1. Copy the default security rules default stream Name & condition & disable rule
Note: The apps should disappear in the stream
2. Create a new security rule similar to the default rule you just disabled
3. Use the App access template
4. Assign the same default name like: Stream Rule – Apps Default Rule
5. Resource Filter: App_*
6. Copy the default security rule condition you copied above & add this text after: resource.stream.Has.Privilege(“read”) and before the “) or”
a. This text: and resource.AppLevelRestrictions.empty()
7. Check action “read”
Note: you should now see all the apps again in the stream
Something we noticed that there is a problem is when we copied in the default Stream rule, the text was highlighted with red underlines telling me it is not correct. When we try to validate the rule it returns a validate message.
Step 3:
1. Now go to the Finance App you want restricted and add the custom property AppLevelRestrictions:
a. “Finance Restrictions”
Note: you should not see the Finance apps in the stream