{"id":11711,"date":"2022-10-12T07:51:03","date_gmt":"2022-10-12T14:51:03","guid":{"rendered":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/?p=11711"},"modified":"2022-10-12T07:01:28","modified_gmt":"2022-10-12T14:01:28","slug":"app-compliance-automation-tool-for-microsoft-365-launching-in-public-preview","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/app-compliance-automation-tool-for-microsoft-365-launching-in-public-preview\/","title":{"rendered":"App Compliance Automation Tool for Microsoft 365 launching in public preview"},"content":{"rendered":"<p>Enterprise governance, risk and compliance teams, and IT Admins want to ensure that applications deployed in their organization\u2019s Microsoft 365 tenant are secure and compliant. And that they meet the leading industry compliance standards (e.g., SOC2, ISO, GDPR etc.). To provide visibility into an application\u2019s security and compliance posture and to increase our customers\u2019 trust in these applications, Microsoft launched the Microsoft 365 App Compliance program. As a part of this program, developers provide information about the security, data handling and compliance attributes of their application which are most important to enterprise customers. This information is then audited against a set of controls derived from leading industry standard frameworks to award the Microsoft 365 certification. This certification gives customers assurance that apps that have received the certification have strong security and compliance practices in place to protect their data, security, and privacy.<\/p>\n<p>Achieving the Microsoft 365 certification involves collecting the required evidence for application, operational and data security controls. This takes a significant amount of time for you, the app developer. To simplify this process, Microsoft is now launching the App Compliance Automation Tool (ACAT) for Microsoft 365 in public preview. ACAT automates ~37% of the Microsoft 365 certification controls, decreasing the time to achieve the Microsoft 365 certification.<\/p>\n<h2>What is App Compliance Automation Tool for Microsoft 365?<\/h2>\n<p>ACAT is an application-centric compliance automation tool that is deployed as a service in the Azure portal, allowing you to define the compliance boundary for your applications. ACAT enables you to get automated compliance reports and alerts to continuously monitor your application and remediate any compliance failures. And you can download and share these detailed compliance reports with your customers. IT Admins can also leverage these reports to ensure that the application has met the right level of compliance controls before deploying apps into an organization\u2019s Microsoft 365 tenant.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><iframe title=\"YouTube video player\" src=\"https:\/\/www.youtube.com\/embed\/IXFLT87eFWA\" width=\"560\" height=\"315\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/p>\n<p>&nbsp;<\/p>\n<h2 style=\"text-align: left;\">Getting started with App Compliance Automation Tool<\/h2>\n<p style=\"text-align: left;\">ACAT will be available in public preview on November 16, 2022. It will be enabled as service in the Azure portal.<\/p>\n<p>Follow these steps to get started:<\/p>\n<ul>\n<li>Navigate to <strong><em>All Services<\/em><\/strong> in the Azure portal<\/li>\n<li>Search for the <strong><em>App Compliance Automation Tool for Microsoft 365<\/em><\/strong><\/li>\n<li>Launch the ACAT tool.<\/li>\n<\/ul>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/1-Search-result-min-scaled.jpg\"><img decoding=\"async\" class=\"aligncenter wp-image-11721 size-large\" src=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/1-Search-result-min-1024x576.jpg\" alt=\"Example screen of getting started with the App Compliance Automation Tool in Microsoft 365\" width=\"640\" height=\"360\" srcset=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/1-Search-result-min-1024x576.jpg 1024w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/1-Search-result-min-300x169.jpg 300w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/1-Search-result-min-768x432.jpg 768w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/1-Search-result-min-1536x864.jpg 1536w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/1-Search-result-min-2048x1151.jpg 2048w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h2>Creating a new compliance report<\/h2>\n<p>To create a new compliance report, select <strong><em>Reports<\/em><\/strong> from the left navigation menu and click on <strong><em>Create new report<\/em><\/strong><em>. <\/em>You can add details such as the report name, report daily trigger time, Azure subscription and resource details to specify your application\u2019s compliance boundary.<\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/2-create-report-min-scaled.jpg\"><img decoding=\"async\" class=\"aligncenter wp-image-11722 size-large\" src=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/2-create-report-min-1024x576.jpg\" alt=\"Example of creating a new report using the App Compliance Automation Tool\" width=\"640\" height=\"360\" srcset=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/2-create-report-min-1024x576.jpg 1024w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/2-create-report-min-300x169.jpg 300w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/2-create-report-min-768x432.jpg 768w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/2-create-report-min-1536x864.jpg 1536w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/2-create-report-min-2048x1151.jpg 2048w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h2>Viewing compliance results<\/h2>\n<p>To view the compliance results, select <em>Reports <\/em>from the left navigation menu. Click on any compliance report to see its details. To view the controls that failed, you can filter for<strong> Customer responsibility = Failed<\/strong>. To fix these controls, click on the specific customer responsibility to open a flyout where you can identify appropriate unhealthy resources and review associated remediation steps.<\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/3-view-results-min-scaled.jpg\"><img decoding=\"async\" class=\"aligncenter wp-image-11723 size-large\" src=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/3-view-results-min-1024x576.jpg\" alt=\"Example of viewing compliance results\" width=\"640\" height=\"360\" srcset=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/3-view-results-min-1024x576.jpg 1024w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/3-view-results-min-300x169.jpg 300w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/3-view-results-min-768x432.jpg 768w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/3-view-results-min-1536x864.jpg 1536w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/3-view-results-min-2048x1151.jpg 2048w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h2>Sharing compliance results with customers<\/h2>\n<p>Once you have fixed all the compliance controls and you are ready to share your compliance report with your customer, click on <strong><em>Download report. <\/em><\/strong>Select Microsoft 365 certification compliance assessment summary to get a PDF file of your compliance results.<\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/4-share-result-min-scaled.jpg\"><img decoding=\"async\" class=\"aligncenter wp-image-11724 size-large\" src=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/4-share-result-min-1024x576.jpg\" alt=\"Example of sharing compliance results with customers using the App Compliance Automation Tool\" width=\"640\" height=\"360\" srcset=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/4-share-result-min-1024x576.jpg 1024w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/4-share-result-min-300x169.jpg 300w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/4-share-result-min-768x432.jpg 768w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/4-share-result-min-1536x864.jpg 1536w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/4-share-result-min-2048x1151.jpg 2048w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/5-share-result-PDF-min-scaled.jpg\"><img decoding=\"async\" class=\"aligncenter wp-image-11725 size-large\" src=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/5-share-result-PDF-min-1024x577.jpg\" alt=\"Image of Microsoft 365 certification compliance assessment summary\" width=\"640\" height=\"361\" srcset=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/5-share-result-PDF-min-1024x577.jpg 1024w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/5-share-result-PDF-min-300x169.jpg 300w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/5-share-result-PDF-min-768x433.jpg 768w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/5-share-result-PDF-min-1536x866.jpg 1536w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/5-share-result-PDF-min-2048x1155.jpg 2048w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h2>Dashboard view of compliance reports<\/h2>\n<p>You can select <strong><em>Overview <\/em><\/strong>from the left navigation menu to see a dashboard view of all compliance reports and their app\u2019s compliance to Microsoft 365 certification controls.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/6-Dashboard-min-scaled.jpg\"><img decoding=\"async\" class=\"aligncenter wp-image-11726 size-large\" src=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/6-Dashboard-min-1024x576.jpg\" alt=\"Example of dashboard view using the App Compliance Automation Tool for Microsoft 365\" width=\"640\" height=\"360\" srcset=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/6-Dashboard-min-1024x576.jpg 1024w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/6-Dashboard-min-300x169.jpg 300w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/6-Dashboard-min-768x432.jpg 768w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/6-Dashboard-min-1536x864.jpg 1536w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/6-Dashboard-min-2048x1151.jpg 2048w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h2>Achieving Microsoft 365 certification<\/h2>\n<p>ISV developers can use the ACAT report to automate the evidence collection process for achieving the Microsoft 365 certification, making it much faster and easier. Navigate to <em>Microsoft 365 app compliance and certification workflow <\/em>in Partner Center and provide a reference to the specific ACAT report. The Microsoft 365 certification team will review the ACAT report submission to award the Microsoft 365 certification badge.<\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/7-Microsoft-Partner-center-min-scaled.jpg\"><img decoding=\"async\" class=\"aligncenter wp-image-11727 size-large\" src=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/7-Microsoft-Partner-center-min-1024x576.jpg\" alt=\"Example of the automate the evidence collection process to achieve the Microsoft 365 certification\" width=\"640\" height=\"360\" srcset=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/7-Microsoft-Partner-center-min-1024x576.jpg 1024w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/7-Microsoft-Partner-center-min-300x169.jpg 300w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/7-Microsoft-Partner-center-min-768x432.jpg 768w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/7-Microsoft-Partner-center-min-1536x864.jpg 1536w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2022\/10\/7-Microsoft-Partner-center-min-2048x1151.jpg 2048w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h2>Next steps<\/h2>\n<p>ACAT will be available in public preview on November 16, 2022. If you would like to receive a follow-up closer to the public preview launch, please provide your information <a href=\"https:\/\/forms.office.com\/r\/rXuPQcdmb5\">here.<\/a><\/p>\n<p>We encourage you to try it out and share feedback with us in this form &#8211; <a href=\"https:\/\/aka.ms\/acat\/feedback\">https:\/\/aka.ms\/acat\/feedback<\/a>. We appreciate all feedback we receive. It helps us deliver experiences that truly matter to you.<\/p>\n<p>Visit the documentation at <a href=\"http:\/\/aka.ms\/acat\">http:\/\/aka.ms\/acat<\/a> to learn more about how ACAT can help you in your compliance journey and increase your app trust by customers.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We are excited to announce public preview of the App Compliance Automation Tool for Microsoft 365 to simplify the certification process is coming in November.<\/p>\n","protected":false},"author":103173,"featured_media":11917,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[128,11],"tags":[193,192,29],"class_list":["post-11711","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-teams","category-office-add-ins","tag-acat","tag-app-compliance-automation-tool","tag-microsoft-365-app-compliance-program"],"acf":[],"blog_post_summary":"<p>We are excited to announce public preview of the App Compliance Automation Tool for Microsoft 365 to simplify the certification process is coming in November.<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/posts\/11711","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/users\/103173"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/comments?post=11711"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/posts\/11711\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/media\/11917"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/media?parent=11711"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/categories?post=11711"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/tags?post=11711"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}