Note

Access to this page requires authorization. You can try signing in or .

Access to this page requires authorization. You can try .

App compliance program for security, data handling, and privacy

Microsoft 365 app compliance program checks and audits an app against controls that are derived from leading industry-standard frameworks. The program demonstrates that strong security and compliance practices are in place to protect customer data. The program has the following phases:

To help you evaluate app trustworthiness more efficiently, the Teams admin center will soon surface security and compliance data, when available, for apps beyond Microsoft 365 certified or publisher-attested ones. Data from Microsoft Defender for Cloud Apps (MDA) supports quicker assessments against organizational trust requirements. For more information, see MDA documentation.

Important

This is associated with Microsoft 365 Roadmap IDs 503100, 503102, and 502842.

Publisher verification

Before an app developer can submit their app to Microsoft, the developer is required to undergo a verification. A developer verifies their identity using their Microsoft Partner Network (MPN) account and associates this MPN account with their app registration. Publisher verification helps admins and users understand the authenticity of application developers. Publisher verification provides the following benefits:

  • Increased transparency and risk reduction for customers: This capability helps customers understand which apps being used in their organizations are published by developers they trust.
  • Improved branding: A verified badge appears on the Microsoft Entra consent prompt, Enterprise Apps page, and other user interfaces used by users and admins.
  • Smoother enterprise adoption: Admins can configure user consent policies, with publisher verification status as a primary policy criteria.

Publisher attestation

Publisher attestation is the next tier in the app compliance program. Publisher attested apps provide confidence to admins about security and compliance measures of an app. It also helps reduce the time to review this information for an app. The attestation reflects an app's security, data handling, and compliance practices against more than 80 risk factors identified by MDA. Publisher attestation process can start before Publisher verification is complete.

App developers are asked to complete a self-assessment that includes questions frequently asked by customers and IT admins to evaluate the security and compliance of an app. Microsoft then publishes this information for easier and more timely evaluation. To know more, see attestation guide.

Admins can quickly check for Published attested apps in three different ways.

Microsoft 365 certification

App certification is achieved through:

  • Approval of a comprehensive assessment centering on an app's security and compliance frameworks, processes, and procedures.
  • A qualified analyst's review.

We check the app against a series of security controls derived from leading industry-standard frameworks. Developers demonstrate following strong security and compliance practices to protect customer data when their app is used in an organization. More information about how admins and users benefit from the certification is available at overview of Microsoft 365 app compliance program.

Administrators can find Microsoft 365 certified apps and information about such apps in the following ways:

View security, compliance, and privacy information

You can find information about security, privacy, compliance, and behaviors for an attested or certified app in Microsoft documentation and Teams admin center.

Microsoft documentation

You can find the details about security, privacy, compliance, and more for each app listed it the app-specific help articles linked from Microsoft Teams apps security and compliance.

πŸ‘ Detailed information that is provided for apps that undergo Microsoft compliance program.

Teams admin center

Teams admin center provides enhanced tools and expanded security and compliance insights to streamline app and agent evaluations. You can view security and compliance data, when available, for apps beyond Microsoftβ€―365 certified or publisher-attested ones, powered by MDA. Trust-based filters help narrow choices by industry-standard attributes such as SOCβ€―2, ISOβ€―27001, HIPAA, and GDPR, enabling faster, more informed approval decisions.

Important

For timelines, see 503100, 503102, and 502842.

Security and compliance information on Teams admin center

Teams admin center helps you quickly assess security and compliance-related information for agents and apps. This information includes industry-standard data such as SOCβ€―2, HIPAA, ISOβ€―27001, GDPR, CCPA, and FedRAMP, plus Microsoft Entra ID integration for Single Sign-On, Penetration Testing, and CSA STAR compliance. You'll also see privilege-level insights and permission risk ratings powered by MDA.

Here's how you can view the security and compliance information:

  1. Sign in to Microsoft Teams admin center.

  2. Go to Manage apps to view and govern apps that are available in your organization's app catalog.

  3. Use the Security and compliance info column to see industry standard attributes and sort apps by the desired attributes.

    πŸ‘ Screenshot showing the newly added column displaying trust-based attributes.

  4. Select the Filter icon located between the Excel and Settings icons in the top-right corner to filter apps by compliance attributes.

    πŸ‘ Screenshot showing the filter option for the security compliance info column, displaying compliance attributes.

  5. Select Apply to see all the filtered compliance attributes.

    πŸ‘ Screenshot showing the detailed filters, displaying apply button.

    Alternatively, you can select any particular agent or app under the All apps section and go to the Security and compliance tab to view information about the particular agent or app.

    πŸ‘ Screenshot showing an individual app and the security and compliance tab.

View Microsoft 365 certified apps and download evidence

The Manage apps page shows an enhanced tile for apps that are Microsoft 365 certified, Certified with evidence, and Publisher attested, that you might allow in your organization.

πŸ‘ Screenshot showing the tile with three trust-based attributes.

View privacy policy and terms of use of an app

In Teams admin center, each app page links to the privacy statement and terms of use of the app.

πŸ‘ From Teams admin center, admins can access the link to the privacy policy and terms of use for every app.

Related articles


Feedback

Was this page helpful?

Additional resources