8.4.1 (L1) Ensure app permission policies are configured

Information

This policy setting controls which class of apps are available for users to install.

Allowing users to install third-party or unverified apps poses a potential risk of introducing malicious software to the environment.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To remediate using the UI:

- Navigate to Microsoft Teams admin center

https://admin.teams.microsoft.com

.
- Click to expand Teams apps select Manage apps
- In the upper right click Actions > Org-wide app settings
- For Microsoft apps set Let users install and use available apps by default to On or less permissive.
- For Third-party apps set Let users install and use available apps by default to Off
- For Custom apps set Let users install and use available apps by default to Off
- For Custom apps set Upload custom apps for personal use to Off

Impact:

Users will only be able to install approved classes of apps.

See Also

https://workbench.cisecurity.org/benchmarks/17682

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(5), 800-53|CM-10, CSCv7|2.7

Plugin: microsoft_azure

Control ID: 10c3462a8a8562fe65e1f15f0249a138c2aa883db1393e31d49654725fac05f7