Microsoft Defender for Cloud Apps will update the Microsoft 365 connector configuration page in January 2026, adding clearer layouts and new default values for new connectors to reduce misconfigurations. Existing connectors remain unchanged. Admins should review current settings to ensure required Entra permissions are enabled.
Introduction
Microsoft Defender for Cloud Apps is updating the Microsoft 365 connector configuration page with revised default values for new connector setups. These improvements are designed to help security administrators more easily understand the Microsoft Entra data signals required to support SaaS Identity–related security features. This update also reduces the likelihood of misconfigurations so that capabilities such as SaaS Identity Discovery, Threat Protection, Response, and Posture insights continue to receive the data they depend on.
This is also a good opportunity to verify that your existing connector configurations are set correctly for the security features in your environment.
When this will happen
We will begin rolling out in mid-January 2026 and expect to complete by late January 2026.
How this will affect your organization
Who is affected: Admins who manage Microsoft Defender for Cloud Apps and configure the Microsoft 365 connector.
What will happen:
What you need to do to prepare

Compliance considerations
No compliance considerations identified. Review as appropriate for your organization.