Microsoft on Wednesday began rolling out a long-awaited governance upgrade for Organizational Data in the Microsoft 365 admin center, giving administrators the power to restrict custom workforce attributes to hand-picked users and groups. The feature, tracked under roadmap ID 564805, replaces an overly broad access model with fine-grained policies that also let IT decide whether leaders can share sensitive non-public data with Workforce Insights delegates. The update, which entered preview in June and is reaching general availability for Worldwide Standard Multi-Tenant customers through July 2026, marks a decisive shift from broad, indiscriminate exposure toward least-privilege access for HR-derived data flowing into AI-assisted tools.
What actually changed
Organizational Data in Microsoft 365 is the pipeline that funnels workforce information from HR systems into services like Microsoft Viva Insights, People Skills, and the Workforce Insights agent. Until now, administrators importing custom attributes—tenant-defined fields such as cost center, retention risk, clearance level, or succession status—had limited audience choices: typically all employees, all managers, or a similarly broad population. That model forced many organizations to either accept widespread exposure of sensitive classifications or avoid importing valuable data altogether.
The July 2026 update introduces three new policy levers:
- Attribute audience targeting: Instead of all-or-nothing, administrators can now release a custom attribute exclusively to specific users, a Microsoft Entra group, or a controlled pilot population. A regional executive can therefore query a field like
WorkforcePlanwithout making it visible to every manager in the company. - Delegation governance: Workforce Insights lets leaders appoint delegates—executive assistants, chiefs of staff, HR business partners—to perform queries on their behalf. The new controls let admins decide whether non-public information may pass to those delegates. This creates an explicit boundary: a company might allow delegates to see job titles and reporting lines but block access to compensation bands, talent-review scores, or confidential workforce-planning labels.
- Population scoping: The audience determines who can access an attribute, while a separate population scope determines which employee records they can examine. Combined with the attribute policy and delegation rule, this creates a four‑dimensional access matrix that was not possible before.
Microsoft describes the change as a more conservative default posture for sensitive organizational information. The underlying principle is simple: importing an attribute does not automatically mean it should be discoverable by everyone who could technically see it.
What it means for you
For Microsoft 365 administrators
You gain precise control but also greater configuration responsibility. Broad defaults were operationally simple; granular policies demand decisions about audience design, group ownership, delegation boundaries, and lifecycle management. The Organizational Data Source Administrator role becomes critical—it lets specific staff manage ingestion and policies without Global Admin privileges.
You must now:
- Inventory every custom attribute currently flowing to Workforce Insights.
- Assign a data owner, business purpose, and classification (public, confidential, custom) to each field.
- Decide whether to use direct user targeting or, preferably, dedicated Entra security groups with accountable owners.
- Explicitly set delegation rules: can managers share non-public data with their assistants? The answer likely varies by attribute and role.
- Test policies with ordinary managers, senior leaders, delegates, and unauthorized users before going live.
Configuration drift is a real risk. When multiple overlapping groups, hierarchy-based managerial rights, and delegate assignments combine, effective access can become opaque. Plan to periodically test with representative accounts and document the access logic.
For managers and leaders
You will start seeing a more relevant Workforce Insights experience. Administrators can now release specialized attributes only to the leaders who genuinely need them—a sales executive might receive territory classifications, while an engineering lead sees skills-taxonomy fields. This reduces clutter and lowers the chance of stumbling across sensitive information irrelevant to your role.
But granular access also means two managers with similar titles may see different datasets. Microsoft 365 teams should communicate three distinct states where possible: the organization doesn’t collect the attribute; the attribute exists but isn’t available for your population; or the attribute exists but you aren’t authorized. Ambiguity can breed distrust or pressure for broader access.
If you delegate Workforce Insights queries, be aware that administrators can now block non-public data from flowing to your assistant. A query that worked last month may return fewer details after a policy update—that’s intentional, not a bug.
For employees
You remain the subjects of this data. Imported custom attributes can carry labels like “future leader,” “mobility risk,” or “performance concern”—classifications that may materially affect restructuring, promotion, or planning decisions. Microsoft states that Viva Insights is not intended for employee tracking, profiling, or automated employment decisions, but customers bear the responsibility for how they define attributes and interpret AI-generated output.
Transparency matters. Organizations should provide clear notice about what workforce data is collected, for what purposes, and who can access it. A technically sound access policy does not absolve a company from lawful processing obligations, especially across multinational jurisdictions.
How we got here
Microsoft introduced Organizational Data as a way to enrich experiences like Viva Insights, Microsoft 365 Copilot, and the Workforce Insights agent with HR context that directory fields alone cannot capture—reporting lines, job functions, locations, skills. The initial access model treated most attributes as either public to all employees or restricted to a manager population. That worked for job titles and office locations but became untenable as organizations began importing highly sensitive custom fields.
Two trends elevated the risk. First, AI-assisted analysis can summarize, correlate, and rank information far faster than a human scanning a spreadsheet, magnifying the impact of inappropriate access. Second, Workforce Insights allows delegation, which meant a carefully restricted manager could simply pass visibility to an assistant or analyst, circumventing controls.
Microsoft responded incrementally. In 2025, the company separated attributes into three broad categories: public, confidential, and custom. It also introduced the Organizational Data Source Administrator role to decouple data ingestion from Global Admin. Roadmap ID 564805 represents the most significant governance expansion since that initial classification, bringing user- and group-level targeting, delegation toggles, and a staged rollout capability that lets organizations pilot a field with a small group before wider release.
The competitive landscape also shaped the update. Enterprise AI buyers increasingly judge products by how reliably they refuse to answer unauthorized questions. A workforce assistant with excellent analytics but blunt access controls is difficult to deploy around sensitive HR information. Microsoft needed to make controlled experimentation possible without tenant-wide exposure.
What to do now
The rollout is happening through July 2026. Your first step is to check whether the updated controls have landed in your tenant; not all organizations receive the interface simultaneously. Before touching any settings, take a snapshot of your current configuration.
Here is a practical deployment checklist:
- Inventory custom attributes: List every custom field currently shared with Workforce Insights. For each, record its data owner, business purpose, classification, and source system.
- Classify sensitivity: Determine whether the attribute is public, internal, confidential, or regulated. Custom fields require explicit classification because Microsoft cannot infer sensitivity from a name like
RegionCode. - Define pilot audiences: Create dedicated Microsoft Entra security groups for workforce planning, HR operations, finance, and regional management. Avoid reusing broad distribution lists—their membership wasn’t designed for confidential data access.
- Set delegation policies: Decide by attribute whether non-public data may pass to delegates. A typical starting point: allow delegates to see job titles and reporting structures, block compensation bands, talent-review categories, and workforce-planning labels unless explicitly justified.
- Validate source quality: Granular access cannot fix bad data. Confirm that HR exports have correct reporting lines, allowed values, and refresh schedules. Outdated or ambiguous values will still produce misleading AI summaries.
- Test representative queries: As a pilot user, run queries that combine small teams, rare job titles, narrow geographic filters, and unique employment categories. Check whether aggregated results inadvertently expose individuals.
- Review with stakeholders: Involve HR, privacy, legal, and security teams to assess whether output reveals more than intended. Approval should come from the data owner, not just the IT team.
- Expand deliberately: After the pilot succeeds, add groups in controlled stages. Avoid the temptation to flip from a small test audience directly to “all managers”—that defeats the purpose of staged rollout.
- Establish recurring access reviews: Group membership, attribute definitions, data owners, and delegation settings should be reviewed at least quarterly. Integrate with Microsoft Entra access reviews and lifecycle workflows where possible.
- Train leaders: Managers need guidance on appropriate use. Access does not authorize every possible query. A field derived from a talent-review model should not be treated as an immutable fact, and aggregate workforce planning insights should not become the sole basis for individual employment decisions.
For larger enterprises, separate the duties: HR data owners approve field definitions, privacy teams classify sensitivity, Microsoft 365 admins configure policies, identity teams manage group membership, and security teams monitor for anomalies.
Outlook
The immediate question is how consistently the new controls appear across tenants as Microsoft completes general availability. Administrators should compare the production interface with preview behavior and watch for any changes to policy default values, group-selection options, or delegation toggles.
Longer term, three developments will determine how valuable this update becomes:
- Effective‑access reporting: Enterprises need a straightforward answer to “Can this user access this attribute for this employee population, including through delegation?” Without built‑in reporting that resolves group membership, hierarchy‑based rights, admin roles, and delegate relationships into a clean view, troubleshooting will stay a manual chore.
- Audit and identity‑governance integration: Delegation must be auditable—who assigned access, to whom, for what scope, and when. Expect Microsoft to tighten integration with Entra access reviews, lifecycle workflows, and privileged identity management, so that attribute audiences automatically adjust after role changes and terminate when employment ends.
- Broader application support: Today the policies primarily govern Workforce Insights. Microsoft’s business‑context strategy spans Microsoft 365 Copilot, Viva, profiles, and skills experiences. If the same granular policy model expands to those products, administrators will need cross‑application visibility before they can treat Organizational Data policies as a central governance layer.
Finally, watch for Microsoft to enforce a secure default: newly imported custom attributes should require an explicit audience selection before they become available to any user, and the admin center should warn when an unusually large group is targeted or non‑public delegation is enabled tenant‑wide.
These controls arrive at a pivotal moment. AI‑assisted workforce analysis is rapidly moving sensitive employee information from static HR reports into conversational tools that can correlate, rank, and re‑identify with frightening speed. The organizations that thrive will treat this rollout not as an invitation to import more HR fields, but as a reason to establish durable ownership, classification, testing, and review around every data point placed within reach of Microsoft 365’s expanding AI layer.