Home > What’s New in this Release?
Download this articleInsider Release Date: May 22, 2026
General Availability Date for the Commercial Environment: June 7, 2026
General Availability Date for the U.S. Government Environment: June 14, 2026
The following features are in preview in the AvePoint Policies for Microsoft 365 insider environment, and they will be available in the commercial and U.S. Government environments on the general availability dates.
Policies for Microsoft 365 now includes a "Human-in-the-Loop" verification step for automated assignments of site owners and site collection administrators.
Administrators can customize adaptive card email templates for notifications sent to newly assigned site owners and site collection administrators.
Recipients will receive a notification with the site name and URL, and are provided with one-click options to accept or reject the assignment.
Related rules:
Site Owner Number Restriction
Site Collection Administrator Number Restriction
Owner Number Restriction
Private Channel Owner Number Restriction
You can now define a custom scan start time for each rule that supports an independent scan interval. This allows individual rules to run on their own schedule, independent of the broader policy-level timing.
The Ghost Guest User Detection tenant-level policy rule has been improved with the following enhancements:
Support for Defined Groups, allowing administrators to precisely target or exclude specific sets of users from the rule's enforcement.
Support skipping guest users who have never signed in from detection.
The Sharing Link Expiration Enforcement service-level rule has been improved to support expiring sharing links based on the time since their last access, in addition to the time since their creation. This ensures active links remain usable while automatically removing those that are no longer in use.
The Site Collection Administrator Enforcement rule has been improved with the following enhancements:
It now logs a Skipped violation with a descriptive reason when the primary or secondary contact cannot be found, providing clearer visibility instead of silently bypassing the site.
It now supports enforcing the primary or secondary contact to be site collection administrators for Microsoft Teams and Microsoft 365 Group sites, aligning with the established behavior for SharePoint sites.
The Site Collection Administrator Restriction and User/Group Restriction rules now support scanning domain groups on sites. To ensure uninterrupted site management, the core [Group Name] Owners group for Microsoft 365 group team sites is automatically excluded from rule checks.
The Demote out-of-policy users/groups to members setting has been added to the Site Owner Restriction and Site Collection Administrator Restriction rules, allowing site owners or site collection administrators to be demoted to members.
The following updates have been made to this user guide for this release:
Updated Notification Settings.
UPdated Email Templates.
Updated Detailed Rule Settings for service-level policies.
Updated Detailed Rule Settings for tenant-level policies.
For additional technical information on the new functionality and known issues in this release, see the Release Notes.