8.4.1 Ensure app permission policies are configured

Information

This policy setting controls which class of apps are available for users to install.

Rationale:

Allowing users to install third-party or unverified apps poses a potential risk of introducing malicious software to the environment.

Impact:

Users will only be able to install approved classes of apps.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To set app permission policies:

Navigate to Microsoft Teams admin center https://admin.teams.microsoft.com.

Click to expand Teams apps select Permission policies.

Click Global (Org-wide default).

For Microsoft apps set app permission policies to Allow all apps.

For Third-party apps set app permission policies to Block all apps OR Allow specific apps and block all others.

For Custom apps set app permission policies to Block all apps OR Allow specific apps and block all others.

Default Value:

Microsoft apps: Allow all apps

Third-party apps: Allow all apps

Custom apps: Allow all apps

See Also

https://workbench.cisecurity.org/benchmarks/12934