Native App Permission Policy to App Centric Management in MS Teams

“Microsoft says, lets Keep it simple“
I know Copilot and several other AI features are making life simple for those in need, but I felt this article should be more of the good old days with genuine walkthrough of how a feature is being explored and implemented. No offence to AI features, just trying not to forget my tech blogging skills.
Things to consider before we migrate the native app permission policy management to App Centric Management in MS Teams,
- Any org which doesn’t have a custom policy can just jump the gun and get back to your work as Microsoft got your back, they are automatically migrated to App Centric Management.
- Any org which has one or two custom policies, need a little bit of attention in fine tuning your custom policies and migrate to App centric management using the wizard as mentioned in the TechNet article
- Any org with 2 or more custom policies, let’s chat! It sounds like you have a thrilling game of “Policy Jenga” going on!
How to get started?
App permission policies so far was, you determined access to apps using the following three settings:
- Permission policy: It applies at a user-level and controls if a specific user is allowed to use an app or not.
- Org-wide app setting for third party apps: It applies at an org-level and controls if all third party apps are available for every user or not.
- App status: It applies at an app-level as allow or block and controls if it’s available to any user or not.
Every time when a new app is introduced in the organization and only limited users are bound to have access to it we end up creating a custom policy to meet the business need. From the administrator’s end this was adding up a lot of efforts and there was a question on the app policy hygiene.
Now, with App centric policy in place we can either let everyone access it, block for all or allow only for specific set of users. this granular access control on apps will ensure smooth management of Teams Apps in future.
“It is better to look ahead and prepare than to look back and regret”
Why did i mention this quote? This migration is just a click away but this can cost you more if you aren’t prepared for this,
Lets dig deeper into the logic behind, how these policies are transformed into app centric management.
Lets assume, you have three custom policies in the org,

1 Global (org-wide default) and 3 custom policies
Just an example, below is the list of allowed and blocked apps in the respective policies,
In the process of migration, it considers the apps which was allowed in all the app permission policies as “Allowed to Everyone“, Apps that are blocked in all the app permission policies are considered to be “Available to No One“, all other apps which has conflicts of allowed in one app and blocked in another will fall under “Available to specific users and groups” which required the admin to manually add the users or groups to the allow list (number of entries to a access list cant exceed 99 (users & groups together)

Your entire migration happens at this step where you sit with your team and work on a policy hygiene mission to clean up this multiple conflicting policies to reduce manual interventions of adding the users and group on this 2k+ apps in the organization.
Here is how it looks after the policy hygiene mission,

Again this depends on how your business wants you to make the app availability for its users, it varies from business to business. Also remember, the best way to manage the app centric management is to have a dedicated group for each app which are listed under these “Available to specific users and group”.
During the migration, at the next phase you get to see an option to verify which app is available for which user,
Moving to the next phase, always remember You can only migrate one time. Review app availability and make any changes before completing the migration process
Now you can verify the changes and “Start Migration”
Or you can still take a step back to either finish it later or reset all changes to do this sometime later.
With alignment to this change, there is an important change which MS has made which is “Integrated Apps” which will be covered in the upcoming post.
Thank you for your patience is scrolling this far! Happy learning 🙂
Storm the comment section for any questions.









