Instiq
Chapter 3 · Manage teams, channels, chats, and apps·v1.0.0·Updated 6/29/2026·~13 min

What's changed: Created MS-700 Chapter 3 (domain: Manage teams, channels, chats, and apps). Create/manage teams (Advisor for Teams; create via admin center/client/PowerShell/Graph/from existing groups or templates; template policies; owner/member; privacy/sensitivity; frontline teams), channels and chats (standard/private/shared channels, channel settings, messaging policies), and apps (org-wide app settings, app setup policies, app permission policies, consent/block, extensibility tabs/messaging extensions/workflows, Teams app store, upload).

3.3Manage apps

Key points

Understand org-wide app settings, app setup policies, app permission policies, permissions/consent and blocking, extensibility (tabs/messaging extensions/workflows), and the Teams app store.

App management separately controls which apps are allowed and which apps are shown/pre-installed.

3.3.1Allow and setup

The org-wide app settings set the broad allow/disallow of third-party/custom apps tenant-wide. App permission policies control which apps users can use (allow/block by Microsoft/third-party/custom). App setup policies control presentation—pinning apps to the user’s bar and pre-installing them. Distinguish "allowed or not" = permission policy from "where shown/pinned" = setup policy.

3.3.2Extensibility and the app store

Manage permissions/consent and block risky apps. Extensibility includes tabs, messaging extensions, in-meeting apps, and workflows—recommend per scenario. The Teams app store supports purchasing and customizing the store’s appearance; distribute in-house apps by uploading them.

Exam point

Cues: "which apps users can use (allow/block)" = app permission policy. "pin/pre-install apps in the bar" = app setup policy. "tenant-wide third-party/custom allow" = org-wide app settings. "distribute an in-house app" = upload. Extensibility = tabs/messaging extensions/in-meeting apps/workflows.

Warning

Watch the mix-ups: (1) App permission policy (allowed or not) vs app setup policy (pin/pre-install). (2) Org-wide app settings are the tenant-wide broad control; policies are granular. (3) Blocking bans a specific app. (4) Extensibility (tabs/extensions) is a kind of app, separate from policies.

Diagram: an app permission policy controls which apps users can use (allow/block); an app setup policy pins/pre-installs apps; org-wide app settings set tenant-wide third-party/custom allow; block risky apps; extensibility = tabs/messaging extensions/in-meeting apps/workflows; distribute in-house apps via upload in the Teams app store.
Allow and present

3.3.3Section summary

  • App permission policy = allowed or not; app setup policy = pin/pre-install
  • Org-wide app settings set tenant-wide allow; block risky apps
  • Extensibility = tabs/messaging extensions/in-meeting apps/workflows; upload in-house apps

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. You want to limit which apps a department’s users can use to Microsoft and approved third-party only. Best?

Q2. You want a specific business app pinned in all users’ Teams app bar from the start. Best?

Q3. You want to set the broad tenant-wide allow/disallow of third-party and custom apps. Best?

Q4. You want to bring an in-house custom app into Teams and distribute it. Best?

Q5. What correctly distinguishes an app permission policy from an app setup policy?

Check your understandingPractice questions for Chapter 3: Manage teams, channels, chats, and apps