Find Verified, Attested, and Certified apps with the Microsoft 365 App Compliance Program
Published Sep 15 2022 09:00 AM 5,200 Views
Microsoft

The Microsoft 365 App Compliance Program offers assurance to organizations that their data and privacy are secured when deploying 3rd party applications. This includes apps built for Microsoft Teams, Outlook, Word, Excel, SharePoint, OneNote, and Project. 

The Microsoft 365 App Compliance Program is a two-step approach to app security and compliance:  

  • Publisher Verification provides identity verification of app publishers, so users are assured the apps they utilize are authentic.  
  • Microsoft 365 Certified apps have undergone self-attestation and a comprehensive 3rd party audit to ensure proper data handling, encryption, antivirus, and firewall security like those found in SOC-2, PCI-DSS, and ISO-27001. These apps are awarded the Microsoft 365 Certification Badge.  

Krishna_Mawani_0-1660672747448.png

Microsoft 365 Certification Badge 

 

Apps that have completed verification and certification can be found across multiple storefronts and admin centers through dedicated filters. Apps that have undergone self-attestation but have yet to complete full certification can also be found through filtering.  

Current locations include: 

  • Teams Admin Center 
  • Teams Store 
  • AppSource / Microsoft Admin Center 
  • Office Add-ins Store 
  • Azure Active Directory 
  • Microsoft App Compliance Doc Pages 

 

1. Microsoft Teams Admin Center 

Manage Apps provides the ability for users to filter based on certification status: 

     1. Click Manage apps >click on the column header labeled Certification to sort 

Krishna_Mawani_1-1660672747450.png

 

     2. Apps will be populated by Microsoft 365 Certified apps first followed by Publisher Attested. 

 

Krishna_Mawani_2-1660672747452.png

 

2. Microsoft Teams Store

When searching for apps to deploy in Teams, look for the Microsoft 365 Certified badge in the app summary page. 

Krishna_Mawani_3-1660672747454.png

 

3. AppSource 

AppSource gives users the ability to filter by Microsoft 365 Certified or attested apps: 

  1. Log in to AppSource and click See all apps
  2. Under Filters click Compliance > Publisher Attestation. 
  3. You will see a list of all the apps that have completed attestation. 
  4. Under Compliance click Microsoft Certified. 

Krishna_Mawani_4-1660672747456.png

You will now see the apps that have completed the Microsoft 365 Certification. 

 

The Microsoft 365 Certification badge has been added to the Overview page for each app that has completed certification. The certification status is also listed on the Details and Support tab. Clicking on the status links to the app’s dedicated Microsoft docs page where you can find a full compliance report. 

Krishna_Mawani_5-1660672747458.png

 

The same filters, badges, and basic functionality for finding compliant apps found in AppSource are also available in the Microsoft Admin Center. 

 

4. Microsoft Office Add-ins Store 

For Microsoft Excel, OneNote, Outlook, PowerPoint, Project, and Word users can search for certified apps within the Office Add-ins store. 

The Microsoft 365 Certification badge is reflected in all certified app listings, next to the reviews: 

Krishna_Mawani_1-1660674115972.png

 

The badge is also present within the summary page pop-out for each certified app: 

Krishna_Mawani_8-1660672747462.png

 

5. Azure Active Directory (Now Microsoft Entra)

IT Admins can now manage app consent experiences based on app certification status. For AAD apps, users can:   

     1. Set user consent policies based on Microsoft 365 Certification status through APIs in Microsoft Graph Beta. 

Krishna_Mawani_9-1660672747465.png

 

     2. See the status of app certification in the app consent UX where consent decisions are made by the users.         

Krishna_Mawani_10-1660672747468.png

User consent prompt App information 

 

6. Microsoft 365 App Compliance Docs Pages  

All apps that have completed either publisher attestation or Microsoft 365 Certification receive dedicated docs pages with a detailed overview of their current security posture. This reporting can help in cutting down security screening with transparency into the apps data handling aligning to industry standard practices. These reports cover the following areas: 

  • General publisher and app information 
  • Data handling 
  • Security 
  • Compliance 
  • Privacy 
  • Identity 
  • Certification controls 

Krishna_Mawani_11-1660672747471.jpeg

 

For more information about the Microsoft 365 App Compliance Program, check out the following resources: 

App Compliance Program | Microsoft 365 Dev Center 

Microsoft 365 App Compliance Program - Microsoft 365 App Certification | Microsoft Docs 

Microsoft 365 App Compliance Program – Microsoft 365 Certification ensures apps are secure! - YouTub... 

 

Contact > appcert@microsoft.com 

 

1 Comment
Co-Authors
Version history
Last update:
‎Aug 17 2022 09:41 AM
Updated by: