Microsoft Defender for Cloud Apps
Cloud and workloads

Create activity policies | Microsoft Defender for Cloud Apps

In brief

The page now uses a clearer custom-alerts heading and explains that alerts apply when policy-defined activities are detected. It also clarifies that the affected user can be suspended and adds a related-policy reference lead-in.

What Defender admins need to know

Administrators can more easily find and interpret guidance about alert triggers and user suspension; no configuration change is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Create Microsoft Defender for Cloud Apps activity policies

  • Policies that trigger more than 200,000 matches per day, or 100,000 matches per 3 hours, may be disabled automatically. You can try refining policies by adding additional filters or, if you're using policies for reporting purposes, consider saving activity filters as queries instead.
  • It may take up to 15 minutes from setting up a new policy to deployment.

CustomCreate custom alerts for activity policies

Activity policies allow custom alerts to be sent or actions taken when user activity is detected. For example, you want to know every time:

  • A user downloads 7,000 files
  • A user is logged in from an unfamiliar country/region

You can set activity alerts to be sent to yourself or to the user when these events occur.the activities defined in the policy are detected. You can even suspend the affected user until you have finished investigating what happened.the activity.

To create a new activity policy, follow this procedure:

Activity policy reference

The following referenceThis section describes activity policy types, their components, and the fields that can be configured for each policy.

An Activity policy is an API-based policy that enables you to monitor your organization's activities in the cloud. The policy takes into account over 20 file metadata filters including device type and location. Based on the policy results, notifications can be generated and users can be suspended from the cloud app. Each policy is composed of the following parts:

Next steps

Learn more about related policy types in the following article:

[!div class="nextstepaction"] Data protection policies