CoreView Release Notes July 2026

  • Last update on July 21st, 2026

July 21 enhancements

IN THE SPOTLIGHT

[PLAYBOOKS] New policies for permanent active role assignments and email-exposed admins: two new out-of-the-box policies are now available in Governance Center > Security & Identity: “Permanent Active Role Assignments” and “Permanent Active Admins Using Email”.
The first policy identifies users with permanent active role assignments and flags them for review. The second identifies users with a permanent active admin assignment who have used email in the last 90 days. These accounts may present higher phishing exposure because they combine persistent privileged access with active email usage.
For both policies, the related report can be scheduled as a remediation action.

OTHER IMPROVEMENTS

[COREVIEW CONTROL FOR SHAREPOINT] Warning for long-running filters on large SharePoint datasets: when filtering string columns across large datasets in the “Items with Unique Permissions” and “SharePoint Item Level” reports, a warning is displayed if the filter takes more than 10 seconds to run.
The warning recommends narrowing the dataset first by filtering by “Site ID”.

[USER CARD] Mailbox access widgets available to delegated operators: the mailbox access widgets in the “Exchange” tab of the User Card are now visible to operators who have access to the user.

These widgets show:

  • the mailboxes the user can access
  • the users who can access that user’s mailbox.

ANNOUNCEMENTS

[REPORTS] Aggregated monthly sign-in reports removed: the following aggregated sign-in reports have been deprecated and removed:

  • Monthly sign-ins by user
  • Monthly sign-ins by app

For broader sign-in investigation, use the “Sign-in events” pivot.
For user-level checks, use the “Sign-ins” tab in the User Card.

[WORKFLOWS] Workflow actions now support extension attributes: the “Edit user properties” and “Edit user properties (on-prem)” workflow actions now support CoreView extension attributes. This aligns workflow-based user updates with the corresponding native CoreView management actions.


July 07 enhancements

[REPORTS] Invitation State and Sponsor attributes added to guest user reports: two Entra ID attributes — Invitation State and Sponsor — are now available in the Active Users report and other guest-based reports, including Guest Users and Inactive Guest Users. 

Tenant Admins can use these columns to monitor whether a guest invitation is pending or accepted and to identify who is responsible for each guest account.

This enhancement was inspired by a CoreVoice idea.

[WORKFLOWS] Audit logging for workflow and template creation: 
CoreView now generates audit log entries when workflow governance assets are created. Tenant Admins and authorized auditors can trace who created an asset, when it was created, and from which source Workflow.
Audit log entries are generated for the following events:

  • Creation of a draft Workflow, capturing the user, timestamp, and relevant identifying details.
  • Creation of a Workflow template from a draft workflow, recording the originating draft as the source.
  • Creation of a Workflow template from a non-draft workflow, recording the originating workflow as the source.

[ACCESS REVIEWS] Default template content now available in French: the default content of Access Review templates is now translated into French, including Title, Description, Why is it important, Email subject, and Email body. Customization of these fields is still supported where needed.

[DATA CONNECTOR] New export collections: Security Group members, Device data and M365 Service Health: three new datasets are now available for export through the Data Connector add-on, enabling reporting and analysis in external tools such as Power BI and Excel.

  • Security Group members — export group membership data to support access reviews, identify overprivileged accounts, and assist compliance reporting.
  • Device (Microsoft-related columns) — export device data including all supported Microsoft-managed columns to build inventory, lifecycle, and security posture dashboards.
  • M365 Service Health (raw table) — export raw service health data to report on outages, trends, and service performance over time.

All three collections support scheduled and triggered exports and are available to Data Connector customers. However, collections must be configured on your environment: contact your Technical Account Manager to proceed.

 

ANNOUNCEMENTS

[V-TENANTS] Virtual Tenant segmentation for Call Queues and Auto Attendants without a resource account: Call Queues and Auto Attendants with no linked resource account are now excluded from V-Tenant visibility. Operators see only objects associated with resource accounts within their authorized scope, protecting sensitive telephony configurations from unauthorized access. Tenant Admins without a V-Tenant assignment retain full visibility across all objects.
This applies to the following reports: Teams Holidays, Routing Numbers, Auto Attendant, and Call Queues.