admin
6553 TopicsUnable to add record types to Sales Chat
When attempting to add record types to Sales Chat, we are receiving an error message about being unable to display records. Refreshing from this window does nothing, and refreshing data from the Sales Chat settings page does nothing. This is happening within Version 59.26213.002, did not happen previously within our environment (we were able to add record types as soon as a few weeks ago), and we have validated that we have met all of the prereqs (https://learn.microsoft.com/en-us/microsoft-sales-copilot/set-up-sales-chat#prerequisites).Microsoft Customer Agreement created without Billing Profile after CSP deauthorization
I am the Global Administrator of a Microsoft 365 tenant that previously had an Exchange Online Plan 1 subscription supplied through Endurance International Holding B.V. (Bluehost). This is not a mailbox migration issue. My mailbox already resides in Exchange Online within my existing Microsoft 365 tenant. The only intended change is to move from the former Cloud Solution Provider (CSP) to direct Microsoft billing after the CSP was deauthorized. The Partner Relationships page now displays: Endurance International Holding B.V. (Netherlands)'s account is closed. Find a new partner using Partner app finder or buy from Microsoft directly. Following Microsoft's guidance, I have: Created a Microsoft Customer Agreement (MCA) Created a Billing Account ("Pecten Development") Added and verified a SEPA payment method Updated the Sold-to and Technical Contact details However: Purchasing Exchange Online Plan 1 continually requests a Billing Profile. Completing the Billing Profile workflow never creates one. My Billing Account contains no Billing Profile or Billing Scope. Azure Cost Management reports that there is no supported billing account or subscription. I therefore cannot purchase Exchange Online Plan 1 directly from Microsoft before the existing subscription expires. I have also confirmed that: The former reseller account is closed. There are no delegated partner roles remaining. Microsoft support repeatedly directs me back to the former CSP. Bluehost have confirmed they can no longer escalate through Microsoft CSP channels because their reseller relationship has ended. My current diagnosis is that the Microsoft Customer Agreement has been created successfully, but the associated Billing Profile/Billing Scope was never provisioned. This leaves the tenant unable to purchase services directly from Microsoft despite the former CSP relationship having been closed. Has anyone encountered this after a CSP deauthorization? Does this require intervention by the Microsoft Commerce team, or is there another way to force creation of the missing Billing Profile? If a Microsoft moderator requires my tenant ID or billing account details, I would be happy to provide them by private message. Thank you.35Views0likes1CommentSensitivity Auto-labelling via Document Property
Why is this needed? Sensitivity labels are generally relevant within an organisation only. If a file is labelled within one environment and then moved to another environment, sensitivity label content markings may be visible, but by default, the applied sensitivity label will not be understood. This can lead to scenarios where information that has been generated externally is not adequately protected. My favourite analogy for these scenarios is to consider the parallels between receiving sensitive information and unpacking groceries. When unpacking groceries, you might sit your grocery bag on a counter or on the floor next to the pantry. You’ll likely then unpack each item, take a look at it and then decide where to place it. Without looking at an item to determine its correct location, you might place it in the wrong location. Porridge might be safe from the kids on the bottom shelf. If you place items that need to be protected, such as chocolate, on the bottom shelf, it’s not likely to last very long. So, I affectionately refer to information that hasn’t been evaluated as ‘porridge’, as until it has been checked, it will end up on the bottom shelf of the pantry where it is quite accessible. Label-based security controls, such as Data Loss Prevention (DLP) policies using conditions of ‘content contains sensitivity label’ will not apply to these items. To ensure the security of any contained sensitive information, we should look for potential clues to its sensitivity and then utilize these clues to ensure that the contained information is adequately protected - We take a closer look at the ‘porridge’, determine whether it’s an item that needs protection and if so, move it to a higher shelf in the pantry so that it’s out of reach for the kids. Effective use of Purview revolves around the use of ‘know your data’ strategies. We should be using as many methods as possible to try to determine the sensitivity of items. This can include the use of Sensitive Information Types (SITs) containing keyword or pattern-based classifiers, trainable classifiers, Exact Data Match, Document fingerprinting, etc. Matching items via SITs present in the items content can be problematic due to false positives. Keywords like ‘Sensitive’ or ‘Protected’ may be mentioned out of context, such as when referring to a classification or an environment. When classifications have been stamped via a property, it allows us to match via context rather than content. We don’t need to guess at an item’s sensitivity if another system has already established what the item’s classification is. These methods are much less prone to false positives. Why isn’t everyone doing this? Document properties are often not considered in Purview deployments. SharePoint metadata management seems to be a dying artform and most compliance or security resources completing Purview configurations don’t have this skill set. There’s also a lack of understanding of the relevance of checking for item properties. Microsoft haven’t helped as the documentation in this space is somewhat lacking and needs to be unpicked via some aligning DLP guidance (Create a DLP policy to protect documents with FCI or other properties). Many of these configurations will also be tied to regional requirements. Document properties being used by systems where I’m from, in Australia, will likely be very different to those used in other parts of the world. In the following sections, we’ll take a look at applicable use cases and walk through how to enable these configurations. Scenarios for use Labelling via document property isn’t for everyone. If your organisation is new to classification or you don’t have external partners that you collaborate with at higher sensitivity levels, then this likely isn’t for you. For those that collaborate heavily and have a shared classification framework, as is often seen across government, this is a must! This approach will also be highly relevant to multi-tenant organisations or conglomerates where information is regularly shared between environments. The following scenarios are examples of where this configuration will be relevant: 1. Migrating from 3 rd party classification tools If an item has been previously stamped by a 3 rd party classification tool, then evaluating its applied document properties will provide a clear picture of its security classification. These properties can then be used in service-based auto-labelling policies to effectively transition items from 3 rd party tools to Microsoft Purview sensitivity labels. As labels are applied to items, they will be brought into scope of label-based controls. 2. Detecting data spill Data spill is a term that is used to define situations where information that is of a higher than permitted security classification land in an environment. Consider a Microsoft 365 tenant that is approved for the storage of Official information but Top Secret files are uploaded to it. Document properties that align with higher than permitted classifications provide us with an almost guaranteed method of identifying spilled items. Pairing this document property with an auto-labelling policy allows for the application of encryption to lock unauthorized users out of the items. Tools like Content Explorer and eDiscovery can then be used to easily perform cleanup activities. If using document properties and auto-labelling for this purpose, keep in mind that you’ll need to create sensitivity labels for higher than permitted classifications in order to catch spilled items. These labels won’t impact usability as you won’t publish them to users. You will, however, need to publish them to a single user or break glass account so that they’re not ignored by auto-labelling. 3. Blocking access by AI tools If your organization was concerned about items with certain properties applied being accessed by generative AI tools, such as Copilot, you could use Auto-labelling to apply a sensitivity label that restricts EXTRACT permissions. You can find some information on this at Microsoft 365 Copilot data protection architecture | Microsoft Learn. This should be relevant for spilled data, but might also be useful in situations where there are certain records that have been marked via properties and which should not be Copilot accessible. 4. External Microsoft Purview Configurations Sensitivity labels are relevant internally only. A label, in its raw form, is essentially a piece of metadata with an ID (or GUID) that we stamp on pieces of information. These GUIDs are understood by your tenant only. If an item marked with a GUID shows up in another Microsoft 365 tenant, the GUID won’t correspond with any of that tenant’s labels or label-based controls. The art in Microsoft Purview lies in interpreting the sensitivity of items based on content markings and other identifiers, so that data security can be maintained. Document properties applied by Purview, such as ClassificationContentMarkingHeaderText are not relevant to a specific tenant, which makes them portable. We can use these properties to help maintain classifications as items move between environments. 5. Utilizing metadata applied by Records Management solutions Some EDRMS, Records or Content Management solutions will apply properties to items. If an item has been previously managed and then stamped with properties, potentially including a security classification, via one of these systems, we could use this information to inform sensitivity label application. 6. 3 rd party classification tools used externally Even if your organisation hasn’t been using 3rd party classification tools, you should consider that partner organisations, such as other Government departments, might be. Evaluating the properties applied by external organisations to items that you receive will allow you to extend protections to these items. If classification tools like Janus or Titus are used in your geography/industry, then you may want to consider checking for their properties. Regarding the use of auto-classification tools Some organisations, particularly those in Government, will have organisational policies that prevent the use of automatic classification capabilities. These policies are intended to ensure that each item is assessed by an actual person for risk of disclosure rather than via an automated service that could be prone to error. However, when auto-labelling is used to interpret and honour existing classifications, we are lowering rather than raising the risk profile. If the item’s existing classification (applied via property) is ignored, the item will be treated as porridge and is likely to be at risk. If auto-labelling is able to identify a high-risk item and apply the relevant label, it will then be within scope of Purview’s data security controls, including label-based DLP, groups and sites data out of place alerting, and potentially even item encryption. The outcome is that, through the use of auto-labelling, we are able to significantly reduce risk of inappropriate or unintended disclosure. Configuration Process Setting up document property-based auto-labelling is fairly straightforward. We need to setup a managed property and then utilize it an auto-labelling policy. Below, I've split this process into 6 steps: Step 1 – Prepare your files In order to make use of document properties, an item with the properties applied will first need to be indexed by SharePoint. SharePoint will record the properties as ‘crawled properties’, which we’ll then need to convert into ‘managed properties’ to make them useful. If you already have items with the relevant properties stored in SharePoint, then they are likely already indexed. If not, you’ll need to upload or create an item or items with the properties applied. For testing, you’ll want to create a file with each property/value combination so that you can confirm that your auto-labelling policies are all working correctly. This could require quite a few files depending on the number of properties you’re looking for. To kick off your crawled property generation though, you could create or upload a single file with the correct properties applied. For example: In the above, I’ve created properties for ClassificationContentMarkingHeaderText and ClassificationContentMarkingFooterText, which you’ll often see applied by Purview when an item has a sensitivity label content marking applied to it. I’ve also included properties to help identify items classified via JanusSeal, Titus and Objective. Step 2 – Index the files After creating or uploading your file, we then need SharePoint to index it. This should happen fairly quickly depending on the size of your environment. I'd expect to wait sometime between 10 minutes and 24 hrs. If you're not in a hurry, then I'd recommend just checking back the next day. You'll know when this has been completed when you head into SharePoint Admin > Search > Managed Search Schema > Crawled Properties and can find your newly indexed properties: Step 3 – Configure managed properties Next, the properties need to be configured as managed properties. To do this, go to SharePoint Admin > More features > Search > Managed Search Schema > Managed Properties. Create a new managed property and give it a name. Note that there are some character restrictions in naming, but you should be able to get it close to your document property name. Set the property’s type to text, select queryable and retrievable. Under ‘mappings to crawled properties’, choose add mapping, search for and select the property indexed from the file property. Note that the crawled property will have the same name as your document property, so there’s no need to browse through all of them: Repeat this so that you have a managed property for each document property that you want to look for. Step 4 – Configure Auto-labelling policies Next up, create some auto-labelling policies. You’ll need one for each label that you want to apply, not one per property as you can check multiple properties within the one auto-labelling policy. - From within Purview, head to Information Protection > Policies > Auto-labelling policies. - Create a new policy using the custom policy template. - Give your policy an appropriate name (e.g. Label PROTECTED via property). - Select the label that you want to apply (e.g. PROTECTED). - Select SharePoint based services (SharePoint and OneDrive). - Name your auto-labelling rules appropriately (e.g. SPO – Contains PROTECTED property) - Enter your conditions as a long string with property and value separated via a colon and multiple entries separated with a comma. For example: ClassificationContentMarkingHeaderText:PROTECTED,ClassificationContentMarkingFooterText:PROTECTED,Objective-Classification:PROTECTED,PMDisplay:PROTECTED,TitusSEC:PROTECTED Note that the properties that you are referencing are the Managed Property rather than the document property. This will be relevant if your managed property ended up having a different name due to character restrictions. After pasting in your string into the UI, the resultant rule should look something like this: When done, you can either leave your policy in simulation mode or save it and then turn it on from the auto-labelling policies screen. Just be aware of any potential impacts, such as accidently locking users out by automatically deploying a label with encryption configuration. You can reduce any potential impact by targeting your auto-labelling policy at a site or set of sites initially and then expanding its scope after testing. Step 5 - Test Testing your configuration will be as easy as uploading or creating a set of files with the relevant document properties in place. Once uploaded, you’ll need to give SharePoint some time to index the items and then the auto-labelling policy some time to apply sensitivity labels to them. To confirm label application, you can head to the document library where your test files are located and enable the sensitivity column. Files that have been auto-labelled will have their label listed: You could also check for auto-labelling activity in Purview via Activity explorer: Step 6 – Expand into DLP If you’ve spent the time setting up managed properties, then you really should consider capitalizing on them in your DLP configurations. DLP policy conditions can be configured in the same manner that we configured Auto-labelling in Step 3 above. The document property also gives us an anchor for DLP conditions that is independent of an item’s sensitivity label. You may wish to consider the following: DLP policies blocking external sharing of items with certain properties applied. This might be handy for situations where auto-labelling hasn’t yet labelled an item. DLP policies blocking the external sharing of items where the applied sensitivity label doesn’t match the applied document property. This could provide an indication of risky label downgrade. You could extend such policies into Insider Risk Management (IRM) by creating IRM policies that are aligned with the above DLP policies. This will allow for document properties to be considered in user risk calculation, which can inform controls like Adaptive Protection. Here's an example of a policy from the DLP rule summary screen that shows conditions of item contains a label or one of our configured document properties: Thanks for reading and I hope this article has been of use. If you have any questions or feedback, please feel free to reach out.3.8KViews9likes9CommentsHCW - Hybrid Configuration Wizard for Hybrid Certificate
I've gone through about 5 Microsoft Exchange Support Engineers for last two years with Exchange on-line migration and 80% of time running HCW, it caused email outages where the engineers did not know what to do. They've also gave conflicting information on how to correctly run HCW for adding server and to replace certificate. Some say use powershell and some says do not use powershell. Now, I need to replace the hybrid certificate, do I uncheck everything and check only "Update Secure Mail Certificate for connectors" in a centralized transport setup (email flows through on-prem servers) ? I assume uncheck everything will not roll back configurations. I have Microsoft Exchange engineers says it will and some say it won't and they all say they have 20+ experience.53Views0likes2CommentsOutlook.de DKIM and DMARC records broken
Outbound mail from outlook.de carries a DKIM-Signature with d=OUTLOOK.DE; s=selector1, but the corresponding DNS TXT record at selector1._domainkey.outlook.de does not exist. This causes receiving servers to report dkim=permerror (no key for signature). To reproduce: Send a mail from any @outlook.de account Check the DKIM-Signature header — it references selector1 Run: dig TXT selector1._domainkey.outlook.de — no record returned The domain outlook.de also has no DMARC record published (dmarc=none). Some header information: Received: by 2002:a05:6a11:e41c:b0:73b:6833:703f with SMTP id em28csp1732536pxc; Tue, 21 Jul 2026 07:23:10 -0700 (PDT) [...] ARC-Authentication-Results: i=2; mx.google.com; dkim=permerror (no key for signature) header.i=@OUTLOOK.DE header.s=selector1 header.b=mWWTJtqO; arc=pass (i=1); spf=pass (google.com: domain of email address removed for privacy reasons designates 2a01:111:f403:d20f::3 as permitted sender) [...] I leave out DNS this time as the discussion was marked as spam, but you can easily check it yourself: dig TXT selector1._domainkey.outlook.de and dig TXT _dmarc.outlook.de return no entries as all. So obviously the DNS records are not published. This leads to bad email reputation - so emails are either in SPAM folders or get rejected completely. Can someone from MS look into this and fix it. This is at least the case since June 2026 - see also https://borncity.com/blog/2026/07/02/patzt-microsoft-bei-dkim-fuer-outlook-de/ (which is in German unfortunately) - but that is the exact issue.125Views0likes5CommentsBlock/prevent specific folders from being sync'ed
As OneDrive admins we would like to block/prevent specific folders from being sync'ed (i.e node_modules), using policies. In the roadmap there is this item: https://www.microsoft.com/microsoft-365/roadmap?id=178292 that was supposed to be rolling by now, any information about its status? Thanks344Views0likes2CommentsUser can't see some emails after loading PST
Recently I helped a user migrate from an IMAP mail to Outlook. I downloaded the PST file from the old IMAP account and loaded the file into his new account, all in Classic Outlook as this user refuses to use the new Outlook. However, during the load of old mail he would stop receiving any new mail. To fix this I created a new profile and that did allow new mail to arrive, however, the mail from the backup didn’t show. I then loaded the backup into the new Outlook and it only loaded mail up to 2022. After this, we loaded the PST into Outlook Classic on a different device as to not disrupt workflow, but that also didn’t solve the issue. I loaded the PST file into a testing account, and it did load all the files, from 2020 to the date the file was created.58Views0likes1CommentHow can specific users be exempted from a tenant-scoped Microsoft 365 Apps Policy?
Hello, I am looking for guidance regarding Microsoft 365 Apps Cloud Policy Service behavior and policy precedence. Current configuration: In Microsoft 365 Apps Admin Center → Policy Management (config.office.com), we have the following policies: Policy 1 Name: Shorten Meeting Global Scope: Tenant Priority: 0 Configured settings: Shorten appointments and meetings = Enabled Reduce the end time of short appointments and meetings = 5 minutes Reduce the end time of long appointments and meetings = 10 minutes Policy 2 Name: Test Scope: User (Security Group) Priority: 1 Assigned only to a dedicated test group Relevant settings configured as Not Configured Observed client behavior: On corporate-managed devices, affected users receive the following registry values: HKCU\Software\Policies\Microsoft\Cloud\Office\16.0\Outlook\Options\Calendar shortenevents = End_Early endearlyshort = 5 endearlylong = 10 The Outlook option: File > Options > Calendar > Shorten appointments and meetings is greyed out. Additional validation: Using the same Microsoft 365 account on an external non-corporate device: The above registry path is not present. The Outlook option is editable. Testing performed: A user-scoped Cloud Policy was created and assigned to a dedicated security group. For the "Shorten appointments and meetings" setting, only the following options are available: Enabled Not Configured There is no Disabled option. but the Tenant policy continued to apply and the Outlook option remained locked. Questions Is there a supported way to exempt specific users from a tenant-scoped Microsoft 365 Apps Cloud Policy when the setting only supports "Enabled" and "Not Configured" and does not provide a "Disabled" option? Does Not Configured in a User-scoped policy allow evaluation to continue to the lower-priority Tenant policy? If policy precedence is changed so that: Test Policy = Priority 0 Tenant Policy = Priority 1 would the User policy potentially suppress the Tenant setting? Is there a supported way in Microsoft 365 Apps Cloud Policy Service to provide exceptions for specific users while keeping the Tenant policy as the organizational default? Has anyone successfully implemented an exclusion or override scenario for the "Shorten appointments and meetings" setting? Any guidance or documentation references would be greatly appreciated. Thank you.Feature Request: Extend Security Copilot inclusion (M365 E5) to M365 A5 Education tenants
Background At Ignite 2025, Microsoft announced that Security Copilot is included for all Microsoft 365 E5 customers, with a phased rollout starting November 18, 2025. This is a significant step forward for security operations. The gap Microsoft 365 A5 for Education is the academic equivalent of E5 — it includes the same core security stack: Microsoft Defender, Entra, Intune, and Purview. However, the Security Copilot inclusion explicitly covers only commercial E5 customers. There is no public roadmap or timeline for extending this benefit to A5 education tenants. Why this matters Education institutions face the same cybersecurity threats as commercial organizations — often with fewer dedicated security resources. The A5 license was positioned as the premium security offering for education. Excluding it from Security Copilot inclusion creates an inequity between commercial and education customers holding functionally equivalent license tiers. Request We would like Microsoft to: Confirm whether Security Copilot inclusion will be extended to M365 A5 Education tenants If yes, provide an indicative timeline If no, clarify the rationale and what alternative paths exist for education customers Are other EDU admins in the same situation? Would appreciate any upvotes or comments to help raise visibility with the product team.662Views12likes3Comments