Skip to content

Ops Log tag

#Microsoft 365

Reviewed Ops Log notes tagged Microsoft 365, written by Michal Jatczak with source links, test context and operational checks.

24 reviewed notes

Operator RunbookSecurity & Infrastructure

A Microsoft 365 DKIM CNAME target has two documented formats: read it per domain, never build it

Microsoft documents two DKIM CNAME target formats for Microsoft 365 custom domains, one ending in onmicrosoft.com and one in dkim.mail.microsoft. The page splits them by new versus existing custom domain and never mentions tenant age. Read each domain's values with Get-DkimSigningConfig.

By Michal Jatczak
Decision MemoModern Workspace

A CSP partner may not sell to itself or an affiliate: Microsoft names two own-use routes instead

Microsoft's CSP documentation says partners are barred by contract from selling Microsoft or third-party offers to themselves or an affiliate as end customer. The same page names two own-use routes: a Shared Services tenant for Azure, or a separate tenant bought through another CSP partner.

By Michal Jatczak
Decision MemoSecurity & Infrastructure

The Graph site permissions endpoint lists application grants: Sites.FullControl.All buys an empty array

GET /sites/{siteId}/permissions lists the grants held by applications on a site, not the people who can open it, and returns an empty array on any tenant that never used Sites.Selected. Microsoft documents Sites.FullControl.All as its least privileged permission. Two cheaper reads answer the real question.

By Michal Jatczak
Change NoteSecurity & Infrastructure

Teams call records left chat retention policies in late April 2026: the replacement policy is PowerShell only

Since late April 2026 a new Teams call data record is covered only by a retention policy for the Teams call logs location, which exists only in PowerShell and reaches nothing created before it went active. The old chat policy stays green. This note gives the read-only check and the boundary of the gap.

By Michal Jatczak
Decision MemoSecurity & Infrastructure

Editing a Conditional Access custom control means deleting it, and creation stops in September 2026

Microsoft blocks the creation and editing of Conditional Access custom controls from September 2026, and the only editing procedure it documents is to delete the control and create a replacement. This note gives the read-only check that finds the affected policies, and the decision to take before the block lands.

By Michal Jatczak
Lab NoteAI & Automation

A Graph meeting export can return an empty page that still carries a next link

During a planned Microsoft Graph service update, paginated calls to getAllRecordings or getAllTranscripts can return HTTP 200 with an empty collection alongside a next link, then restart and re-serve items. An export loop that exits on no items stops there and reports success over a short archive.

By Michal Jatczak
Change NoteModern Workspace

Windows 11 24H2 stops receiving updates a year earlier on Pro than on Enterprise, from the identical build

Windows 11 version 24H2 ends updates on 2026-10-13 for the Pro family and on 2027-10-12 for the Enterprise family, from one table row and one identical build. Count the fleet by edition, not by build, before the earlier date arrives.

By Michal Jatczak
Operator RunbookSecurity & Infrastructure

Microsoft 365 E3 gained Defender Plan 1 in July and impersonation protection is still off by default

Microsoft 365 E3 has included Defender for Office 365 Plan 1 since 1 July 2026, but user and domain impersonation protection stays applied to nobody until an administrator configures it. This runbook gives the read-only check that settles whether anything in the tenant is actually enforcing it.

By Michal Jatczak
Change NoteModern Workspace

Auto-renew off without an explicit cancel bills as an Extended Service Term

In the Microsoft CSP program, setting an EST-eligible subscription to auto-renew false with no explicit cancel instruction converts it to a paid Extended Service Term that renews monthly. The API confirms the cancelled state first and a background job reverses it, so the read-back has to happen the next day.

By Michal Jatczak
Operator RunbookSecurity & Infrastructure

An empty Baseline scopes settings page proves nothing about the enforcement rollout

A Conditional Access policy targeting All resources with a resource exclusion now enforces on sign-ins requesting only baseline scopes, and the Baseline scopes settings page renders empty whether or not the rollout reached the tenant. Inventory the policy shape, the only part a read-only call can measure.

By Michal Jatczak
Operator RunbookModern Workspace

A Purview hold does not stop an unpaid OneDrive being deleted at day 365

Since 1 July 2026 an unlicensed OneDrive that is neither relicensed nor covered by unlicensed-account billing is subject to deletion after 365 cumulative unpaid days, whatever Purview retention or hold sits on it, and it drops out of eDiscovery at day 275. This note gives the read-only check.

By Michal Jatczak
Change NoteAI & Automation

Anthropic in Excel and PowerPoint is a separate setting, on by default for EU tenants created after 25 March 2026

Copilot in Word, Excel and PowerPoint has its own Anthropic setting, a different object from the global Anthropic subprocessor control, and it defaults to on for EU, EFTA and UK tenants created after 25 March 2026. Whether anything actually leaves the EU Data Boundary turns on the second control, so read the tenant creation date and then read both.

By Michal Jatczak

Adjacent tags

Ops Log briefing

Evidence you can inspect.

Michal's field notes on Microsoft 365, Azure and AI operations for regulated European teams.

  • Primary-source analysis
  • Tenant checks and tested configuration paths
  • Named author, test context, and visible limits

We send a confirmation link first. No briefing is scheduled before you confirm.