Microsoft Defender for Cloud Apps
Cloud and workloads

Conditional Access app control known limitations | Microsoft Defender for Cloud Apps

In brief

The article now documents that Teams or Teams-integrated functionality launched from a proxied Gmail session might not be supported. It recommends accessing Teams directly instead.

What Defender admins need to know

Admins using session control with Google Workspace should inform affected users about the limitation and workaround.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Known limitations in Conditional Access app control

Overview

This article describeslists known limitationslimits for working with Conditional Access app control in Microsoft Defender for Cloud Apps. These limitationslimits cover file size limits for session policies andsize, content inspection, encrypted file handling,files, IPv6 support, reverse proxy session behavior,sessions, and Microsoft Edge in-browser protection. Review this informationpage when you configure sessionset up policies or access policies, or when you troubleshootfix unexpected policy behavior.

To learn more about security limitations, contact our support team.

Limitations for sessions that the reverse proxy serves

The following built-in app, context loss, and file upload limitations in this section apply only to sessions that the reverse proxy serves. Users of Microsoft Edge can benefit from in-browser protection instead of using the reverse proxy, so these limitations don't affect them.

Built-in app and browser plug-in limitations

|A user tries to upload a selection of 200 files by using the file upload dialog. Some are sensitive, and some aren't. |Nonsensitive files are uploaded.

Sensitive files are blocked. | |A user tries to upload a selection of 200 files by using a drag-and-drop operation. Some are sensitive, and some aren't. |The full set of files is blocked. |

Teams add-ins launched from proxied Google Workspace sessions

When you use Defender for Cloud Apps session control with Google Workspace, launching Microsoft Teams or Teams-integrated functionality from within a proxied Gmail session might not be supported. Certain third-party and nested application authentication flows use separate authentication contexts that can't be maintained through the session proxy. In these scenarios, the Teams experience might bypass the proxied session or fail to load as expected. This behavior is by design and is a known limitation of the current architecture.

To work around this limitation, access Microsoft Teams directly rather than launching it from within the proxied Google Workspace session.

Limitations for sessions that are served with Microsoft Edge in-browser protection

The following Google Workspace, deep link, and outdated policy enforcement limitations in this section apply only to sessions that are served with Microsoft Edge in-browser protection.

Secure Microsoft Edge Session Controls can't be used with Google Workspace in Enterprise Microsoft Edge browsers

Google Workspace isn't supported with in-browser protection in the Enterprise Microsoft Edge browser. As a result, Secure Microsoft Edge Session controls in Google Workspaces aren't supported. In Google Workspaces, real real-time DLP filesdata loss prevention (DLP) file scans aren't supported, the fallback authentication of suffixes is used, and file upload, download, cut, and copy aren't supported.

Deep link is lost when user switches to Microsoft Edge by clicking 'Continue in Microsoft Edge'