Microsoft Defender for Cloud Apps
Cloud and workloads

Create and manage OAuth app policies with app governance | Microsoft Defender for Cloud Apps

In brief

The article now uses clearer headings and navigation anchors, improves wording and screenshot text, and adds steps for editing user-defined policies plus a link to investigate generated alerts.

What Defender admins need to know

Admins can find policy template, editing, and alert-investigation guidance more easily.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Create and manage OAuth app policies

App policy templates are grouped into these categories: Usage, Permissions, and Certification.

UsageUsage-based app policy templates

The following table lists the app governance templates supported to generate alerts for app usage.

|New app with high data usage|Find newly registered apps that have uploaded or downloaded large amounts of data using Microsoft Graph and EWS APIs. This policy checks the following conditions:

  • Registration age: Seven days or less (customizable)
  • Data usage: Greater than 1 GB in one day (customizable)
| |Increase in users|Find apps with a sizable increase in the number of users. This policy checks the following conditions:
  • Time range: Last 90 days
  • Increase in consenting users: At least 50% (customizable)
|

PermissionsPermission-based app policy templates

The following table lists the app governance templates supported to generate alerts for app permissions.

|New highly privileged app|Find newly registered apps that have been granted write access and other powerful permissions to Microsoft Graph and other common Microsoft first-party APIs. This policy checks the following conditions:

  • Registration age: Seven days or less (customizable)
| |New app with non-Graph API permissions|Find newly registered apps that have permissions to non-Graph APIs. These apps can expose you to risks if the APIs they access receive limited support and updates.

This policy checks the following conditions:
  • Registration age: Seven days or less (customizable)
  • Non-Graph API permissions: Yes
|

CertificationCertification-based app policy templates

The following table lists the app governance templates supported to generate alerts for Microsoft 365 certification.

|---|---| |New uncertified app|Find newly registered apps that don't have publisher attestation or Microsoft 365 certification. This policy checks the following conditions:

  • Registration age: Seven days or less (customizable)
  • Certification: No certification (customizable)
|

CustomCreate custom OAuth app policies

Use a custom app policy when you need to do something not already done by one of the built-in templates.

:::image type="content" source="media\app-governance\mapg-cc-policies-policy.png" alt-text="Screenshot of the app governance policies summary page in Microsoft Defender XDR, with a highlighted policy." lightbox="media\app-governance\mapg-cc-policies-policy.png":::

If the number of alerts is an unexpectedly low value, edit the settings of the app policy to ensure you've configured it correctly before setting itsthe policy status.

Here's an example of a process for creating a new policy, testing it, and then making it active:

  1. Filter the apps according to your needs. For example, you might want to view all apps that request Permission to Modify calendars in your mailbox.
  1. You might want to set the policy based on the group memberships of the users who authorized the apps. For example, an admin can decide to set a policy that revokes uncommon apps if they ask for high permissions, only if the user who authorized the permissions is a member of the Administrators group.

In addition to Oauth app policies that you can create, Microsoft Defender for Cloud Apps provides out-of-the-box anomaly detection policies that profile metadata of OAuth apps to identify ones that are potentially malicious. Defender for Cloud Apps is the Microsoft security service that helps protect your organization's cloud app environment, including OAuth apps connected to Salesforce and Google Workspace.

The out-of-the-box anomaly detection policies are only relevant for Salesforce and Google Workspace applications.

- **Actions**: Change the autoremediation action for alerts generated by the policy.
- **Status**: Change the policy status.

:::image type="content" source="media/app-governance-app-policies-manage/edit-user-defined-policy.png" alt-text="Screenshot of the Edit policy pane for a user-defined app policy in App Governance." lightbox="media/app-governance-app-policies-manage/edit-user-defined-policy.png":::

Delete an app policy

  • Select the policy in the policy list, and then select Delete on the app policy pane.

An alternative to deleting an app policy is to change the app policy status to disabled. Once disabled, the policy doesn't generate alerts. For example, rather than deleting an app policy for an app with a specific set of conditions that are useful for a future policy, rename the app policy to indicate its usefulness and set its status to disabled.

Edit an existing user-defined policy

Follow these steps to edit an existing user-defined policy:

  1. On the App governance page, select the Policies tab and select the policy you want to edit. A panel opens on the right side with the details of the existing policy.

  2. Select Edit.

Next step

After you create and configure your app policies, investigate the alerts they generate:

[!div class="nextstepaction"] Investigate predefined app policy alerts