Microsoft Defender for Cloud Apps
Architecture and deployment

Onboard non-Microsoft IdP custom apps for Conditional Access app control | Microsoft Defender for Cloud Apps

In brief

The procedure now refers to the Defender portal, points SSO configuration details to step 8, adds a “Before you begin” section, and formats the support link as a tip.

What Defender admins need to know

Administrators following the procedure get clearer navigation and setup guidance; no configuration change is specified.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Onboard non-Microsoft IdP custom apps for Conditional Access app control

Prerequisites

Before you begin, make sure your environment meets the following requirements:

  • Your organization must have the following licenses to use conditional access app control:

    • The license required by your identity provider (IdP) solution

Add the admins who will onboard and maintain your apps for Conditional Access app control.

  1. In Microsoftthe Defender XDR,portal, select Settings > Cloud Apps > Conditional Access App Control > App onboarding/maintenance.

  2. Enter the usernames or emails of any users who will be onboarding your app, and then select Save.

    • Some identity providers do not allow you to change the SAML attributes or URL properties of a gallery / catalog app.
    • When you configure a custom app, you can test the app with Defender for Cloud Apps access and session controls, without changing your organization's existing configured behavior.

    Copy your app's single sign-on configuration information. You enter these values inwhen configuring your IdP configuration's custom app settings in a later step.step 8 of this procedure. When you're finished, select Next to continue.

  3. Continuing on the IDENTITY PROVIDER page of the wizard, either upload a metadata file from your IdP or enter app data manually.

    • The Single sign-on service URL. This is the URL that your IdP uses to receive single sign-on requests.
    • A SAML certificate, if your IdP provides one. In such cases, select the Use identity provider's SAML certificate option, and then upload the certificate file.
  4. Continuing on the IDENTITY PROVIDER page of the wizard, copy both the single sign-on URL and all attributes and values to enter inwhen configuring your IdP's custom app settings in the next step.step 8 of this procedure.

    When you're done, select Next to continue.

Related content

For more information, see the following articles:

[!INCLUDE