Microsoft Defender for Cloud Apps
Developer and API

Secure OAuth apps accessing non-Graph APIs using app governance

In brief

The article now has an Overview section and revised wording explaining visibility into OAuth apps that access Microsoft Graph and other APIs. It also clarifies that the Permissions tab lists Graph and non-Graph API permissions.

What Defender admins need to know

Administrators can use the updated guidance to better understand app visibility and review API permissions.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Secure OAuth apps accessing non-Graph APIs using app governance

Overview

Many apps use APIs other than Microsoft Graph to access Microsoft 365 and other resources. With visibility over such apps, you can identify and defend against risks inherent to these apps, including the APIs that theythe apps access. Some of thesenon-Microsoft Graph APIs might receive limited support and updates.

App governance provides visibility over OAuth apps registered on Microsoft Entra ID, regardless of whether they access Graph API or other APIs. Additionally, you can monitor these apps and automatically take action if they'rethe apps are noncompliant or exhibit suspicious behavior.

You can better protect your organization with the new functionalities and enhancements in the following ways:

View APIs used by an app

The Permissions tab in the app details pane showslists all permissions granted to an app, including both Graph API and non-Graph API permissions. To view the APIs that an app uses:

  1. In the App governance page, select the app you want to investigate.

  2. In the app details pane, select the Permissions tab.

The Permissions tab lists all permissions granted to the app, including Graph API permissions and non-Graph API permissions.

:::image type="content" source="media/app-governance-secure-apps-access-non-graph-api/other-apis-permissions.png" alt-text="Screenshot that shows the list of APIs and their assigned permissions." lightbox="media/app-governance-secure-apps-access-non-graph-api/other-apis-permissions.png":::

Create policies for apps accessing non-graph APIs