Microsoft Defender for Cloud Apps
Cloud and workloads

Govern discovered apps

In brief

The article now requires a supported on-premises security appliance to be configured and available before importing a block script. It also clarifies unsanctioned-app blocking across integrations and governance-action precedence.

What Defender admins need to know

If you use block scripts, verify the appliance is supported, configured, and available before importing the script.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Govern discovered apps in Microsoft Defender for Cloud Apps

AfterMicrosoft Defender for Cloud Apps lets you review the list ofgovern discovered apps in your environment, you can secure your environment by approving safe apps (Sanctioned) or prohibiting unwanted apps (Unsanctioned). Sanctioned apps are marked as approved for use, while unsanctioned apps can be monitored or blocked. This article covers how to sanction or unsanction apps, block apps by using built-in the following ways.streams or block scripts, and resolve governance conflicts.

Prerequisites

Before you can block discovered cloud apps, make sure you must meet the followingthese requirements:

Sanctioning/unsanctioning an app

An app that is onboarded to inline proxy or connected via app connector, all such applications would be auto sanctioned state in Cloud Discovery.

Blocking apps with built-in streams

If your organization's Microsoft 365 tenant uses Microsoft Defender for Endpoint, onceapps you mark an app as unsanctioned, it's automatically blocked. Moreover, youunsanctioned are blocked automatically. You can also scope blocking to specific Defender for Endpoint device groups, monitor applications,apps, and use the warn and educate users when accessing risky apps features. For more information, see Govern discovered apps using Microsoft Defender for Endpoint.

Otherwise, ifIf your tenant uses Zscaler NSS, iboss, Corrata, Menlo, or Open Systems, you can still enjoy seamless blocking capabilities when an app is unsanctioned, butunsanctioned apps are also blocked. However, you can't use the scope blocking by device groups or use the warn and educate users when accessing risky apps features. For more information, see Integrate with Zscaler, Integrate with iboss, Integrate with Corrata, Integrate with Menlo, and Integrate with Open Systems.

Block apps by exporting a block script

Defender for Cloud Apps enables you to block access to unsanctioned apps by using your existing on-premises security appliances. You can generate a dedicated block script and import it to your appliance. This solutionUsing a block script doesn't require redirection of all of the organization's web traffic to a proxy.

Before you begin, make sure you have a supported on-premises security appliance configured and available to import the block script.

  1. In the cloud discovery dashboard, tag any apps you want to block as Unsanctioned.

Blocking unsupported streams

If your tenant doesn't use Microsoft Defender for Endpoint, Zscaler NSS, iboss, Corrata, Menlo, or Open Systems, you can still export a list of all the domains of allfor unsanctioned apps andapps. Then configure your third-party nonsupported appliance to block those domains.

In the Discovered apps page, filter all Unsanctioned apps and then use the export capability to export all the domains.

Nonblockable applications

Some services are critical to business operations. To prevent users from accidentally blocking business-critical services and causing downtime, the following servicesyou can't be blocked usingblock these services in Defender for Cloud Apps, viawhether through the UI or policies:

  • Microsoft Defender for Cloud Apps
  • Microsoft Defender Security Center

Resolve governance conflicts between manual actions and policies

If there's a conflict between manually sanctioning or unsanctioning an appa manual sanction or unsanction action and a governance action set by a cloud discovery policy, the last operation applied takes precedence.

Next steps