Latest Microsoft Licensing Updates October 2024

Privacy & Security Terms Updates

Microsoft has significantly updated its Privacy & Security Terms page, now explicitly highlighting which services are not covered by these terms. Previously, this information was covered across individual service pages, but it has now been consolidated on this central page.

The following has been added:

Azure AI Services

Services in Containers

Services in Containers are excluded from the P&S Terms because the operating environment of containers installed on Customer’s dedicated hardware is not under Microsoft’s control.

Inactive Services Configurations and Custom Models

Any inactive services may be treated, at Microsoft’s discretion, as an expired subscription and will not be covered by the terms.

Multi-Cloud Scanning Connectors for Microsoft Purview

The Multi-Cloud Scanning Connectors for Microsoft Purview is a separate add-on to Microsoft Purview. The Multi-Cloud Scanning Connectors for Microsoft Purview is not a Microsoft Azure Core Service and the following sections of the DPA do not apply to the Multi-Cloud Scanning Connectors for Microsoft Purview:

  • Educational Institutions
  • CJIS Customer Agreement
  • HIPAA Business
  • Appendix A – Security Measures

Microsoft employs least privilege access mechanisms to control access to Customer Data and the Auditing Compliance section does not extend to third-party computers.

Visual Studio App Center

Visual Studio App center is covered by the terms listed here.

SQL Managed Instance enabled by Azure Arc

If you run SQL Managed Instance enabled by Azure Arc outside of an environment controlled by Microsoft, this is not covered.

Microsoft Genomics

The DPA does not cover Microsoft Genomics. Instead, it is covered by the terms here.

Azure SQL Edge

The terms of the DPA do not apply to Azure SQL Edge installed on Customer’s IoT Device, except to the extent any Personal Data is collected to enable Azure management services and to meter usage for billing purposes.

Azure Stack HCI & Azure Stack Hub

Microsoft’s position here is clear:

Microsoft will be a controller of Personal Data when customers turn on collection of Windows diagnostic data as described in product documentation. When Microsoft is a controller, Microsoft will handle this Personal Data in accordance with the Microsoft Privacy Statement at aka.ms/privacy, and the DPA terms do not apply.

Azure VMWare Solution

Microsoft will transfer customer data to VMWare in the event this is required to support an incident. This is covered by the VMWare and Microsoft Support Transfer Agreement. Additionally, find the terms for this here.

Bing

The DPA is not in effect for Bing and the terms and conditions are listed here.

GitHub

The GitHub Privacy statement and the GitHub Data Protection Agreement remain in effect for this product.

Office 365 Services

For Office 365 Services there are cases where Education tenants in particular can be set up and have data transferred to the US, even if set up in the EU or EFTA. This can be avoided by purchasing an Advanced Data Residency for Education add-on.

Dynamics 365 Services

Dynamics 365 has a very elaborate clause for the Danish Bookkeeping act. As this is so specific, I have not summarized it here. I would advice you to check the link if you’re interested. 

Microsoft 365

Customer’s access to and use of Legacy Glint Services are governed by the terms set forth in Customer’s most recently active LinkedIn Order Form(s) for Legacy Glint Services. No Microsoft terms, including without limitation the Microsoft Product Terms, DPA, or any agreements between Customer and Microsoft shall apply to Legacy Glint Services.

Other Online Services

  • If you’re using the Intune Company Portal app, all services related to this under the control of Microsoft are covered, but third-party providers are not
  • Managed Devices and Applications: Microsoft Managed Desktop (MMD) integrates data from different sources, and when data is transferred from one product to another the service that stores that data is the one that is covered by the DPA. Be aware that this can have different implications, for example when moving between Windows and Office Services.

Microsoft Licensing Updates

Office Desktop Applications & Office for Mac

Updated Availability Table and corresponding references for Office LTSC 2024, and Office LTSC 2024 Applications.

Windows desktop Operating System

Windows 11 Enterprise LTSC and Windows 11 IoT Enterprise LTSC have been added to the availability table

Windows Server Standard, Datacenter & Essentials

A Self-hosting and Disaster Recovery clause has been added stating that customers with subscription licenses are granted similar rights that are provided to SA customers

Project

Project Plans renamed to Planner and Project plans. Removal of Office 365 Education clause.

Microsoft 365

  • Microsoft 365 A5 Security offerings added for Students to Availability and Prerequisite Tables.
  • Microsoft Copilot for M365 renamed to M365 Copilot. The Sales and Services plans have also been renamed to this standard.
  • Removal of Data Handling clause and Legacy Glint Entitlement clause

GitHub

  • GitHub Copilot Business and Enterprise added to availability tables.
  • GitHub Codespaces and GitHub Large File Storage added to the License Prerequisites table. A GitHub Enterprise license is required.
  • GitHub Core online services defined: Copilot Business, Copilot Enterprise and GitHub Enterprise
  • GitHub Security practices: Copilot Business, Copilot Enterprise and GitHub Enterprise are SOC 1 Type II and SOC 2 Type II compliant
  • Removal of Defense of Third Party Claims and Privacy clause

Glossary updates

  • Covered Product: Updated clause now includes the exclusion of free previews and clarifies that this applies specifically to services used through a paid subscription.
  • External users: Updated clause reflects the changes we described in the licensing update a few months ago. The term now means: “External Users means users that are not (a) employees or onsite agents of Customer or its Affiliates, (b) contractors or agents that typically work for Customer or its Affiliates for more than 30 hours on average per week, or (c) contractors or agents that typically work onsite for Customer or its Affiliates on each working day.”
  • Addition of GitHub Core Online Services means those Online Services listed as GitHub Core Online Services in the GitHub Offerings section

Other items

  • Self-service purchases for Copilot customers: Microsoft 365 Business Basic, Standard, and Premium business suites will be able to purchase Copilot for Microsoft 365 for themselves through self-service purchasing.
  • Microsoft releases O365 E1 Plus license in select markets (ASEAN, LATAM, India, and the Middle East, Africa, and Central Asia). Office 365 E1 Plus combines the basic productivity and email value found in Office 365 E1 with key security value – Endpoint Management (Intune), Conditional Identity Access (Microsoft Entra ID), and Data Loss Prevention.
  • Microsoft removed the option for license assignment from the Azure Admin portal and it is now only available from the M365 Admin center.