If you are using Classic API Data Protection with Microsoft Office 365 apps (OneDrive, Outlook, SharePoint, and Teams), you are required to re-grant access to ensure uninterrupted coverage.
Why Is Re-granting Required?
Microsoft is making important changes that affect how Microsoft Office 365 apps connect with Netskope. These changes mean that certain older methods of integration will stop working from March 31 2026.
To ensure continuous protection of your OneDrive, Outlook, SharePoint, and Teams data, you must re-grant your Microsoft Office 365 app instances in the Netskope tenant UI. To read more about the re-grant, click here.
Key Takeaway
To avoid disruption, re-grant your Microsoft Office 365 apps (OneDrive, Outlook, SharePoint, and Teams) on the Netskope tenant UI before the deadline. The process is quick, requires only a global administrator login, and ensures continuous protection with Classic API Data Protection.
How to Re-grant Access for Microsoft Office 365 Apps
In some older tenants, the configured administrator email may no longer be valid (for example, if the original admin has left the organization or ownership was transferred). In such cases, update the administrator email before attempting the re-grant:
– OneDrive and SharePoint: You can update the Admin Email directly in the Netskope tenant UI. Click the app instance name and edit the Admin Email field.
– Teams and Outlook: Open a support ticket with Netskope to request an update to the Admin Email for your app instance.
After updating the Admin Email, retry the re-grant process using the updated administrator account.
Follow these steps to re-grant access:
-
Sign in to your Netskope tenant UI.
-
Navigate to Settings > Configure App Access > Classic > SaaS.
-
Select the appropriate instance:
-
For OneDrive, choose the Microsoft Office 365 OneDrive for Business icon.
-
For Outlook, choose the Microsoft Office 365 Outlook.com icon.
-
For SharePoint, choose the Microsoft Office 365 SharePoint Sites icon.
-
For Teams, choose the Microsoft Teams icon.
-
-
Click Grant Access for the existing app instance.

-
When prompted, log in using your global administrator credentials.
-
Review and accept the requested permissions, then click Close to complete the process
You have successfully re-granted access.
Frequently Asked Questions
-
Which customers are impacted by this change?
If you are using Classic API Data Protection with Microsoft Office 365 apps (OneDrive, Outlook, SharePoint, and Teams), you are required to re-grant access to ensure uninterrupted coverage.
-
Why do I need to re-grant?
You must re-grant due to the following reasons:
-
End of Support for Legacy Authentication
Starting March 2026, Microsoft Entra ID will no longer support app authentication without a service principal. To learn more, read this Microsoft article. Although Microsoft’s documentation suggests taking action directly in your Microsoft tenant, do not make changes on your own. Instead, follow the re-grant process documented here.
Impacted apps: OneDrive, Outlook, SharePoint, Teams
-
Deprecation of SharePoint Add-Ins
Microsoft is retiring SharePoint Add-Ins, which will stop functioning for all tenants on April 2, 2026. Netskope has created a new application that requires customer consent, making re-granting necessary. Follow the reg-grant process documented here.
Impacted apps: OneDrive, SharePoint
Re-granting ensures uninterrupted coverage for all your apps.
-
-
Will the re-grant trigger a re-listing of files or affect coverage?
No. Re-granting does not trigger file re-listing and will not cause any loss of coverage if re-granted on or before the stipulated deadlines.
-
Will the re-grant cause downtime?
No downtime will occur if the re-grant is completed before the deadlines.
-
What happens if I miss the deadlines?
Classic API Data Protection for Microsoft Office 365 apps will stop working unless re-granted. You should re-grant immediately. API Data Protection will then catch up on coverage for any new changes between March 31 2026 and the date you perform the re-grant.
-
Who can perform the re-grant?
Any user with global administrator privileges can perform the re-grant.

