Description:
This setting controls whether users in the organization are allowed to add applications from the Azure AD / Microsoft Entra ID application gallery directly to their My Apps portal. Allowing end users to add gallery apps themselves may introduce unauthorized or unapproved applications into the environment, which can increase security risk, reduce governance control, and bypass application onboarding processes.
Rationale:
Disabling this feature ensures users cannot independently assign or add applications without administrator approval. This helps maintain proper governance, prevents unauthorized app usage, and reduces the risk of users granting permissions to malicious or overly permissive applications. Enforcing centralized control aligns with application lifecycle management and security best practices.
Impact:
Restricting users from adding gallery apps ensures better access governance and reduces security risks. However, users may experience reduced flexibility in self-service application use.
Default Value:
By default, users may be allowed to add gallery apps unless explicitly disabled by administrators.
Pre-Requisites:
Microsoft Entra ID (Azure AD) administrator permissions
Access to the Azure Portal
Test Plan:
Sign in to the Azure Portal at https://portal.azure.com
Open Microsoft Entra ID
Under the Manage section, select Enterprise applications
Under Manage, select User settings
Verify that Users can add gallery apps to My Apps is set to No
If Users can add gallery apps to My Apps is not set to No, follow the implementation steps
Implementation Steps:
Sign in to the Azure Portal at https://portal.azure.com
Open Microsoft Entra ID
Under the Manage section, select Enterprise applications
Under the Mange Select, User settings.
Set Users can add gallery apps to My Apps to No
Save the changes
Backout Plan:
Sign in to the Azure Portal at https://portal.azure.com
Open Microsoft Entra ID
Under the Manage section, select Enterprise applications
Under Manage, Select User settings
Set Users can add gallery apps to My Apps to Yes
Save the changes
Reference:

