Message Center
Starting June 2026, Microsoft will update the default user consent policy for Microsoft Graph to require admin consent for additional Exchange-related permissions. Users cannot grant consent for these unless apps are approved in the Mail client policy. Existing consents and custom policies remain unaffected.
Introduction
As part of the Microsoft Secure Future Initiative (SFI), and in alignment with the Secure by Default principle, we’re updating the Microsoft‑managed default user consent policy for Microsoft Graph. This change increases administrator control over third‑party application access to Exchange data and aligns default consent behavior with industry best practices for protecting email and related content.
When this will happen
General Availability (Worldwide): We will begin rolling out in early June 2026 and expect to complete by early July 2026.
How this affects your organization
Who is affected
What will happen
What you can do to prepare
Learn more:
Compliance considerations
| Question | Answer |
| Does the change alter how existing customer data is processed, stored, or accessed? | Yes. Access to Exchange data via delegated Microsoft Graph permissions will require admin approval for the additional permissions listed in this message when using the Microsoft‑managed default user consent policy. Existing approved access is not affected. |
| Does the change include an admin control, and can it be managed through Entra ID? | Yes. Admins can manage access using Microsoft Graph app consent policies and the admin consent workflow in Microsoft Entra ID. |