Forum Discussion

mhuntOAI's avatar
mhuntOAI
Copper Contributor
May 27, 2019

No capability to admin Microsoft Office Store Addins

My company is required by federal contracts to restrict end-users capabilities to install applications, share data, and such under NIST 800-171 without specific allowance by IT. We recently learned that end-users are still capable of accessing the Microsoft Office Store, and signing up for the various cloud-based applications found there.

 

We have tried to file a help-desk ticket inside the Office 365 Admin Portal, but they keep sending us over to the Azure Support; we worked all the way through that and discovered that they are unable to help. We have searched through the Office 365 Admin Portal, and there seems to be no way to control users, or even audit users, on a "Office Store" level.

 

We would like to be able to have the capability to allow specific users to use specific Office Store Applications once these are vetted and approved by the ISSEC team. For now, I have used a GPO to block the capability for the icon to bring up the Office Store; but we may already have users signed up for "Boomerang for Outlook" but we have no way of knowing what users are using what.

 

There is an article posted here titled "Blocking Office Store may be harder than you think" but both the links are 404 now; plus this isn't office Microsoft documentation so we are wary of using it.  We need actual documentation from Microsoft (the vendor) on this.

 

Due to the "separation of duties" requirement, our ISSEC team are not Admins in the Office 365 portal, so any troubleshooting on this has to be passed to the Network team.  The ISSEC team needs to be able to audit Office Store usage, but not actually change anything.  This may be outside of the scope of this question; but hopefully anyone able to answer the first question will know how to answer this too.

3 Replies