Microsoft is preparing to make a quiet but far-reaching change to Microsoft 365: a batch of employee details long hidden inside profile cards will suddenly become visible by default across Outlook, Teams, and other applications. Organizations have until August 24, 2026, to opt out, or data like employee numbers, cost centers, and street addresses will surface on every profile card for anyone in the company to see.

Why Microsoft is Flipping the Default on Profile Card Data

A Microsoft 365 profile card is the pop-up panel that appears when you hover over or click a colleague’s name in Outlook, Teams, OneDrive, SharePoint, and other Microsoft 365 apps. It already shows basic details—name, title, department, email, phone, and office location—by default. Behind the scenes, it can pull from many systems: Microsoft Entra ID, on-premises Active Directory, HR platforms, and custom people-data connectors.

Until now, Microsoft kept eleven additional fields hidden by default. They were there, populated with data from your identity and HR systems, but IT had to manually enable each one from the admin center if the organization wanted them displayed. Starting with a coming update—first reported by Neowin on July 26, 2026, citing a Microsoft 365 admin center advisory—Microsoft is reversing that logic. The company will surface those eleven fields automatically whenever the data is present. The advisory labels this a “major change,” and sets the opt-out deadline as August 24, 2026.

The 11 Fields That Could Expose Sensitive Details

Here is exactly what becomes visible by default after the deadline if you don’t intervene:

  • Division
  • Role
  • Employee number
  • Employee type
  • Cost center
  • User principal name (UPN)
  • Alias
  • Fax
  • Street address
  • State
  • Postal code

Many of these come across as mundane directory tidbits. But together, they can paint a detailed picture of someone’s organizational placement, payroll categories, physical location, and internal identifiers—information many businesses prefer to keep confined to HR and finance systems.

The risk varies by field. An employee number might be harmless in one company and a critical piece of a verification puzzle in another. A cost center can reveal the internal funding structure, sometimes associated with confidential projects. Street address, state, and postal code—grouped under “Business address” on the card—might be a central office location for some, but for remote or field workers, they could stem from outdated or even personal address data if not carefully governed.

UPN and alias are more technical: the UPN might look like an email but often uses an older domain or a SAMAccountName form; the alias (mailNickname) is used for mail routing and legacy apps. Both are helpful for IT, but confusing for everyday users. Fax is likely irrelevant in many modern workplaces but still lurks in some directories.

The key issue is not that these fields are new. They’ve been in your tenant all along. The change is that Microsoft will now show them to anyone in the organization—including contractors, guests, and new hires—without your explicit consent, unless you say no.

Who Needs to Worry About the August 2026 Deadline?

Every organization that uses Microsoft 365 for collaboration should check, but hospitals, law firms, government contractors, financial services, and any business subject to strict privacy regulations will feel the greatest urgency. If your employee directory is tightly managed, the change may be welcome. But years of data migration, merged tenants, incomplete HR updates, and inconsistent onboarding workflows can leave behind stale or inappropriate values. Once those values appear on a profile card, they look authoritative. Employees will trust them.

There is also a governance angle. A cost center, for example, might have been populated solely for finance chargebacks. An employee type could differentiate a full-time staffer from a contractor in a way that, if visible, might inadvertently signal job status that some organizations prefer to keep confidential. A hidden property doesn’t delete the underlying data—it only suppresses it on the profile card. So this is not a substitute for cleaning up your directory; it’s a stopgap to prevent embarrassing or risky disclosure while you sort out the source data.

Five Steps to Take Before the Deadline

Microsoft has provided a straightforward off switch, but you must act. Merely being aware of the change won’t help unless someone logs into the admin center and flips the correct toggles. Here’s a practical plan:

1. Inventory which fields have data and where they come from

Do not assume a field is empty because you never used it. Legacy sync rules, past HR exports, or identity-management scripts may have seeded values years ago. Use the Microsoft 365 admin center, Entra ID, or the Microsoft Graph API to check if these eleven attributes are populated across your user base. For each, identify the authoritative source—Entra ID, an HR system, or a custom connector—and assign a data owner.

2. Decide what should be visible, by role or workforce type

Group the fields into three tiers:
- Broadly useful: e.g., division and role—these help colleagues find the right people.
- Operational but sensitive: e.g., employee number, cost center, employee type—these may need to stay hidden from general users.
- Location quirks: street address, state, postal code, fax—validate accuracy and decide whether they help or confuse.

You might keep some fields visible for permanent employees but suppress them for contractors or guests. The admin center allows you to disable each property globally; there’s no per-user toggle, but you can configure visibility once for the tenant.

3. Go to the right admin center page and flip the switches

Navigate to Settings > Org settings > People settings in the Microsoft 365 admin center. Select Profile card, then Contact info. You’ll see the list of optional properties with on/off toggles. Turn off any property you don’t want broadly visible. The change applies tenant-wide.

You need the Global Administrator or People Administrator role to modify these settings. Microsoft recommends using the People Administrator role to follow the principle of least privilege. If you’re delegating the task to HRIT, identity, or collaboration admins, assign that role rather than granting full global admin rights.

4. Wait, then test with real accounts

After saving the changes, Microsoft says it can take up to 24 hours for the profile cards to reflect the new visibility. Don’t test immediately. After the propagation window, check profile cards in Outlook, Teams, and OneDrive using representative accounts: a regular employee, a manager, a contractor, a remote worker, and someone with address details or a legacy UPN. Make sure the fields you suppressed are truly gone.

5. Tell employees and provide a correction path

A short communication to end users can prevent confusion and support tickets. Explain that profile cards may now show additional organization-managed details and that the organization has reviewed and hidden certain fields for privacy or accuracy reasons. Tell employees whom to contact if they see incorrect information—many will notice stale job titles or wrong office addresses for the first time. Because some data is controlled by HR or IT systems, users can’t edit it themselves. The source system must be corrected.

The Broad Implications for Workplace Data Governance

This profile card update isn’t a one-off. It’s a signal that Microsoft increasingly treats directory data as a resource to be surfaced everywhere: in Copilot experiences, in people search, in organizational charts, and in contextual collaboration tools. Fields that once lived only in a HR system or an identity management console are now part of the everyday employee interface.

For years, IT admins could treat many of these fields as “back-end-only.” The new default visibility breaks that assumption. Going forward, treat every persistent attribute in Entra ID or connected people-data sources as potentially public within the organization. The profile card might be the first place it surfaces, but it won’t be the last.

If you have your data house in order, the change may simply make Microsoft 365 more useful. If your directory is a mess, you have until August 2026 to clean up or cover up. The smart move: use this deadline to start a conversation between your identity, HR, security, and collaboration teams about who owns each field and what its disclosure threshold should be.

Outlook

The August 24 deadline is firm, but the real story is the gradual erosion of the wall between administrative data and end-user interfaces. Microsoft wants a richer, more connected people experience, and that means pushing more information forward. It’s up to each organization to decide where the line falls between helpful transparency and unnecessary overexposure. The toggle is in the admin center—use it before someone else decides for you.