Policy Enforcer shows people only what's relevant to them. Admins get the whole app, while Team Owners get the violations affecting the Spaces they actually own, and nothing else.
Who counts as which isn't decided inside Policy Enforcer at all, which catches people out. Settle it before you hand out access.
đĽ Who Counts as an Admin
Policy Enforcer takes its list of Admins directly from the Teams Manager instance you connected it to. If you're in that admin set, you're an Admin in Policy Enforcer.
Being a Microsoft 365 Global Admin is not enough on its own. A Teams Global Admin who isn't in the Teams Manager admin set sees the same restricted view as anybody else, no matter what their tenant role says.
If a colleague tells you they can't see the Enforcements tab despite being a Global Admin, the fix is to add them to your Teams Manager admin set rather than adjusting anything in Policy Enforcer.
Admins get everything: the Overview dashboard, Enforcements, the full Violations list across every governed Space, and Settings.
đ¤ What Team Owners See
A Team Owner who isn't in the admin set gets a deliberately narrow view: the Violations tab, showing only violations in Spaces they own.
They can't configure Enforcements, can't reach Settings, and can't see violations in Spaces that belong to somebody else.
What they can do is resolve. When a violation in one of their Spaces is routed to Team Owners, they get the card, they get the resolution options, and they get the people picker where one applies.
One difference worth knowing: a Team Owner has to give a reason before they can dismiss a violation, while an Admin doesn't. Dismissals by owners are recorded with their justification, which is what makes owner-level resolution safe to delegate.
If no Enforcements exist yet, a Team Owner is told that violations will appear once an administrator adds one, rather than being left looking at an empty screen wondering whether it's broken.
Once enforcement is running and their Spaces are clean, they see a straightforward confirmation that everything is being watched.
đ§ Before Setup Is Finished
Until Policy Enforcer is connected to Teams Manager, there is no admin set to read, so nobody is an Admin yet.
Everyone who opens the app in that state sees Policy Enforcer isn't ready yet, explaining that a Teams Manager administrator still needs to finish setting things up.
The one exception is whoever is doing that setup, who gets the onboarding flow instead.
This same screen appears if the connection to Teams Manager is lost later on, so it isn't only a first-run message. If your whole team suddenly sees it, check the connection under Settings.
đ When Permissions Can't Be Verified
Occasionally Policy Enforcer can't reach Microsoft Graph to confirm what you're allowed to do. Rather than guessing, it tells you that some permissions couldn't be verified and warns that some actions might be hidden.
If buttons you expect are missing, this is usually why, and it isn't a change to your access. There's a retry available, and the app returns to normal once the check succeeds.
This is deliberately cautious: Policy Enforcer would rather hide an action it can't confirm you're allowed to take than offer one that will fail.
đŁ Next Steps
Now that you know who can do what, it's worth making sure your enforcement setup matches those responsibilities.
We recommend starting here:
âď¸ Need more help?
Get further assistance with Policy Enforcer through our support chat widget within the app, or reach out to us at [email protected]

