A family of Microsoft word processing software products for creating web, email, and print documents.
Hello, I have just received a message from Microsoft indicating that this was investigated and is now fixed (and linking to this thread). I have copied the message below FYI:
My name is [edited], I am Microsoft 365 Support Ambassador and happened to come across this case while performing an internal audit. I am able to confirm that the issue you reported was investigated by the SharePoint Online and Office Product Groups and a 'fix' was pushed out on February 9th to prevent it from happening moving forward. For transparency, here is a forum post where a few other customers are discussing the same issue: Random people showing up in Track Changes?? - Microsoft Community
Our product engineering team received reports of an issue in which users noticed that several formatting edits that were made with “Track Changes” enabled in Microsoft Word were showing the name of an individual outside of their organization. We have determined the source of the problem, and stopped the issue as of Thursday, February 9, 2023 from occurring going forward; however, documents already affected by this issue may still see the incorrect author. Additionally, we’re proactively exploring additional service monitoring to detect and prevent this issue from occurring again.
For clarity, document permissions were not affected*, and this issue did not allow users to access any document without proper permissions or authorization. Document names or content from within your organization were never visible to any user who was not explicitly granted permission to the document.*
Here are a few FAQs on this issue that engineering provided.
Q: Which versions of Microsoft Word were affected?
A: Any version of Microsoft 365 apps including Semi-Annual Channel were in scope for this issue.
Q: What is the timeframe of impact?
A: Between January 31, 2023 and February 9, 2023.
Q: What caused this issue?
A: A code issue caused a problem with the attribution of Tracked Changes edits in documents in some scenarios, such as coauthoring. In these cases, Track Changes may incorrectly show that edits were made by unknown users that may be outside the document owner’s organization. This misattribution applies to both new edits as well as edits with Track Changes that are already in the document when it’s opened. In these cases, the unknown users are shown by mistake and did not, at any time, have any access or visibility of your affected documents.
Q: Is there a breach of our security or Microsoft’s services or apps?
A: There is no security incident for this event. We have confirmed that this issue did not allow external access to your documents.
Q: Was our data exposed to anyone outside our organization without our consent?
A: No, we have confirmed that this issue did not allow external access or visibility to your documents. This was a Microsoft Word document metadata problem which incorrectly listed contributing users within the user interface of your affected documents that are not part of your organization.
Q: Will this issue continue to occur for further Microsoft Word documents?
A: This issue was mitigated as of Friday, February 10, 2023, at 3:00 AM UTC. Your organization will not experience any newly occurring instances of this issue within your co-authored documents.
Q: How can I repair my affected documents to remove the incorrectly tagged contributors?
A: Users can leverage version history to return the document to its last known good state prior to the appearance of these external user tags within the user interface.
Q: What data was shown from my organization and where?
A: This issue may have resulted in the first and last names of one or more of your users contributing to a shared document being inadvertently tagged as a contributor within an unrelated document external to your environment.