Concept

Progressive Scanning

  • Timeline: Preview open immediately, General rollout planned for December 2025
  • Impact: All Rencore Governance Customers

Based on your feedback, these changes will affect how quickly your Inventory objects are updated, Policy violations are triggered, and Automation thresholds work.

Who is Impacted

During the preview phase, only customers who opt-in are impacted. After the preview phase, the changes will be rolled out to all customers. We recommend reading through the changes below carefully and preparing your workspace as needed, even if you do not plan to join the preview from the very beginning, because this change is going to be rolled out to all regions throughout the next weeks.

What is Changing

Since scanning is a core component of our product, the changes are impacting different areas, and there are required actions for you if you use our Automations feature.

1. Improved scanning performance

What’s changing: We’ve optimized our scanning engine to process scans more efficiently, focusing on delivering value to your workspaces as fast as possible. Therefore, we changed the scanning approach to save updated data to your inventory more often, instead of at the very end of a scan - especially in large workspaces, we expect this to have a great impact on your experience. The changes take speed and data consistency into consideration; therefore, some complex policies might only be updated at a later stage.

Previous behaviour: Scans updated the inventory only once during the finalization phase at the very end of the scan.

New behavior: Scans will run a finalization phase after every batch, i.e. 1,000 Teams and update your Inventory, accordingly, reducing the time it takes to see fresh data in your inventory.

Action Required: No actions required.

2. Frequent Updates to Rencore Artifacts

What’s changing: Based on the updated inventories, we also update Rencore artifacts (Segments, Reports, Policies) more often if they are based only on a certain type of object. Artifacts spanning across relations will still only be updated once we have all the updated data to ensure data integrity.

Previous behaviour: Artifacts updated at the very end of a scan.

New behaviour: Artifacts that only contain objects at the very top of the hierarchy, i.e., User, Teams, Site Collections, etc., will be updated after every batch. We can update some additional objects more frequently and are trying to deliver the frequent updates to as many configurations as possible, without harming data integrity.

Example: A policy reporting a violation for every Team with a few owners was only updated once after the full Teams scan finished. Depending on the environment size, it could be hours or sometimes multiple days. With the new approach, we will update the policy after every batch, multiple times a day, independently of the environment size.

Action Required: No actions required.

3. Shortened Time to Action for Automations

What’s changing: Through updating the artifacts, like policies, more frequently, violations will also trigger attached automation runs once they are picked up. This will decrease the time you need to wait for your Automation to start running.

Previous behaviour: At the very end of a scan, we updated the Rencore artifacts, like for example policies, which triggered attached Automations. Even though this behaviour worked for small to medium-sized Automations, at a large scale, the time to run a scan, and the time to run sometimes hundreds of thousands of Automations needed improvement.

New behaviour: Policies eligible for batch updates are also triggering their attached Automations multiple times a day (we do not change the trigger logic, just the time when it triggers). Violations that have already been processed will not be re-triggered. The threshold of an Automation will now be handled as a daily threshold; the result will therefore be similar to the current logic of the threshold.

Action Required: Prepare and be aware that Automations running on policy violations are being triggered more frequently compared to the current experience. Prepare for daily thresholds compared.

4. Reduced Impact of Graph API Exceptions

What’s changing: We closely monitor all your jobs, even though the Graph API is largely reliable, there are cases where the API is unresponsive or returns unexpected responses. In these cases, we have various fallback mechanisms or check them manually if needed, which can impact your experience through so-called “Job Pausings”. With our new approach, we are changing this slightly to pause only a certain batch encountering issues and proceed with other batches to reduce the impact on your experience.

Previous behaviour: API exceptions may have caused paused scanning jobs to block updates to your inventory for a specific service.

New behaviour: In the future, a paused batch will not impact other batches, and we will be able to reduce the impact on your experience. If data from a paused batch is required to update Rencore artifacts, it might still impact the updates of these.

Action Required: No actions required.

Benefits for Your Organization

We are aiming to deliver multiple benefits to our customers through these improvements; the impact of the changes will largely depend on the size of your Rencore and Microsoft 365 implementation.

  • Get actionable insights faster with progressive results delivery
  • Respond faster to compliance issues with more up-to-date data
  • Reduce the impact of Graph API exceptions

Need Help?

Support: Contact [email protected]

Last updated: 12/2/2025