Microsoft 365 Alert – Service Degradation – Microsoft Defender XDR – Some users may be unable to use unused OAuth app policies in App Governance – ONGOING
19/05/2026 09:15:00 AM
NHS.net Connect Reference: INC46829911
Microsoft Reference: DZ1314603
Issue Status: ONGOING
Issue Description: Users may be unable to use unused OAuth app policies in App Governance.
More info: Affected users may notice policy evaluation has been temporarily suspended, meaning alerts won’t be generated and governance actions won’t be executed. Existing policy configurations remain unchanged and will resume once normal operation is restored.
Current Update: 17/08/2026 08:56:00 AM – Microsoft is progressing with their efforts to validate the effectiveness of the deployed fix. They have observed some applications affected by the original issue haven’t generated new activity since the remediation was implemented, and they are assessing what additional mitigation steps may be required to fully address impact.
Scope of impact: Your organization is affected by this event, and any users with unused OAuth app policies configured in App Governance may be impacted. This section may be updated as the investigation progresses.
Root cause: A pre-existing code issue within the service, related to how “last used” data is calculated, was triggered under specific conditions, which is resulting in data inconsistencies.
Next update by: Wednesday, August 26, 2026, at 1:00 PM UTC