Cyber Security News

Microsoft Teams New Feature Enables Admins to Manage M365 Apps for Enhanced Security

Microsoft has announced a significant security enhancement for Microsoft Teams administrators, introducing a new feature that enables bulk management of Microsoft 365-certified applications through rule-based controls. 

This development, identified under Microsoft 365 Roadmap ID 485712, represents a major advancement in organizational app governance and security posture management within the Teams ecosystem.

Summary
1. Microsoft Teams introduces rule-based admin controls for bulk managing Microsoft 365 certified apps with enhanced security.
2. Worldwide rollout begins mid-August 2025, completing by early September 2025, with default "All apps available" setting.
3. Admins can filter apps by publisher verification, permissions, and compliance through automated validation.
4. 30-day grace period for settings adjustment after activation, then immediate policy enforcement.

Automated Rule-Based App Management System

The new feature will begin its worldwide rollout in mid-August 2025, with full deployment expected by early September 2025. 

This automated management system introduces sophisticated controls through the Teams admin center, specifically within the Org-wide app settings under the Manage apps section. 

The feature leverages an intelligent filtering mechanism that automatically evaluates Microsoft 365-certified applications against administrator-defined criteria, including publisher verification, permission scopes, and security compliance standards.

The system operates through a centralized control panel located at Manage apps > Actions > Org-wide app settings > Microsoft 365 certified apps, where administrators can configure the “All apps available” option, which will be enabled by default post-rollout. 

This represents a fundamental shift from the previous third-party app tenant settings model, where bulk management capabilities were limited.

Enhanced Customization Options

The platform introduces advanced customization options through the “Customize availability” feature, allowing administrators to implement granular controls based on specific API permissions, data access levels, and publisher authenticity verification. 

This multi-layered approach ensures that only applications meeting stringent security requirements gain access to organizational resources.

The system’s rule-based architecture automatically validates applications against predefined security policies, checking for Microsoft 365 certification status, OAuth scope compliance, and tenant-specific security configurations. 

This automated validation process significantly reduces the administrative burden while maintaining robust security standards across the organization’s app ecosystem.

Organizations currently utilizing third-party app tenant settings will experience seamless integration with no required action. 

However, tenants with disabled Org-wide app settings must review their configuration strategies before the rollout. 

Microsoft has implemented a 30-day grace period following feature activation, during which administrators can adjust settings without immediate impact on app availability.

The delayed implementation mechanism provides organizations sufficient time to assess their current app governance policies and update relevant documentation. 

After this initial period, all configuration changes will have immediate effects on Microsoft 365-certified app availability, ensuring real-time security policy enforcement.

Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -> Try ANY.RUN now 

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago