Remediate OAuth app threats with app governance alerts
In brief
The page now refers to the Defender portal Alerts and Incidents pages, clarifies which approval, ban, notification, and permission-revocation procedures apply to Salesforce and Google Workspace, and improves screenshot descriptions.
What Defender admins need to know
Administrators can use the updated portal terminology and clearer scope guidance when investigating alerts and managing connected apps.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Remediate OAuth app threats with app governance alerts
You can investigate alerts about malicious cloud apps and apps that may present risks to your organization in the Microsoft Defender XDRportal Alerts or Incidents pages.
For example:
View alert details
By default, the Microsoft Defender XDRportal Alerts page lists new alerts generated by app governance based on threat detection rules and your active policies. View the details of a specific alert by selecting the alert. A page opens with additional information about the alert and options for managing the alert.
For example:
On the Google apps or Salesforce apps tabs, select the app to open the App pane and view more information about the app and the permissions it was granted.
For example:

Type the message you want to send to the app users in the Enter a custom notification message box. Select Ban app to send the mail, and ban the app from your connected app users.
To approve the app, select the approve icon at the end of the row in the table.

- The icon turns green, and the app is approved for all your connected app users.
- When you mark an app as approved, there's no effect on the end user. This color change is meant to help you see the apps that you've approved to separate them from ones that you haven't reviewed yet.
For Google Workspace and Salesforce, it's possible to revoke permission to an app or to notify the user that they should change the permission. When you revoke permission it removes all permissions that were granted to the application under "Enterprise Applications" in Microsoft Entra ID.
- On the Google apps or Salesforce apps tabs, select the three dots at the end of the app row and select Notify user. By default, the user is notified as follows: You authorized the app to access your Google Workspace account. This app conflicts with your organization's security policy. Reconsider giving or revoking the permissions you gave this app in your Google Workspace account. To revoke app access, go to: Google Workspace security permissions page Select the app and select 'Revoke access' on the right menu bar. You can customize the message that is sent.
@@ -1,16 +1,16 @@ --- title: Remediate OAuth app threats with app governance alerts-ms.date: 06/16/2026+ms.date: 07/03/2026 ms.topic: how-to description: Investigate and manage app governance alerts in Microsoft Defender XDR to identify risky or malicious cloud apps and take remediation actions. ms.reviewer: shragar-ms.custom: sfi-image-nochange, msecd-doc-authoring-1014+ms.custom: sfi-image-nochange, msecd-doc-authoring-1016 ai-usage: ai-assisted --- # Remediate OAuth app threats with app governance alerts -You can investigate alerts about malicious cloud apps and apps that may present risks to your organization in the Microsoft Defender XDR **Alerts** or **Incidents** pages.+You can investigate alerts about malicious cloud apps and apps that may present risks to your organization in the Defender portal **Alerts** or **Incidents** pages. For example: @@ -18,7 +18,7 @@ For example: ## View alert details -By default, the Microsoft Defender XDR **Alerts** page lists new alerts generated by app governance based on threat detection rules and your active policies. View the details of a specific alert by selecting the alert. A page opens with additional information about the alert and options for managing the alert.+By default, the Defender portal **Alerts** page lists new alerts generated by app governance based on threat detection rules and your active policies. View the details of a specific alert by selecting the alert. A page opens with additional information about the alert and options for managing the alert. For example: @@ -46,7 +46,7 @@ Based on app alert patterns, you can update the appropriate app policy and chang > [!Note]-> This section is only relevant for Salesforce and Google Workspace applications.+> The following app approval and ban procedures are only relevant for Salesforce and Google Workspace applications. 1. On the **Google apps** or **Salesforce apps** tabs, select the app to open **the App** pane and view more information about the app and the permissions it was granted. @@ -63,14 +63,14 @@ Based on app alert patterns, you can update the appropriate app policy and chang For example: - +  1. Type the message you want to send to the app users in the Enter a custom notification message box. Select **Ban app** to send the mail, and ban the app from your connected app users. 1. To approve the app, select the approve icon at the end of the row in the table. - +  - The icon turns green, and the app is approved for all your connected app users. - When you mark an app as approved, there's no effect on the end user. This color change is meant to help you see the apps that you've approved to separate them from ones that you haven't reviewed yet.@@ -79,7 +79,7 @@ Based on app alert patterns, you can update the appropriate app policy and chang > [!Note]-> This section is only relevant for Salesforce and Google Workspace applications.+> The following notification and permission revocation procedures are only relevant for Salesforce and Google Workspace applications. For Google Workspace and Salesforce, it's possible to revoke permission to an app or to notify the user that they should change the permission. When you revoke permission it removes all permissions that were granted to the application under "Enterprise Applications" in Microsoft Entra ID. 1. On the **Google apps** or **Salesforce apps** tabs, select the three dots at the end of the app row and select **Notify user**. By default, the user is notified as follows: *You authorized the app to access your Google Workspace account. This app conflicts with your organization's security policy. Reconsider giving or revoking the permissions you gave this app in your Google Workspace account. To revoke app access, go to: [Google Workspace security permissions page](https://security.google.com/settings/security/permissions?hl=en&pli=1) Select the app and select 'Revoke access' on the right menu bar.* You can customize the message that is sent. 