I've created a custom app and make available to a certain role, I've hidden all other apps for that role.
The problem is that if these users deletes the URL information after dynamics.com… They log into full CRM anyway.
If this behavior is by design then Apps are not a viable ‘security’ method to limit access.





