Microsoft Defender for Cloud Apps
Cloud and workloads

Investigate predefined OAuth app policy alerts with app governance | Microsoft Defender for Cloud Apps

In brief

The page now names three disabled policies, clarifies detection coverage for overprivileged and highly privileged apps, adds a sensitive-data access description, and updates a link title.

What Defender admins need to know

Administrators can more easily identify these disabled policies in the Defender portal; no action is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Investigate predefined OAuth app policy alerts

Increase in data usage by an overprivileged or highly privileged app

An overprivileged app has permissions that exceed what it needs for its intended function, while a highly privileged app holds powerful permissions such as full mailbox or directory access. This alert detects unusual increases in data usage by theseoverprivileged and highly privileged apps.

Severity: Medium

A priority account is a high-value account, such as an executive or service administrator, that you tag in Microsoft Defender for Cloud Apps. This alert triggers when an app that a priority account has consented to exhibits unusual activity.

Severity: Medium

Access to sensitive data

This alert detects apps that access sensitive data in ways that might indicate risky or malicious behavior.

Severity: Medium

Related content