Microsoft Defender for Cloud Apps
Cloud and workloads

Governing connected apps

In brief

The page now clarifies role restrictions, that malware governance actions apply only to connected apps, and that Microsoft Entra synchronization can revert the Suspend user or other affected governance actions. It also refines OAuth permission guidance and wording.

What Defender admins need to know

Administrators can more accurately interpret governance action availability and synchronization behavior. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Govern actions for connected apps in Defender for Cloud Apps

  • Trash – Move the file to the trash folder. (Box, Dropbox, Google Drive, OneDrive, SharePoint)

The malware governance actions listed in this sectionAvailable malware governance actions (Preview) are restricted to users with specific administrative roles. If the malware governance action options in this sectionlisted earlier are not visible or accessible, confirm with your system administrator that your account has one of the following roles assigned:

  • Security Operator
  • Security administrator

    Microsoft Defender for Office 365 customers can control detected malware files in SharePoint and OneDrive on the Files tab of the Quarantine page in the Microsoft Defender portal at https://security.microsoft.com/quarantine?viewid=Files. For example, supported activities include recovering files, deleting files, and downloading files in password-protected ZIP files. These activities are limited to files that were not already quarantined by Microsoft Defender for Cloud Apps.

    ActionsMalware governance actions show only for connected apps.

Available activity governance actions

  • Suspend user – Suspend the user from the application.
  • Require user to sign in again – Signs the user out and requires them to sign in again.

  • Confirm user compromised - Set the user's risk level to high. This causes the relevant policy actions defined in Microsoft Entra ID to be enforced. For more information about how Microsoft Entra ID works with risk levels, see How does Microsoft Entra ID use my risk feedback.

Screenshot of activity governance actions showing suspend user, require sign-in, and confirm user compromised options.

Revoke an OAuth app and notify user

As part of governing connected apps, you can also manage OAuth app permissions. For Google Workspace and Salesforce, it's possible to revoke permission to an OAuth app or to notify the user that they should change the permission. When you revoke permission it removes all permissions that were granted to the application under "Enterprise Applications" in Microsoft Entra ID.

  1. On the Google or Salesforce tabs on the App governance page, select the three dots at the end of the app row and select Notify user. By default, the user is notified as follows: You authorized the app to access your Google Workspace account. This app conflicts with your organization's security policy. Reconsider giving or revoking the permissions you gave this app in your Google Workspace account. To revoke app access, go to: https://security.google.com/settings/security/permissions?hl=en&pli=1 Select the app and select 'Revoke access' on the right menu bar. You can customize the message that is sent.
  2. You can also revoke permissions to use the app for the user. Select the icon at the end of the app row in the table and selecting Revoke app. For example:

User sync between on-premises Active Directory and Microsoft Entra ID can affect how governance actions are applied:

  • If your Microsoft Entra ID is set to automatically sync with the users in your Active Directory on-premises environment, the settings in the on-premises environment override the Microsoft Entra settings and thisthe affected governance actionactions are reverted.

Review the governance log