Loading...

Upcoming Secure by Default Settings Changes for Exchange and Teams APIs

Upcoming Secure by Default Settings Changes for Exchange and Teams APIs

Starting late October to November 2025, Microsoft will require admin consent for third-party apps accessing Exchange and Teams content via Microsoft-managed default consent policy. This enhances security by restricting user consent, affecting new app permissions but not existing approved apps. Admins should review app access and configure consent workflows accordingly. As part of the Microsoft Secure Future Initiative (SFI) and in alignment with the “Secure by Default” principle, we are updating the Microsoft-managed default consent policy in Microsoft 365 Graph to align with Microsoft’s ongoing security improvements, help you to meet industry best practices, and harden your tenant’s security posture. These changes enable admins to better control third-party app access for Exchange and Teams content. This is the next step in a broader effort to evaluate and evolve Microsoft 365 defaults through the lens of SFI. This update follows our recent SharePoint and OneDrive changes that blocked legacy protocols and required admin consent for third-party apps accessing files and sites. The Exchange and Teams updates are a continuation of this same approach. admin consent for third-party apps accessing files and sites. The Exchange and Teams updates are a continuation of this same approach. When this will happen: These changes will begin rolling out by end of October 2025 and are expected to be completed by late-November 2025. How this affects your organization: The following settings will be updated: Change Impact Require admin consent for apps accessing Exchange and Teams content  For customers using the Microsoft-managed default consent policy, admin approval will be required for third-party apps accessing Exchange and Teams content via Microsoft Graph, Exchange Web Services (EWS), Exchange ActiveSync (EAS), POP3, and IMAP4. To preserve end-user experience, some Exchange email clients are exempted from this change. Administrators can review and modify as noted below. These changes will be reflected as an update to the Microsoft-managed default consent policy. With this change, any organization using the Microsoft-managed user consent policy will require admin consent for Mail, Teams Chat and Meetings functionality across various protocols. Learn more about Graph permissions. Organizations using other user consent policies will not be affected. These changes […]

The post Upcoming Secure by Default Settings Changes for Exchange and Teams APIs appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Upcoming Secure by Default Settings Changes for Exchange and Teams APIs

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Preparing the Windows ecosystem for next-generation code signing

Rollout schedule: Microsoft guidance is already available. October 19, 2026: Microsoft Windows Production PCA 2011 expires. End of 2026: Windo...

1 hour ago

Microsoft Viva: Viva Learning retirement of Microsoft 365 training content

Microsoft is retiring 161 Microsoft 365 training modules and selected articles from Viva Learning on September 21, 2026, removing outdated con...

1 hour ago

Improved capabilities for files with Copilot in OneDrive Web

Copilot in OneDrive Web enables users with a Microsoft 365 Copilot license to find, understand, analyze, create, and act on files using natura...

1 hour ago

Microsoft Teams: Prepare custom apps for private and shared channel compatibility

Microsoft Teams will roll out a feature by September 2026 to help admins identify custom line-of-business apps needing updates for private and...

1 hour ago

Microsoft Entra ID: Passkey support for B2B users

Microsoft Entra ID will support passkey registration and sign-in for B2B users to meet resource tenant MFA requirements, enhancing phishing re...

1 hour ago

Microsoft 365 admin center: Usage reports migrating to new domains

Microsoft 365 admin center Usage reports domains will change starting mid-August 2026, with current and new domains active in parallel for at ...

1 hour ago

Microsoft Teams: Local Pan-tilt-zoom (PTZ) controls for Microsoft Teams Rooms on Windows

Microsoft Teams Rooms on Windows will add native local Pan-Tilt-Zoom (PTZ) camera controls for compatible mechanical or optical PTZ cameras, a...

1 hour ago

New in Microsoft 365 Copilot: Self-serve Copilot Connectors

Microsoft 365 Copilot now offers self-serve connectors, allowing users to securely sync external data like Jira and Confluence with their cred...

1 hour ago

Microsoft Teams: Admin policy to automatically block identified external meeting bots from joining meetings

Microsoft Teams will introduce a new admin policy, starting August 2026, allowing automatic blocking of identified external meeting bots from ...

1 hour ago

Microsoft 365 Copilot: Personalized Copilot Suggestions Coming to Frontier

Microsoft 365 Copilot will introduce personalized AI suggestions in Copilot Chat for eligible Frontier program users starting early August 202...

1 hour ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.