Onboard non-Microsoft IdP custom apps for Conditional Access app control | Microsoft Defender for Cloud Apps
In brief
The procedure now refers to the Defender portal, points SSO configuration details to step 8, adds a “Before you begin” section, and formats the support link as a tip.
What Defender admins need to know
Administrators following the procedure get clearer navigation and setup guidance; no configuration change is specified.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Onboard non-Microsoft IdP custom apps for Conditional Access app control
Prerequisites
Before you begin, make sure your environment meets the following requirements:
Your organization must have the following licenses to use conditional access app control:
- The license required by your identity provider (IdP) solution
Add the admins who will onboard and maintain your apps for Conditional Access app control.
In
Microsoftthe DefenderXDR,portal, select Settings > Cloud Apps > Conditional Access App Control > App onboarding/maintenance.Enter the usernames or emails of any users who will be onboarding your app, and then select Save.
- Some identity providers do not allow you to change the SAML attributes or URL properties of a gallery / catalog app.
- When you configure a custom app, you can test the app with Defender for Cloud Apps access and session controls, without changing your organization's existing configured behavior.
Copy your app's single sign-on configuration information. You enter these values
inwhen configuring your IdPconfiguration's custom app settings ina later step.step 8 of this procedure. When you're finished, select Next to continue.Continuing on the IDENTITY PROVIDER page of the wizard, either upload a metadata file from your IdP or enter app data manually.
- The Single sign-on service URL. This is the URL that your IdP uses to receive single sign-on requests.
- A SAML certificate, if your IdP provides one. In such cases, select the Use identity provider's SAML certificate option, and then upload the certificate file.
Continuing on the IDENTITY PROVIDER page of the wizard, copy both the single sign-on URL and all attributes and values to enter
inwhen configuring your IdP's custom app settings inthe next step.step 8 of this procedure.When you're done, select Next to continue.
Related content
For more information, see the following articles:
- Protect apps with Microsoft Defender for Cloud Apps Conditional Access app control
- Deploy Conditional Access app control for catalog apps with non-Microsoft IdPs
- Troubleshooting access and session controls
[!INCLUDE
@@ -1,11 +1,11 @@ --- title: Onboard non-Microsoft IdP custom apps for Conditional Access app control | Microsoft Defender for Cloud Apps description: Learn how to deploy Conditional Access app control with Microsoft Defender for Cloud Apps, for custom apps with a non-Microsoft IdP.-ms.date: 06/16/2026+ms.date: 07/03/2026 ms.topic: how-to ms.reviewer: AmitMishaeli ai-usage: ai-assisted-ms.custom: msecd-doc-authoring-1014+ms.custom: msecd-doc-authoring-1016 --- # Onboard non-Microsoft IdP custom apps for Conditional Access app control@@ -18,6 +18,8 @@ This section explains how to configure your IdP to work with Defender for Cloud ## Prerequisites +Before you begin, make sure your environment meets the following requirements:+ - Your organization must have the following licenses to use conditional access app control: - The license required by your identity provider (IdP) solution@@ -30,7 +32,7 @@ This section explains how to configure your IdP to work with Defender for Cloud Add the admins who will onboard and maintain your apps for Conditional Access app control. -1. In Microsoft Defender XDR, select **Settings > Cloud Apps > Conditional Access App Control > App onboarding/maintenance**.+1. In the Defender portal, select **Settings > Cloud Apps > Conditional Access App Control > App onboarding/maintenance**. 1. Enter the usernames or emails of any users who will be onboarding your app, and then select **Save**. @@ -73,7 +75,7 @@ The following procedure describes how to route app sessions from other IdP solut > - Some identity providers do not allow you to change the SAML attributes or URL properties of a gallery / catalog app. > - When you configure a custom app, you can test the app with Defender for Cloud Apps access and session controls, without changing your organization's existing configured behavior. - Copy your app's single sign-on configuration information. You enter these values in your IdP configuration in a later step. When you're finished, select **Next** to continue.+ Copy your app's single sign-on configuration information. You enter these values when configuring your IdP's custom app settings in step 8 of this procedure. When you're finished, select **Next** to continue. 1. Continuing on the **IDENTITY PROVIDER** page of the wizard, either upload a metadata file from your IdP or enter app data manually. @@ -82,7 +84,7 @@ The following procedure describes how to route app sessions from other IdP solut - The **Single sign-on service URL**. This is the URL that your IdP uses to receive single sign-on requests. - A SAML certificate, if your IdP provides one. In such cases, select the **Use identity provider's SAML certificate** option, and then upload the certificate file. -1. Continuing on the **IDENTITY PROVIDER** page of the wizard, copy both the single sign-on URL and all attributes and values to enter in your IdP's custom app settings in the next step.+1. Continuing on the **IDENTITY PROVIDER** page of the wizard, copy both the single sign-on URL and all attributes and values to enter when configuring your IdP's custom app settings in step 8 of this procedure. When you're done, select **Next** to continue. @@ -152,8 +154,11 @@ For more information, see [App doesn't appear on the conditional access app cont ## Related content +For more information, see the following articles:+ - [Protect apps with Microsoft Defender for Cloud Apps Conditional Access app control](proxy-intro-aad.md) - [Deploy Conditional Access app control for catalog apps with non-Microsoft IdPs](proxy-deployment-featured-idp.md) - [Troubleshooting access and session controls](troubleshooting-proxy.md) -[!INCLUDE [Open support ticket](includes/support.md)]+> [!TIP]+> [!INCLUDE [Open support ticket](includes/support.md)] 