AvePoint Cloud Governance January 2022

Release Date for the Commercial Environment: January 9, 2022

Release Date for the U.S. Government Environment: January 16, 2022

What’s new in the new Cloud Governance admin center?

- IT administrators can now share the report in the new Cloud Governance admin center to business users by configuring a report permission group and grant specific report permissions. Users in the group can access the report and perform allowed management actions based on applied permissions. - When configuring a guest user renewal profile, if IT administrators **Allow renewal task assignees to review and change primary and secondary guest contacts**, they can now choose to **Notify the newly assigned contacts** and select an email template for the notification emails. - IT administrators can now click the "Go to the end user portal" button on the upper-right corner to navigate to the Cloud Governance Portal directly. - When end users click **Approve**, **Reject**, **Retry**, or **Skip** in notification emails to perform the corresponding action, they will be directed to a modern page in the modern Cloud Governance Portal now. - A guest user contact can be specified as the guest user manager. The guest user contact may be updated via the guest user renewal profile, specify contact process, or automatic/manual import process for guest user. In **Settings** > **System settings** > **Contact membership**, the IT administrators can now enable automatic guest user contact membership management, and choose to **Automatically update the guest user's manager when**: - **The primary contact specified as the manager is updated** - **The secondary contact specified as the manager is updated** - Access to a Microsoft 365 Group can be restricted due to an incomplete group lifecycle task. In the **Workspace report** in the new Cloud Governance admin center, IT administrators can now choose one or more groups that have access restricted and activate them. - In the **Workspace report** in the new Cloud Governance admin center, there is now a **Last** **active time** column showing the last active time of a site collection or group team site. - Private channels will have the same external settings, unique access settings, and site quota as set in the parent team policy to ensure the private channel stays consistent in the parent team governance policy. Note that when the policy of a team is changed, the external sharing settings, unique access settings, and site quota of the team's private channel will also be updated based on the newly applied policy.

What’s new in the classic Cloud Governance admin center?

- The following renewal features are now available in the renewal profiles: - Currently, the **Settings** page is the homepage of the classic Cloud Governance admin center. Additionally, all Microsoft 365 user related provisioning and management functionalities are no longer supported in Cloud Governance, such as Create User service, User Policy, User Report, etc. - When configuring the **Renewal Option** in a group/team/community renewal profile, IT administrators can now choose whether to allow the renewal task assignee to **Only renew external users** if the **Membership renewal** or **Permission renewal** options are enabled. Additionally, they can now enable the **Sharing link renewal** for the renewal task assignee. - When configuring the **Renewal Option** in a site collection renewal profile, IT administrators can now choose whether to allow the renewal task assignee to **Only renew external users** if the **Permission renewal** option is enabled. Additionally, they can now enable the **Sharing link renewal** for the renewal task assignee. - When configuring a group/team renewal profile, IT administrators can now configure the following **Recommended Renewal Actions** for the renewal task assignee, and the renewal task assignee will see the selected actions that IT administrators recommend performing when they complete the group/team renewal tasks: - **Minimum** **amount** **of owners required** - **Remove users who have been blocked from signing in Azure AD** - **Remove all direct guest user access to** **high risk** **content** - **Remove all user permissions except owners and members** - **Remove sharing links with external user access** - When configuring a Yammer community renewal profile, IT administrators can now configure the following **Recommended Renewal Actions** for the renewal task assignee, and the renewal task assignee will see the selected actions that the IT administrators recommend performing when they complete the group/team renewal tasks: - **Minimum** **amount** **of owners required** - **Remove users who have been blocked from signing in Azure AD** - **Remove all direct guest user access to** **high risk** **content** - **Remove all user permissions except owners and members** - **Remove sharing links with external user access** - When configuring a site collection renewal profile, IT administrators can now configure the following **Recommended Renewal Actions** for the renewal task assignee, and the renewal task assignee will see the selected actions that the IT administrators recommend performing when they complete the group/team renewal tasks: - **Remove all direct guest user access to** **high risk** **content** - **Remove sharing links with external user access** - When configuring an approval process, IT administrators can now select the user role **$Primary guest contact** or **$Secondary guest contact** as the approver. - With sensitivity label integration enabled in the new Cloud Governance admin center, there is now a **Group/Team Sensitivity Label** section in the Change Group/Team Settings service. IT administrators can now choose whether to allow business users to change the sensitivity label in the service request form. With the checkbox selected, IT administrators must select one or more sensitivity labels from the table, which will be available for requesters to select in the service request form. - When configuring the **Group/Team Sensitivity Label** in a Create Group/Team service, IT administrators can now view the parent sensitivity label in the table if there is any for a sensitivity label. The parent label of the selected sensitivity label will also be displayed in the service request form. - With sensitivity label integration enabled in the new Cloud Governance admin center, when configuring the **Changed Site Collection Settings** in a Change Site Collection Settings service, IT administrators can now choose whether to allow business users to change the sensitivity labels in the service request form. With the checkbox selected, select one or more sensitivity labels from the table, which will be available for requesters to select in the service request form. - When configuring site collection sensitivity labels in the Change Site Collection Settings service, IT administrators can now view the tenant that a sensitivity label belongs to. - When configuring a manual import job for Microsoft 365 Group/Microsoft Team, IT administrators can now choose to **Include archived teams** to import to Cloud Governance. - The user role **$Site property ("Property name")** is now newly supported when configuring the site collection, group/team, or Yammer community automatic import profile. Note that IT administrators must enter the full role name, such as **$Site property ("Manager")**. - When configuring a manual import job for site collections, groups, teams, or Yammer communities, IT administrators can now specify the **Object last active time** or **Object imported time** as the start time for calculating the inactivity time for inactivity management. - If there are email references in notification emails sent by AvePoint Cloud Governance that display the specific time, the display time varies based on the email recipients: - If the email recipient is a group or multiple users, the time zone configured in **Global System Settings** will be applied. - If the email recipient is a single user, the time zone that the user configured in personal settings in Cloud Governance will be applied. If this user has never signed in to Cloud Governance and the time zone has never been configured in personal settings, the time zone configured in **Global System Settings** will be applied.

What’s new in the Cloud Governance Portal?

- The classic Cloud Governance end user interface is no longer in use and has been replaced by the modern Cloud Governance Portal. All end user functionalities in the classic Cloud Governance admin center have been moved to the modern Cloud Governance Portal. - Any user who has permissions to use a service request can now access the request form via the request URL. - In the Cloud Governance portal, when there are new updates published by administrators, end users can now view a prompt message displayed below the **News & updates** icon. - In Cloud Governance portal > **Hubs**, if the membership of a workspace is defined and updated automatically, then the Dynamic membership label in the Members section on the workspace details page can now be displayed in the upper-right corner. - In Cloud Governance portal > **Hubs**, if a shared hub has no workspace to display when the organizational tags (metadata) are hidden by the organization, a message can now appear, prompting end users to contact the administrator for assistance. - There is now a new renewal experience available for the renewal task assignee when they complete the renewal task. Before starting the renewal process, the renewal task assignees can view the detailed workspace information and renewal overview details. - When a business user selects a Microsoft 365 Group or Microsoft Team and clicks **Start a request** button on the ribbon to start an Invite new guest user request for the group/team, in the request form, the name of the selected group/team will be automatically filled in the people picker. - The site collection storage quota or group team site storage quota, including the current quota and used quota, are now displayed in the request form, request details page, and task details page. - When configuring the site collection quota threshold in a site collection policy or configuring the group team site quota threshold in a group/team/community policy, IT administrators can now select an email template that will be used to send the notification email. - The AvePoint Online Services local users are no longer supported when configuring the approval process.

Resolved Known Issues

- Resolved a regression issue with Cloud Governance API integration, where cache mapping lookup logic was sometimes incorrect when validating a user ID. - In a hub, if business users edit the group settings on the **Overview** page and update the **Send copies of group conversations and events to group members** setting, after the edits are saved, there is no longer a delay for the updates to take effect.