Policy Enforcer keeps every governed Space on your tenant compliant with the Policies you've already defined in Teams Manager.
Installing it works like any other Teams App, apart from a couple of extra steps that connect it to Teams Manager and grant it the access it needs.
This article walks the whole setup, so by the end your Policy Enforcer instance is running.
đ Prerequisites
You must be a Microsoft 365 Global Teams Administrator and a Teams Manager Administrator to set up Policy Enforcer. The permission grant can't be delegated, so if that isn't you, please forward this article to whoever holds the role.
A working Teams Manager instance. Policy Enforcer reads your Policies and your governed Spaces from Teams Manager, and it can't do anything at all without one.
A service account. Policy Enforcer uses it to read from Teams Manager and to act on your governed Spaces. Setup isn't complete until one is connected.
âď¸ Initial Setup
Opening Policy Enforcer for the first time walks you through connecting it to Teams Manager.
Here's how you can get Policy Enforcer connected:
Start by adding Policy Enforcer to your Microsoft Teams account.
Opening it for the first time takes you to the Welcome to Policy Enforcer screen. Click on Get started.
On the Set up Policy Enforcer screen, pick your instance from the Select a Teams Manager instance dropdown.
Click on Connect.
Policy Enforcer will look for reachable instances and connect to the one you chose.
If nothing turns up in that dropdown, you'll see a message telling you that no reachable Teams Manager instance was found. That's the most common snag at this stage, and it means Policy Enforcer couldn't see your Teams Manager deployment rather than that anything is broken.
â Granting Permissions
Policy Enforcer talks to several Microsoft Graph endpoints to watch your Spaces and put changes right, so the next screen asks you to grant that access.
Clicking on Grant permissions takes you to Microsoft to confirm consent, then returns you to Policy Enforcer. You only have to do it once.
Here's what you're granting:
Read governed Teams & SharePoint spaces - so it can see the spaces it's meant to be watching
Rename and revert names - so it can put a breached naming convention right
Change visibility & sensitivity labels - so it can restore a space that was made public, or reapply the required sensitivity label
Manage owners & members - so your reviewers can re-add somebody who was removed
Post notifications as the PE bot - so violation cards and General channel posts can be delivered
This step can't be skipped. Detection and resolution stay switched off until the grant is complete, so a Policy Enforcer that looks installed but never reports anything is usually one that never got its permissions.
đ¤ Connecting a Service Account
Policy Enforcer uses a Service Account to read from Teams Manager and to act on your governed Spaces. Without one connected, it can't read your Policies at all.
Navigate to Settings in Policy Enforcer and click on Connect service account to sign in with the account you want to use.
Once it's connected, use Test connection at any point to confirm it's still healthy. A Connection healthy confirmation means everything is working.
The service account can't authenticate while permissions are revoked. If you ever re-grant permissions, check the Service Account afterwards, since the two are linked.
đ Final Results
The last screen you'll see is You're all set, and it carries the single most important thing to understand about Policy Enforcer.
Policy Enforcer only detects policy-breaking changes from this point forward. Any drift already sitting in your governed Spaces is never picked up retroactively, no matter how long it's been there.
If a Team was made public three months ago, Policy Enforcer won't flag it today. The moment somebody changes that Team's visibility again, you'll hear about it.
Audit your governed Spaces by hand once, right after setup, so you start from a clean baseline rather than assuming enforcement has caught everything.
Click on Continue and you'll land in the app proper, ready to set up your first Enforcement.
đŁ Next Steps
Now that Policy Enforcer is connected and permitted, it's time to tell it which Policies to watch and how to respond.
We recommend starting here:
âď¸ Need more help?
Get further assistance with Policy Enforcer through our support chat widget within the app, or reach out to us at [email protected]




