Create policies to control OAuth apps
In brief
The article now explains creating and managing app permission policies to control OAuth app behavior, including notifications, permission investigation, and approval or banning. It also notes that OAuth app policies trigger alerts only for policies authorized by users in the tenant.
What Defender admins need to know
Use the clarified alert scope when evaluating policy coverage and investigating OAuth app activity.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Create policies to control OAuth apps
In Microsoft Defender for Cloud Apps, you can create app permission policies to monitor and control OAuth app behavior. Use these policies to get automated notifications when apps meet specific criteria, investigate requested permissions, and mark permissions as approved or banned.
Create OAuth app policies
Set permission policies so that you get automated notifications when an OAuth app meets certain criteria. For example, you can automatically be alerted when there are apps that require a high permission level and are authorized by more than 50 users. For more information about investigating OAuth apps, see Manage app permissions.
OAuth app policies enable you to investigate which permissions each app requested and which users authorized them for Microsoft 365, Google Workspace, and Salesforce. You're also able to mark these permissions as approved or banned. Marking permissionsan app permission as banned disables the corresponding Enterprise Application.enterprise application associated with that OAuth app.
Along with a built-in set of capabilities to detect anomalous app behavior and generate alerts based on machine learning algorithms, app policies in app governance are a way for you to:
If you have Microsoft Defender preview features and app governance enabled (get started with app governance), create the policy from the App governance page rather than from Policy management.
To create a new OAuth app policy:
In the Microsoft Defender Portal, underCloud Apps, selectPoliciesand then selectPolicy management. :::image type="content" source="create-oauth-app-policies/oauth-app-policy.png" alt-text="Screenshot that shows where to enter the details for your new Oauth app policy." lightbox="create-oauth-app-policies/oauth-app-policy.png":::Filter the apps according to your needs. For example, you can view all apps that requestPermissiontoModify calendars in your mailbox.You can use theCommunity usefilter to get information on whether allowing permission to this app is common, uncommon, or rare. TheCommunity usefilter can be helpful if you have an app that's rare and requests permission that has a high severity level or requests permission from many users.Select theNew policy from searchbutton.
To create a new OAuth app policy:
In the Microsoft Defender Portal, under Cloud Apps, select Policies and then select Policy management. :::image type="content" source="create-oauth-app-policies/oauth-app-policy.png" alt-text="Screenshot that shows where to enter the details for your new Oauth app policy." lightbox="create-oauth-app-policies/oauth-app-policy.png":::
Filter the apps according to your needs. For example, you can view all apps that request Permission to Modify calendars in your mailbox.
You can use the Community use filter to determine whether granting permission to a selected app is common, uncommon, or rare. The Community use filter can be helpful if an app has a rare community-use classification and requests a high-severity permission or has been granted permission by many users.
Select the New policy from search button.
@@ -1,19 +1,21 @@ --- title: Create policies to control OAuth apps -description: This article provides instructions for creating and working with app permission policies in Microsoft Defender for Cloud Apps.-ms.date: 06/16/2026+description: Create and manage app permission policies in Microsoft Defender for Cloud Apps to control OAuth app behavior and permissions.+ms.date: 07/03/2026 ms.topic: how-to-ms.custom: sfi-image-nochange, msecd-doc-authoring-1014+ms.custom: sfi-image-nochange, msecd-doc-authoring-1016 ai-usage: ai-assisted --- # Create policies to control OAuth apps +In Microsoft Defender for Cloud Apps, you can create app permission policies to monitor and control OAuth app behavior. Use these policies to get automated notifications when apps meet specific criteria, investigate requested permissions, and mark permissions as approved or banned.+ ## Create OAuth app policies Set permission policies so that you get automated notifications when an OAuth app meets certain criteria. For example, you can automatically be alerted when there are apps that require a high permission level and are authorized by more than 50 users. For more information about investigating OAuth apps, see [Manage app permissions](manage-app-permissions.md). -OAuth app policies enable you to investigate which permissions each app requested and which users authorized them for Microsoft 365, Google Workspace, and Salesforce. You're also able to mark these permissions as approved or banned. Marking permissions as banned disables the corresponding Enterprise Application.+OAuth app policies enable you to investigate which permissions each app requested and which users authorized them for Microsoft 365, Google Workspace, and Salesforce. You're also able to mark these permissions as approved or banned. Marking an app permission as banned disables the enterprise application associated with that OAuth app. Along with a built-in set of capabilities to detect anomalous app behavior and generate alerts based on machine learning algorithms, app policies in app governance are a way for you to: @@ -29,6 +31,9 @@ You can create a new OAuth app policy from **Policy management** or from **App g If you have [Microsoft Defender preview features](/microsoft-365/security/defender/preview) and [app governance enabled (get started with app governance)](app-governance-get-started.md), create the policy from the **App governance** page rather than from **Policy management**. +> [!NOTE]+> OAuth apps policies will trigger alerts only on policies that were authorized by users in the tenant.+ To create a new OAuth app policy: 1. In the Microsoft Defender Portal, under **Cloud Apps**, select **Policies** and then select **Policy management**.@@ -42,7 +47,7 @@ To create a new OAuth app policy: :::image type="content" source="create-oauth-app-policies/oauth-app-policy.png" alt-text="Screenshot that shows where to enter the details for your new Oauth app policy." lightbox="create-oauth-app-policies/oauth-app-policy.png"::: 1. Filter the apps according to your needs. For example, you can view all apps that request **Permission** to **Modify calendars in your mailbox**.-1. You can use the **Community use** filter to get information on whether allowing permission to this app is common, uncommon, or rare. The **Community use** filter can be helpful if you have an app that's rare and requests permission that has a high severity level or requests permission from many users.+1. You can use the **Community use** filter to determine whether granting permission to a selected app is common, uncommon, or rare. The **Community use** filter can be helpful if an app has a rare community-use classification and requests a high-severity permission or has been granted permission by many users. 1. Select the **New policy from search** button. 