Microsoft Defender for Cloud Apps
Cloud and workloads

Create policies to control OAuth apps

In brief

The article now explains creating and managing app permission policies to control OAuth app behavior, including notifications, permission investigation, and approval or banning. It also notes that OAuth app policies trigger alerts only for policies authorized by users in the tenant.

What Defender admins need to know

Use the clarified alert scope when evaluating policy coverage and investigating OAuth app activity.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Create policies to control OAuth apps

In Microsoft Defender for Cloud Apps, you can create app permission policies to monitor and control OAuth app behavior. Use these policies to get automated notifications when apps meet specific criteria, investigate requested permissions, and mark permissions as approved or banned.

Create OAuth app policies

Set permission policies so that you get automated notifications when an OAuth app meets certain criteria. For example, you can automatically be alerted when there are apps that require a high permission level and are authorized by more than 50 users. For more information about investigating OAuth apps, see Manage app permissions.

OAuth app policies enable you to investigate which permissions each app requested and which users authorized them for Microsoft 365, Google Workspace, and Salesforce. You're also able to mark these permissions as approved or banned. Marking permissionsan app permission as banned disables the corresponding Enterprise Application.enterprise application associated with that OAuth app.

Along with a built-in set of capabilities to detect anomalous app behavior and generate alerts based on machine learning algorithms, app policies in app governance are a way for you to:

If you have Microsoft Defender preview features and app governance enabled (get started with app governance), create the policy from the App governance page rather than from Policy management.

To create a new OAuth app policy:

  1. In the Microsoft Defender Portal, under Cloud Apps, select Policies and then select Policy management. :::image type="content" source="create-oauth-app-policies/oauth-app-policy.png" alt-text="Screenshot that shows where to enter the details for your new Oauth app policy." lightbox="create-oauth-app-policies/oauth-app-policy.png":::

  2. Filter the apps according to your needs. For example, you can view all apps that request Permission to Modify calendars in your mailbox.

  3. You can use the Community use filter to get information on whether allowing permission to this app is common, uncommon, or rare. The Community use filter can be helpful if you have an app that's rare and requests permission that has a high severity level or requests permission from many users.

  4. Select the New policy from search button.

To create a new OAuth app policy:

  1. In the Microsoft Defender Portal, under Cloud Apps, select Policies and then select Policy management. :::image type="content" source="create-oauth-app-policies/oauth-app-policy.png" alt-text="Screenshot that shows where to enter the details for your new Oauth app policy." lightbox="create-oauth-app-policies/oauth-app-policy.png":::

  2. Filter the apps according to your needs. For example, you can view all apps that request Permission to Modify calendars in your mailbox.

  3. You can use the Community use filter to determine whether granting permission to a selected app is common, uncommon, or rare. The Community use filter can be helpful if an app has a rare community-use classification and requests a high-severity permission or has been granted permission by many users.

  4. Select the New policy from search button.