Building, integrating, or customizing apps and workflows within Microsoft Teams using developer tools and APIs
The setting Let users install and use available apps by default affects all custom Teams apps and custom agents that are available in the tenant, not just Copilot Agents. Microsoft Copilot Studio agents published to Teams are governed through the same Teams app management framework as other custom Teams apps.
Regarding your questions:
1.What are the security implications of enabling this setting?
Enabling "Let users install and use available apps by default" allows users to install and use custom apps and agents that have been made available in the organization's app catalog. It does not by itself allow users to upload arbitrary custom app packages or bypass other app governance controls.
The broader impact depends on the custom apps that are currently available in the tenant. Users can install and use any custom app or custom agent that has been made available through the organization's Teams app catalog and applicable governance settings. For this reason, it is worth reviewing the current custom app catalog and app governance processes before enabling the setting.
2.Does this apply only to Copilot Agents?
This setting applies to custom Teams apps and custom agents that are available in the tenant, including:
- Copilot Agents published to Teams
- Microsoft Copilot Studio agents
- Line-of-business (LOB) Teams apps
- Custom bots
- Message extensions
- Tabs
- Other internally developed Teams applications
Therefore, the setting is not limited to a specific Copilot Agent.
3.Are there any governance or compliance considerations?
Before enabling the setting, you may want to review:
- Which custom apps and agents are currently available in Teams Admin Center > Teams apps > Manage apps
- The organization's approval and publishing process for custom apps
- Whether app access should be limited to specific users or groups
- Security, privacy, and compliance requirements for internally published applications
- Auditing and monitoring practices for Teams app usage
Microsoft provides per-app controls and app governance capabilities that can be used alongside org-wide settings. Please refer to Manage your apps in the Microsoft Teams admin center - Microsoft Teams | Microsoft Learn
4.Is there an alternative to enabling this tenant-wide setting?
App-Centric Management allows app and agent availability to be controlled on a per-app basis. Instead of enabling "Let users install and use available apps by default" for all custom apps across the tenant, you can make only the required Copilot Agent available to specific users or groups.
This can be configured in the Teams Admin Center: Teams apps > Manage apps > [Agent] > Users and groups
With App-Centric Management, an app or agent can be assigned to:
- Everyone
- Specific users or groups
- No one
This provides more granular control over app availability, eliminating the need to enable all custom apps tenant-wide when only a specific Copilot Agent should be accessible to selected users.
You can read more at App centric management to manage user access to Teams apps - Microsoft Teams | Microsoft Learn
I hope this information is helpful.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.