When you assign an app setup policy to a security group in Microsoft Teams, you expect the pinned app to appear automatically for every member. But sometimes the app never shows up, even after you wait and refresh. This problem usually comes from a policy assignment conflict, a missing app permission, or a delay in propagation. This article explains the root cause and gives you clear steps to verify and fix the policy so the app pins correctly for your security group.
Key Takeaways: Pin Apps to a Security Group with App Setup Policy
- Teams admin center > Users > Manage users > Policies: Shows the effective Teams policy assignments that can override the security group assignment.
- Teams admin center > Teams apps > Setup policies > Add apps: Adds the app to the pinned app list for the policy.
- Teams admin center > Teams apps > Manage apps > Allow: Grants org-wide permission so the app is available to the security group.
Why the App Setup Policy Does Not Pin an App for a Security Group
App setup policies control which apps appear in the Teams app bar and the meeting stage. When you assign a policy to a security group, Teams uses group policy assignment to apply that policy to all members. The policy itself contains a pinned app list. If the app is not in that list, or if the policy is not the effective one for the user, the app will not appear.
The most common root cause is a conflict with a user-level policy assignment. If a user already has a direct policy assignment, that policy takes precedence over the group policy. Group policy assignment is lower in priority. Also, the app must be allowed in the org-wide app settings. If the app is blocked, it will never pin, even if the setup policy lists it.
Priority of Policy Assignments
Teams applies policies in this order: user-level assignment first, then group assignment, then the global policy. If a user has a direct policy assignment, that policy wins. Your security group policy will be ignored for that user. You must check the effective policy for each affected user.
App Permissions and Availability
The app must be allowed at the org level. Go to Teams admin center > Teams apps > Manage apps and confirm the app status is Allowed. If the app is blocked, you must allow it before it can be pinned. Also, the app must be available in the Teams app store for your tenant.
Steps to Diagnose and Fix the App Setup Policy Pinning Issue
Follow these steps in order. Each step verifies a different part of the configuration.
- Check the app is allowed in the org-wide settings
Go to Teams admin center > Teams apps > Manage apps. Search for the app name. Confirm the Status column shows Allowed. If it shows Blocked, select the app and click Allow in the top menu. Wait a few minutes for the change to propagate. - Verify the setup policy contains the pinned app
Go to Teams admin center > Teams apps > Setup policies. Select your policy. Under Pinned apps, click Add apps. Search for the app and add it. Then reorder the apps if needed. Click Save. This step is required because a policy without the app in the list will not pin it. - Check the group assignment of the policy
Still in the setup policy page, look at the Assignments section. Confirm that your security group is listed. If not, click Assignments > Add and select the security group. Set the priority if you have multiple groups. Save the assignment. - Check the effective policy for a specific user
Go to Teams admin center > Users > Manage users. Find a user who belongs to the security group. Click the user, then go to Policies. Look at the App setup policy assignment. If it shows a different policy name, that user has a direct assignment that overrides your group policy. Remove the direct assignment by setting it to Global (Org-wide default) or by assigning the same policy directly. - Wait for propagation and restart Teams
After making changes, wait up to 24 hours for full propagation. Ask the user to sign out of Teams and sign back in, or restart the app. The pinned app should appear in the left app bar.
If the App Still Does Not Pin
If the app is allowed, the policy is correct, and the group assignment is in place, but the app still does not appear, check the user’s Teams version. The new Teams desktop app sometimes caches policies. Have the user clear the Teams cache. Also, confirm the user is not in another security group that has a conflicting policy. The group with the higher priority wins.
If Teams Still Has Issues After the Main Fix
Teams Shows the App in the Policy but Not in the App Bar
This happens when the app is not allowed at the org level or the user has a direct policy. Recheck step 1 and step 4. Also, the app might require specific permissions that the user does not have. Check the app’s permissions in the Teams admin center.
App Pins for Some Users but Not Others in the Same Group
One user may have a direct policy assignment, while another does not. Use the effective policy check from step 4 for each user. If the user has a direct assignment, you must remove it or align it with your group policy.
Policy Changes Do Not Take Effect Immediately
Teams policies can take up to 24 hours to propagate. If you need faster results, you can force a refresh by signing the user out and back in. In some cases, restarting the Teams client is enough. Do not expect instant changes after every edit.
New Teams Desktop vs Teams on the Web: Key Differences
| Item | New Teams Desktop | Teams on the Web |
|---|---|---|
| Policy refresh | Requires app restart or cache clear | Refreshes on page reload |
| App bar behavior | Shows pinned apps after sign-in | Shows pinned apps after reload |
| Cache impact | Cache can delay policy updates | Cache is less likely to cause issues |
Now you can verify the app permission, the policy content, and the group assignment. Start with the effective policy check for the affected user. Then confirm the app is allowed and listed in the policy. If the app still does not pin, clear the Teams cache and sign in again. Use the policy priority rules to resolve any conflicts with direct assignments.