Home > Appendices > App Profiles in Classic Mode Required by Rules

Export to PDF

App Profiles in Classic Mode Required by Rules

When referring to app profiles in classic mode required by Policies for Microsoft 365, there are two distinct app types: Microsoft Entra ID and Microsoft 365 (All permissions). The following sections list the app profiles in classic mode required by rules for service-level policies and tenant-level policies.

Rules for Service Level Policies

The table below lists the app profiles in classic mode required by rules for service-level policies.

Rule NameRule DescriptionMicrosoft Entra ID RequiredMicrosoft 365 (All permissions) Required
Access Request SettingsControl access request settings within a site to manage who can request and approve access to a site.NoYes
Automatic Forwarding RestrictionRestrict users from auto-forwarding emails.NoYes
Classification Change RestrictionPrevent changes to the classification of Groups or Teams.YesNo
Classification EnforcementEnforce that all Groups or Teams have a classification assigned to them and assign a default classification if there is none.YesNo
Content Creation and Upload RestrictionControl content creation and upload including items, attachments, and documents based on user, size, file extension, content type, and sensitivity label.NoYes
Content Sensitivity Label EnforcementEnforce sensitivity labels for documents based on their risk level, sensitivity level, and exposure level.NoYes
Control Access from Unmanaged DevicesBlock or limit access to SharePoint and OneDrive content from unmanaged devices.NoYes
Control Group Visibility in Global Address ListControl the visibility of mail-enabled security groups and distribution lists in the global address list.YesNo
Deleted Item Retention Period EnforcementSet the retention period that permanently deleted mailbox items are kept in the Recoverable Items folder.NoYes
Deletion RestrictionControl users and groups that have the ability to delete objects in sites.NoYes
External Sharing SettingsControl the external sharing settings for Groups or Teams.YesNo
Guest User Access EnforcementControl users who have the ability to add guest users to Groups or Teams.YesNo
Groups/Teams Creation RestrictionControl users who have the ability to create Groups or Teams.YesNo
Guest User Full Control Permission RestrictionReport guest users who have the site-level Full Control permission and remove this permission from them.NoYes
Library Default Sensitivity Label EnforcementEnforce a default sensitivity label for document libraries so that the sensitivity label will be applied to all newly created or edited Office files.NoYes
Library Versioning Settings EnforcementEnforce the versioning settings for all libraries in sites.NoYes
List/Library Creation RestrictionControl users who have the ability to create lists and libraries.NoYes
List/Library Object Number RestrictionControl the number of items, documents, and folders in a list/library.NoYes
Membership RestrictionControl users who can be added to Microsoft 365 Groups, Teams, security groups, or distribution lists as members.YesNo
Member Number RestrictionControl the number of members in Microsoft 365 Groups, Teams, security groups, or distribution lists.YesNo
Microsoft 365 Group Visibility in Outlook ClientControl if a Microsoft 365 Group is visible in the Outlook client.YesNo
Owner Number RestrictionControl the number of owners in Microsoft 365 Groups, Teams, security groups, and distribution lists.YesNo
Ownership EnforcementEnforce specific users to be in the owner group of a site.YesNo
Ownership RestrictionControl users who can be added to Groups or Teams as owners.YesNo
Permission Inheritance ProtectionProtect permission inheritance from being broken at specific object levels.NoYes
Permission Level Enforcement for Built-in SharePoint GroupsEnforce permission levels for built-in SharePoint groups, including site owners, site members, and site visitors.NoYes
Pre-defined Group Members (Cloud Governance)Enforce that users you have defined via site collection properties (example: Cloud Governance site contacts) can be added to specified SharePoint Online groups.NoYes
Privacy RestrictionControl the privacy settings of Groups or Teams.YesNo
Private Channel Ownership EnforcementEnforce specific users to be owners of Teams private channels.YesNo
Private Channel Owner Number RestrictionControl the number of owners in Teams private channels.YesNo
Remove Licenses from Inactive UsersRemove licenses from users who do not have activities in Microsoft 365 services for a certain period.YesNo
Remove Licenses from Blocked UsersRemove licenses from users who have been blocked from signing in.YesNo
Remove Shadow UsersRemove users who have access to the SharePoint Online site but are not part of the Group/Team membership.YesNo
Restrict Member InvitationsControl users who have the ability to add users to Groups or Team.YesNo
Restrict Member RemovalControl users who have the ability to remove members from Microsoft 365 Groups or Teams.YesNo
Restrict Sharing LinksRestrict sharing links that are created by or shared with specific users and groups.NoYes
Restrict Sharing Links with Edit PermissionRestrict sharing links with Edit permission that are created by or shared with specific users and groups.NoYes
Scan External UsersScan external users in sites where external sharing is disabled.NoYes
Scan Orphaned UsersScan users or groups that have been deleted or blocked in your Microsoft Entra ID.NoYes
Search and Offline Availability EnforcementControl whether site content can be searched or downloaded to offline clientsNoYes
Shared Channel Ownership EnforcementEnforce specific users to be owners of Teams shared channels.YesNo
SharePoint Permission EnforcementControl permission levels for the specified users and groups on SharePoint sites.NoYes
Shared Channel Creation RestrictionControl users who have the ability to create shared channels inside Teams.YesNo
SharePoint Group Membership EnforcementEnforce specific users to be in the owners, members, or visitors group of a site.NoYes
Sharing Link Expiration EnforcementEnforce the duration of how long sharing links remain active after being created in sites.NoYes
Site Collection Administrator EnforcementEnforce specific users and groups to be in the Site Collection Administrators group of a site.NoYes
Site Collection Administrator Number RestrictionControl the number of site collection administrators in a site.NoYes
Site Collection Administrator RestrictionControl users who can be added to the Site Collection Administrators group of a site.NoYes
Site Content Sharing SettingsControl the external sharing settings for sites.NoYes
Site Owner Number RestrictionControl the number of site owners in a site.NoYes
Site Owner RestrictionControl users who can be added to the owner group of a site.NoYes
Site Sensitivity Label EnforcementEnforce a defined sensitivity label on sites and remove any existing ones.NoYes
Site Storage EnforcementEnforce storage limit for sites.NoYes
Groups/Teams Name EnforcementPrevent owners of Groups or Teams from changing their Group or Team name.YesNo
Teams Settings EnforcementEnforce certain Teams settings.YesNo
User Permission ReplacementReport or remove permissions from a specific user and assign the permissions to other designated users.NoYes
User/Group RestrictionControl users and groups that can be added to sites.NoYes
Legacy Email Protocols RestrictionRestrict the use of legacy email protocols, including POP, SMTP, and IMAP protocols, to prevent password spray attacks that may breach mailboxes in your tenants.NoYes
Message Size RestrictionRestrict the maximum size for messages sent and received by mailboxes.NoYes
NOTE

For app profiles in classic mode, a Microsoft 365 (All permissions) app profile will be required if you want to filter SharePoint Online and OneDrive sites in rules.

Rules for Tenant Level Policies

The table below lists the app profiles in classic mode required by rules for tenant-level policies.

Rule NameRule DescriptionMicrosoft Entra ID RequiredMicrosoft 365 (All permissions) Required
Automatic Forwarding RestrictionRestrict users from auto-forwarding emails.NoYes
Bypass Spam Filtering Rule RestrictionRestrict users from creating the mail flow rule to skip spam filtering when receiving emails from specific domains.NoYes
Control Access from Unmanaged DevicesBlock or limit access to SharePoint and OneDrive content from unmanaged devices.NoYes
Control Anonymous Calendar SharingControl whether users are allowed to share their calendars with anonymous users outside the organization.NoYes
Control Exchange Online PowerShell Access for Non-administratorsControl Exchange Online PowerShell access for non-administrators.YesYes
Control Focused InboxControl whether to enable the focused inbox view for users.NoYes
Control Mailbox Auditing for All UsersControl whether to enable mailbox auditing for all users.NoYes
Control Plus AddressingControl whether users can use plus addressing to quickly create custom email addresses based on their standard email addresses.NoYes
Control Sending Emails from AliasesControl whether users are allowed to send emails from aliases.NoYes
Deleted Item Retention Period EnforcementSet the retention period that permanently deleted mailbox items are kept in the Recoverable Items folder.NoYes
DKIM Signature EnforcementSign emails with DKIM (Domain Keys Identified Mail) signatures for your domains to help recipients ensure the identities of senders.NoYes
Ghost Guest User DetectionDetect guests who do not have any membership in SharePoint Online sites, Groups, and Teams.(Groups include Microsoft 365 Groups, distribution groups, dynamic distribution groups, security groups, mail-enabled security groups, and shared mailboxes.)NoYes
Groups Guest Access RestrictionControl whether people outside your organization can be invited as guests and access group content.YesNo
Groups/Teams Creation RestrictionControl users who have the ability to create Groups or Teams.YesNo
Groups/Teams Deletion RestrictionControl users who have the ability to delete Groups or Teams.YesNo
International Spam PreventionPrevent email messages that are written in specific languages or sent from specific countries or regions.NoYes
Legacy Email Protocols RestrictionRestrict the use of legacy email protocols, including POP, SMTP, and IMAP protocols, to prevent password spray attacks that may breach mailboxes in your tenants.NoYes
Malware PreventionProtect your organization from malware by quarantining email messages where malware is detected.NoYes
Message Size RestrictionRestrict the maximum size for messages sent and received by mailboxes.NoYes
Outbound Spam PreventionProtect your organization from outbound spam.NoYes
Outlook External Email Tag EnforcementChoose whether to add tags to external emails in Outlook to help users identify emails from external senders.NoYes
Remove Inactive Guest UsersRemove guest users who do not have any activities in SharePoint Online sites, Groups, and Teams for certain days.NoYes
Rich-Text Format RestrictionRestrict the rich-text format in emails to prevent malformed emails sending to other users.NoYes
Shared Mailbox Sign-In RestrictionControl whether to allow users to sign in to the shared mailboxes by their associated user accounts.YesYes
Tenant-level Site Content External Sharing SettingsControl the tenant-level external sharing settings for SharePoint and OneDrive.YesYes
Teams Tagging SettingsControl how tags are used across your organization.YesNo
User RestrictionEnforce that specific users can only be assigned membership of the specified Groups/Teams.YesNo