Planner: Refreshed experience and new capabilities
🚨 The Signal: Planner's refreshed interface and new 'Goals' feature in basic plans could introduce new vectors for information disclosure or unapproved task tracking if not properly governed. This impacts GCC High tenants.
The Impact
All users are affected by the interface change, and the introduction of 'Goals' could pose a low security risk if sensitive data is inadvertently tracked.
- End users: Risk of inadvertently exposing sensitive project details via new 'Goals' feature.
- Admins: Need to understand new Planner capabilities to guide appropriate usage and data handling.
- Security Team: Potential for new data exposure vectors if 'Goals' are used for sensitive information.
- Compliance Officers: Need to assess if 'Goals' usage aligns with data classification and privacy policies.
The Action
- Review existing data classification and handling policies for Planner to ensure they cover new 'Goals' functionality.
- Communicate best practices for using Planner, especially the 'Goals' feature, to prevent sensitive data exposure.
- Monitor Planner usage for any unapproved tracking of sensitive information.
- Consult Microsoft documentation for any new governance controls specific to Planner 'Goals'.
Domain: Other · Impact: low · Workload: M365 Apps