How to Handle Unverified Publisher Alerts in Microsoft Defender
Question details
Users and administrators are receiving excessive alerts because Microsoft Defender App Governance is flagging various applications, including internal and official Microsoft apps, as having an unverified publisher.
- Product
- Microsoft Defender App Governance
- Device & OS
- not provided
- Scenario
- Monitoring application security and managing user permissions within an organization's Microsoft 365 or Azure environment.
- Observed behavior
- The system generates an excessive volume of security alerts, labeling applications as having an unverified publisher due to verification, authorization, or detection issues.
Ensure you have the necessary IT administrative privileges in your Microsoft 365 or Azure AD portal if you plan to modify organizational app policies or add trusted certificates.
Manage Trusted Certificates and Developer Verification (For Admins)
Best for IT administrators who need to reduce false positive alerts for internal, self-signed, or trusted third-party applications.
End users cannot bypass publisher verification statuses on their own. Instead, organizations must manage these alerts centrally by adding trusted certificates for internally developed applications or working with developers to ensure proper Microsoft Cloud Partner Program (MCPP) verification.
Log into the Microsoft 365 Defender portal and navigate to App Governance to review the specific permissions requested by the flagged applications.
For internal or self-signed applications, deploy your organization's trusted certificates to the relevant endpoints via Group Policy or MDM to establish trust.
If a third-party application is flagged, contact the vendor and request that they complete the official Microsoft publisher verification process.
Verify App Sources Manually (For End Users)
Since end users cannot disable publisher verification warnings, they must rely on manual safety checks before granting app permissions.
Try a Secure, Lightweight Microsoft Office Alternative
Dealing with complex enterprise security policies, unverified publisher alerts, and strict governance settings in Microsoft environments can be overwhelming. If you want a secure, hassle-free document editing experience, try WPS Office. It provides powerful productivity tools without the administrative overhead.
- 1. Download the software: Visit the official WPS Office website and click the free download button for your operating system.
- 2. Install WPS Office: Run the installer and follow the simple on-screen instructions to set up your new office suite.
- 3. Start working securely: Open WPS Office and instantly enjoy a secure, highly compatible environment for editing your documents.

Frequently Asked Questions
Why do official Microsoft apps sometimes show as having an unverified publisher?
This usually happens due to temporary parsing issues, incomplete authorization scopes, or backend detection glitches within the Defender App Governance evaluation engines.
Can I disable the unverified publisher warning as a regular user?
No, end users generally cannot bypass or disable publisher verification warnings. Only IT administrators have the authority to manage organizational trust policies or whitelist specific applications.
What must developers do to remove the unverified status from their apps?
Developers must complete the Microsoft Cloud Partner Program (MCPP) verification process and link their verified MPN ID to their Azure application registration.




