Home > New Features and Improvements from Previous Versions > AvePoint Online Services August 2025
Download this articleGeneral Availability Date for the Commercial Environment: August 10, 2025
General Availability Date for the U.S. Government Environment: August 17, 2025
For organizations that have implemented the MFA policy for local accounts under Administration > Security, it is now possible to reset MFA for individual local users by navigating to Management > User management. Select the relevant local users, confirm their status is Activated, and click Reset MFA. Once MFA has been reset, these local users will be able to reconfigure their MFA settings on their respective devices.
When configuring the Invite support form to invite AvePoint support for An existing issue, you can now choose to create a temporary account that will be deleted in 15 days and grant access to management and auto discovery features in your organization's AvePoint Online Services environment.
Organizations using Cloud Backup for Dynamics 365 or Opus can now retrieve audit records via the following methods:
In AvePoint Online Services, navigate to Administration > General settings and configure Integration with Microsoft Azure Event Hubs.
In AvePoint Online Services, navigate to Administration > App registrations and register an app with the audit.read.all permission, and then use the AvePoint Online Services Graph APIs to retrieve details.
In accordance with the Microsoft announcement about legacy Yammer application registrations, AvePoint Online Services no longer supports the creation or authorization of custom Viva Engage apps profiles. For organizations using Cloud Governance, Cloud Backup for Microsoft 365, or tyGraph, if your tenant has configured a custom Viva Engage app, please contact your AvePoint representative for advice on any necessary next steps.
The following apps have API permission updates:
The Policies for Microsoft 365 service app now includes the Content.SuperUser and Content.Writer Azure Rights Management Services application permissions, supporting the newly added rule to apply sensitivity labels to files.
The Fly for Entra ID source and Fly for Entra ID source and destination service apps now include the MailboxSettings.Read Microsoft Graph application permission to check if the source user is shared mailbox.
The Cense service app now includes the UserAuthenticationMethod.Read.All and Policy.Read.All Microsoft Graph application permissions to retrieve users’ MFA settings and statuses.
If your organization has configured app profiles for any of the service apps above, navigate to AvePoint Online Services > Management > App management to re-authorize the app profiles. This will apply the new API permissions and enable access to the related features.
*Note: Reauthorization is only required if you want to use the new features. Existing functionalities will remain unaffected if no action is taken.
The app profile status terminology has been updated from Expired to Invalid to better reflect the current state of the provisioning profile.
To help you easily find the apps with delegated permissions, on the App management, Consent to Apps, and App profile details pages, the related AvePoint default apps are marked with the icons as below:
Apps that utilize both application and delegated API permissions are marked with the hybrid (
) icon.
Apps that have delegated API permissions only are marked with the purebred (
) icon.
For organizations using the following apps to manage Microsoft 365 objects, you can now choose a consent method between Administrator consent and User consent.
| Service | App type |
|---|---|
| Insights | Insights for Microsoft 365 |
| Insights | Insights for Power Platform |
| Cloud Governance | Cloud Governance delegated app |
| Cloud Governance | Viva Engage |
| MyHub | MyHubCustom app with delegated permissions |
| tyGraph | tyGraph SuitetyGraph for Viva EngageCustom app with delegated permissions |
| Cloud Backup for Microsoft 365 | Cloud Backup ExpressViva Engage |
| AvePoint Portal Manager | AvePoint Portal ManagerAvePoint Portal Manager for Room - Terminal Interface ViewCustom app with delegated permissions |
| Document Management System Online | DMS Online |
) icon next to the tyGraph Suite option when you select services to configure an app profile. The tooltip will appear indicating that the tyGraph Suite option includes all modules in tyGraph. Note that you do not need to select other modules once you select the tyGraph Suite option for the app profile.In Auto discovery > Scan profiles, when configuring an advanced mode scan profile to filter specific Microsoft 365 objects into a single container, you can now utilize the Equals any of and Does not equal any of conditions to set multiple values for the following criteria.
Exchange mailbox
Department
Display name
Email address
Group membership
OneDrive
Site collection property: Primary administrator, URL
Basic user information: Department, Group membership, Username
User profile property: Email, URL
SharePoint site
Creator: Department, Group membership
Primary administrator
Title
URL
Hub site name
Microsoft 365 Group / Microsoft Team / Viva Engage community
Group / Team / Viva Engage community property: Display name, Creator: Department, Primary email address, Owner, Member
Group team site property: Title, URL
Project site
Primary administrator
Title
URL
Exchange public folder: Display name
Microsoft 365 user
Department
Display name
Email address
Group membership
Primary email domain
User ID
Security and distribution group
Display name
Owner
Member
Primary email address
*Note: When you configure multiple values for the Equals any of or Does not equal any of condition, separate the values with a semicolon (;).
In Auto discovery > Scan profiles, when configuring an advanced mode scan profile to scan SharePoint site, Microsoft 365 Group / Microsoft Team / Viva Engage community, or Project site objects into a specified container, you can now use the Archive status criterion and set the Equals condition to filter sites with the Archived or Not archived status.
In Auto discovery > Containers, when you configure settings to batch import SharePoint site objects into a selected container, you can now define the following settings:
How would you like to handle the imported objects in auto discovery scan jobs?
How would you like to handle the imported objects in batch import jobs?
In Auto discovery, the Security and distribution group object type now includes room lists. Room lists are designated distribution groups that function similarly to standard distribution groups.
If your organization uses EnPower and has installed agents that support auto discovery for Active Directory objects, you can now configure scan profiles for the Active Directory mailbox objects.
The backend logic for auto-discovery scan jobs has been enhanced to ignore errors caused by Microsoft 365 Groups that lack connected sites. When these groups are identified during a scan, they will be marked as Partially added in the job report and accompanied by relevant comments, but these errors will not impact the overall job status.