Microsoft Teams: Enable Teams apps and agents for existing applications in your organization

🚨 The Signal: New Teams admin center recommendations will surface existing third-party applications with available Teams apps or agents. This aims to reduce context switching by integrating business applications into Teams, potentially increasing the attack surface if not managed securely.

The Impact

Teams administrators are affected by new app recommendations, posing a security risk if integrations are enabled without proper vetting and access controls.

  • Teams administrators: Must vet new app recommendations for security and compliance before deployment.
  • Security teams: Need to assess the risk of new third-party integrations and data flows.
  • Users: May gain access to new integrated experiences, potentially exposing them to unapproved applications if not controlled.

The Action

  1. Review the Teams admin center for new app and agent recommendations for third-party applications.
  2. Assess each recommended app/agent against your organization's security policies, data handling requirements, and compliance frameworks (ISM, PSPF).
  3. Implement granular app permission policies in the Teams admin center to control which users or groups can access specific integrated applications.
  4. Ensure that data governance and retention policies are extended to cover data processed or stored by newly integrated Teams apps and agents.
  5. Regularly audit enabled Teams apps and agents to ensure they remain compliant and necessary.

Domain: Teams · Impact: medium · Workload: Teams · Essential Eight: Application Control · ISM: ISM-0843, ISM-1490, ISM-1544, ISM-1582, ISM-1656, ISM-1657, ISM-1658, ISM-1659, ISM-1660, ISM-1870, ISM-1871