Microsoft Teams: App centric management in Teams Admin Center to manage the Apps access for tenants, end-users, and groups in DoD

🚨 The Signal: Teams now offers granular, app-centric management for who can install apps, replacing broad permission policies. This improves control over third-party app access, reducing shadow IT and potential data exfiltration risks.

The Impact

Admins are affected by new app management options, reducing the risk of unauthorized app installations and potential data exposure.

  • Security Teams: Reduced risk from unapproved apps accessing sensitive data.
  • Admins: New configuration options for app installation permissions.
  • End-users: May find certain apps restricted based on new policies.

The Action

  1. Review existing Teams app permission policies in Teams Admin Center.
  2. Navigate to Teams Admin Center > Teams apps > Manage apps.
  3. For each app, configure 'Availability' to 'Specific users and groups can install' or 'No user can install' as appropriate.
  4. Define a default value for new apps published to the Teams app store.
  5. Communicate changes to end-users regarding app availability.

Domain: Teams · Impact: high · Workload: Teams · Essential Eight: Application Control · ISM: ISM-0843, ISM-1490, ISM-1544, ISM-1582, ISM-1656, ISM-1657, ISM-1658, ISM-1659, ISM-1660, ISM-1870, ISM-1871