Microsoft Defender for Cloud Apps
Cloud and workloads

Remediate OAuth app threats with app governance alerts

In brief

The page now refers to the Defender portal Alerts and Incidents pages, clarifies which approval, ban, notification, and permission-revocation procedures apply to Salesforce and Google Workspace, and improves screenshot descriptions.

What Defender admins need to know

Administrators can use the updated portal terminology and clearer scope guidance when investigating alerts and managing connected apps.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Remediate OAuth app threats with app governance alerts

You can investigate alerts about malicious cloud apps and apps that may present risks to your organization in the Microsoft Defender XDRportal Alerts or Incidents pages.

For example:

View alert details

By default, the Microsoft Defender XDRportal Alerts page lists new alerts generated by app governance based on threat detection rules and your active policies. View the details of a specific alert by selecting the alert. A page opens with additional information about the alert and options for managing the alert.

For example:

  1. On the Google apps or Salesforce apps tabs, select the app to open the App pane and view more information about the app and the permissions it was granted.

    For example:

    Screenshot of the Ban app confirmation dialog with options to notify users before blocking the app.

  2. Type the message you want to send to the app users in the Enter a custom notification message box. Select Ban app to send the mail, and ban the app from your connected app users.

  3. To approve the app, select the approve icon at the end of the row in the table.

    Screenshot of the Approve app control for marking an app as allowed for connected app users.

    • The icon turns green, and the app is approved for all your connected app users.
    • When you mark an app as approved, there's no effect on the end user. This color change is meant to help you see the apps that you've approved to separate them from ones that you haven't reviewed yet.

For Google Workspace and Salesforce, it's possible to revoke permission to an app or to notify the user that they should change the permission. When you revoke permission it removes all permissions that were granted to the application under "Enterprise Applications" in Microsoft Entra ID.

  1. On the Google apps or Salesforce apps tabs, select the three dots at the end of the app row and select Notify user. By default, the user is notified as follows: You authorized the app to access your Google Workspace account. This app conflicts with your organization's security policy. Reconsider giving or revoking the permissions you gave this app in your Google Workspace account. To revoke app access, go to: Google Workspace security permissions page Select the app and select 'Revoke access' on the right menu bar. You can customize the message that is sent.