27-March-2026 Below you will find a collection of news published yesterday. This news consists of Microsoft’s Roadmap when it is updated it will be below with items. Then there will be a section with the message center, if there is anything new there, this will be automatically included. And it contains a piece from blogs that I follow myself and would like to share with you. If I miss something in the blogs that do have an RSS feed, please let me know.
This entire post was automated via Microsoft Flow
have fun reading!
Office 365 Roadmap Updated: 2026-03-27
Additions : 5
Updates : 2
More Details At: www.roadmapwatch.com
| New Features | Current Status | |||
|---|---|---|---|---|
| Microsoft Teams: Attendant Agent | In Development | |||
| Microsoft Teams: Enhanced media quality for Direct Guest Join | In Development | |||
| Microsoft Teams: AI Interpreter Agent on Teams Phone Devices | In Development | |||
| Outlook: View, edit & share Copilot Pages with Outlook for Android | In Development | |||
| OneDrive: Discover Copilot actions in File Preview | In Development | |||
| Updated Features | Current Status | Update Type | ||
| Microsoft Teams: Intelligent meeting recap available without saving transcript | In Development | Title | ||
| Microsoft Viva: Feature conversations to all network members | Rolling Out | Status |
Items from the MessageCenter in Microsoft 365
| (Updated) Microsoft Teams: Automatically set work location by connecting to a Wi-Fi networkCategory:Microsoft TeamsNummer:MC1081568Status:stayInformed | Updated March 26, 2026: We have updated the timeline. Thank you for your patience. Coming soon to Microsoft Teams: When users connect to their organization’s Wi-Fi, Teams can automatically set their work location to reflect the building they are working in. This makes it easier for users to coordinate work with their coworkers and connect in person. This feature is opt-in and requires you to take action to configure it. After you turn it on, end-users remain in control and can choose whether to share their work location with their coworkers. This message applies to Teams for Windows desktop and Teams for Mac desktop. This message is associated with Microsoft 365 Roadmap ID 488800. [When this will happen:] General Availability (Worldwide): We will begin rolling out early May 2026 (previously early April) and expect to complete by late May 2026 (previously mid-April). [How this will affect your organization:] This feature allows you to map Wi-Fi networks and devices to buildings, which allows your users to have their work location automatically updated when they connect. This is a major improvement over the current experience which relies on end-users to manually set their work location. When this feature is configured and enabled, Teams can automatically update the work location of users who connect their laptop to your organization’s Wi-Fi network or peripherals. The feature can leverage the mapping between your building names and your Wi-Fi networks to set the work location of your users to the right building. It can also leverage mappings to specific peripherals, such as monitors. Teams uses the same policy to enable or disable automatic updates of work location for Wi-Fi and peripherals. Learn more: New-CsTeamsWorkLocationDetectionPolicy (MicrosoftTeamsPowerShell) | Microsoft Learn Teams will not update the location of your users if they connect after their working hours (that they can configure in the Microsoft Outlook Calendar). Also, their work location will be cleared at the end of their working hours.
[What you need to do to prepare:] Automatic update of work location is off by default, but it can greatly improve the experience of your users. We recommend turning it on and configuring it in your tenant. Before rollout, we will update this post with new documentation. | ||||||||||||
| (Updated) Microsoft Teams: Enhanced peripheral data in Pro Management portal reports for BYOD spacesCategory:Microsoft TeamsNummer:MC1090689Status:planForChange | Updated March 26, 2026: We have updated the timeline. Thank you for your patience. We’re adding new peripheral health reporting capabilities to the Pro Management portal, enabling admins to proactively monitor device issues in bring your own device (BYOD) rooms and desks. These reports help identify when peripherals are faulty, missing, moved, or undetectable by a PC—allowing admins to take action before users report problems. Reports for rooms require a Teams Shared Devices license. Desk reporting is currently in public preview. This change is associated with Microsoft 365 Roadmap ID: 493319
[When this will happen:] General Availability (Worldwide and GCC): Rollout will begin in early May 2026 (previously early April) and is expected to complete by mid-May 2026 (previously mid-April). [How this affects your organization:] Admins can now use peripheral status data to detect hardware issues in BYOD rooms and desks before they impact users. This proactive monitoring can reduce support tickets and improve meeting space reliability.
[What you can do to prepare:] To ensure accurate peripheral status reporting:
[Compliance considerations:]
| ||||||||||||
| (Updated) Viva Engage: Agents in Viva Engage communities Public PreviewCategory:Microsoft Viva Microsoft Copilot (Microsoft 365)Nummer:MC1155311Status:planForChange | Updated March 26, 2026: We have updated the timeline. Thank you for your patience. [Introduction] Agent in Viva Engage communities are now available in Public Preview. Community admins can add agents to communities to help draft answers to questions without best or verified answers based on community content and add context to posts by answering follow up questions using the community’s conversations and SharePoint site and library. We are also adding a new capability: tagging by community members. Tagging by community members enables Microsoft 365 copilot-licensed users to @-mention the community agent in the comments and replies of threads with follow up questions and requests to add context to posts. When tagged, the community agent will reply in the post. Tagging by community members will be enabled by default, but can be disabled by community admins in the agent settings. [When this will happen:]
Figure i. Add agent to community The agent will proactively draft answers to unanswered questions using past conversations. By default, the agent posts answers automatically. Admins can configure whether the agent posts answers automatically or only after approval and if tagging by community members is enabled. Figure ii. Configure the agent’s capabilities and knowledge sources
[Grounding on SharePoint sites outside the community]
If Require review is enabled, admins and designated experts will be notified when the agent drafts an answer. They can approve, edit, or dismiss the response. Figure iii. Community admins and experts can review agent suggestions
If tagging by community members is enabled, then community members can @-mention the agent in messages. Coming soon (General Availability): The agent will only use content that all community members can access. Admins must be owners of the SharePoint sites they wish to configure. Admins can add additional SharePoint sites to expand the agent’s grounding knowledge. The agent will be grounded by default on the community’s SharePoint site. Community members can tag the community agent in community posts. All Microsoft 365 Copilot licensed users will have access to the Community Agent by default. The Community Agent Public Preview toggle will be retired. [What you can do to prepare:]
Learn more: Set up and manage agents in Viva Engage communities | Microsoft Learn [Compliance considerations:]
| ||||||||||||
| (Updated) Microsoft OneNote | Sensitivity labels now available on desktop, web, iOS, Android, and MacCategory:Microsoft 365 apps Microsoft PurviewNummer:MC1157712Status:stayInformed | Updated March 25, 2026: We have updated the content with some additional support articles. Thank you for your patience. Introduction We’re introducing support for Microsoft Purview sensitivity labels in OneNote. This update enables users to manually classify and protect OneNote sections using the same compliance standards available across Microsoft 365 apps. Labels can be applied to each OneNote Section, helping ensure sensitive content is encrypted, access-controlled, and aligned with organizational policies. This change supports consistent data protection across platforms and endpoints. This message is associated with Microsoft 365 Roadmap ID 500020. When this will happen General Availability (Worldwide, GCC, GCCH, and DoD): We expect to complete the rollout by late February 2026 (previously late January). How this affects your organization This update enhances data protection and compliance capabilities by introducing sensitivity labeling to OneNote sections. Admins will gain greater control over how sensitive information is handled within OneNote, aligning it with other Microsoft 365 apps. This is particularly beneficial for organizations in regulated industries, helping mitigate risk and enforce compliance policies across endpoints. Who is affected: All users of supported OneNote clients across platforms, including organizations in regulated industries and those with compliance requirements. What will happen:
What you can do to prepare To prepare for this rollout:
Getting Started: OneNote uses the same sensitivity labels configured for files. However, the labeling capability in OneNote is not enabled by default and must be enabled manually by the IT administrator. For detailed guidance, please refer to ‘Enable sensitivity labels for files in SharePoint and OneDrive’ and to ‘Microsoft Purview sensitivity labels in OneNote’. Learn more: Learn about sensitivity labels | Microsoft Purview | Microsoft Learn Compliance considerations
| ||||||||||||
| (Updated) Viva Engage: Community feeds improvementsCategory:Microsoft VivaNummer:MC1187781Status:stayInformed | Updated March 26, 2026: We have updated the timeline. Thank you for your patience. [Introduction:] We’re introducing a simpler way to view conversations in Viva Engage communities, organized by recent posts rather than recent activity. This new view is designed to make it easier for users to follow discussions and will be available as an option, alongside the current system, for those who prefer sorting by recent activity and filtering to new conversations only. This message is associated with Microsoft 365 Roadmap ID 513275. [When this will happen:] General Availability (Worldwide): We will begin rolling out in May 2026 (previously February). [How this will affect your organization:] This change should align better with how people expect to browse and engage with content in their communities, while still preserving the triage flow for those who prefer it. Who is affected: All Viva Engage users in your organization. Current experience:
New experience:
[What you can do to prepare:] No action is required. [Compliance considerations:] No compliance considerations identified, review as appropriate | ||||||||||||
| (Updated) Microsoft 365: Modern Access Request and Access Denied web pageCategory:SharePoint Online Microsoft OneDrive Microsoft 365 appsNummer:MC1188599Status:stayInformed | Updated March 25, 2026: We have updated the timeline. Thank you for your patience. [Introduction:]
We’re introducing a visual refresh of the Access Request and Access Denied page experience across Microsoft 365, redesigned to help users quickly request access to content such as documents, SharePoint sites, or Teams meeting recordings. This update features modern Fluent illustrations, animations, and clearer messaging to make it easier to understand and resolve access issues for a more seamless collaboration experience. This message is associated with Roadmap ID 553214.
[When this will happen:] General Availability (Worldwide, GCC, GCC High, DoD): We will begin rolling out in early May 2026 (previously late March) and expect to complete by end of May 2026 (previously mid-April). [How this will affect your organization:] Who is affected: All users requesting access to content stored on OneDrive and SharePoint. What will happen:
[What you need to do to prepare:] No action is required to enable this update; it will be applied automatically. However, to ensure a smooth experience for your users, we recommend the following:
[Compliance considerations:] No compliance considerations identified, review as appropriate for your organization. | ||||||||||||
| (Updated) Express voice enrollment in Microsoft TeamsCategory:Microsoft Teams Microsoft Copilot (Microsoft 365)Nummer:MC1197146Status:planForChange | Updated March 26, 2026: We have updated the timeline. Thank you for your patience. [Introduction] Express voice enrollment in Microsoft Teams makes registering your voice profile quick and seamless. A voice profile enables features such as voice isolation, speaker recognition, identification in meeting rooms, improved transcripts, and enhanced meeting recaps and insights powered by Microsoft 365 Copilot. If you haven’t enrolled, you’ll receive an in-product prompt to opt in and enroll simply by speaking during a meeting. Admins can enable or disable this feature for their organization. This message is associated with Roadmap ID 537269. [When this will happen:]
[How this will affect your organization:] Who is affected:
What will happen:
[What you can do to prepare:]
[Compliance considerations:] No compliance considerations identified; review as appropriate for your organization. | ||||||||||||
| (Updated) Microsoft Teams: Viva Engage communities in TeamsCategory:Microsoft Teams Microsoft VivaNummer:MC1218423Status:stayInformed | Updated March 26, 2026: We have updated the timeline. Thank you for your patience. [Introduction] We’re introducing Viva Engage communities in Microsoft Teams to make it easier for employees to connect, share, and learn across your organization. This new experience brings discoverable, asynchronous conversations and leadership engagement into Teams—helping employees explore ideas and perspectives beyond project-based collaboration. This message is associated with Microsoft 365 Roadmap ID 513274. [When this will happen]
[How this affects your organization] Who is affected: All Microsoft Teams users with access to Viva Engage. What will happen:
[What you can do to prepare]
Learn more:
[Compliance considerations] No compliance considerations identified. Review as appropriate for your organization. | ||||||||||||
| (Updated) Microsoft 365 Copilot: Create and view Outlook rulesCategory:Microsoft Copilot (Microsoft 365)Nummer:MC1223821Status:stayInformed | Updated March 25, 2026: We have updated the content and timeline. Thank you for your patience. [Introduction] Outlook is adding new Microsoft 365 Copilot capabilities that let users create and view Inbox rules using natural language. This update helps users stay organized more efficiently by allowing them to ask Copilot to set up new rules or list existing rules directly in chat, without navigating Outlook settings. A Microsoft 365 Copilot license is required to access this new feature. Supported platforms: Available via Microsoft 365 Copilot Chat (Work mode). When used within Outlook, it’s supported on Classic and New Outlook for Windows, Outlook on the web, Outlook for Mac, and Outlook mobile (iOS and Android). [When this will happen] General Availability (Worldwide): We began rolling out in early April 2026 (previously early February) and expect to complete by mid-May 2026 (previously mid-March). [How this affects your organization] Who is affected: Users with Microsoft 365 and Copilot licenses who use Outlook for email management.. What will happen:
[What you can do to prepare]
[Compliance considerations] No compliance considerations identified. Review as appropriate for your organization. | ||||||||||||
| (Updated) Transitioning Teams Android Device Management from Teams admin Center to the Teams Rooms Pro Management portalCategory:Microsoft Teams Microsoft 365 for the webNummer:MC1227622Status:planForChange | Updated March 26, 2026: We have updated the content. Thank you for your patience. [Introduction] As part of our ongoing mission to deliver a modern, secure, and scalable one-stop management portal for admins, we are transitioning Teams Android device management from the Teams admin center (TAC) to the Teams Rooms Pro Management portal (PMP). This move consolidates management of all Teams devices, including Teams Rooms on Windows, Teams Rooms on Android, Teams phones, and Teams panels, into a single unified portal, providing IT admins a consistent and seamless experience for managing devices at scale. [When this will happen:]
[How this affects your organization:] Who is affected: Admins who manage Teams Rooms on Android, Teams phones, and Teams panels. What will happen:
[What you need to do to prepare:]
[Compliance considerations] No compliance considerations identified, review as appropriate for your organization. | ||||||||||||
| (Updated) User reported security signals in Teams admin centerCategory:Microsoft TeamsNummer:MC1227625Status:stayInformed | Updated March 26, 2026: We have updated the timeline. Thank you for your patience. [Introduction] As part of our ongoing protection investments in Microsoft Teams, we will continue expanding the ways users can report suspicious or incorrect activity. Users can already report security concerns and incorrect detections in chats and channels (MC1037768, MC1147984), and more recently in calls (MC1223828). These user‑submitted reports help identify potential malicious activity and strengthen your organization’s security posture. Building on this foundation, we will introduce new capabilities that allow Teams administrators to review and export user‑reported security submissions directly in the Teams admin center. A new Protection reports section will be added under Analytics and reports, giving admins unified visibility into user‑reported calls, chats, and channels. This message relates to Microsoft 365 Roadmap ID 536571. [When this will happen] Phase 1 – User‑reported call data
Phase 2 – User‑reported chats and channels
[How this affects your organization] Who is affected: Teams administrators who have access to Analytics and reports in the Teams admin center. What will happen:
[What you can do to prepare] To ensure reporting data is available when rollout begins, verify that end‑user reporting features are enabled:
[Compliance considerations]
| ||||||||||||
| (Updated) DLP policies will be able to block Copilot processing of sensitivity‑labeled files in all storage locationsCategory:Microsoft 365 suite Microsoft 365 apps Microsoft Copilot (Microsoft 365) Microsoft PurviewNummer:MC1234661Status:stayInformed | Updated March 25, 2026: We have updated the timeline. Thank you for your patience. [Introduction] We’re expanding Microsoft Purview Data Loss Prevention (DLP) controls to provide broader governance for Microsoft 365 Copilot. With this update, DLP policies that prevent Copilot from processing content based on sensitivity labels will now apply to Word, Excel, and PowerPoint files regardless of where they are stored. This enhancement responds to customer feedback requesting more consistent protection coverage across local and cloud-based file locations. This feature is associated with Microsoft 365 Roadmap ID 557255. [When this will happen]
[How this affects your organization] Who is affected
What will happen
Implementation detail: This update does not modify Copilot capabilities. Instead, Office clients and AugLoop have been enhanced so AugLoop can read a file’s sensitivity label directly from the client. Today, AugLoop retrieves the label by calling Microsoft Graph using the file’s SharePoint or OneDrive URL, which limits DLP enforcement to files stored in OneDrive and SharePoint. By enabling the client to provide the label, DLP enforcement now applies uniformly across all storage locations, including local files. [What you can do to prepare] No action is required to enable this feature. If your organization uses DLP controls for Copilot, you may optionally:
Learn about managing DLP policies: Learn about data loss prevention | Microsoft Purview | Microsoft Learn [Compliance considerations] No compliance considerations identified. Review as appropriate for your organization. | ||||||||||||
| (Updated) Microsoft Teams: Ad-hoc room reservation from Teams Rooms on Windows consoleCategory:Microsoft TeamsNummer:MC1245225Status:stayInformed | Updated March 26, 2026: We have updated the timeline. Thank you for your patience. [Introduction] We’re introducing ad-hoc room reservation directly from the Microsoft Teams Rooms on Windows console. This update enables users to reserve an available room on the spot without relying on a personal device or hallway panel, supporting quick, spontaneous meetings and helping reduce scheduling conflicts. This feature requires a Teams Rooms Pro license. This message is associated with Microsoft 365 Roadmap ID 548648. [When this will happen]
[How this will affect your organization] Who is affected
What will happen
[What you can do to prepare]
[Compliance considerations] No compliance considerations identified. Review as appropriate for your organization. | ||||||||||||
| Microsoft Purview: Endpoint DLP – Add support of hyperlinks in warn and block toast messages for Edge browserCategory:Microsoft PurviewNummer:MC1261590Status:stayInformed | [Introduction] Microsoft Purview Endpoint Data Loss Prevention (DLP) now supports hyperlinks in warn and block toast messages in Microsoft Edge. A toast message is a small, temporary notification shown to users to provide immediate feedback or guidance. With this update, data officers can include clickable links in these notifications to direct users to internal policies, training resources, or support guidance when a DLP rule is triggered. This change is associated with Microsoft 365 Roadmap ID 558688. [When this will happen:]
[How this affects your organization:] Who is affected:
What will happen:
[What you can do to prepare:]
Screenshot: Example of configuring a hyperlink in an Endpoint DLP warn or block notification in the Microsoft Purview portal [Compliance considerations:]
| ||||||||||||
| View and edit Markdown files in OneDrive and SharePointCategory:SharePoint Online Microsoft OneDriveNummer:MC1261592Status:stayInformed | [Introduction] OneDrive and SharePoint now support viewing and editing Markdown (.md) files directly in the browser. No downloads or third-party tools are needed. Open any Markdown file to see a clean, formatted view, or switch to the built-in editor with a toolbar, side-by-side preview, and syntax support. Whether you’re working with documentation, README files, Markdown files generated by your AI assistant, or notes, OneDrive makes it easy to read and update Markdown content right where your files live. [When this will happen:]
[How this affects your organization:] Who is affected:
What will happen:
[What you can do to prepare:]
Before rollout, we will update this post with new documentation. [Compliance considerations:] No compliance considerations identified, review as appropriate for your organization. | ||||||||||||
| Outlook: Improved handling of disallowed and failed email reactionsCategory:Exchange OnlineNummer:MC1261593Status:stayInformed | [Introduction] We’re improving how Outlook respects the x‑ms‑reactions: disallow header in Classic Outlook for Windows. This update ensures that when reactions are disallowed, the Reactions button is correctly disabled and any failed reaction attempts are fully reverted. This provides a more consistent and trustworthy user experience across Outlook clients and prevents user confusion. This message is associated with Roadmap ID 558442. [When this will happen:]
[How this affects your organization:] Who is affected:
What will happen:
[What you can do to prepare:] No action is required. You may optionally:
Learn more: Disallow reactions in Outlook | Microsoft Learn [Compliance considerations:] No compliance considerations identified, review as appropriate for your organization. | ||||||||||||
| Microsoft Teams town halls now support backup Real-Time Messaging Protocol (RTMP) streamsCategory:Microsoft TeamsNummer:MC1261595Status:stayInformed | [Introduction] To improve reliability for large-scale live events, Microsoft Teams town halls will soon support a backup Real-Time Messaging Protocol (RTMP) stream. RTMP is a standard live‑streaming protocol used by event organizers to send live video and audio to a streaming service, such as Microsoft Teams. This enhancement helps ensure uninterrupted broadcasts by automatically failing over to a secondary RTMP stream if the primary stream experiences an interruption. This change increases resiliency for high-visibility events without adding complexity for organizers. This message applies to Teams for Windows desktop, Teams for Mac desktop, and Teams for the web. It is associated with Roadmap ID 554932. [When this will happen:] General Availability (Worldwide, GCC): Rollout begins late April 2026 and completes by late April 2026 [How this affects your organization:] Who is affected:
What will happen:
[What you can do to prepare:]
Learn more: Use RTMP-In in Microsoft Teams | Microsoft Support (will be updated before rollout) [Compliance considerations:] No compliance considerations identified, review as appropriate for your organization. | ||||||||||||
| Notice: Security Copilot will be included as part of your Microsoft 365 E5 plan soonCategory:Microsoft Entra Microsoft Intune Microsoft Defender XDR Microsoft PurviewNummer:MC1261596Status:stayInformed | Introduction Microsoft Security Copilot agents are built into the flow of work of security teams using Microsoft Defender, Microsoft Entra, Microsoft Intune and Microsoft Purview. At Ignite 2025, Microsoft introduced a dozen new agents across these products, bringing agentic defense across workflows to enable autonomous and proactive protection. To make it easier for teams to get started, Microsoft announced that Security Copilot will be included with Microsoft 365 E5. Eligible tenants will automatically transition to the new entitlement—no action required. When this will happen As part of your existing Microsoft 365 E5 entitlement, you’ll gain access to Security Copilot features and agents through a phased rollout between April 20, 2026, and June 30, 2026. You’ll receive a notification 7 days before your tenant is enabled, and again on the enablement date. How this affects your organization Your organization will have access to Security Copilot with:
We recommend:
| ||||||||||||
| Microsoft Dataverse – Restore deleted Dataverse records within a specified timeframeCategory:Microsoft DataverseNummer:MC1262302Status:stayInformed | We are announcing the ability to restore Dataverse table records within a specified timeframe from any type of delete scenario. This feature will reach general availability on April 27, 2026. How does this affect me? With the ability to restore deleted records with a configurable retention period of up to 30 days in Microsoft Dataverse, you gain greater control and resilience in your data management processes, reducing the risk of permanent data loss. This feature includes the following capabilities:
This message is for awareness, and no action is required. If you would like more information about this feature, please visit: | ||||||||||||
| Microsoft Copilot Studio – Analyze user sentiment from agent conversationsCategory:Power PlatformNummer:MC1262498Status:stayInformed | We are announcing the ability to analyze user sentiment from agent conversations in Microsoft Copilot Studio. This feature will reach general availability on March 31, 2026. How does this affect me? Copilot Studio uses AI models to analyze the tone, language, and user interactions throughout the conversation to calculate an overall sentiment score. The new sentiment analysis is an additional metric to understand customer satisfaction. Sentiment analysis works alongside existing CSAT scores and will help you quickly identify sessions with negative sentiment, enabling you to investigate issues and continuously improve your agent’s performance with the following features:
This message is for awareness, and no action is required. | ||||||||||||
| The March 2026 Windows non-security preview update is now availableCategory:WindowsNummer:MC1262522Status:stayInformed | The March 2026 non-security preview update is now available for Windows 11, versions 26H1, 25H2, and 24H2. Information about the contents of this update is available from the release notes, which are accessible from the Windows 11 update history page. To learn more about the different types of monthly quality updates, see Windows monthly updates explained. Looking to explore upcoming features and improvements in Windows 11? Check out the Windows roadmap. It includes what’s coming to the Windows Insider Program, what’s gradually rolling out, and what’s generally available. Highlights for the Windows 11, version 25H2 update:
For instructions on how to install this update, see the KB for your operating system listed below: | ||||||||||||
| New resources to help organizations prepare for Secure Boot certificate expirationsCategory:WindowsNummer:MC1262523Status:stayInformed | Secure Boot certificates begin expiring in June 2026, and IT admins should take action now to help ensure devices remain secure. Timely deployment of updated certificates is essential to preserving device startup integrity and avoiding servicing (i.e., updates) disruptions. New guidance has recently been published to support a range of deployment scenarios. Whether your organization manages certificates through Microsoft Intune, Group Policy, or manual processes, the resources below provide detailed steps, recommended practices, and troubleshooting guidance to help you plan your updates:
When will this happen: These resources are available now. IT admins should begin reviewing the new guidance and complete certificate update planning and deployment activities as soon as possible to ensure devices remain protected and to avoid servicing or startup disruptions. Secure Boot certificate expiration begins in June 2026. How will this affect your organization: Devices that do not receive the updated Secure Boot certificates before expiration may encounter startup integrity issues or Windows servicing interruptions. The new resources provide guidance for organizations using Microsoft Intune, Group Policy, or manual processes and help ensure devices are fully prepared for upcoming certificate changes. What you need to do to prepare: Begin developing and executing your Secure Boot certificate update strategy as soon as possible. Review the newly published resources to determine the best approach for your organization. These new resources provide detailed steps, recommended practices, and insights to support planning, automation, and certificate update readiness. Additional Information: | ||||||||||||
| Power Platform admin center – Upcoming update to the enforcement of tenant isolationCategory:Power PlatformNummer:MC1262537Status:stayInformed | Following customer feedback and support ticket evaluation, we have updated our tenant isolation enforcement policy. Starting March 30, 2026, only new tenants will have tenant isolation enabled by default. Additionally, existing tenants will not have their existing tenant isolation turned on if the option is blank as setup is opt-in. How does this affect me? Tenant isolation only applies to connectors running within a tenant. The default tenant isolation behavior will block all connection attempts from one tenant to another; inbound (connections to the tenant from external tenants), outbound (connections from the tenant to external tenants), or both (inbound – outbound) will be blocked by Power Platform. Communications within the same tenant will not be affected. In addition, users who sign in as guests (guest user access) will remain unaffected. What do I need to do to prepare? For existing tenants, we highly recommend enabling tenant isolation following the instructions outlined in Allow tenant isolation and configure the allow list. If you want to allow cross-tenant connections in Power Platform prior to the enforcement date, you can set up tenant isolation and explicitly allow individual tenants. Alternatively, you can disable tenant isolation entirely. If either of these actions are performed prior to March 30, 2026, your configuration will not be changed as part of the enforcement. For more information and to learn how to configure a tenant isolation policy, please review the Cross-tenant inbound and outbound restrictions documentation. | ||||||||||||
| (Updated) Microsoft Loop – Require Existing Microsoft 365 Group for New Loop workspacesCategory:Microsoft 365 appsNummer:MC929022Status:planForChange | Updated March 16, 2026: We have updated the timeline. Thank you for your patience. Admins will be able to ensure that new Loop workspaces are connected to and managed by an existing Microsoft 365 Group, similar to SharePoint Team sites. This message is associated with Microsoft 365 Roadmap ID 422725 [When this will happen:] General Availability (Worldwide): We will begin rolling out early April 2026 (previously early March) and expect to complete by late April 2026 (previously late March). [How this will affect your organization:] Once Microsoft 365 Roadmap ID 422725 is available, end-users will have the ability to choose existing Microsoft 365 Groups for managing new Loop workspaces. This means that new Loop workspaces can optionally be connected to and managed by an existing Microsoft 365 Group, similar to how SharePoint Team sites are managed. Additionally, Microsoft 365 Roadmap ID 422725 covers the capability to ensure that new Loop workspaces are connected to and managed by an existing Microsoft 365 Group, similar to SharePoint Team sites (it will not be an option for users to skip selecting an existing Microsoft 365 group if this policy is configured). While this setting may align with existing governance processes, it’s important for admins to note that scenarios like automatic aggregation of Teams meeting content into a Loop workspace, or the creation of small, short-term project workspaces, will be more challenging for end-users unless they can skillfully select an existing M365 group during creation. Please consider this tradeoff in your adoption strategy. If your organization has governance tools for SharePoint Communication sites that work effectively in a reactive manner (i.e., governance is applied after the site is created), Microsoft recommends extending this process to include Loop workspaces rather than using this policy. [What you need to do to prepare:] There is nothing you need to do to prepare. This capability will roll to your tenant automatically. | ||||||||||||
| Microsoft Purview | Data Loss Prevention: Restrict Access action for semantic models in Microsoft Fabric (preview)Category:Microsoft PurviewNummer:MC937920Status:planForChange | Updated March 26, 2026: We have updated the timeline below. Thank you for your patience. Your organization can already apply Microsoft Purview Data Loss Prevention (DLP) policies to Microsoft Fabric, but soon you will also be able to restrict access to Fabric sematic models and lakehouses by applying DLP policies. After this rollout, admins will be able to configure DLP policies that automatically detect sensitive information in sematic models and lakehouses and then restrict access to this data to internal users or data owners This message is associated with Microsoft 365 Roadmap ID 422501. [When this will happen:] Public Preview: DLP restrict access for sematic models is already available in Public Preview as of November 2024. For Fabric lakehouse, public preview of restrict access will begin rollout mid-April 2025 and is expected to complete by late April 2025.
General Availability: We will begin rolling out late October 2026 (previously June) and expect to complete by late November 2026 (previously end of June). [How this will affect your organization:] Before this rollout, you can configure DLP policies for Fabric workspaces to audit and notify users through Policy Tips based on sensitive content. After this rollout, DLP policies can also be configured to block or restrict access to internal users or data owners. This action is especially valuable when your organization has guest users, and you want to enforce proper restrictions to ensure these users do not accidentally access sensitive information. This change is available by default for admins to configure. Configuring the Restrict access action in DLP policy for Fabric:
[What you need to do to prepare:] This rollout will happen automatically by the specified date with no admin action required before the rollout. If your organization does not wish to start using the Restrict access action for Fabric, no additional action is required. If you would like to start restricting access to internal users or data owners, your security or compliance admin will need to update or create new DLP policies for Fabric to include the new Restrict access action. Review your current configuration to determine the impact for your organization. You may want to notify your users about this change and update any relevant documentation. Learn more |








