Home > New Features and Improvements from Previous Versions > AvePoint Online Services August 2025

Download this article

AvePoint Online Services August 2025

General Availability Date for the Commercial Environment: August 10, 2025

General Availability Date for the U.S. Government Environment: August 17, 2025

General Updates

For organizations that have implemented the MFA policy for local accounts under Administration > Security, it is now possible to reset MFA for individual local users by navigating to Management > User management. Select the relevant local users, confirm their status is Activated, and click Reset MFA. Once MFA has been reset, these local users will be able to reconfigure their MFA settings on their respective devices.

When configuring the Invite support form to invite AvePoint support for An existing issue, you can now choose to create a temporary account that will be deleted in 15 days and grant access to management and auto discovery features in your organization's AvePoint Online Services environment.

  • Organizations using Cloud Backup for Dynamics 365 or Opus can now retrieve audit records via the following methods:

    • In AvePoint Online Services, navigate to Administration > General settings and configure Integration with Microsoft Azure Event Hubs.

    • In AvePoint Online Services, navigate to Administration > App registrations and register an app with the audit.read.all permission, and then use the AvePoint Online Services Graph APIs to retrieve details.

What’s New in App Management?

  • In accordance with the Microsoft announcement about legacy Yammer application registrations, AvePoint Online Services no longer supports the creation or authorization of custom Viva Engage apps profiles. For organizations using Cloud Governance, Cloud Backup for Microsoft 365, or tyGraph, if your tenant has configured a custom Viva Engage app, please contact your AvePoint representative for advice on any necessary next steps.

  • The following apps have API permission updates:

    • The Policies for Microsoft 365 service app now includes the Content.SuperUser and Content.Writer Azure Rights Management Services application permissions, supporting the newly added rule to apply sensitivity labels to files.

    • The Fly for Entra ID source and Fly for Entra ID source and destination service apps now include the MailboxSettings.Read Microsoft Graph application permission to check if the source user is shared mailbox.

    • The Cense service app now includes the UserAuthenticationMethod.Read.All and Policy.Read.All Microsoft Graph application permissions to retrieve users’ MFA settings and statuses.

If your organization has configured app profiles for any of the service apps above, navigate to AvePoint Online Services > Management > App management to re-authorize the app profiles. This will apply the new API permissions and enable access to the related features.

*Note: Reauthorization is only required if you want to use the new features. Existing functionalities will remain unaffected if no action is taken.

  • The app profile status terminology has been updated from Expired to Invalid to better reflect the current state of the provisioning profile.

  • To help you easily find the apps with delegated permissions, on the App management, Consent to Apps, and App profile details pages, the related AvePoint default apps are marked with the icons as below:

    • Apps that utilize both application and delegated API permissions are marked with the hybrid (Icon: hybrid) icon.

    • Apps that have delegated API permissions only are marked with the purebred (Icon: purebred) icon.

  • For organizations using the following apps to manage Microsoft 365 objects, you can now choose a consent method between Administrator consent and User consent.

ServiceApp type
InsightsInsights for Microsoft 365
InsightsInsights for Power Platform
Cloud GovernanceCloud Governance delegated app
Cloud GovernanceViva Engage
MyHubMyHubCustom app with delegated permissions
tyGraphtyGraph SuitetyGraph for Viva EngageCustom app with delegated permissions
Cloud Backup for Microsoft 365Cloud Backup ExpressViva Engage
AvePoint Portal ManagerAvePoint Portal ManagerAvePoint Portal Manager for Room - Terminal Interface ViewCustom app with delegated permissions
Document Management System OnlineDMS Online
  • If your organization uses tyGraph, you can now click the information (Icon: information) icon next to the tyGraph Suite option when you select services to configure an app profile. The tooltip will appear indicating that the tyGraph Suite option includes all modules in tyGraph. Note that you do not need to select other modules once you select the tyGraph Suite option for the app profile.

What’s New in Auto Discovery?

  • In Auto discovery > Scan profiles, when configuring an advanced mode scan profile to filter specific Microsoft 365 objects into a single container, you can now utilize the Equals any of and Does not equal any of conditions to set multiple values for the following criteria.

    • Exchange mailbox

      • Department

      • Display name

      • Email address

      • Group membership

    • OneDrive

      • Site collection property: Primary administrator, URL

      • Basic user information: Department, Group membership, Username

      • User profile property: Email, URL

    • SharePoint site

      • Creator: Department, Group membership

      • Primary administrator

      • Title

      • URL

      • Hub site name

    • Microsoft 365 Group / Microsoft Team / Viva Engage community

      • Group / Team / Viva Engage community property: Display name, Creator: Department, Primary email address, Owner, Member

      • Group team site property: Title, URL

    • Project site

      • Primary administrator

      • Title

      • URL

    • Exchange public folder: Display name

    • Microsoft 365 user

      • Department

      • Display name

      • Email address

      • Group membership

      • Primary email domain

      • User ID

    • Security and distribution group

      • Display name

      • Owner

      • Member

      • Primary email address

*Note: When you configure multiple values for the Equals any of or Does not equal any of condition, separate the values with a semicolon (;).

  • In Auto discovery > Scan profiles, when configuring an advanced mode scan profile to scan SharePoint site, Microsoft 365 Group / Microsoft Team / Viva Engage community, or Project site objects into a specified container, you can now use the Archive status criterion and set the Equals condition to filter sites with the Archived or Not archived status.

  • In Auto discovery > Containers, when you configure settings to batch import SharePoint site objects into a selected container, you can now define the following settings:

    • How would you like to handle the imported objects in auto discovery scan jobs?

    • How would you like to handle the imported objects in batch import jobs?

  • In Auto discovery, the Security and distribution group object type now includes room lists. Room lists are designated distribution groups that function similarly to standard distribution groups.

  • If your organization uses EnPower and has installed agents that support auto discovery for Active Directory objects, you can now configure scan profiles for the Active Directory mailbox objects.

  • The backend logic for auto-discovery scan jobs has been enhanced to ignore errors caused by Microsoft 365 Groups that lack connected sites. When these groups are identified during a scan, they will be marked as Partially added in the job report and accompanied by relevant comments, but these errors will not impact the overall job status.