Skip to content

Plugins and Integration Governance

Atlanta, USA

GitHub Cloud2BR OSS - Learning Hub

Last updated: 2026-08-04


References

Objective

Control plugin enablement, customization, and publishing to reduce risk while still enabling analyst productivity.

Governance controls

Control area Guidance
User-scope plugin creation Define whether contributors can add custom plugins
Tenant-scope plugin publishing Restrict organization-wide publishing to approved roles
Preinstalled plugin visibility Set availability to all users or owners only
Data access pathways Govern plugin access to licensed Microsoft 365 service data

Plugin lifecycle model

  1. Evaluate plugin risk and business need.
  2. Pilot at individual user scope.
  3. Approve tenant-wide publication if validated.
  4. Monitor usage and disable when no longer required.

Governance checklist

  • Plugin publishing policy documented.
  • Security review exists for custom plugin files.
  • Embedded experience dependencies are understood.
  • Periodic plugin review cadence established.