Microsoft Defender for Cloud Apps
Cloud and workloads

Cloud discovery policies

In brief

The article now explains that selecting “Tag app as unsanctioned” automatically blocks access when the policy matches, and defines app tags as labels for filtering and targeting discovered apps.

What Defender admins need to know

Administrators can more clearly understand the blocking effect and use of app tags when configuring discovery policies.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Create cloud discovery policies in Defender for Cloud Apps

1. Select **Daily traffic** greater than 2,000 GB (or other).
  1. Configure governance actions to be taken when an alert is triggered. Under Governance, select Tag app as unsanctioned.
    Access to the app will be automatically blocked when the policy is matched.

  2. Optional: Apply Defender for Cloud Apps native integrations

  1. Optional: Apply Defender for Cloud Apps native integrations with Secure Web Gateways to block app access.

Create an unsanctioned app discovery policy

App tags are labels you assign to discovered apps so you can filter and target them in discovery policies. Perform the following steps to detect use of unsanctioned business apps.

  1. In the Cloud app catalog, search for your business-ready apps and mark them with a custom app tag.

  2. Add an App tag filter and choose the app tags you created for your business-ready apps.

  3. Configure governance actions to be taken when an alert is triggered. Under Governance,Governance, select Tag app as unsanctioned.
    Access to the app will be automatically blocked when the policy is matched.

  4. Optional: Use Defender for Cloud Apps native integrations

  1. Optional: Use Defender for Cloud Apps native integrations with Secure Web Gateways to block app access.