Microsoft 365 Alert – Service Degradation – Microsoft Defender XDR – Some users may be unable to use unused OAuth app policies in App Governance – ONGOING

19/05/2026 09:15:00 AM

NHS.net Connect Reference: INC46829911

Microsoft Reference: DZ1314603

Issue Status: ONGOING

Issue Description: Users may be unable to use unused OAuth app policies in App Governance.

More info: Affected users may notice policy evaluation has been temporarily suspended, meaning alerts won’t be generated and governance actions won’t be executed. Existing policy configurations remain unchanged and will resume once normal operation is restored.

Current Update: 07/09/2026 09:22:00 AM The previously identified issue with the application Last Used Date signal has been remediated, and affected data has been corrected where possible.

As an additional precaution, automated App Governance policies that rely on Last Used Date for app disablement will continue to remain disabled for some more time while Microsoft complete enhancements designed to further improve the accuracy and consistency of this signal. During this period, impacted users can continue to review and disable unused applications manually using Last Used Date.

They will provide further updates once these enhancements are complete and the related policies are ready to be safely re-enabled.

Scope of impact: Your organisation is affected by this event, and any users with unused OAuth app policies configured in App Governance may be impacted. This section may be updated as the investigation progresses.

Root cause: A pre-existing code issue within the service, related to how “last used” data is calculated, was triggered under specific conditions, which is resulting in data inconsistencies.

Next update by: Monday, October 5, 2026, at 1:00 PM UTC

back to top