Policy Enforcer watches every governed Space on your tenant and corrects Policy breaches automatically, without any manual auditing on your part.
Teams Manager creates your Spaces and defines the Policies that shape them. Policy Enforcer picks up from there, keeping those Policies respected weeks and months later, once a Team has taken on a life of its own.
Every renamed Team, flipped visibility setting, and removed owner gets caught, recorded, and either put right on the spot or sent to the people you nominate for review.
It's a separate Microsoft Teams app with its own licence, and its connection to Teams Manager is read-only, so your Policies stay exactly where you author them.
Let's go through the main components and how they work together.
đ Detecting Violations
Policy Enforcer watches eight kinds of Policy breach across every governed Space, continuously and without any scripting on your part.
Five can be corrected automatically:
A Naming Convention breach
A Visibility change from private to public
A renamed Planner
A renamed OneNote
A changed Sensitivity Label
The other three always need a human decision, because Policy Enforcer can work out what a Team should be called, but not who should own it:
The 2-owner Policy breach
Default Owners removed
Default Members removed
Detection only looks forward. Policy Enforcer catches changes from the moment it starts watching, never retroactively.
A Team that was made public last month stays public and silent until someone changes its visibility again. Audit your governed Spaces by hand once before you rely on enforcement, so you start from a clean baseline.
âď¸ Resolving Violations
Resolution Types decide in advance what happens the moment a breach is detected.
You have three choices:
Ignore - records the change and leaves it in place
Automatically resolve and notify - corrects the change on its own and notifies the resolution groups you chose
Let resolution groups review - notifies them and lets one of them decide how to resolve it
When a violation is corrected automatically, a renamed Team is returned to its previous name, a Space that was made public is set back to Private, and a changed Sensitivity Label is restored to the one your Policy requires.
đ Enforcements
Enforcements bundle those decisions together and tie them to a single Teams Manager Policy. You build one Enforcement per Policy you want watched.
Rather than setting all eight types by hand, start from a Preset:
Recommended - corrects whatever it can automatically and hands the rest to Team Owners
Strict - forwards everything to Admins for review, including the changes that could have been handled automatically
Adjust any individual setting and the Enforcement is labelled Custom.
You might run Recommended on your project Teams so renames are fixed silently, and Strict on anything holding sensitive material so a person reviews every change.
đ Notifications
Adaptive Cards let you review and resolve violations without leaving Teams. When a breach needs attention, the Policy Enforcer bot sends one to the Resolution Group you nominated: Team Owners, Teams Manager Admins, or both.
The card shows what changed, what it changed from, and who changed it.
Some outcomes are also announced in the team's General channel, and the pattern isn't symmetrical:
Renames and Sensitivity Label changes are posted once resolved
A Visibility change is posted only if someone dismisses it
Owner and member violations are never posted
Dismissing a public-visibility violation announces it to the whole team, while quietly resolving one says nothing.
Dismissing is never invisible either. Your IT department is told about every dismissal, and a Team Owner has to give a reason before dismissing anything.
đď¸ Overview Dashboard
The Overview tab shows whether all of this is paying off.
It gives you:
How many Policies you're enforcing
How many violations have come up over a window you choose
A chart of violations over time
If the permissions Policy Enforcer relies on ever lapse, detection and resolution pause until an admin grants them again, and the app carries on looking normal.
A violation count that suddenly drops to zero is usually a lapsed permission rather than a sudden outbreak of good behaviour, so it's your cue to check Settings.
đŁ Next Steps
Now that you've got a feel for what Policy Enforcer does, it's time to get it onto your tenant and pointed at Teams Manager.
We recommend starting here:
âď¸ Need more help?
Get further assistance with Policy Enforcer through our support chat widget within the app, or reach out to us at [email protected]




