Apps overview for admins (preview)

[This article is prerelease documentation and is subject to change.]

Important

  • This is a preview feature.
  • These features are subject to supplemental terms of use, and are available before an official release so that customers can get early access and provide feedback.

Apps in Cowork help teams create internal line-of-business solutions while following your organization's IT governance policies. Each app appears in the Microsoft 365 admin center, where admins can track usage, monitor health, and manage its lifecycle.

Important

To use this feature, your tenant must be enrolled in the Frontier preview program.

The app creation experience brings three audiences together:

  • Users discover and run apps from a web portal.
  • App creators build apps in Cowork.
  • Administrators govern apps across the tenant.

Key features

  • Microsoft Entra authentication and authorization out of the box
  • Access to more than 1,500 connectors
  • Automatic adherence to your IT policies, including sharing limits, conditional access, advanced connector policies, and data loss prevention (DLP)
  • Centralized inventory, usage analytics, and operational health in the Microsoft 365 admin center

Common scenarios

Apps created in Cowork fit scenarios where teams need flexibility while staying within enterprise governance boundaries:

  • Personal productivity apps. Tools an individual builds and uses to streamline their work.
  • Team productivity apps. Shared apps that small teams use to automate workflows and collaborate.
  • Organizational apps. Broader solutions that teams deploy across the tenant with admin-controlled distribution.

Key concepts

To manage app creation effectively, understand the following key concepts:

Term Description
Cowork An app creation experience available to eligible users through the Microsoft Copilot Frontier Program.
Governance policies Rules that control how apps are deployed, who can access them, what data they connect to, and how their lifecycle is managed. The app creation process enforces these policies automatically.
App inventory A centralized, real-time view in the Microsoft 365 admin center of apps across the tenant, including usage, health, and compliance state.
Distribution controls Admin-managed settings that determine who can discover and use each app across the tenant.

Enable app creation for your tenant

Onboard your tenant and users to the Microsoft Copilot Frontier Program to enable app creation in Cowork. After your tenant is onboarded, app creators who have access to Cowork can build apps.

Permissions

Role What they can do
Global Administrator Onboard the tenant to the Microsoft Copilot Frontier Program.
Power Platform Administrator, Global Reader, AI Administrator, AI Reader View only. Guided to contact an administrator to enable features.

Enabling the Cowork app builder skill requires onboarding the tenant to the Microsoft Copilot Frontier Program. Power Platform administrators can't enable Frontier; they're guided to contact an administrator with the required permissions. See Get started with the Microsoft Copilot Frontier Program.

Govern apps

Apps are governed from the moment they're created, with no extra setup required. The governance model is built around three principles: apps are safe by default, admins can govern at scale, and the platform balances controls with productivity.

Safe by default

Every app has governance built in from the moment it's created. Admins don't need to add governance as a configuration step afterward:

  • Built-in authentication. Every app uses Microsoft Entra ID—no extra identity configuration needed.
  • Automatic policy enforcement. Conditional access, data loss prevention (DLP), advanced connector policies, sharing limits, and data source restrictions apply to every app by default.
  • Environment isolation. Apps use Microsoft-managed environments that inherit these policies automatically.

Govern at scale

As the number of apps in a tenant grows, a centralized governance layer keeps them manageable:

  • Centralized inventory. Every app appears in the Microsoft 365 admin center, so admins know what exists and who owns it—no manual registration.
  • Usage analytics and health. Built-in adoption metrics and health alerting help admins track use and resolve issues before they affect users.
  • Lifecycle management. Admins manage the full app lifecycle from the Microsoft 365 admin center.

Balance controls and productivity

The governance model is designed so that security and compliance controls don't impose unnecessary friction on app creators or end users:

  • Governance is built in. Built-in platform capabilities apply governance without extra configuration.
  • Admins get granular control. Set controls around distribution, data access, and lifecycle instead of blocking custom apps entirely.
  • Users find apps easily. Apps surface in familiar Microsoft 365 experiences, reducing shadow IT.

Licensing

For details about managing Cowork and understanding licensing, usage-based billing, and cost management, see the following resources:

Note

During preview, users who don't meet the credit requirements to run an app receive a warning at first. Access is blocked after the user completes 20 app operations or uses the app for five minutes, whichever occurs first.

Environment routing for apps