{"id":6525,"date":"2021-07-08T09:36:45","date_gmt":"2021-07-08T16:36:45","guid":{"rendered":"https:\/\/officedevblogs.wpengine.com\/?p=6525"},"modified":"2022-05-25T18:23:04","modified_gmt":"2022-05-26T01:23:04","slug":"raise-the-bar-for-your-app-security-get-microsoft-365-certification-by-passing-these-security-controls","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/raise-the-bar-for-your-app-security-get-microsoft-365-certification-by-passing-these-security-controls\/","title":{"rendered":"Get Microsoft 365 Certification by demonstrating app security controls"},"content":{"rendered":"<p>As an app developer, you can work with analysts in the <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365-app-certification\/overview\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft 365 App Compliance<\/a> team to demonstrate that your application and its supporting infrastructure are qualified to protect the security and privacy of your customers\u2019 sensitive data.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-6526 size-full\" src=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2021\/07\/app_certification_security.png\" alt=\"Image of a lock on a circuit board\" width=\"525\" height=\"324\" srcset=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2021\/07\/app_certification_security.png 525w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2021\/07\/app_certification_security-300x185.png 300w\" sizes=\"(max-width: 525px) 100vw, 525px\" \/><\/p>\n<h2><\/h2>\n<p>When an app undergoes Microsoft 365 Certification, a third-party assessor validates and assesses the app and its supporting infrastructure. To certify, your app must pass the controls in each of the following security domains:<\/p>\n<ul>\n<li>Application security<\/li>\n<li>Operational security<\/li>\n<li>Data handling security and privacy<\/li>\n<li>Optional external compliance audit review<\/li>\n<\/ul>\n<h2>Raise the bar for your app\u00a0security<\/h2>\n<p>The application security domain focuses on the\u00a0following\u00a0three areas:<\/p>\n<ul>\n<li><strong>Microsoft Graph API permission validation <\/strong>&#8211; Carry out permission validation to validate that the app\/add-in does not request overly permissive permissions. For example, request permissions that are required for the functionality of the app.<\/li>\n<li><strong>External connectivity checks <\/strong>&#8211; Identify connections in your app outside of Microsoft 365 by performing a walkthrough with an analyst. Flag and discuss any connections you do not identify as Microsoft or any direct connections to an external service.<\/li>\n<li><strong>Application security testing <\/strong>&#8211; If your app has any connectivity to any service not published by Microsoft, you must carry out application security testing in the form of penetration testing. If your app operates standalone without connectivity to any non-Microsoft service or backend, this isn&#8217;t required.<\/li>\n<\/ul>\n<p>For details, see <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365-app-certification\/docs\/certification-submission-guide#application-security\" target=\"_blank\" rel=\"noopener noreferrer\">Application security<\/a>.<\/p>\n<h2>Operations security<\/h2>\n<p>This domain measures the alignment of an app&#8217;s supporting infrastructure and deployment processes with security best practices. Assess various controls in this layer, including malware protection, patch management, vulnerability scanning and firewalls, account management and incident management, and change control.<\/p>\n<p>For details, see <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365-app-certification\/docs\/certification-submission-guide#operational-security\" target=\"_blank\" rel=\"noopener noreferrer\">Operational security<\/a>.<\/p>\n<h2>Data handling security and privacy<\/h2>\n<p>Protect data in transit between the application user, intermediary services, and app developer\u2019s systems by encryption through a TLS connection (required). If an application retrieves and stores customer data, you are also required to implement a data storage encryption scheme that follows the <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365-app-certification\/docs\/certification-submission-guide#appendix-b\" target=\"_blank\" rel=\"noopener noreferrer\">encryption profile configuration requirements<\/a>.\u00a0This\u00a0domain\u00a0also\u00a0tests\u00a0controls like data at rest,\u00a0data retention and disposal, data access management, and\u00a0GDPR.<\/p>\n<p>For details, see <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365-app-certification\/docs\/certification-submission-guide#data-handling-security-and-privacy\" target=\"_blank\" rel=\"noopener noreferrer\">Data handling security and privacy<\/a>.<\/p>\n<h2>Optional external compliance audit review<\/h2>\n<p>If the Publisher Attestation includes external compliance audit reports, a certification analyst checks the validity of those reports as part of the Microsoft 365 Certification assessment. To expedite the certification assessment process, the analyst uses evidence for these external compliance audit reports:<\/p>\n<ul>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365-app-certification\/docs\/certification-submission-guide#isms\" target=\"_blank\" rel=\"noopener noreferrer\">ISMS<\/a>\/\u00a0<a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365-app-certification\/docs\/certification-submission-guide#iec\" target=\"_blank\" rel=\"noopener noreferrer\">IEC<\/a>\u2013 IS0\/IEC 27001 specification<\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365-app-certification\/docs\/certification-submission-guide#pci-dss\" target=\"_blank\" rel=\"noopener noreferrer\">PCI DSS<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365-app-certification\/docs\/certification-submission-guide#soc-2\" target=\"_blank\" rel=\"noopener noreferrer\">SOC 2<\/a><\/li>\n<\/ul>\n<p>For details, see <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365-app-certification\/docs\/certification-submission-guide#optional-external-compliance-frameworks-review\" target=\"_blank\" rel=\"noopener noreferrer\">Optional external compliance audit review<\/a>.<\/p>\n<p>In conclusion, please reach out to <a href=\"mailto:appcert@microsoft.com\" target=\"_blank\" rel=\"noopener noreferrer\">appcert@microsoft.com<\/a>.<\/p>\n<p>Try the following resources to\u202flearn more about the Microsoft 365 App Compliance Program:<\/p>\n<ul>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365-app-certification\/overview\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft 365 App Compliance Program<\/a><\/li>\n<li><a href=\"https:\/\/techcommunity.microsoft.com\/t5\/microsoft-365-blog\/microsoft-365-app-compliance-program-helps-admins-in-creating-a\/ba-p\/1878437\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft 365 App Compliance Program helps admins in creating a secure app ecosystem &#8211; Microsoft Tech Community<\/a><\/li>\n<li><a href=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/new-renewal-offering-for-your-apps-publisher-attestation-and-microsoft-365-certification\/\" target=\"_blank\" rel=\"noopener noreferrer\">New renewal offering for your app\u2019s Publisher Attestation and Microsoft\u202f365 Certification &#8211; Microsoft 365 Developer Blog<\/a><\/li>\n<\/ul>\n<p>Happy coding!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As an app publisher, you can work with analysts\u00a0in the\u00a0Microsoft 365 App Compliance team\u00a0to demonstrate that both your application and its supporting infrastructure are qualified to protect the security and privacy of your customers\u2019 sensitive data.\u00a0<\/p>\n","protected":false},"author":69080,"featured_media":25159,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[3,11],"tags":[29],"class_list":["post-6525","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-graph","category-office-add-ins","tag-microsoft-365-app-compliance-program"],"acf":[],"blog_post_summary":"<p>As an app publisher, you can work with analysts\u00a0in the\u00a0Microsoft 365 App Compliance team\u00a0to demonstrate that both your application and its supporting infrastructure are qualified to protect the security and privacy of your customers\u2019 sensitive data.\u00a0<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/posts\/6525","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/users\/69080"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/comments?post=6525"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/posts\/6525\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/media\/25159"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/media?parent=6525"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/categories?post=6525"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/tags?post=6525"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}