that you use with Customer Key when your security or compliance requirements dictate that you must roll the key. **Do not delete or disable any keys that are or were associated with policies, including older versions of keys that you used.** When you roll your keys, there will be content encrypted with the previous keys. For example, while active mailboxes will be re-encrypted frequently, inactive, disconnected, and disabled mailboxes may still be encrypted with the previous keys. SharePoint Online performs backup of content for restore and recovery purposes, so there may still be archived content using older keys.
[!INCLUDE [purview-preview](../includes/purview-preview.md)]
compliance Customer Key Set Up https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/compliance/customer-key-set-up.md
Title: "Set up Customer Key" Last updated : 03/24/2023 Previously updated : 09/11/2019 audience: ITPro
You'll need to define three separate sets of permissions for each key vault, dep
Get-AzKeyVault -VaultName <vault name> | fl ```
-> [!Tip]
+ - If you're using Role-Based Access Control (RBAC) to assign `wrapKey`, `unwrapkey`, and `get` permissions, you must assign the ΓÇ£*Key Vault Crypto Service Encryption User*ΓÇ¥ role to the corresponding Microsoft 365 app. See [Grant permission to applications to access an Azure key vault using Azure RBAC | Microsoft Learn](/azure/key-vault/general/rbac-guide?tabs=azure-cli).
+
+> [!TIP]
> Before moving on, make sure the permissions are configured properly for the key vault, the *Permissions to Keys* will return **wrapKey, unwrapKey, get**. > Make sure to correct the permissions to the correct service you are onboarding to. The *Display Name* for each service is listed below: >
To enable Soft Delete on your key vaults, complete these steps:
### Add a key to each key vault either by creating or importing a key
-There are two ways to add keys to an Azure Key Vault; you can create a key directly in Key Vault, or you can import a key. Creating a key directly in Key Vault is less complicated, but importing a key provides total control over how the key is generated. Use the RSA keys. Azure Key Vault doesn't support wrapping and unwrapping with elliptical curve keys.
+There are two ways to add keys to an Azure Key Vault; you can create a key directly in Key Vault, or you can import a key. Creating a key directly in Key Vault is less complicated, but importing a key provides total control over how the key is generated. Use the RSA keys. Customer Key supports RSA Key lengths up to 4096. Azure Key Vault doesn't support wrapping and unwrapping with elliptical curve keys.
For instructions to add a key to each vault, see [Add-AzKeyVaultKey](/powershell/module/az.keyvault/add-azkeyvaultkey).
compliance Deploy Scanner Prereqs https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/compliance/deploy-scanner-prereqs.md
You must have a Windows Server computer to run the scanner, which has the follow
||| |**Processor** |4 core processors | |**RAM** |8 GB |
-|**Disk space** |10-GB free space (average) for temporary files. </br></br>The scanner requires sufficient disk space to create temporary files for each file that it scans, four files per core. </br></br>The recommended disk space of 10 GB allows for 4 core processors scanning 16 files that each have a file size of 625 MB.
-|**Operating system** |64-bit versions of: <br><br>- Windows Server 2019 </br>- Windows Server 2016 </br>- Windows Server 2012 R2 </br></br>**Note**: For testing or evaluation purposes in a non-production environment, you can also use any Windows operating system that is [supported by the Azure Information Protection client](/azure/information-protection/requirements#client-devices).
-|**Network connectivity** | Your scanner computer can be a physical or virtual computer with a fast and reliable network connection to the data stores to be scanned. </br></br> If internet connectivity is not possible because of your organization policies, see [Deploying the scanner with alternative configurations](#deploying-the-scanner-with-alternative-configurations). </br></br>Otherwise, make sure that this computer has internet connectivity that allows the following URLs over HTTPS (port 443):</br><br />- \*.aadrm.com <br />- \*.azurerms.com<br />- \*.informationprotection.azure.com <br /> - informationprotection.hosting.portal.azure.net <br /> - \*.aria.microsoft.com <br />- \*.protection.outlook.com |
+|**Disk space** |10-GB free space (average) for temporary files. </br></br>The scanner requires sufficient disk space to create temporary files for each file that it scans, four files per core. </br></br>The recommended disk space of 10 GB allows for 4 core processors scanning 16 files that each have a file size of 625 MB.|
+|**Operating system** |64-bit versions of: <br><br>- Windows Server 2022 </br>- Windows Server 2019 </br>- Windows Server 2016 </br>- Windows Server 2012 R2 </br></br>**Note**: For testing or evaluation purposes in a non-production environment, you can also use any Windows operating system that is [supported by the Azure Information Protection client](/azure/information-protection/requirements#client-devices).|
+|**- Network connectivity** | Your scanner computer can be a physical or virtual computer with a fast and reliable network connection to the data stores to be scanned. </br></br> If internet connectivity is not possible because of your organization policies, see [Deploying the scanner with alternative configurations](#deploying-the-scanner-with-alternative-configurations). </br></br>Otherwise, make sure that this computer has internet connectivity that allows the following URLs over HTTPS (port 443):</br><br />- \*.aadrm.com <br />- \*.azurerms.com<br />- \*.informationprotection.azure.com <br /> - informationprotection.hosting.portal.azure.net <br /> - \*.aria.microsoft.com <br />- \*.protection.outlook.com |
|**NFS shares** |To support scans on NFS shares, services for NFS must be deployed on the scanner machine. <br><br>On your machine, navigate to the **Windows Features (Turn Windows features on or off)** settings dialog, and select the following items: **Services for NFS** > **Administrative Tools** and **Client for NFS**. | | **Microsoft Office iFilter** |When your scanner is installed on a Windows server machine, you must also install the Microsoft Office iFilter in order to scan .zip files for sensitive information types. <br><br>For more information, see the [Microsoft download site](https://www.microsoft.com/en-us/download/details.aspx?id=17062).|
If your labels do not have any auto-labeling conditions, plan to use one of the
Once you've confirmed that your system complies with the scanner prerequisites, continue with [Configuring and installing the information protection scanner](deploy-scanner-configure-install.md). For an overview about the scanner, see [Learn about the information protection scanner](deploy-scanner.md).+
compliance Whats New https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/compliance/whats-new.md
Title: What's new in Microsoft Purview risk and compliance solutions
-description: Whether it be adding new solutions to the compliance center, updating existing features based on your feedback, or rolling out fresh and updated documentation, Microsoft Purview helps you stay on top of the ever-changing compliance landscape. Find out what we've been up to this month.
+description: Whether it be adding new solutions to the compliance portal, updating existing features based on your feedback, or rolling out fresh and updated documentation, Microsoft Purview helps you stay on top of the ever-changing compliance landscape. Find out what we've been up to this month.
f1.keywords: - NOCSH Previously updated : 03/21/2023 Last updated : 03/24/2023 audience: Admin
Whether it be adding new solutions to the [Microsoft Purview compliance portal](
## March 2023
+### Audit
+
+- Updates for *UserKey* and *UserType* schema values to address [scenarios](/microsoft-365/compliance/audit-log-detailed-properties#usertype-and-userkey-scenarios) for enumeration for audit records generated by guest users and to remove ambiguity for accepted data.
+- Updates for [audit search records and activities](/microsoft-365/compliance/audit-log-search) related to Microsoft Defender for Identity (MDI).
+- Updates for [new audit log fields](/microsoft-365/compliance/audit-log-detailed-properties) added to support Microsoft Information Protection.
+- Updates for across all [audit content](/microsoft-365/compliance/audit-solutions-overview) for new UTC support in audit solutions.
+- Updates for all [events that are logged](/microsoftteams/audit-log-events) for the **Updates app** activities in Teams in the audit log.
+ ### Communication compliance -- **New topic**: Added topic that includes a list of [best practices to help reduce alert "noise"](communication-compliance-alerts-best-practices.md). -- **New topic**: Added topic that summarizes the [privacy principles for communication compliance](insider-risk-solution-privacy.md).
+- **New article**: Added article that includes a list of [best practices to help reduce alert "noise"](communication-compliance-alerts-best-practices.md).
+- **New article**: Added article that summarizes the [privacy principles for communication compliance](insider-risk-solution-privacy.md).
- Clarification on the [Filter email blasts feature and why the report might include unexpected senders](communication-compliance-configure.md#step-5-required-create-a-communication-compliance-policy). - Clarification that [Translation view includes associated conversation view messages](communication-compliance-investigate-remediate.md#step-2-examine-the-message-details).
+### eDiscovery
+
+- Updates for [hold type values](/microsoft-365/compliance/ediscovery-identify-a-hold-on-an-exchange-online-mailbox#review-the-results-of-the-mailbox-diagnostics-logs) in the Mailbox diagnostic logs.
+- Clarifications for [self-chat messages support](/microsoftteams/ediscovery-investigation) in content search in Microsoft Teams.
+- [Updates](/microsoft-365/compliance/ediscovery-view-documents-in-review-set) for new **Add Notes** feature in viewing review sets and updates for the review set user experience.
+- Clarification for custom [sensitive information type requirement](/microsoft-365/compliance/ediscovery-keyword-queries-and-search-conditions) to use a GUID for search in eDiscovery.
+- Clarification for [excluding partially indexed items](/microsoft-365/compliance/ediscovery-partially-indexed-items-in-content-search) by using a date range in a search query.
+- New [clarification section](/microsoft-365/compliance/ediscovery-keyword-queries-and-search-conditions#searchable-sensitive-data-types) that that only Microsoft default sensitive information types are searchable by name, including new example.
+- New update for review set viewer and pagination [limits](/microsoft-365/compliance/ediscovery-premium-limits#review-set-viewer-limits).
+
+### Information barriers
+
+- **New article**: Added new article to support the [new multi-segment mode](/microsoft-365/compliance/information-barriers-multi-segment) in information barriers. The multi-segment mode enables you to assign users in your organization to up to 10 segments in information barriers instead of being limited to just one segment. This allows support for more diverse communication rules between individuals and groups to support more complex organizational and operational scenarios.
+- Clarifications for [hidden/disabled/guest user accounts](/microsoft-365/compliance/information-barriers-policies) and the *HiddenFromAddressListEnabled* parameter.
+- Updates for information barriers policy application and the background processor in [Microsoft Teams](/microsoftteams/information-barriers-in-teams#ib-policy-application-in-teams).
+ ### Insider risk management - **Forensic Evidence GA**: With the GA release of Forensic Evidence, you can now: - [Specify websites or desktop apps to include or exclude when you create a policy](insider-risk-management-forensic-evidence-configure.md#step-4-create-a-policy). - [View and explore a list of captured clips and filter the list to find just the information you need](insider-risk-management-forensic-evidence-manage.md#viewing-captured-clips). - [Purchase/analyze capacity for captured clips and/or sign up for 20 GB of trial capacity](insider-risk-management-forensic-evidence-manage.md#capacity-and-billing).-- **New topic**: Added topic that [summarizes the privacy principles for insider risk management](insider-risk-solution-privacy.md).
+- **New article**: Added article that [summarizes the privacy principles for insider risk management](insider-risk-solution-privacy.md).
- Clarification about [adding "webhook.ingestion.office.com" to the allowlist when setting up a connector to import HR data](import-hr-data.md#before-you-begin). - Clarification about the [past activity detection period for email activities (contrasted to audit activities)](insider-risk-management-settings.md#policy-timeframes). - Clarification on the [retention time for user activities reports](insider-risk-management-activities.md#retention-and-item-limits).
+### Permissions
+
+- [Clarifications](/microsoft-365/compliance/microsoft-365-compliance-center-permissions) for role group support for security groups and blocked and unblocked groups.
+ ### Sensitivity labels - **AIP add-in disabled by default**: Now rolling out, the AIP add-in for Office apps is disabled by default with version 2302. Starting with this version, you must [configure an Office setting](sensitivity-labels-aip.md#how-to-configure-newer-versions-of-office-to-enable-the-aip-add-in) if you need to continue to use the Azure Information Protection (AIP) add-in rather than the labels that are built into Office apps.
Whether it be adding new solutions to the [Microsoft Purview compliance portal](
- **General availability (GA)**: Both Outlook for Windows and Outlook for Mac are rolling out in general availability for [protected meetings](sensitivity-labels-meetings.md). - **General availability (GA)**: Now in general availability for built-in labeling for Windows, support for a [default sublabel for a parent label](sensitivity-labels-office-apps.md#specify-a-default-sublabel-for-a-parent-label) as a parity feature for the AIP add-in. - **General availability (GA)**: For labeling built into Windows, macOS, iOS, and Android, auditing actions for sensitivity labels include encryption details such as a change in the encryption status and settings, and the Rights Management owner.-- **In preview**: The ability to [scope labels to files and emails](sensitivity-labels-office-apps.md#scope-labels-to-just-files-or-emails), so that for example, a sensitivity label is visible to users in Outlook but not in Word, Excel, or PowerPoint. This configuration can be used as a parity feature for the AIP add-in, which could be disabled per app.
+- **In preview**: The ability to [scope labels to files and emails](sensitivity-labels-office-apps.md#scope-labels-to-just-files-or-emails), so that, for example, a sensitivity label is visible to users in Outlook but not in Word, Excel, or PowerPoint. This configuration can be used as a parity feature for the AIP add-in, which could be disabled per app.
- **In preview**: Prevent [oversharing of labeled emails as a DLP policy tip](dlp-create-deploy-policy.md#scenario-2-show-policy-tip-as-oversharing-popup-preview). This DLP policy configuration is an equivalent for the AIP add-in with PowerShell advanced settings that implement pop-up messages in Outlook that warn, justify, or block emails being sent. - **In preview**: As a parity feature for the AIP add-in, built-in labeling for Windows supports [label inheritance from email attachments](sensitivity-labels-office-apps.md#configure-label-inheritance-from-email-attachments). - **In preview**: Preview versions of Outlook for Mac now support [label colors](sensitivity-labels-office-apps.md#label-colors) but don't yet support the sensitivity bar.
Whether it be adding new solutions to the [Microsoft Purview compliance portal](
- **New cumulative exfiltration button**: [The new cumulative exfiltration button on the user activity chart provides a visual chart of how activity is building over time for a user](insider-risk-management-activities.md#user-activity) - **Filter out activity that has already been reviewed**: [Use the Review status filter to filter out any activity that was part of a dismissed or resolved alert](insider-risk-management-activities.md#activity-explorer-1). - [Clarification for why user activity data outside the selected calendar control range might be included](insider-risk-management-activities.md#user-activity-reports) -- [Clarification that scoped admins cannot select the quick setup option for Adaptive Protection](insider-risk-management-adaptive-protection.md#quick-setup)-
+- [Clarification that scoped admins can't select the quick setup option for Adaptive Protection](insider-risk-management-adaptive-protection.md#quick-setup)
### On-premises scanner
Whether it be adding new solutions to the [Microsoft Purview compliance portal](
### Trainable classifiers - [Trainable classifiers definitions](classifier-tc-definitions.md) - more than 20 new classifiers have been added, so the definitions for all trainable classifiers have been broken out into this new article.-
-## Changes to product names
-
-To meet the challenges of today's decentralized, data-rich workplace, we're introducing [Microsoft Purview](https://aka.ms/microsoftpurview), a comprehensive set of solutions which helps you understand, govern, and protect your entire data estate. This new brand family combines the capabilities of the former Microsoft Purview Data Map and the Microsoft 365 compliance portfolio that customers already rely on, providing unified data governance and risk management for your organization.
-
-| **Former Name** | **New Name** | **Description** |
-|:-|:-|:-|
-| Microsoft 365 Advanced Audit <br><br> Microsoft 365 Basic Audit | Microsoft Purview Audit (Premium) <br><br> Microsoft Purview Audit (Standard)| Auditing solutions provide an integrated solution to help organizations effectively respond to security events, forensic investigations, internal investigations, and compliance obligations. To learn more, see [Microsoft Purview Advanced Audit (Premium)](audit-premium.md) and [Microsoft Purview Advanced Audit (Standard)](audit-standard-setup.md). |
-| Microsoft 365 Communication Compliance | Microsoft Purview Communication Compliance | Communication Compliance helps minimize risks by helping you quickly detect, capture, and take remediation actions for company communication channels and policy violations. To learn more, see [Microsoft Purview Communication Compliance](communication-compliance-solution-overview.md). |
-| Microsoft Compliance Manager | Microsoft Purview Compliance Manager | Compliance Manager can help you throughout your compliance journey, from taking inventory of your data protection risks to managing the complexities of implementing controls, staying current with regulations and certifications, and reporting to auditors. To learn more, see [Microsoft Purview Compliance Manager](compliance-manager.md). |
-| Microsoft 365 Customer Key | Microsoft Purview Customer Key | Customer Key provides extra protection against viewing of data by unauthorized systems or personnel, and complements BitLocker disk encryption in Microsoft data centers. To learn more, see [Microsoft Purview Customer Key](customer-key-overview.md). |
-| Office 365 Customer Lockbox | Microsoft Purview Customer Lockbox | Customer Lockbox ensures that Microsoft can't access your content to do service operations without your explicit approval. Customer Lockbox brings you into the approval workflow process that Microsoft uses to ensure only authorized requests allow access to your content. To learn more, see [Microsoft Purview Customer Lockbox](customer-lockbox-requests.md). |
-| Data Loss Prevention | Microsoft Purview Data Loss Prevention | DLP helps protect sensitive data and reduce risk by preventing users from inappropriately sharing that data with people who shouldn't have it. To learn more, see [Microsoft Purview Data Loss Prevention](dlp-learn-about-dlp.md). |
-| Double Key Encryption for Microsoft 365 | Microsoft Purview Double Key Encryption | Double Key Encryption (DKE) uses two keys together to access protected content. Microsoft stores one key in Microsoft Azure, and you hold the other key. To learn more, see [Microsoft Purview Double Key Encryption](double-key-encryption.md) |
-| Microsoft 365 Information Barriers | Microsoft Purview Information Barriers | Information Barriers is a solution which restricts communication and collaboration between certain people inside your organization to safeguard internal information. To learn more, see [Microsoft Purview Information Barriers](information-barriers-solution-overview.md). |
-| Microsoft Information Protection | Microsoft Purview Information Protection | Information protection helps you discover, classify, and protect sensitive information wherever it lives or travels. To learn more, see [Microsoft Purview Information Protection](information-protection.md). |
-| Microsoft Information Governance | Microsoft Purview Data Lifecycle Management | Data lifecycle management provides you with tools and capabilities to retain the content that you need to keep and delete the content that you don't. To learn more, see [Microsoft Purview Data Lifecycle Management](data-lifecycle-management.md). |
-| Microsoft 365 Insider Risk Management | Microsoft Purview Insider Risk Management | Insider risk management uses the full breadth of service and 3rd-party indicators to help you quickly identify, triage, and act on risky user activity. To learn more, see [Microsoft Purview Insider Risk Management](insider-risk-management.md). |
-| Office 365 Message Encryption | Microsoft Purview Message Encryption | With Message Encryption, your organization can send and receive encrypted email messages between people inside and outside your organization. To learn more, see [Microsoft Purview Message Encryption](ome.md). |
-| Privileged Access Management in Microsoft 365 | Microsoft Purview Privileged Access Management | Privileged Access Management helps protect your organization from breaches and helps to meet compliance best practices by limiting standing access to sensitive data or access to critical configuration settings. To learn more, see [Microsoft Purview Privileged Access Management](privileged-access-management-solution-overview.md). |
-| Microsoft data connectors | Microsoft Purview data connectors | Microsoft 365 lets administrators use data connectors to import and archive non-Microsoft, third-party data from social media platforms, instant messaging platforms, and document collaboration platforms, to mailboxes in your Microsoft 365 organization. To learn more, see [Microsoft Purview data connectors](compliance-extensibility.md). |
-| Microsoft 365 Advanced eDiscovery <br><br> Microsoft 365 Core eDiscovery | Microsoft Purview eDiscovery (Premium) <br><br> Microsoft Purview eDiscovery (Standard) | Electronic discovery, or eDiscovery, is the process of identifying and delivering electronic information that can be used as evidence in legal cases. To learn more, see [Microsoft Purview eDiscovery (Premium)](ediscovery-overview.md) and [Microsoft Purview eDiscovery (Standard)](ediscovery-standard-get-started.md). |
-| Microsoft 365 compliance center | Microsoft Purview compliance portal | Admin portal to access solutions and solution catalog within the Microsoft 365 E5 Compliance suite. To learn more, see [Microsoft Purview compliance portal](microsoft-365-compliance-center.md). |
security Ios Install https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/defender-endpoint/ios-install.md
Last updated 12/18/2020
> Want to experience Defender for Endpoint? [Sign up for a free trial.](https://signup.microsoft.com/create-account/signup?products=7f379fee-c4f9-4278-b0a1-e4c8c2fcdf7e&ru=https://aka.ms/MDEp2OpenTrial?ocid=docs-wdatp-investigateip-abovefoldlink)
-This topic describes deploying Defender for Endpoint on iOS on Microsoft Intune Company Portal enrolled devices. For more information about Microsoft Intune device enrollment, see [Enroll iOS/iPadOS devices in Microsoft Intune](/mem/intune/enrollment/ios-enroll).
+This topic describes deploying Defender for Endpoint on iOS on Microsoft Intune Company Portal enrolled devices. For more information about Microsoft Intune device enrollment, see [Enroll iOS/iPadOS devices in Intune](/mem/intune/enrollment/ios-enroll).
## Before you begin
Admins can automate the Defender onboarding for users in two different ways with
Admins can configure Microsoft Defender for Endpoint to deploy and activate silently. In this flow, the administrator creates a deployment profile and the user is simply notified of the installation. Defender for Endpoint is automatically installed without the need for the user to open the app. Follow the steps below to set up zero-touch or silent deployment of Defender for Endpoint on enrolled iOS devices: 1. In the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431), go to **Devices** > **Configuration Profiles** > **Create Profile**.
-1. Choose **Platform** as **iOS/iPadOS** and **Profile type** as **VPN**. Select **Create**.
+1. Choose **Platform** as **iOS/iPadOS**, **Profile type** as **Templates** and **Template name** as **VPN**. Select **Create**.
1. Type a name for the profile and select **Next**. 1. Select **Custom VPN** for Connection Type and in the **Base VPN** section, enter the following: - Connection Name = Microsoft Defender for Endpoint
security Mac Whatsnew https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/defender-endpoint/mac-whatsnew.md
search.appverid: met150+ # What's new in Microsoft Defender for Endpoint on Mac
search.appverid: met150
[!INCLUDE [Microsoft 365 Defender rebranding](../../includes/microsoft-defender.md)] **Applies to:**-- [Microsoft Defender for Endpoint Plan 2](https://go.microsoft.com/fwlink/p/?linkid=2154037)-- [Microsoft 365 Defender](https://go.microsoft.com/fwlink/?linkid=2118804)++ > Want to experience Microsoft Defender for Endpoint? [Sign up for a free trial.](https://signup.microsoft.com/create-account/signup?products=7f379fee-c4f9-4278-b0a1-e4c8c2fcdf7e&ru=https://aka.ms/MDEp2OpenTrial?ocid=docs-wdatp-exposedapis-abovefoldlink) + For more information on Microsoft Defender for Endpoint on other operating systems: -- [What's new in Microsoft Defender for Endpoint on Linux](linux-whatsnew.md)-- [What's new in Microsoft Defender for Endpoint on iOS](ios-whatsnew.md)++ **Mac devices to soon receive built-in protection**
Apple has fixed an issue on macOS [Ventura upgrade](<https://developer.apple.com
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as Apple ended support for Catalina (10.15) in December 2022. </br>
+### Mar-2023 (Build: 101.98.30 | Release version: 20.123012.19830.0)
+
+| Build: | **101.98.30** |
+|--|--|
+| Release version: | **20.123012.19830.0** |
+| Engine version: | **1.1.20100.6** |
+| Signature version: | **1.385.924.0** |
+
+##### What's new
+
+- Bug and performance fixes
+ ### Feb-2023 (Build: 101.97.94 | Release version: 20.123011.19794.0) | Build: | **101.97.94** |
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/>
-<details>
- <summary>Jan-2023 (Build: 101.96.85 | Release version: 20.122112.19413.0)</summary>
- &ensp;Build: **101.96.85**<br/> &ensp;Release version: **20.122112.19413.0**<br/> &ensp;Engine version: **1.1.19900.2**<br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details>
- <summary>Dec-2022 (Build: 101.90.97 | Release version: 20.122102.19097.0)</summary>
- &ensp;Build: **101.90.97**<br/> &ensp;Release version: **20.122102.19097.0**<br/> &ensp;Engine version: **1.1.19900.2**<br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details>
- <summary>Nov-2022 (Build: 101.87.30 | Release version: 20.122082.18681.0)</summary>
- &ensp;Released: **Nov 5, 2022**<br/> &ensp;Published: **Nov 5, 2022**<br/> &ensp;Build: **101.87.30**<br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details>
- <summary>Oct-2022 (Build: 101.86.81 | Release version: 20.122082.18681.0)</summary>
- &ensp;Released: **Oct 25, 2022**<br/> &ensp;Published: **Oct 25, 2022**<br/> &ensp;Build: **101.86.81**<br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details>
- <summary>Aug-2022 (Build: 101.78.13 | Release version: 20.122072.17813.0)</summary>
- &ensp;Build: **101.78.13**<br/> &ensp;Release version: **20.122072.17813.0**<br/> &ensp;Engine version: **1.1.19500.2**<br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details>
- <summary>Aug-2022 (Build: 101.75.90 | Release version: 20.122071.17590.0)</summary>
- &ensp;Released: **Aug 3, 2022**<br/> &ensp;Published: **Aug 3, 2022**<br/> &ensp;Build: **101.75.90**<br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details>
- <summary>Jul-2022 (Build: 101.73.77 | Release version: 20.122062.17377.0)</summary>
- &ensp;Released: **Jul 21, 2022**<br/> &ensp;Published: **Jul 21, 2022**<br/> &ensp;Build: **101.73.77**<br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details>
- <summary>Jul-2022 (Build: 101.71.18 | Release version: 20.122052.17118.0)</summary>
- &ensp;Released: **Jul 7, 2022**<br/> &ensp;Published: **Jul 7, 2022**<br/> &ensp;Build: **101.71.18**<br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details>
- <summary>Jun-2022 (Build: 101.70.19 | Release version: 20.122051.17019.0)</summary>
- &ensp;Released: **Jun 14, 2022**<br/> &ensp;Published: **Jun 14, 2022**<br/> &ensp;Build: **101.70.19**<br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details>
- <summary>Jun-2022 (Build: 101.70.18 | Release version: 20.122042.17018.0)</summary>
- &ensp;Released: **Jun 2, 2022**<br/> &ensp;Published: **Jun 2, 2022**<br/> &ensp;Build: **101.70.18**<br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details>
- <summary>May-2022 (Build: 101.66.54 | Release version: 20.122041.16654.0) </summary>
- &ensp;Released: **May 11, 2022**<br/> &ensp;Published: **May 11, 2022**<br/> &ensp;Build: **101.66.54**<br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details>
- <summary>Apr-2022 (Build: 101.64.15 | Release version: 20.122032.16415.0)</summary>
- &ensp;Released: **Apr 26, 2022**<br/> &ensp;Published: **Apr 26, 2022**<br/> &ensp;Build: **101.64.15**<br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details>
- <summary>Mar-2022 (Build: 101.61.69 | Release version: 20.122022.16169.0) </summary>
- &ensp;Released: **Mar 25, 2022**<br/> &ensp;Published: **Mar 25, 2022**<br/> &ensp;Build: **101.61.69**<br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details>
- <summary>Mar-2022 (Build: 101.60.91 | Release version: 20.122021.16091.0)</summary>
- &ensp;Released: **Mar 8, 2022**<br/> &ensp;Published: **Mar 8, 2022**<br/> &ensp;Build: **101.60.91**<br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details>
- <summary>Feb-2022 (Build: 101.59.50 | Release version: 20.122021.15950.0) </summary>
- &ensp;Released: **Feb 28, 2022**<br/> &ensp;Published: **Feb 28, 2022**<br/> &ensp;Build: **101.59.50**<br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details>
- <summary>Feb-2022 (Build: 101.56.62 | Release version: 20.121122.15662.0)</summary>
- &ensp;Released: **Feb 7, 2022**<br/> &ensp;Published: **Feb 7, 2022**<br/> &ensp;Build: **101.56.62**<br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details>
- <summary> Jan-2022 (Build: 101.56.35 | Release version: 20.121121.15635.0)</summary>
- &ensp;Released: **Jan 30, 2022**<br/> &ensp;Published: **Jan 30, 2022**<br/> &ensp;Build: **101.56.35**<br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details>
- <summary>Jan-2022 (Build: 101.54.16 | Release version: 20.121111.15416.0) </summary>
- &ensp;Released: **Jan 12, 2022**<br/> &ensp;Published: **Jan 12, 2022**<br/> &ensp;Build: **101.54.16**<br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>2021 releases </summary><blockquote>
- <details><summary>(Build: 101.49.25 | Release version: 20.121092.14925.0)</summary>
- &ensp;Build: **101.49.25**<br/> &ensp;Release version: **20.121092.14925.0** <br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.47.27 | Release version: 20.121082.14727.0)</summary>
- &ensp;Build: **101.47.27**<br/> &ensp;Release version: **20.121082.14727.0** <br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.43.84 | Release version: 20.121082.14384.0)</summary>
- &ensp;Build: **101.43.84**<br/> &ensp;Release version: **20.121082.14384.0** <br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.41.10 | Release version: 20.121072.14110.0)</summary>
- &ensp;Build: **101.41.10**<br/> &ensp;Release version: **20.121072.14110.0** <br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.40.84 | Release version: 20.121071.14084.0)</summary>
- &ensp;Build: **101.40.84**<br/> &ensp;Release version: **20.121071.14084.0** <br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.37.97 | Release version: 20.121062.13797.0)</summary>
- &ensp;Build: **101.37.97**<br/> &ensp;Release version: **20.121062.13797.0** <br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.34.28 | Release version: 20.121061.13428.0)</summary>
- &ensp;Build: **101.34.28**<br/> &ensp;Release version: **20.121061.13428.0** <br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.34.27 | Release version: 20.121052.13427.0)</summary>
- &ensp;Build: **101.34.27**<br/> &ensp;Release version: **20.121052.13427.0** <br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.34.20 | Release version: 20.121051.13420.0)</summary>
- &ensp;Build: **101.34.20**<br/> &ensp;Release version: **20.121051.13420.0** <br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.32.69 | Release version: 20.121042.13269.0)</summary>
- &ensp;Build: **101.32.69**<br/> &ensp;Release version: **20.121042.13269.0** <br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.29.64 | Release version: 20.121042.12964.0)</summary>
- &ensp;Build: **101.29.64**<br/> &ensp;Release version: **20.121042.12964.0** <br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.27.50 | Release version: 20.121022.12750.0)</summary>
- &ensp;Build: **101.27.50**<br/> &ensp;Release version: **20.121022.12750.0** <br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.25.69 | Release version: 20.121022.12569.0)</summary>
- &ensp;Build: **101.25.69**<br/> &ensp;Release version: **20.121022.12569.0** <br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.23.64 | Release version: 20.121021.12364.0)</summary>
- &ensp;Build: **101.23.64**<br/> &ensp;Release version: **20.121021.12364.0** <br/>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-</details>
-
-<details><summary>Prior releases </summary><blockquote>
-<details><summary>(Build: 101.22.79 | Release version: 20.121012.12279.0)</summary>
- &ensp;Build: **101.22.79** <br> &ensp;Release version: **20.121012.12279.0**<br>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.19.88 | Release version: 20.121011.11988.0)</summary>
- &ensp;Build:**101.19.88**<br> &ensp;Release version: **20.121011.11988.0**<br>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.19.48 | Release version: 20.120121.11948.0)</summary>
- &ensp;Build: **101.19.48**<br> &ensp;Release version: **20.120121.11948.0**<br>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.19.21 | Release version: 20.120101.11921.0)</summary>
- &ensp;Build: **101.19.21**<br> &ensp;Release version: **20.120101.11921.0** <br>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.15.26 | Release version: 20.120102.11526.0)</summary>
- &ensp;Build: **101.15.26**<br> &ensp;Release version: **20.120102.11526.0**<br>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.13.75 | Release version: 20.120101.11375.0)</summary>
- &ensp;Build: **101.13.75**<br> &ensp;Release version: **20.120101.11375.0**<br>
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.10.72)</summary>
- &ensp;Build: **101.10.72** <br> **What's new**
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.09.61)</summary>
- &ensp;Build: **101.09.61**<br> **What's new**
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.09.50)</summary>
- &ensp;Build: **101.09.50**<br> **What's new**
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.09.49)</summary>
- &ensp;Build: **101.09.49**<br> **What's new**
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.07.23)</summary>
- &ensp;Build: **101.07.23**<br> **What's new**
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.06.63)</summary>
- &ensp;Build: **101.06.63**<br> **What's new**
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.05.17)</summary>
- &ensp;Build: **101.05.17**<br> **What's new**
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.05.16)</summary>
- &ensp;Build: **101.05.16**<br> **What's new**
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.03.12)</summary>
- &ensp;Build: **101.03.12**<br> **What's new**
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.01.54)</summary>
- &ensp;Build: **101.01.54**<br> **What's new**
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 101.00.31)</summary>
- &ensp;Build: **101.00.31** <br> **What's new**
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 100.90.27)</summary>
- &ensp;Build: **100.90.27** <br> **What's new**
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 100.86.92)</summary>
- &ensp;Build: **100.86.92**<br> **What's new**
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 100.86.91)</summary>
- &ensp;Build: **100.86.91**<br> **What's new**
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 100.83.73)</summary>
- &ensp;Build: **100.83.73**<br> **What's new**
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 100.82.60)</summary>
- &ensp;Build: **100.82.60** <br> **What's new**
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 100.80.42)</summary>
- &ensp;Build: **100.80.42**<br> **What's new**
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 100.79.42)</summary>
- &ensp;Build: **100.79.42**<br> **What's new**
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 100.72.15)</summary>
- &ensp;Build: **100.72.15**<br> **What's new**
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 100.70.99)</summary>
- &ensp;Build: **100.70.99**<br> **What's new**
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 100.68.99)</summary>
- &ensp;Build: **100.68.99**<br> **What's new**
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/> </details>
-<details><summary>(Build: 100.65.28)</summary>
- &ensp;Build: **100.65.28**<br> **What's new**
Microsoft Defender for Endpoint no longer supports macOS Catalina (10.15) as App
<br/><br/> </details>++
security Microsoft Defender Antivirus Updates https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/defender-endpoint/microsoft-defender-antivirus-updates.md
description: Manage how Microsoft Defender Antivirus receives protection and pro
keywords: updates, security baselines, protection, schedule updates, force updates, mobile updates, wsus ms.localizationpriority: high Previously updated : 03/20/2023 Last updated : 03/24/2023 audience: ITPro
For more information, see [Manage the sources for Microsoft Defender Antivirus p
## Monthly platform and engine versions
-For information how to update or install the platform update, see [Update for Windows Defender antimalware platform](https://support.microsoft.com/help/4052623/update-for-windows-defender-antimalware-platform).
- All our updates contain - Performance improvements
security Network Protection Macos https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/defender-endpoint/network-protection-macos.md
ms.mktglfcycl: manage
ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium Previously updated : 01/31/2023 Last updated : 03/24/2023 audience: ITPro
Network protection expands the scope of Microsoft 365 Defender [SmartScreen](/wi
## Availability
-Network Protection for macOS will soon be available for all Microsoft Defender for Endpoint onboarded macOS devices which meet the minimum requirements. Microsoft will begin incrementally rolling out the functionality for all macOS devices to enable Network Protection on 1/31/2023 with target completion, subject to change, by 3/24/23. When this feature rolls to production, all of your currently configured Network Protection and Web Threat Protection policies will be enforced on macOS devices where Network Protection is configured for block mode.
+Network Protection for macOS will soon be available for all Microsoft Defender for Endpoint onboarded macOS devices which meet the minimum requirements. Microsoft will begin incrementally rolling out the functionality for all macOS devices to enable Network Protection on 1/31/2023 with target completion, subject to change, in May 2023. When this feature rolls to production, all of your currently configured Network Protection and Web Threat Protection policies will be enforced on macOS devices where Network Protection is configured for block mode.
To prepare for the macOS network protection rollout, we recommend the following:
security Onboarding Endpoint Manager https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/defender-endpoint/onboarding-endpoint-manager.md
To confirm that the configuration policy has been applied to your test device, f
### Confirm Attack Surface Reduction - Attack surface reduction rules
-1. Before applying the policy on a test device, pen a PowerShell Window and type `Get-MpPreference`.
+1. Before applying the policy on a test device, open a PowerShell Window and type `Get-MpPreference`.
2. This should respond with the following lines with no content:
security Tamperprotection Macos https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/defender-endpoint/tamperprotection-macos.md
search.appverid: met150 Previously updated : 05/10/2022 Last updated : 03/24/2023 # Protect macOS security settings with tamper protection
Last updated 05/10/2022
Tamper protection in macOS helps prevent unwanted changes to security settings from being made by unauthorized users. Tamper protection helps prevent unauthorized removal of Microsoft Defender for Endpoint on macOS. This capability also helps important security files, processes, and configuration settings from being tampered.
+> [!IMPORTANT]
+> Between March and May of 2023, Microsoft Defender for Endpoint on macOS will start respecting the selection for tamper protection applied via the global tamper protection switch under advanced settings in the Microsoft 365 Defender portal ([https://security.microsoft.com](https://security.microsoft.com)). You can choose to enforce (block/audit/disable) your own macOS tamper protection settings by using a Mobile Device Management (MDM) solution such as Intune or JAMF (recommended). If the tamper protection setting was not enforced via MDM, a local administrator can continue to manually change the setting with the following command: `sudo mdatp config tamper-protection enforcement-level --value (chosen mode)`.
+ You can set tamper protection in the following modes: |Topic|Description|
When tamper protection is set to audit or block mode, you can expect the followi
Here is an example of a system message in response to a blocked action:
-![Image of operation blocked](images/operation-blocked.png)
+![Screenshot of operation blocked message.](images/operation-blocked.png)
+ You can configure the tamper protection mode by providing the mode name as enforcement-level.
full_disk_access_enabled : true
### Manual configuration
-1. Use the following command:
+Use the following command:
```console
- sudo mdatp config tamper-protection enforcement-level --value block
- ```
+sudo mdatp config tamper-protection enforcement-level --value block
+```
![Image of manual configuration command](images/manual-config-cmd.png)
full_disk_access_enabled : true
2. Verify the result.
- ```bash
- mdatp health
- ```
-
- ```console
- healthy : true
- health_issues : []
- licensed : true
- engine_version : "1.1.19300.3"
- app_version : "101.70.19"
- org_id : "..."
- log_level : "info"
- machine_guid : "..."
- release_ring : "InsiderFast"
- product_expiration : Dec 29, 2022 at 09:48:37 PM
- cloud_enabled : true
- cloud_automatic_sample_submission_consent : "safe"
- cloud_diagnostic_enabled : false
- passive_mode_enabled : false
- real_time_protection_enabled : true
- real_time_protection_available : true
- real_time_protection_subsystem : "endpoint_security_extension"
- network_events_subsystem : "network_filter_extension"
- device_control_enforcement_level : "audit"
- tamper_protection : "block"
- automatic_definition_update_enabled : true
- definitions_updated : Jul 06, 2022 at 01:57:03 PM
- definitions_updated_minutes_ago : 5
- definitions_version : "1.369.896.0"
- definitions_status : "up_to_date"
- edr_early_preview_enabled : "disabled"
- edr_device_tags : []
- edr_group_ids : ""
- edr_configuration_version : "20.199999.main.2022.07.05.02-ac10b0623fd381e28133debe14b39bb2dc5b61af"
- edr_machine_id : "..."
- conflicting_applications : []
- network_protection_status : "stopped"
- data_loss_prevention_status : "disabled"
- full_disk_access_enabled : true
- ```
+```bash
+mdatp health
+```
+
+```console
+healthy : true
+health_issues : []
+licensed : true
+engine_version : "1.1.19300.3"
+app_version : "101.70.19"
+org_id : "..."
+log_level : "info"
+machine_guid : "..."
+release_ring : "InsiderFast"
+product_expiration : Dec 29, 2022 at 09:48:37 PM
+cloud_enabled : true
+cloud_automatic_sample_submission_consent : "safe"
+cloud_diagnostic_enabled : false
+passive_mode_enabled : false
+real_time_protection_enabled : true
+real_time_protection_available : true
+real_time_protection_subsystem : "endpoint_security_extension"
+network_events_subsystem : "network_filter_extension"
+device_control_enforcement_level : "audit"
+tamper_protection : "block"
+automatic_definition_update_enabled : true
+definitions_updated : Jul 06, 2022 at 01:57:03 PM
+definitions_updated_minutes_ago : 5
+definitions_version : "1.369.896.0"
+definitions_status : "up_to_date"
+edr_early_preview_enabled : "disabled"
+edr_device_tags : []
+edr_group_ids : ""
+edr_configuration_version : "20.199999.main.2022.07.05.02-ac10b0623fd381e28133debe14b39bb2dc5b61af"
+edr_machine_id : "..."
+conflicting_applications : []
+network_protection_status : "stopped"
+data_loss_prevention_status : "disabled"
+full_disk_access_enabled : true
+```
Notice that the "tamper_protection" is now set to "block".
The result will show "block" if tamper protection is on:
![Image of tamper protection in block mode](images/tp-block-mode.png) + You can also run full `mdatp health` and look for the "tamper_protection" in the output ## Verify tamper protection preventive capabilities
You can verify that tamper protection is on through various ways.
Tampering alert is raised in the Microsoft 365 Defender portal
-![Image of tampering alert raised in the Microsoft 365 Defender portal](images/tampering-sensor-portal.png)
+ ### Verify block mode and audit modes - Using Advanced hunting, you'll see tampering alerts appear - Tampering events can be found in the local device logs: `sudo grep -F '[{tamperProtection}]' /Library/Logs/Microsoft/mdatp/microsoft_defender_core.log`
-![Image of tamper protection log](images/tamper-protection-log.png)
+![Screenshot of tamper protection log.](images/tamper-protection-log.png)
+ ### DIY scenarios
Add the following configuration in your Intune profile:
If running the command `mdatp health` reports that the tamper protection is disabled, even if you enabled it and more than an hour has passed since the onboarding, then you can check if you have the right configuration by running the following command: ```console
-$ sudo grep -F '\[{tamperProtection}\]: Feature state:' /Library/Logs/Microsoft/mdatp/microsoft_defender_core.log | tail -n 1
+$ sudo grep -F '[{tamperProtection}]: Feature state:' /Library/Logs/Microsoft/mdatp/microsoft_defender_core.log | tail -n 1
``` The mode must be "block" (or "audit"). If it is not, then you haven't set the tamper protection mode either through `mdatp config` command or through Intune.+
security Troubleshoot Microsoft Defender Antivirus When Migrating https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/defender-endpoint/troubleshoot-microsoft-defender-antivirus-when-migrating.md
- Title: Troubleshoot Microsoft Defender Antivirus while migrating from a third-party solution
-description: Troubleshoot common errors when migrating to Microsoft Defender Antivirus
-keywords: event, error code, logging, troubleshooting, microsoft defender antivirus, windows defender antivirus, migration, microsoft defender antivirus
-
-ms.sitesec: library
---------- m365-security-- tier1 Previously updated : 04/08/2021--
-# Troubleshoot Microsoft Defender Antivirus while migrating from a third-party solution
--
-**Applies to:**
-- [Microsoft Defender for Endpoint Plan 1](https://go.microsoft.com/fwlink/p/?linkid=2154037)-- [Microsoft Defender for Endpoint Plan 2](https://go.microsoft.com/fwlink/p/?linkid=2154037)-- [Microsoft Defender Antivirus](https://www.microsoft.com/windows/comprehensive-security)-
-**Platforms**
-- Windows-
-You can find help here if you encounter issues while migrating from a third-party security solution to Microsoft Defender Antivirus.
-
-## Review event logs
-
-1. Open the Event viewer app by selecting the **Search** icon in the taskbar, and searching for *event viewer*.
-
- Information about Microsoft Defender Antivirus can be found under **Applications and Services Logs** \> **Microsoft** \> **Windows** \> **Windows Defender**.
-
-1. From there, select **Open** underneath **Operational**.
-
- Selecting an event from the details pane will show you more information about an event in the lower pane, under the **General** and **Details** tabs.
-
-## Microsoft Defender Antivirus won't start
-
-This issue can manifest in the form of several different event IDs, all of which have the same underlying cause.
-
-### Associated event IDs
-
-Event ID|Log name|Description|Source
-|||
-15|Application|Updated Windows Defender status successfully to SECURITY_PRODUCT_STATE_OFF.|Security Center
-5007|Microsoft-Windows-Windows Defender/Operational|Microsoft Defender Antivirus Configuration has changed. If this is an unexpected event you should review the settings as this may be the result of malware. <p> **Old value:** Default\IsServiceRunning = 0x0 <p> **New value:** HKLM\SOFTWARE\Microsoft\Windows Defender\IsServiceRunning = 0x1|Windows Defender
-5010|Microsoft-Windows-Windows Defender/Operational|Microsoft Defender Antivirus scanning for spyware and other potentially unwanted software is disabled.|Windows Defender
-
-### How to tell if Microsoft Defender Antivirus won't start because a third-party antivirus is installed
-
-On a Windows 10 or Windows 11 device, if you are not using Microsoft Defender for Endpoint, and you have a third-party antivirus installed, then Microsoft Defender Antivirus will be automatically turned off. If you are using Microsoft Defender for Endpoint with a third-party antivirus installed, Microsoft Defender Antivirus will start in passive mode, with reduced functionality.
-
-> [!TIP]
-> The scenario just described applies only to Windows 10 and Windows 11. Other versions of Windows have [different responses](microsoft-defender-antivirus-compatibility.md) to Microsoft Defender Antivirus being run alongside third-party security software.
-
-#### Use Services app to check if Microsoft Defender Antivirus is turned off
-
-To open the Services app, select the **Search** icon from the taskbar and search for *services*. You can also open the app from the command-line by typing *services.msc*.
-
-Information about Microsoft Defender Antivirus will be listed within the Services app under **Windows Defender** \> **Operational**. The antivirus service name is *Microsoft Defender Antivirus Service*.
-
-While checking the app, you may see that *Microsoft Defender Antivirus Service* is set to manual, but when you try to start this service manually, you get a warning stating, *The Microsoft Defender Antivirus Service service on Local Computer started and then stopped. Some services stop automatically if they are not in use by other services or programs.*
-
-This indicates that Microsoft Defender Antivirus has been automatically turned off to preserve compatibility with a third-party antivirus.
-
-#### Generate a detailed report
-
-You can generate a detailed report about currently active group policies by opening a command prompt in **Run as admin** mode, then entering the following command:
-
-```console
-GPresult.exe /h gpresult.html
-```
-
-This will generate a report located at *./gpresult.html*. Open this file and you might see the following results, depending on how Microsoft Defender Antivirus was turned off.
-
-##### Group policy results
-
-##### If security settings are implemented via group policy (GPO) at the domain or local level, or though System center configuration manager (SCCM)
-
-Within the GPResults report, under the heading, *Windows Components/Microsoft Defender Antivirus*, you may see something like the following entry, indicating that Microsoft Defender Antivirus is turned off.
-
-Policy|Setting|Winning GPO
-||
-Turn off Microsoft Defender Antivirus|Enabled|Win10-Workstations
-
-###### If security settings are implemented via Group policy preference (GPP)
-
-Under the heading, *Registry item (Key path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender, Value name: DisableAntiSpyware)*, you may see something like the following entry, indicating that Microsoft Defender Antivirus is turned off.
-
-DisableAntiSpyware|-
-|
-Winning GPO|Win10-Workstations
-Result: Success|
-**General**|
-Action|Update
-**Properties**|
-Hive|HKEY_LOCAL_MACHINE
-Key path|SOFTWARE\Policies\Microsoft\Windows Defender
-Value name|DisableAntiSpyware
-Value type|REG_DWORD
-Value data|0x1 (1)
-
-###### If security settings are implemented via registry key
-
-The report may contain the following text, indicating that Microsoft Defender Antivirus is turned off:
-
-> Registry (regedit.exe)
->
-> HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender
-> DisableAntiSpyware (dword) 1 (hex)
-
-###### If security settings are set in Windows or your Windows Server image
-
-Your imagining admin might have set the security policy, **[DisableAntiSpyware](/windows-hardware/customize/desktop/unattend/security-malware-windows-defender-disableantispyware)**, locally via *GPEdit.exe*, *LGPO.exe*, or by modifying the registry in their task sequence. You can [configure a Trusted Image Identifier](/windows-hardware/manufacture/desktop/configure-a-trusted-image-identifier-for-windows-defender) for Microsoft Defender Antivirus.
-
-### Turn Microsoft Defender Antivirus back on
-
-Microsoft Defender Antivirus will automatically turn on if no other antivirus is currently active. You'll need to turn the third-party antivirus completely off to ensure Microsoft Defender Antivirus can run with full functionality.
-
-> [!WARNING]
-> Solutions suggesting that you edit the *Windows Defender* start values for *wdboot*, *wdfilter*, *wdnisdrv*, *wdnissvc*, and *windefend* in HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services are unsupported, and may force you to re-image your system.
-
-Passive mode is available if you start using Microsoft Defender for Endpoint and a third-party antivirus together with Microsoft Defender Antivirus. Passive mode allows Microsoft Defender Antivirus to scan files and update itself, but it will not remediate threats. In addition, behavior monitoring via [Real Time Protection](configure-real-time-protection-microsoft-defender-antivirus.md) is not available under passive mode, unless [Endpoint data loss prevention (DLP)](/microsoft-365/security/defender-endpoint/information-protection-in-windows-overview) is deployed.
-
-Another feature, known as [limited periodic scanning](limited-periodic-scanning-microsoft-defender-antivirus.md), is available to end-users when Microsoft Defender Antivirus is set to automatically turn off. This feature allows Microsoft Defender Antivirus to scan files periodically alongside a third-party antivirus, using a limited number of detections.
-
-> [!IMPORTANT]
-> Limited periodic scanning is not recommended in enterprise environments. The detection, management and reporting capabilities available when running Microsoft Defender Antivirus in this mode are reduced as compared to active mode.
-
-> [!TIP]
-> If you're looking for Antivirus related information for other platforms, see:
-> - [Set preferences for Microsoft Defender for Endpoint on macOS](mac-preferences.md)
-> - [Microsoft Defender for Endpoint on Mac](microsoft-defender-endpoint-mac.md)
-> - [macOS Antivirus policy settings for Microsoft Defender Antivirus for Intune](/mem/intune/protect/antivirus-microsoft-defender-settings-macos)
-> - [Set preferences for Microsoft Defender for Endpoint on Linux](linux-preferences.md)
-> - [Microsoft Defender for Endpoint on Linux](microsoft-defender-endpoint-linux.md)
-> - [Configure Defender for Endpoint on Android features](android-configure.md)
-> - [Configure Microsoft Defender for Endpoint on iOS features](ios-configure-features.md)
--
-### See also
--- [Microsoft Defender Antivirus compatibility](microsoft-defender-antivirus-compatibility.md)-- [Microsoft Defender Antivirus in the Windows Security app](microsoft-defender-security-center-antivirus.md)
solutions Collaborate Teams Direct Connect https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/solutions/collaborate-teams-direct-connect.md
When you enable shared channels in Teams with another organization:
- Your organization's custom (line of business) apps will be available in shared channels and external participants will be able to access them. - Your organization's apps list will be available in shared channels and external participants will be able to access them.
-> [!NOTE]
-> [Guest settings for Microsoft 365 Groups](/microsoft-365/admin/create-groups/manage-guest-access-in-groups) must be enabled to use shared channels with external participants.
+## Prerequisites
+
+Collaborating with external participants in a shared channel requires that guest access be turned on for SharePoint and Microsoft 365 Groups. These settings are enabled by default, but if your organization has made changes to them, confirm the following settings before configuring shared channels:
+
+- [Microsoft 365 Groups sharing settings](/microsoft-365/solutions/microsoft-365-guest-settings#microsoft-365-groups) must both be enabled.
+- SharePoint [organization level](/microsoft-365/solutions/microsoft-365-guest-settings#sharepoint-and-onedrive-organization-level) and [site level](/microsoft-365/solutions/microsoft-365-guest-settings#sharepoint-site-level) sharing settings must allow guests. The domains you're sharing with must not be blocked.
## Video demonstration