Microsoft Defender for Cloud Apps
Cloud and workloads

In-browser protection with Microsoft Edge for Business | Microsoft Defender for Cloud Apps

In brief

The documentation now clarifies the suitcase indicator, states that Endpoint DLP takes priority when the same context and action overlap, and explains that users may switch browsers when policy or operating system compatibility prevents in-browser protection.

What Defender admins need to know

Administrators can use the clarified guidance to explain protection status and policy precedence; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

In-browser protection with Microsoft Edge for Business (Preview)

User experience with in-browser protection

To confirm that in-browser protection is active, users need to select the "lock" icon in the browser's address bar and look for the "suitcase" symbol in the form that appears. The suitcase symbol indicates that the session is protected by Defender for Cloud Apps. For example:

Screenshot of the lock icon in the Edge address bar showing the suitcase symbol indicating the session is protected by Defender for Cloud Apps.

Also, the .mcas.ms suffix doesn't appear in the browser address bar with in-browser protection, as it does with standard Conditional Access app control, and developer tools are turned off with in-browser protection.

When you're finished on the Edge for Business protection page, select Save.

Working with Microsoft Purview Endpoint data loss prevention

Endpoint DLPdata loss prevention (DLP) policies are prioritized and applied if the same context and action are configured for the Endpoint policy and either a Defender for Cloud Apps session policy or a Purview DLP policy for cloud apps.

For example, if you have an Endpoint DLP policy that blocks a file upload to Salesforce,Salesforce and you also have a Defender for Cloud Apps session policy that monitors file uploads to Salesforce. In this scenario,Salesforce, the Endpoint DLP policy takes priority and is applied.

For more information, see Learn about Endpoint data loss prevention.

 For example, a user is subject to a policy that doesn't align with in-browser protection capabilities (for example, **Protect file upon download**) OR the operating system is incompatible (for instance, Android).

 In this scenario, becauseWhen the user lacks control overpolicy or operating system is incompatible with in-browser protection, the context, theyuser might opt to use a different browser.

 If the applicable policies allow it and the operating system is compatible (Windows 10, 11, macOS), the user is required to use Microsoft Edge.