Category | Microsoft Docs article | Related commit history on GitHub | Change details |
---|---|---|---|
copilot-for-microsoft-365-admin | Copilot For Microsoft 365 Admin | https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/copilot/copilot-for-microsoft-365-admin.md | description: "Learn about Copilot for Microsoft 365 admin and how it can help si # Copilot for Microsoft 365 admin (Preview) -Microsoft 365 Copilot harnesses the value of generative AI to boost IT admins' productivity by simplifying administration of Microsoft 365 and Microsoft 365 Copilot, and empowering you to focus on more strategic priorities. Copilot for Microsoft 365 admin helps admins perform tasks across different Microsoft 365 services using natural language interactions, contextual guidance, and proactive suggestions. Copilot for Microsoft 365 admin also leverages the power of Copilot to provide transferable skills across different admin centers and surfaces, breaking the barriers of switching between multiple admin tools and interfaces. +Copilot for Microsoft 365 admin harnesses the value of generative AI to boost IT admins' productivity by simplifying administration of Microsoft 365 and Microsoft 365 Copilot, and empowering you to focus on more strategic priorities. Copilot for Microsoft 365 admin helps admins perform tasks across different Microsoft 365 services using natural language interactions, contextual guidance, and proactive suggestions. Copilot for Microsoft 365 admin also leverages the power of Copilot to provide transferable skills across different admin centers and surfaces, breaking the barriers of switching between multiple admin tools and interfaces. >[!NOTE] > Copilot for Microsoft 365 admin is currently available in an invite-only preview. |
lighthouse | M365 Lighthouse Manage Tenant List | https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/lighthouse/m365-lighthouse-manage-tenant-list.md | description: "For Managed Service Providers (MSPs) using Microsoft 365 Lighthous # Manage your tenant list in Microsoft 365 Lighthouse -To help you manage your tenant list in Microsoft 365 Lighthouse, you can apply custom tags to your tenants. These tags can be used to organize your tenants and can also help you filter the existing views and insights available to relevant sets of tenants. You can manage your tags from the Tenants page. Once created and assigned, you can filter the data within the Tenants, Users, Devices, Threat management, and Windows 365 pages based on a tag. +To help you manage your tenant list in Microsoft 365 Lighthouse, you can apply custom tags to your tenants. These tags can be used to organize your tenants and can also help you filter the existing views and insights available to relevant sets of tenants. You can manage your tags from the Tenants page. Once tags are created and assigned, you can go to any page in Lighthouse that has a Tenants filter and use it to filter the data based on a tag. ## Before you begin -You must be a Global Administrator of the partner tenant. +You must be a Global Administrator in the partner tenant. ## Create a tag You must be a Global Administrator of the partner tenant. 3. In the **Manage tags** pane, select **Create tag**. -4. Enter a name and description. +4. Enter a name and optional description. 5. Select **Save**. You must be a Global Administrator of the partner tenant. 2. Select **Manage Tags**. -3. In the **Manage tags** pane, select the tag that you want to edit. +3. In the **Manage tags** pane, select the three dots (more actions) next to the tag that you want to edit, and then select **Edit tag**. -4. Edit the name and/or description as needed. +4. Edit the name, description, or assigned tenants as needed. 5. Select **Save**. -## Assign a tag +## Assign a tag to a tenant 1. In the left navigation pane in <a href="https://go.microsoft.com/fwlink/p/?linkid=2168110" target="_blank">Lighthouse</a>, select **Tenants**. -2. From the list of tenants, select the three dots (more actions) next to the tenant you want to tag. +2. From the list of tenants, select the three dots (more actions) next to the tenant that you want to tag, and then select **Tags**. -3. Select **Tags**. +3. Select a tag from the list. You can select only one tag at a time. -4. Select a tag from the list. You can select only one tag at a time. + Tags that are already assigned to the tenant have a check mark next to the tag name. -Tags that are already assigned to the tenant have a check mark to the right of the tag name. You can also assign a tag to multiple tenants by selecting the checkbox next to each tenant in the list, selecting **Assign Tags**, and then selecting a tag from the list. +You can also assign a tag to multiple tenants by selecting the checkbox next to each tenant in the list that you want to tag, selecting **Assign Tags**, and then selecting a tag from the list. > [!NOTE] > You can create up to 30 unique Tags and assign them to as many tenants as needed. Tags that are already assigned to the tenant have a check mark to the right of t 2. Select **Manage Tags**. -3. In the **Manage tags** pane, select the tag that you want to delete. +3. In the **Manage tags** pane, select the three dots (more actions) next to the tag that you want to delete, and then select **Delete tag**. -4. Select **Delete**. +4. In the confirmation dialog, select **Confirm**. -5. In the confirmation dialog, select **Confirm**. --## Remove a tag +## Remove a tag from a tenant 1. In the left navigation pane in <a href="https://go.microsoft.com/fwlink/p/?linkid=2168110" target="_blank">Lighthouse</a>, select **Tenants**. -2. From the list of tenants, select the three dots (more actions) next to the tenant you want to edit. --3. Select **Tags**. +2. From the list of tenants, select the three dots (more actions) next to the tenant that you want to edit, and then select **Tags**. 4. Select the tag you want to remove. -Tags that are currently assigned have a check mark to the right of the name. You can also remove a tag from multiple tenants by selecting the checkbox next to each tenant in the list, selecting **Assign Tags**, and then selecting a checked tag from the list. + Tags that are currently assigned to the tenant have a check mark next to the name. ++You can also remove a tag from multiple tenants by selecting the checkbox next to each tenant in the list that has a tag you want to remove, selecting **Assign Tags**, and then selecting a checked tag from the list. ## Next steps -After you've created and assigned tags, you can use them to filter your tenants. Go to any of the other pages (Users, Devices, Threat management, or Windows 365) and select one or more tags from the Tenants filter. You can create new tags to support specific views based on each page. +After you create and assign tags, you can use them to filter your tenants. Go to any page in Lighthouse that has a Tenants filter, select the filter, and then enter a tag to filter by or browse tags and select one or more tags from the list. You can also create new tags to support specific views based on each page. ## Related content |
lighthouse | M365 Lighthouse Review Audit Logs | https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/lighthouse/m365-lighthouse-review-audit-logs.md | Microsoft 365 Lighthouse audit logs record actions that generate a change in Lig ## Before you begin -To view audit logs, you must have one of the following permissions: +To view audit logs, you must have one of the following roles: -- Microsoft Entra role - Global Administrator of partner tenant+- Microsoft Entra role: Global Administrator in partner tenant -- Microsoft Partner Center role - Admin Agent+- Microsoft Partner Center role: Admin Agent > [!CAUTION] > To help keep your organization secure, Microsoft recommends that you use roles with the minimum level of permissions needed to perform a job. Global Administrator is a highly privileged role that should be limited to scenarios where you can't use a less-privileged role. To view audit logs, you must have one of the following permissions: 1. In the left navigation pane in <a href="https://go.microsoft.com/fwlink/p/?linkid=2168110" target="_blank">Lighthouse</a>, select **Audit logs**. > [!NOTE]- > It might take up to 1 hour to see new logs. Go to the respective service to see the most recent changes. + > It might take up to an hour to see new logs. Go to the respective service to see the most recent changes. -2. Filter the logs, as needed, by using the following options: -- - **Date range** - Previous month, week, or day. - - **Tenants** - Tenant tags or customer tenant names. - - **Activity** - Microsoft 365 activity type that corresponds to the action taken. For more information, see the [Activities](#activities) table. - - **Initiated by** - Who initiated the action. +2. Select a tab to view specific logs: **Audit logs**, **Graph logs**, **Directory logs**, **Sign-in logs**. -3. Select a log from the list to see full details, including the **Request** body. +2. Filter the logs, as needed, by using the following options: + - Audit logs tab + - **Tenants** - Tenant tags or customer tenant names. + - **Time range** - Last day, last 7 days, last 30 days. + - **Activity** - Microsoft 365 activity type that corresponds to the action taken. For more information, see the [Activities](#activities) table. + - **Initiated by** - Who initiated the action. ++ - Graph logs tab + - **Tenants** - Tenant tags or customer tenant names. + - **Time range** - Last day, last 7 days, last 30 days. + - **Request type** - Type of request that the Microsoft Graph service received and processed for a tenant. + - **Response code** - The HTTP response status code for the event. ++ - Directory logs tab + - **Tenants** - Tenant tags or customer tenant names. + - **Time range** - Last day, last 7 days, last 30 days. + - **Type** - User management, Group management, Device management, App management, Role management, Policy management + - **Operation type** - Add, Assign, Update, Unassign, Delete Service API ++ - Sign-in logs tab + - **Tenants** - Tenant tags or customer tenant names. + - **Time range** - Last day, last 7 days, last 30 days. + - **Is interactive** - Yes (by a user), No (by a client app or OS components on behalf of a user) + - **Risk state** - None, Confirmed safe, Remediated, Confirmed compromised, Dismissed, At risk + - **Risk level during sign-in** - Risk level of the sign-in session (likelihood that the sign-in is compromised) ++3. Select a log from the list to see full details, including the **Request body**. To export log data to a comma-separated values (.csv) file, select **Export**. The following table lists activities captured within Lighthouse audit logs. The ## Next steps -Use Microsoft Graph API to access more audit events, if needed. For more information, see [Overview for multi-tenant management using the Microsoft 365 Lighthouse API](/graph/managedtenants-concept-overview). +Use the Microsoft Graph API to access more audit events, if needed. For more information, see [Use the Microsoft Graph API](/graph/use-the-api) and [Manage multiple customer tenants using the Microsoft 365 Lighthouse API](/graph/managedtenants-concept-overview). ## Related content |
lighthouse | M365 Lighthouse View Service Health | https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/lighthouse/m365-lighthouse-view-service-health.md | description: "For Managed Service Providers (MSPs) using Microsoft 365 Lighthous # View tenant service health in Microsoft 365 Lighthouse -You can view service health for the tenants you manage in Microsoft 365 Lighthouse. Service health includes incidents and advisories for several services, including Microsoft Intune, Microsoft Entra identity services, and mobile device management (MDM) cloud services. You can also see how many of your managed tenants are affected by incidents. For example, if one of your tenants is experiencing problems, you can check the Service health page to determine whether it's a known issue with a resolution in progress or whether a recent change may be impacting them. This could save you time troubleshooting and reduce support calls. +You can view service health for the tenants you manage in Microsoft 365 Lighthouse. Service health includes incidents and advisories for several services, including Microsoft Intune, Microsoft Entra identity services, and mobile device management (MDM) cloud services. You can also see how many of your managed tenants are affected by incidents. For example, if one of your tenants is experiencing problems, you can check the Service health page to determine whether it's a known issue with a resolution in progress or whether a recent change might be impacting them. Checking service health could save you time troubleshooting and reduce support calls. If you can't sign in to Lighthouse, you can use the [Microsoft 365 service health status page](https://status.office365.com/) to check for known issues preventing you from logging in to your partner tenant. Also, sign up to follow [@MSFT365status](https://twitter.com/MSFT365Status) on Twitter to see information on specific service incidents. ## Before you begin -To view service health, you'll need a Microsoft Entra role in the partner tenant with the following property set: **microsoft.office365.serviceHealth/allEntities/allTasks**. For a list of Microsoft Entra roles, see [Microsoft Entra built-in roles](/azure/active-directory/roles/permissions-reference). +To view service health, you need a Microsoft Entra role in the partner tenant with the following property set: **microsoft.office365.serviceHealth/allEntities/allTasks**. For a list of Microsoft Entra roles, see [Microsoft Entra built-in roles](/azure/active-directory/roles/permissions-reference). -## View service health status for all tenants +## View service health status and issue details 1. In the left navigation pane in <a href="https://go.microsoft.com/fwlink/p/?linkid=2168110" target="_blank">Lighthouse</a>, select **Service health**. -2. On the **Service health** page, review the current service health status, including: +2. At the top of the page, review the current service health status of all your tenants: - Total number of incidents - Total number of advisories affecting any of the managed tenants- - Number of services with active incidents. + - Number of services with active incidents -3. On the **All services** tab, review issues by service. +3. To review issues by service, select the **All services** tab. To review all current issues, select the **All issues** tab. -4. On the **All issues** tab, review all current issues. +4. Select an issue from the list to open the issue details pane. -## Review issue details +5. Select the **Overview** tab to view information including issue type, status, user impact, and issue history. -1. In the left navigation pane in <a href="https://go.microsoft.com/fwlink/p/?linkid=2168110" target="_blank">Lighthouse</a>, select **Service health**. --2. On the **Service health** page, select the **All services** or **All issues** tab. --3. Select an issue from the list. --4. In the issue details pane, review detailed information, including issue type, tenants affected, user impact, and issue history. --On the **Tenants affected** tab, you can export a list of affected tenants to a comma-separated values (.csv) file so you can share it with your support teams. +6. Select the **Tenants affected** tab to see a list of tenants affected by the issue. From here, you can export a list of affected tenants to a comma-separated values (.csv) file so you can share it with your support teams. ## Related content |
loop | Loop Compliance Summary | https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/loop/loop-compliance-summary.md | Where the Loop content was originally created determines its storage location: |Audit logs and events |**Audit** logs for all events: search and export Microsoft 365 service events for security and compliance investigations <ol><li>use the [compliance admin center](https://compliance.microsoft.com/auditlogsearch)<li>search audit logs for "loop" or "loot" or "fluid"<li>further filter exported results by "SourceFileExtension":"loop" or "SourceFileExtension":"loot" (templates) or "SourceFileExtension":"fluid" (deprecated)|**Audit** logs for all events: search and export Microsoft 365 service events for security and compliance investigations <ol><li>use the [compliance admin center](https://compliance.microsoft.com/auditlogsearch)<li>search audit logs for Loop ApplicationID `a187e399-0c36-4b98-8f04-1edc167a0996`</ol>Note: Loop workspaces create and update .pod files to manage content in the workspace.| |Audit log access |**Audit** logs are retained, can be exported, and can be streamed to third party tools|**Audit** logs are retained, can be exported, and can be streamed to third party tools| |***eDiscovery***|||-|Search, Collection, Review, Export (Purview) |Microsoft **[Purview eDiscovery](/microsoft-365/loop/loop-components-teams#do-loop-and-fluid-files-support-ediscovery)** supports search and collection, review (premium only), and export (premium only) as HTML or original. You can also download and reupload the files to any OneDrive to view them in their native format.|Microsoft **[Purview eDiscovery](/microsoft-365/loop/loop-components-teams#do-loop-and-fluid-files-support-ediscovery)** supports search and collection, review (premium only), and export (premium only) as HTML or original. You can also download and reupload the files to any OneDrive to view them in their native format.| +|Search, Collection, Review, Export (Purview) |Microsoft **[Purview eDiscovery](/microsoft-365/loop/loop-components-teams#do-loop-and-fluid-files-support-ediscovery)** supports search and collection, review (premium only), and export (premium only) as HTML or original. You can also download and reupload the files to any OneDrive to view them in their native format.<br><br>**Not Yet Available**: <br>Full text search of content within .loop files in Purview review sets.|Microsoft **[Purview eDiscovery](/microsoft-365/loop/loop-components-teams#do-loop-and-fluid-files-support-ediscovery)** supports search and collection, review (premium only), and export (premium only) as HTML or original. You can also download and reupload the files to any OneDrive to view them in their native format.<br><br>**Not Yet Available**: <br>Full text search of content within .loop files in Purview review sets.| |Export (Third Party Tools) |Microsoft **[Graph API](/graph/api/driveitem-get-content-format)** export support.|**Not Yet Available**: <br>[Programmatic API access to Loop workspace containers](#programmatic-apis-not-yet-available) isn't yet available.| |Legal Hold |**Legal Hold** support to ensure content isn't deleted (as related to litigation and security investigations) and stored in the [Preservation Hold Library](/sharepoint/governance/ediscovery-and-in-place-holds-in-sharepoint-server).|**Legal Hold** support to ensure content isn't deleted (as related to litigation and security investigations) and stored in the [Preservation Hold Library](/sharepoint/governance/ediscovery-and-in-place-holds-in-sharepoint-server).| |***Records Management***||| The following sections detail capabilities that are **not yet available** for Mi - All Loop workspaces are created as tenant-owned, in the tenant default geo. Loop doesn't create **user-owned workspace types**, so when an employee leaves the organization, their non-shared Loop workspaces such as Ideas become ownerless, remain in the tenant, and aren't automatically deleted. - **Individual controls for guest or external sharing** of a specific Loop workspace isn't available. +### eDiscovery Purview capabilities not yet available +- Full text search of content within .loop files in Purview review sets. + ### Records Management not yet available - Retention labels aren't yet available for Loop workspace content. |
loop | Loop Components Configuration | https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/loop/loop-components-configuration.md | There are several IT Admin settings provided to enable the Loop component experi |Configure |Setting Type |Specific Policy |Notes | |||||-|Loop component experiences across Microsoft 365 | Cloud Policy | **Create and view Loop files in Microsoft apps that support Loop** | Applies to: <br/> - Outlook integration<br> - OneNote integration<br> - Whiteboard integration<br> Does **NOT** apply to:<br> - Loop workspaces<br> - Teams integration<br> - Copilot pages | -|Copilot pages integration | Cloud Policy | **Create and view Loop files in Microsoft 365 Copilot Chat** | Applies to Pages in Copilot Chat | +|Loop component experiences across Microsoft 365 | Cloud Policy | **Create and view Loop files in Microsoft apps that support Loop** | Applies to: <br/> - Outlook integration<br> - OneNote integration<br> - Whiteboard integration<br> Does **NOT** apply to:<br> - Loop workspaces<br> - Teams integration<br> - Copilot Pages | +|Copilot Pages integration | Cloud Policy | **Create and view Loop files in Microsoft 365 Copilot Chat** | Applies to Copilot Pages in a Copilot chat experience | |Outlook integration of Loop experiences | Cloud Policy | **Create and view Loop files in Outlook** | First checks **Create and view Loop files in Microsoft apps that support Loop**; then applies **Create and view Loop files in Outlook**, if applicable. | |Teams integration | SharePoint property | See [Settings management for Loop components in Teams](#settings-management-for-loop-functionality-in-teams) | Teams only checks the settings in this row. | There are several IT Admin settings provided to enable the Loop component experi |Scenario |Policies Configured | |||-|Enable Loop components everywhere | **Create and view Loop files in Microsoft apps that support Loop** = Enabled (or Not Configured)<br/>**Create and view Loop files in Microsoft 365 Copilot Chat** = Enabled (or Not Configured)<br/>[Teams-only] `Set-SPOTenant -IsLoopEnabled $true`, `Set-SPOTenant -IsCollabMeetingNotesFluidEnabled $true` | -|Enable Loop components everywhere, but Disable integration in Communication app (Outlook, Teams) | **Create and view Loop files in Microsoft apps that support Loop** = Enabled (or Not Configured)<br/>**Create and view Loop files in Microsoft 365 Copilot Chat** = Enabled (or Not Configured)<br/>**Create and view Loop files in Outlook** = Disabled<br/>[Teams-only] `Set-SPOTenant -IsLoopEnabled $false`, `Set-SPOTenant -IsCollabMeetingNotesFluidEnabled $false` | -|Disable Loop components everywhere | **Create and view Loop files in Microsoft apps that support Loop** = Disabled<br/>**Create and view Loop files in Microsoft 365 Copilot Chat** = Disabled<br/>[Teams-only] `Set-SPOTenant -IsLoopEnabled $false`, `Set-SPOTenant -IsCollabMeetingNotesFluidEnabled $false` | +|Enable Loop components everywhere | **Create and view Loop files in Microsoft apps that support Loop** = Enabled (or Not Configured)<br/><br/>**Create and view Loop files in Microsoft 365 Copilot Chat** = Enabled (or Not Configured)<br/><br/>[Teams-only] `Set-SPOTenant -IsLoopEnabled $true`, `Set-SPOTenant -IsCollabMeetingNotesFluidEnabled $true` | +|Enable Loop components everywhere, but Disable integration in Communication app (Outlook, Teams) | **Create and view Loop files in Microsoft apps that support Loop** = Enabled (or Not Configured)<br/><br/>**Create and view Loop files in Microsoft 365 Copilot Chat** = Enabled (or Not Configured)<br/><br/>**Create and view Loop files in Outlook** = Disabled<br/>[Teams-only] `Set-SPOTenant -IsLoopEnabled $false`, `Set-SPOTenant -IsCollabMeetingNotesFluidEnabled $false` | +|Disable Loop components everywhere | **Create and view Loop files in Microsoft apps that support Loop** = Disabled<br/><br/>**Create and view Loop files in Microsoft 365 Copilot Chat** = Disabled<br/><br/>[Teams-only] `Set-SPOTenant -IsLoopEnabled $false`, `Set-SPOTenant -IsCollabMeetingNotesFluidEnabled $false` | ## User experience expectations when admin settings are configured |
loop | Loop Workspaces Storage Permission | https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/loop/loop-workspaces-storage-permission.md | Where the loop content was originally created determines its storage location. S ## Loop app's usage of organization's storage quota -Loop app workspaces are stored inside your tenant. Loop workspaces and pages count against your tenant's storage quota, starting November 2023. During the Loop app's Public Preview in 2023, Loop app content did **not** use your existing storage quota. +Loop app workspaces are stored inside your tenant. Loop workspaces and pages count against your tenant's storage quota, starting November 2023. ## Content permissions mechanism There are other types of groups and membership lists in the Microsoft ecosystem, ### In the Loop app -The Loop app is designed for shared workspaces and personal workspaces. +The Loop app is designed for both shared and personal workspaces. -Shared workspaces are permissioned with a roster. If the owner leaves the company, the workspace becomes ownerless, remains in the tenant, and isn't automatically deleted. If the creator of the workspace is the person who left the company, then others can't delete the workspace. +#### Shared Workspaces -Personal workspaces are also permissioned with a roster, but there's only one person in them by design. When a user leaves a company, their personal workspaces become ownerless, remain in the tenant, and aren't automatically deleted. +- Shared workspaces are permissioned with a roster. If the owner leaves the company, the workspace becomes ownerless, remains in the tenant, and isn't automatically deleted. +- If the creator of the workspace is the person who left the company, others cannot delete the workspace. ++#### Personal Workspaces ++- There are currently two types of personal workspaces: Ideas and Copilot Pages. +- Personal content is private by default, allowing users to work without forced sharing or coauthoring, similar to OneDrive. ++##### Ideas ++- Ideas is a tenant-owned personal workspace, permissioned with a roster but designed for single-person use. +- When a user leaves the company, like a shared workspace, their Ideas workspace becomes ownerless, remains in the tenant, and is not automatically deleted. ++##### Copilot Pages ++- Copilot Pages is a user-owned workspace, created only by Copilot, and is lifecycle managed with the user account. +- Copilot Pages is deleted when the user account is deleted from the organization. +- User-owned workspaces cannot be permanently reassigned to a new owner. These workspaces follow the same cleanup schedule as OneDrive: 30 days active, then soft deleted, and permanently purged 93 days after soft deletion. +- Admins can recover content during the soft delete period using the SharePoint Admin Center or PowerShell. ++Note: A feature for IT admins to assign additional temporary custodians during the cleanup period of user-owned workspaces to make copies of content is not yet available. ### In Loop components created in Microsoft 365 outside of the Loop app -Loop components created outside of the Loop are stored in the OneDrive of the person who created the component. Therefore, if that user leaves the organization, the standard OneDrive IT policy is applied. +Loop components created outside of Loop are stored in the OneDrive of the person who created the component. Therefore, if that user leaves the organization, the standard OneDrive IT policy is applied. ++For more information on the storage location of components based on where they are created, see [Loop Storage](/microsoft-365/loop/loop-compliance-summary#loop-storage). -## Management of Loop app's storage +## Management of Loop content For more information, see [available admin capabilities](/microsoft-365/loop/loop-compliance-summary#available-admin-capabilities) section of the [Summary of governance, lifecycle, and compliance capabilities](/microsoft-365/loop/loop-compliance-summary). |