Plugins and Integration Governance¶
Atlanta, USA
Last updated: 2026-08-04
References
Objective¶
Control plugin enablement, customization, and publishing to reduce risk while still enabling analyst productivity.
Governance controls¶
| Control area | Guidance |
|---|---|
| User-scope plugin creation | Define whether contributors can add custom plugins |
| Tenant-scope plugin publishing | Restrict organization-wide publishing to approved roles |
| Preinstalled plugin visibility | Set availability to all users or owners only |
| Data access pathways | Govern plugin access to licensed Microsoft 365 service data |
Plugin lifecycle model¶
- Evaluate plugin risk and business need.
- Pilot at individual user scope.
- Approve tenant-wide publication if validated.
- Monitor usage and disable when no longer required.
Governance checklist¶
- Plugin publishing policy documented.
- Security review exists for custom plugin files.
- Embedded experience dependencies are understood.
- Periodic plugin review cadence established.