8.4.1 (L1) Ensure app permission policies are configured

Information

This policy setting controls which class of apps are available for users to install.

Allowing users to install third-party or unverified apps poses a potential risk of introducing malicious software to the environment.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To remediate using the UI:

- Navigate to Microsoft Teams admin center

https://admin.teams.microsoft.com

.
- Click to expand Teams apps select Manage apps
- In the upper right click Actions > Org-wide app settings
- For Microsoft apps set Let users install and use available apps by default to On or less permissive.
- For Third-party apps set Let users install and use available apps by default to Off
- For Custom apps set Let users install and use available apps by default to Off
- For Custom apps set Let users interact with custom apps in preview to Off

Impact:

Users will only be able to install approved classes of apps.

See Also

https://workbench.cisecurity.org/benchmarks/20006

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(5), 800-53|CM-10, CSCv7|2.7

Plugin: microsoft_azure

Control ID: 9b5df609c8863be358c519f859b56f44efd086c15d067ed314cf729e182911ca