SAMexpert logo
SAMexpert
Contact
Licensing

Microsoft Product Terms Update: July 2026

print
share

Summary

Microsoft's mid-June and 1 July Product Terms waves ban scraping, reverse engineering and API workarounds on every Online Service, and write consumption billing into the Universal Terms, where the obligation to pay survives the licence. Agent 365 prerequisites, first published on 1 June, were rewritten two weeks later.

Microsoft published two Product Terms waves since our June update: a quiet mid-month release on 15 June 2026 and the regular monthly release on 1 July 2026. The mid-month release is the substantive one. Microsoft describes it as an Acceptable Use Policy update "for clarity", but the policy gained three entirely new prohibitions that apply to every Online Service, and two new Universal Terms sections put consumption billing, with an obligation that survives licence termination, into the contractual foundation of every Microsoft cloud subscription. The same wave rewrote the Agent 365 licence prerequisites just two weeks after they were first published, removed Priva Subject Rights Requests from the Compliance Services list, and gave Microsoft 365 Copilot its own data residency reference.

Microsoft Product Terms July 2026 licensing update: SAMexpert title card with orange and black hazard tape.
Illustration: SAMexpert

The 1 July wave is smaller but not empty. The AI Builder capacity add-on left the Product Terms as part of its retirement, the Microsoft 365 Unattended Licence became eligible for Amazon WorkSpaces, and the Azure terms picked up two changes Microsoft did not announce: an Azure Hybrid Benefit extension for Windows Server VMs on disconnected Azure Local, and an explicit provision deeming third-party Foundry models subject to Microsoft's AI Code of Conduct. We also cover a Dragon Copilot change from 1 June that reversed February's tenant isolation rule.

Key takeaways:

  • Universal Terms for Online Services: the Acceptable Use Policy now prohibits scraping, reverse engineering and AI model weight exfiltration, and API limit circumvention across all Online Services; new "Excessive Use" and "Purchasing Consumption Services" sections codify throttling and consumption billing, including the rule that consumption payment obligations survive licence expiry or termination

  • Agent 365: licence prerequisites rewritten two weeks after first publication; Microsoft 365 A5 added, and holding both the Microsoft Defender Suite and the Microsoft Purview Suite now qualifies without E5

  • Privacy & Security Terms: Priva Subject Rights Requests removed from the Microsoft 365 Compliance Services list as the product retires into Microsoft Purview eDiscovery (Premium); the terms now reference a dedicated data residency commitment for Copilot interaction content

  • Microsoft Power Platform: AI Builder capacity add-on delisted four months before its documented end of life, part of the move to Copilot Credits

  • Dragon Copilot: the tenant isolation requirement for Physician Practice Per User licences, introduced in February, has been removed

Acceptable Use Policy: Three New Prohibitions for Every Online Service

The Acceptable Use Policy in the Universal Terms for Online Services is the list of things no customer may do with any Microsoft Online Service, from Exchange Online to Azure OpenAI. Violating it can lead to service suspension. Because it sits in the Universal Terms, it binds every Online Services customer on every programme, without exception.

In May, Microsoft added a prohibition on using an Online Service "to replicate product functionality". The 15 June update goes further and adds three more prohibitions. Customers may not use an Online Service:

"to scrape or use other data extraction methods to extract data from the Online Service;"

"to reverse engineer any Online Service or exfiltrate the weights of any AI models or otherwise discover any underlying components, algorithms or systems included in the Online Service;"

"to attempt to circumvent the limitations Microsoft sets on the use of any APIs related to the Online Service;"

A fourth bullet was rewritten. The policy previously prohibited use "in a way that could harm the Online Service or impair anyone else's use of it". The new wording prohibits use "in a way that could adversely impact the integrity, availability, stability, resilience, interaction with or use of the Online Service".

Two of the three prohibitions have precedents in narrower scope. The Microsoft Generative AI Services section already banned "web scraping, web harvesting, or other data extraction methods" and reverse engineering, but only for Generative AI Services. The 15 June update lifts those restrictions to the Acceptable Use Policy level, where they cover every Online Service, and drops the "web" qualifiers from the scraping ban. The API circumvention prohibition is new at any level.

"To scrape or use other data extraction methods to extract data from the Online Service" is broad enough to raise questions about automated data extraction generally, and the Product Terms do not carve out extraction of your own Customer Data through supported interfaces. Microsoft maintains supported data export materials, referenced from the EU Data Act section of the Privacy & Security Terms, so routine exports through documented interfaces remain supported. Automated extraction that works around the product's intended interfaces or API limits is now explicitly a suspension risk. If your organisation runs tenant-to-tenant migration tooling, data warehouse loads, or backup tools that pull data from Microsoft services in unsupported ways, review the new prohibitions with your vendor.

Four prohibitions in two months: replicating product functionality in May, then scraping, reverse engineering and API limit circumvention on 15 June. All four sit in the Acceptable Use Policy, which binds every Online Service on every programme, and a violation there can lead to suspension of the service.

Microsoft's change description says it "Updated the Acceptable Use Policy terms for clarity". The May robotic process automation (RPA) training ban carried a similar "clarifies existing intent" description while expanding its enforceable scope, and Microsoft has used the same framing again here. Whatever the intent was, three prohibitions that previously did not exist at the Universal Terms level now do.

Consumption Billing Enters the Universal Terms

The same 15 June update adds two new sections to the Universal Terms. Both look unremarkable at first reading. Both formalise the commercial model Microsoft is moving its AI portfolio onto.

The first is "Excessive Use":

"Use of an Online Service in excess of any limits set forth in documentation may result in temporary throttling of the Customer's access to the Microsoft Online Service".

The Generative AI Services section already allowed throttling for excessive use of those services. The new section generalises the throttling right to every Online Service and makes "any limits set forth in documentation" the trigger. Documented usage limits, which Microsoft can update outside the Product Terms change cycle, are now contractually enforceable through throttling for all services.

The second new section is "Purchasing Consumption Services". It states that some Online Services are billed at metered Consumption Rates as First-Party Consumption Services, that consumption may be sold as prepayments, reservations or other subscriptions, and that "Prices for consumption are subject to change". Then comes the sentence that matters most:

"The expiration or termination of the User license will not change the User's obligation to pay for consumption".

In plain language, walking away from the subscription does not cancel the consumption bill. Whatever metered usage a user generated remains payable after the licence ends. Before the 15 June update, consumption billing was set out in product-specific terms, most of them in the Azure sections. Now it is part of the universal contractual foundation, which matches where Microsoft's licensing model is heading: Copilot Credits, Copilot Cowork's usage-based billing, Windows 365 for Agents meters, and the broader shift in which the per-user licence is the entry ticket and consumption is the bill. The price-change sentence has its own consequence. Subscription prices are typically protected for the subscription term, and this wording confirms that consumption rates have no such protection.

Responsible Use of AI: "Solely" Disappears

The only textual change in the 1 July Universal Terms is one clause in the Responsible Use of Microsoft AI Services section, in the paragraph covering applications and agents built with Microsoft's starter templates and code samples. The old text made the customer "solely responsible for any application or AI agent it creates". The new text makes the customer "responsible for the design, development and use of any application or AI agent it creates".

Microsoft's change description calls it a "Minor update for clarity to the Responsible Use of Microsoft AI Services language". Removing "solely" from a responsibility allocation is the kind of minor update lawyers notice. The clause now names the activities the customer answers for rather than assigning the customer everything, which leaves more room for argument about where Microsoft's template ends and the customer's application begins. The compliance obligations themselves, including legal, regulatory and licensing requirements for the resulting agent, are unchanged.

One thing the July update did not do is tidy the naming. The Universal Terms still refer to "Azure Direct Models in Microsoft Foundry" in the Use of Content for Training section, a name Microsoft replaced with "Foundry Models sold by Azure" everywhere in the Azure terms in June. The rename cascade has not reached Microsoft's own Universal Terms.

Agent 365: Prerequisites Rewritten After Two Weeks

Our June update reported the first published licence prerequisites for Agent 365: Microsoft 365 E5, Microsoft 365 F5 Defender and Purview, or Microsoft 365 Business Premium. That table lasted two weeks. On 15 June, Microsoft replaced the qualifying list with:

"Microsoft 365 E5/A5/Business Premium, Microsoft Defender Suite and Microsoft Purview Suite, Microsoft Defender Suite Edu and Microsoft Purview Suite Edu, Microsoft Defender and Purview Suite FLW"

Three things changed. Microsoft 365 A5, the education counterpart of E5, is now explicitly eligible, and education customers also gained an availability table for the Enrollment for Education Solutions programme, which Microsoft's change description confirms. The frontline path is now named "Microsoft Defender and Purview Suite FLW" rather than "Microsoft 365 F5 Defender and Purview", reflecting the current suite naming. Microsoft Defender Suite is the renamed Microsoft 365 E5 Security add-on, a rename Microsoft's Entra licensing documentation records, and the Purview Suite is the renamed E5 Compliance add-on.

The third change is the commercially interesting one. "Microsoft Defender Suite and Microsoft Purview Suite" is now a qualifying combination in its own right. An organisation on Microsoft 365 E3 that holds both security add-on suites qualifies for Agent 365 without buying E5. Our June statement that E3 customers' path to Agent 365 "goes through E5 first" is out of date after two weeks. E3 plus the two suites is a valid route, although anyone pricing that route should compare its total cost against a straight E5 upgrade before committing. The bundle logic of Microsoft 365 E7, which includes Agent 365 outright, is unaffected.

A licence prerequisites table published on 1 June was rewritten on 15 June. Procurement teams that built Agent 365 plans around the original qualifying list had two weeks before the rules changed.

Priva Subject Rights Requests Leaves the Compliance Services List

The Microsoft 365 Compliance Services list in the Privacy & Security Terms defines which compliance products carry the Core Online Services commitments: the strongest audit, security and data protection assurances Microsoft offers. In June, we reported the silent removal of Customer Lockbox from this list. On 15 June, Microsoft Priva Subject Rights Requests followed it out, and this time the change description says so, recording the removal of Priva Subject Rights Request from Core Online Services.

The context is the product's retirement. Priva Subject Rights Requests (SRR), the tool for handling data subject access requests under the General Data Protection Regulation (GDPR) and similar laws, is being folded into Microsoft Purview eDiscovery (Premium). Microsoft's Priva service description, updated in May 2026, now describes only Priva Privacy Risk Management, and the Subject Rights Requests documentation redirects to the Purview eDiscovery documentation. Administrators have reported in-product guidance to use Purview eDiscovery (Premium) for subject rights requests from May 2026.

The licensing consequence is a model change. Priva Subject Rights Requests was sold per request. eDiscovery (Premium) is licensed per user, through Microsoft 365 E5, the Purview Suite (the renamed E5 Compliance add-on), or the eDiscovery and Audit add-on. Organisations that bought SRR licences as needed now need the staff who handle subject rights requests to be covered by Purview licensing instead. If your privacy operation budgeted for per-request purchases, that cost now becomes per-user licensing. Note that "Priva Subject Rights Management" remains listed in the EU Data Boundary Services table, so the data boundary commitment continues while the Compliance Services designation has gone, the same split treatment Customer Lockbox received in June.

Copilot Interactions Get a Dedicated Data Residency Reference

The Privacy & Security Terms commit Microsoft to storing certain Office 365 Customer Data at rest within the customer's chosen geography. Since Copilot's arrival, that commitment has covered "any stored content of interactions with Microsoft 365 Copilot or Microsoft 365 Copilot Chat". The 15 June update appends a qualifier: the commitment applies "to the extent not included in the preceding commitments or subject to Data Residency for Microsoft 365 Copilot and Copilot Chat".

The linked page documents a dedicated residency framework for Copilot interaction content. The baseline Product Terms commitment stores the content of interactions and the related semantic index in the local region geography, and the Advanced Data Residency and Multi-Geo add-ons layer additional commitments on top, including per-user storage locations driven by each user's Preferred Data Location. The Product Terms change adds a cross-reference to that framework. Microsoft 365 Copilot interaction data now has its own governing residency document rather than only the general Office 365 commitment.

Teams: Notification Duty Shifts to Your Contact Centre

Microsoft Teams received one new Service Specific Term on 15 June, titled "Notifications":

"Microsoft Teams provides participant standard notifications as required by law, including, but not limited to, recording, transcription, and interaction with AI. If you choose to disable these notifications, you are responsible for ensuring that your contact center solution informs participants in real time in accordance with applicable laws".

Where the law requires participants to be told they are being recorded, transcribed, or handled by AI, Teams shows those notices by default. Contact centre platforms built on Teams can disable the native notices in favour of their own announcements. The new term makes the consequence contractual. Disable the notifications and the duty to inform participants in real time, including about AI interacting with the call, is yours. Organisations running Teams-certified contact centre solutions should confirm, in writing, which side of that boundary their vendor stands on, and whether the vendor's announcements cover AI interaction as well as recording and transcription.

AI Builder Capacity Add-on Delisted

The 1 July Power Platform update removes the AI Builder capacity add-on from the Availability and Purchasing Minimums tables. The add-on sold 1 million AI Builder credits per month, with purchase minimums of 1, 10 or 50 units depending on tier, and AI Builder credits are the currency that pays for AI features inside Power Apps and Power Automate: document processing, text analysis, prompts and similar capabilities.

The delisting is part of a retirement Microsoft announced in October 2025. Sales of the add-on to new customers ended on 1 November 2025. The documented end of life is 1 November 2026, when existing customers lose the ability to renew and, according to Microsoft's frequently asked questions, seeded AI Builder credits "will be removed for all new and existing customers, including those with an Enterprise Agreement". There is no conversion. Microsoft states that "There isn't a conversion of entitlement from one currency into the other currency". Customers are expected to buy Copilot Credits instead, the common consumption currency across Copilot Studio and, increasingly, the whole Power Platform.

Note the sequence: the Product Terms delisting on 1 July arrives four months before the documented 1 November end of life for renewals. Existing customers keep using credits from active add-ons until their contracts expire, but the contractual listing that defined the purchase has already gone. If your organisation runs production workloads on AI Builder credits, price the equivalent workload in Copilot Credits now rather than in November. The rate tables differ by capability, so the translation is not uniform. At pay-as-you-go rates a Copilot Credit costs $0.01, and a premium LLM prompt that costs 10 Copilot Credits per thousand tokens works out around 10 per cent more expensive than the same prompt paid with Tier 1 add-on AI Builder credits, while several document processing capabilities cost several times more in Copilot Credits than they did in AI Builder credits. The AI Builder retirement is not the first time Microsoft has retired a purchased capacity product in favour of consumption billing; the Power Apps per app plan went the same way.

AI Builder's fixed monthly capacity gives way to Copilot Credits. The same update leaves consumption rates subject to change and keeps the payment obligation alive after the licence ends. A capacity add-on has a known monthly cost; metered consumption does not.

Azure Local Disconnected Operations: a Rename and a Quiet Benefit Extension

Disconnected Operations is the Azure Local deployment model for environments with no connection to Azure at all. Microsoft positions it for sovereign and compliance-driven deployments in sectors such as government, healthcare and finance, and for remote or isolated sites such as oil rigs and manufacturing plants. It runs a local copy of the Azure control plane, requires Microsoft's approval to buy, and is licensed for one-year periods covering every physical core under management, with true-up if usage grows. The overview documentation describes the eligibility gate: an eligible agreement, an active support plan, a valid business need to operate disconnected, and an approval process.

Microsoft's only announced Azure change for 1 July is that it "Updated Regional Trade Compliance Addendum to Compliance with Trade Laws in the Disconnected Operations for Azure Local terms". Comparing the two versions confirms that only the heading changed. The four obligations underneath, covering sanctions screening, notice of trade law investigations, global use restrictions, and not supplying Microsoft products to sanctioned entities, are word for word identical.

What Microsoft did not announce is a new sentence in the same section's use rights:

"Azure Hybrid Benefit for Windows Server VM Licensing applies to Windows Server VMs running on Azure Local with disconnected operations".

There are two different Azure Hybrid Benefits in play here, and the June and July updates touched one each. Azure Hybrid Benefit for Azure Local waives the host service fee and the Windows Server guest subscription for a whole cluster; the June update restricted it to hyperconverged deployments, and disconnected deployments remain outside it. Azure Hybrid Benefit for Windows Server VM licensing is the guest-level benefit, letting you cover Windows Server VMs with your own Windows Server licences with Software Assurance or subscription licences instead of paying for Windows Server as part of the service. The new sentence grants that second benefit to Windows Server VMs on disconnected deployments.

For sovereign and air-gapped operators, the sentence answers a question the terms previously left open, namely how Windows Server guest VMs are licensed on a platform that has no Azure billing endpoint to meter them. Bringing your own Datacenter licences with Software Assurance is now the explicitly sanctioned route. Microsoft's Azure Hybrid Benefit documentation has not caught up; it does not yet mention disconnected operations, and it defers to the Product Terms as the governing document, which now say more than the documentation does.

Foundry Models: the Code of Conduct Deeming Is Now in the Terms

In January, Microsoft embedded several thousand words of model-provider terms for Grok, Llama, Black Forest Labs and Mistral into the Azure Product Terms. In June, it removed them in favour of an external documentation page. The 1 July update completes that restructuring with a new "Model-Specific Terms" provision in the Microsoft Foundry Models section, unannounced in the change description.

The provision does three things. It points to the model-specific terms page, which currently hosts the Grok, Llama, Black Forest Labs and Mistral terms. It restates that models from Microsoft other than Foundry Models sold by Azure are First-Party Consumption Services under their own licence terms. And it makes explicit in the Product Terms text what June's change description asserted: third-party models that are neither Foundry Models sold by Azure nor First-Party Consumption Services are Non-Microsoft Products, but "such models will be deemed Microsoft AI Services for purposes of the Microsoft Enterprise AI Services Code of Conduct".

For customers deploying third-party models through Foundry, the position is now unambiguous on the face of the terms. The model's own licence governs your rights, and Microsoft's Code of Conduct governs your behaviour, with suspension available for violations. The advice from our June update stands: the provider-specific restrictions live on a documentation page Microsoft can change without a Product Terms change log entry.

Amazon WorkSpaces: Unattended Licences Allowed

The Product Terms include a dedicated entry permitting Microsoft 365 Apps for enterprise to run in Amazon WorkSpaces, the Amazon Web Services (AWS) virtual desktop service, for users licensed with qualifying plans. The 1 July update adds a new qualifying licence. Microsoft's change description records the addition of the Microsoft 365 E3/A3/G3 Unattended Licence to the list of Eligible Products.

The Microsoft 365 Unattended Licence covers automation that runs Office applications without a human at the keyboard, such as RPA bots generating documents or extracting data. Until now, the Amazon WorkSpaces entry listed only human-user plans: Microsoft 365 E3/E5/E7, A3/A5, G3/G5 and Business Premium. Organisations running Microsoft 365 Apps on AWS can now also run their licensed unattended bots there, rather than keeping automation workloads on separate infrastructure.

The context makes the addition interesting. Since May, the Product Terms have prohibited using RPA and bot outputs from Office applications to train AI models, a restriction that started with the Unattended Licence and now covers every programme including the Services Provider License Agreement (SPLA). Microsoft is simultaneously tightening what unattended automation may do with Office outputs and widening where unattended automation may run. Licensing follows the bot, wherever it executes; so do the restrictions.

Dragon Copilot: February's Tenant Isolation Rule Reversed

Microsoft's Product Terms change log lists a Dragon Copilot update for 1 June 2026, described as "Removed the term indicating that a customer may not deploy licenses in the same tenant". Comparing the current Dragon Copilot terms against the 1 February version confirms it. The tenant isolation sentence is gone.

In February, Microsoft introduced the Physician Practice Per User licence together with a clause stating that "Customers may not deploy Dragon Copilot Physician Practice Per User Licenses in the same tenant as other Dragon Copilot Licenses". We covered it at the time, noting that Microsoft had not explained the rationale. Four months later, the restriction has been removed from both the Microsoft Customer Agreement (MCA) and the Enterprise Agreement and Enterprise Agreement Subscription (EA/EAS) views of the terms. The change description says what was removed but not why. Healthcare organisations that kept Physician Practice Per User in a separate Entra tenant to satisfy the February clause no longer have a Product Terms obligation to do so. One structural point survives the change: Physician Practice Per User appears in the MCA availability chart and not the EA/EAS one, so EA customers still do not see it as an option. Our Dragon Copilot licensing guide covers the licence types in detail.

Services Provider Use Rights: No New Changes

The Services Provider Use Rights (SPUR), the licensing document for SPLA hosting providers, has not changed since the 6 May 2026 update that extended the RPA training ban to Office Suites, Project and Visio under SPLA. We covered those changes in the June update. Microsoft's SPUR change summary lists nothing newer, and the current version remains dated 6 May 2026.


Get in Touch

Microsoft rewrote the ground rules for every cloud subscription in the June and July 2026 Product Terms updates, and most of it arrived in a mid-month release described as a clarification. If you want help working out what the consumption survival clause, the new acceptable use prohibitions, or any of these changes mean for your agreements, get in touch. We don't sell Microsoft licences or cloud services, so our advice is independent.

Table of contents
print
share

Read next

More articles