Saturday, October 3, 2026

Microsoft Teams Adds Feature for Admins to Control 365 Certified Apps with Custom Rules

Microsoft is rolling out a major update to Microsoft Teams, empowering administrators with enhanced control over third-party app availability through new rule-based settings in the Teams admin center.

This change—detailed in Microsoft’s recent Message Center update (MC1085133)—is set to begin global rollout in mid-August 2025, with completion expected by early September 2025.

The new feature, tracked under Microsoft 365 Roadmap ID 485712, allows admins to manage Microsoft 365-certified apps in bulk, directly from the Teams admin center.

Previously, app availability was governed solely by third-party app tenant settings, limiting flexibility and control.

With this update, admins will be able to set rules based on app permissions and publisher names, ensuring only trusted, certified apps are accessible to users.

A key aspect of this rollout is the automatic enablement of the feature—meaning it will be ON by default for all organizations.

The system will automatically evaluate Microsoft 365 certified apps against the rules specified by the admin, making compliant apps available to users. This move aims to bolster security and streamline app management across organizations.

How It Works

Once the feature is live, administrators can access the new controls via the Teams admin center under Manage apps > Actions > Org-wide app settings > Microsoft 365 certified apps.

The default setting will allow all certified apps, but admins can further refine availability using the new Customize availability option.

This enables granular control based on specific criteria, such as required permissions or trusted publishers.

What Organizations Need to Know

  • Automatic Rollout: No immediate action is required from admins before the feature launches.
  • Review and Notify: Admins are encouraged to review their current app configurations and notify users of the upcoming changes. Updating internal documentation is also recommended.
  • 30-Day Grace Period: After the feature releases in a tenant, organizations will have 30 days to adjust settings before the new rules impact app availability. This grace period is a one-time occurrence for this launch; subsequent changes will take effect immediately.

For organizations with Org-wide app settings already enabled, no further action is necessary.

However, those with these settings turned off should review the new tenant settings and prepare to make any needed adjustments.

Find this News Interesting! Follow us on Google News, LinkedIn, and X to Get Instant Updates

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices

A newly identified IoT botnet, Cling, disguises its command-and-control...

Microsoft Warns ClickFix Attacks Use Fake CAPTCHA Lures to Execute Malicious Commands

Microsoft Threat Intelligence has identified a ClickFix campaign in...

Critical GitLab AI Gateway Flaw Lets Attackers Execute Arbitrary Commands

GitLab has issued emergency security updates for a critical...

AWS AI Agent Vulnerabilities Let Attackers Bypass Authentication and Steal Credentials

AWS has released security fixes for four vulnerabilities affecting...

Citrix NetScaler Appliances Reboot Repeatedly After 0-Day Security Update

Citrix NetScaler administrators report repeated appliance crashes and forced...

Sony PS5 Relapse Jailbreak Exploit Uses JSC Memory Corruption and Kernel UAF

A newly released PlayStation 5 jailbreak chain, called Relapse,...

Zammad Vulnerabilities Let Attackers Execute Code and Escalate Privileges to Root

Two critical vulnerabilities in the open-source Zammad helpdesk and...

Safari History Database Tags Can Reveal Users’ Browsing Themes in Forensic Investigations

Safari's History database contains a lesser-known tagging artifact that...

Related Articles

Recent News