Updates from: 06/08/2024 06:39:12
Category Microsoft Docs article Related commit history on GitHub Change details
manage-public-web-access Manage Public Web Access https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/copilot/manage-public-web-access.md
All admin setting updates may take up to 24 hours to reflect any changes.
## End user action required
-There's a separate toggle for end users to enable and disable web access for Microsoft Copilot, and it can be found in the Plugins menu for Copilot. This toggle is initially off by default, and users will have to enable it to receive this experience.
+There's a separate toggle for end users to enable and disable web access for Microsoft Copilot, and it can be found in the Plugins menu for Copilot. This toggle is initially off by default, and users will have to enable it to receive this experience.
+
+When a user submits their prompt with the web toggle turned on, they may receive two separate responses. If resources are found within Microsoft 365, the user will see **From your company's resources, emails, Teams messages, etc**. If resources are found outside of Microsoft 365, the user will see **From the web:**. The user can see results from both. Additionally, if the results are from the web only, the user will see the same **From the web:** heading.
If you turn off web access from the admin center, this control is disabled. However, if you enable web access, your users must enable the toggle in their settings as well to allow web access.
backup Backup Faq https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/backup/backup-faq.md
Example events that aren't versioned or recoverable via backup:
The recovery point objective (RPO) is the maximum amount of time between the most recent backup and a data destruction event. Stated another way, itΓÇÖs the amount data lost due to a data destruction event not recoverable via the backups. In the case of Microsoft 365 Backup, the RPOs are:
-For OneDrive and SharePoint, the RPO for the first two weeks is 15 mins, then one week beyond that. This means for the first two weeks, the most amount of data that can be lost due to a data destruction event is roughly 10 minuteΓÇÖs worth of the most recent data. Likewise, after two weeks, the most amount of data that can be lost is a weekΓÇÖs worth of data.
+For OneDrive and SharePoint, the RPO for the first two weeks is 15 minutes, then one week beyond that. This means for the first two weeks, the most amount of data that can be lost due to a data destruction event is roughly 10 minuteΓÇÖs worth of the most recent data. Likewise, after two weeks, the most amount of data that can be lost is a weekΓÇÖs worth of data.
-For Exchange Online, the RPO is 10 seconds, meaning the most amount of data that can be lost due to a data destruction event is roughly 10 secondΓÇÖs worth of data.
+For Exchange Online, the RPO is 10 minutes, meaning the most amount of data that can be lost due to a data destruction event is roughly 10 minutesΓÇÖs worth of data.
+Let's start with what it doesn't mean: We are *not* taking snapshots every 10 minutes.
+
+Backup frequency of 10 minutes (if the item is modified) means that changes to the item will be saved as a version once every 10 minutes, no matter how many changes are made in that 10-minute interval. For example, if a ransomware attack encrypts the email item every minute, will we take six copies in an hour.
+<!
Let's start with what it doesn't mean: We are *not* taking snapshots every 10 seconds. Backup frequency of 10 seconds (if the item is modified) means that changes to the item will be saved as a version once every 10 seconds, no matter how many changes are made in that 10-second interval. For example, if a ransomware attack encrypts the email item every second, will we take six copies in a minute.-
+>
business-premium M365 Business Premium Setup https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/business-premium/m365-business-premium-setup.md
audience: Admin Previously updated : 05/31/2024 Last updated : 06/07/2024 ms.localizationpriority: medium f1.keywords: NOCSH
Microsoft 365 Business Premium includes a guided setup process, as shown in the
### The guided setup process, step by step
-1. As a global administrator, go to the [Microsoft 365 admin center](https://admin.microsoft.com/) and sign in.
+1. Go to the [Microsoft 365 admin center](https://admin.microsoft.com/) and sign in.
2. A Business Advisor screen opens where you can select your top goals for Microsoft 365. Select and save your goals, or select **Skip for new**.
business-premium M365 Campaigns Setup https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/business-premium/m365-campaigns-setup.md
audience: Admin Previously updated : 05/31/2024 Last updated : 06/07/2024 ms.localizationpriority: medium - M365-Campaigns
Make sure that you meet the following requirements before you begin your setup p
|Requirement|Description| ||| |Subscription|Microsoft 365 Business Premium or Microsoft 365 for Campaigns <br/><br/> To start a trial or purchase your subscription, see the following resources: <ul><li>[Get Microsoft 365 Business Premium](m365-business-premium-setup.md#sign-up-for-microsoft-365-business-premium)</li><li>[Get Microsoft 365 for Campaigns](#get-microsoft-365-for-campaigns)</li></ul>|
-|Permissions|To complete the initial setup process, you must be a Global Admin. [Learn more about admin roles](../admin/add-users/about-admin-roles.md).|
+|Permissions|To complete the initial setup process, you must have an appropriate role assigned. [Learn more about admin roles](../admin/add-users/about-admin-roles.md).|
|Browser requirements|Microsoft Edge, Safari, Chrome or Firefox. [Learn more about browser requirements](https://www.microsoft.com/microsoft-365/microsoft-365-and-office-resources#coreui-heading-uyetipy).| |Operating systems (client)|**Windows**: Windows 10 or 11 Pro <br/> **macOS**: One of the three most recent versions of macOS| |Operating systems (servers)|Windows Server or Linux Server <br/> (Requires an additional license, such as [Microsoft Defender for Business servers](../security/defender-business/get-defender-business.md#how-to-get-microsoft-defender-for-business-servers).)|
Make sure that you meet the following requirements before you begin your setup p
## Sign in to Microsoft 365 for Campaigns
-If you signed up for Microsoft 365 for Campaigns, you're designated as the Microsoft 365 admin (also referred to as the Global Administrator). This allows you to sign in and initiate the system.
-
-Here's how to sign in:
- 1. Find the username and password we sent to the email address you used when you [signed up for Microsoft 365 for Campaigns](m365-campaigns-sign-up.md). 2. In the browser, go to the [Microsoft 365 admin center](https://go.microsoft.com/fwlink/p/?linkid=837890).
You can customize your sign-in page with your branding. You can also add text to
## Customize the text on your sign-in page
-To update the customizable elements on the sign-in page, you have to be a global admin. For specific instructions, see [add company branding](/azure/active-directory/fundamentals/customize-branding) article.
+To update the customizable elements on the sign-in page, you must have an appropriate role assigned. For specific instructions, see [add company branding](/azure/active-directory/fundamentals/customize-branding) article.
The elements you can update are:
business-premium M365bp Intune Admin Roles In The Mac https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/business-premium/m365bp-intune-admin-roles-in-the-mac.md
audience: Admin Previously updated : 05/31/2024 Last updated : 06/07/2024 ms.localizationpriority: medium - tier2
Before adding specific Intune roles, roles must be assigned in Microsoft Entra I
Roles-based access control (RBAC) helps you manage who has access to your organization's resources and what they can do with those resources. By assigning roles to your Intune users, you can limit what they can see and change. There are both built-in and custom roles, and each role has a set of permissions that determine what users with that role can access, or change within your organization. The following information will cover both types of roles in Intune.
-To create, edit, or assign roles, your account must have one of the following permissions in Microsoft Entra ID:
+To create, edit, or assign roles, your account must have the **Intune Service Administrator** (also known as **Intune Administrator** but not to be confused with the built-in **Intune Role Administrator** role.)
-- **Global Administrator**-- **Intune Service Administrator** (also known as **Intune Administrator** but not to be confused with the built-in **Intune Role Administrator** role.)-
-Find more information on [Microsoft Entra roles and RBAC](/azure/active-directory/roles/permissions-reference).
+For more information, see [Microsoft Entra roles and RBAC](/azure/active-directory/roles/permissions-reference).
## Microsoft Intune built-in roles
Here are the built-in roles that you can assign:
You can create custom roles in Intune that include any permissions required for a specific job function. For example, if an IT department group manages applications, policies, and configuration profiles, you can add all those permissions together in one custom role. After creating a custom role, you can assign it to any users that need those permissions.
-As with built-in roles, in order to create, edit, or assign roles, your account must have one of the following permissions in Microsoft Entra ID:
--- **Global Administrator**-- **Intune Service Administrator** (also known as **Intune Administrator** but not to be confused with the built-in **Intune Role Administrator** role.)- To create a custom role:
-1. In the Microsoft Intune admin center, choose **Tenant administration > Roles > All roles > Create**.
+1. In the [Intune admin center](https://intune.microsoft.com), choose **Tenant administration** > **Roles** > **All roles** > **Create**.
1. On the **Basics** page, enter a name and description for the new role, then choose **Next**.
To create a custom role:
To copy a role:
-1. In the Microsoft Intune admin center, choose **Tenant administration > Roles > All roles >** select the checkbox for a role in the list > **Duplicate**.
+1. In the [Intune admin center](https://intune.microsoft.com), choose **Tenant administration** > **Roles** > **All roles >** select the checkbox for a role in the list, and then choose **Duplicate**.
1. On the **Basics** page, enter a name. Make sure to use a unique name.
To copy a role:
## How to assign a role
-You can assign a built-in or custom role to an Intune user. To create, edit, or assign roles, your account must have one of the following permissions in Microsoft Entra ID:
--- **Global Administrator**-- **Intune Service Administrator** (also known as **Intune Administrator** but not to be confused with the built-in **Intune Role Administrator** role.)
+1. In the [Intune admin center](https://intune.microsoft.com), choose **Tenant administration** > **Roles** > **All roles**.
-1. In the Microsoft Intune admin center, choose **Tenant administration > Roles > All roles**.
-
-2. Choose the built-in role you want to assign > Assignments > + Assign.
+2. Choose the built-in role you want to assign, select **Assignments**, and then choose **+ Assign**.
3. On the **Basics** page, enter an Assignment name and optional Assignment description, and then choose **Next**.
You can assign a built-in or custom role to an Intune user. To create, edit, or
If you're working with a Microsoft partner, you can assign them admin roles. They, in turn, can assign users in your company - or their company - admin roles. You might want them to do this, for example, if they're setting up and managing your online organization for you.
-A partner can assign these roles:
--- Full administration, which has privileges equivalent to a global admin, except for managing multi-factor authentication through the Partner Center.--- Limited administration, which has privileges equivalent to a helpdesk admin.- Before the partner can assign these roles to users, you must add the partner as a delegated admin to your account. This process is initiated by an authorized partner. The partner sends you an email to ask you if you want to give them permission to act as a delegated admin. For instructions, see [Authorize or remove partner relationships](../admin/misc/add-partner.md). ## See also
business-premium M365bp Protect Against Malware Cyberthreats https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/business-premium/m365bp-protect-against-malware-cyberthreats.md
To learn more about preset security policies, see [Preset security policies in E
> [!IMPORTANT] > Before you begin, make sure you have one of the following roles assigned in Exchange Online (which is included in your subscription): >
-> - Global Administrator
> - Organization Management > - Security Administrator >
business-premium M365bp Set Up Compliance https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/business-premium/m365bp-set-up-compliance.md
audience: Admin Previously updated : 05/31/2024 Last updated : 06/07/2024 ms.localizationpriority: medium - m365-security
Use this article to get started with your information protection capabilities.
## Before you begin
-Make sure you have one of the following roles assigned in Microsoft Entra ID:
--- Global Administrator-- Compliance Administrator-
-To learn more, see [Get started with the roles page](../admin/add-users/admin-roles-page.md).
+Make sure you have one an appropriate role, such as Compliance Administrator assigned in Microsoft Entra ID. For more information, see [Get started with the roles page](../admin/add-users/admin-roles-page.md).
## Use Compliance Manager to get started
business-premium M365bp Use Labels Encryption https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/business-premium/m365bp-use-labels-encryption.md
ms.audience: Admin Previously updated : 05/31/2024 Last updated : 06/07/2024 ms.localizationpriority: medium - M365-Campaigns
Admins can create mail flow rules to automatically protect email messages that a
You create mail flow rules to encrypt email messages with Microsoft Purview Message Encryption. Define mail flow rules for triggering message encryption by using the <a href="https://go.microsoft.com/fwlink/p/?linkid=2059104" target="_blank">Exchange admin center (EAC)</a>.
-1. In a web browser, using a work or school account that has been granted global administrator permissions, sign in.
-
-2. Choose the Admin tile.
-
-3. In the Admin center, choose **Admin centers** \> **Exchange**.
-
-For more information, see [Define mail flow rules to encrypt email messages](../compliance/define-mail-flow-rules-to-encrypt-email.md).
+See [Define mail flow rules to encrypt email messages](../compliance/define-mail-flow-rules-to-encrypt-email.md).
### Brand your encryption messages
enterprise M365 Dr Workload Other https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/enterprise/m365-dr-workload-other.md
Customers based in EU and UK who signed up for Viva Goals prior to December 5, 2
See the [Static data location information for select workloads](#static-data-location-information-for-select-workloads) section. The data region for Manager/Leader and Advanced is determined by the _Default Geography_ of the _tenant_, not individual users.
-Starting June 2024, Viva Insights (Advanced, Manager, Leader) customer data for new tenants in Australia will be stored in data centers located in Australia.
+Starting June 2024, Viva Insights (Advanced, Manager, Leader) customer data for new tenants in Australia will be provisioned in data centers located in Australia.
## Viva Insights ΓÇô Personal