(Updated) New flexibility and choice for sharing organizational data across Microsoft 365 and Viva apps

🚨 The Signal: Microsoft has cancelled a planned update that would have given administrators granular control over sharing public HR attributes across Microsoft 365 and Viva apps. This means the default broad sharing of 26 attributes continues, impacting data minimisation efforts.

The Impact

Microsoft 365 tenants using MODIS are affected, maintaining a higher risk of unnecessary HR data exposure across apps.

  • Security Teams: Continued broad exposure of HR attributes increases data minimisation risk.
  • Admins: No new controls to restrict HR data sharing, maintaining current default behaviour.
  • Compliance Teams: Potential for non-compliance with data minimisation principles due to broad data sharing.

Domain: M365-Apps · Impact: low · Workload: M365 Apps