Secure OAuth apps with app governance hygiene features | Microsoft Defender for Cloud Apps
In brief
The documentation now uses clearer wording for finding unused apps and managing unused or expiring credentials, adds an example image of app hygiene policy conditions, and updates metadata.
What Defender admins need to know
Administrators can use the revised guidance and example when creating app hygiene policies.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Have you ever wanted to see thefind apps that your organization owns but isndoesn't using, but didn't know how to?use? Or clean up unused or expiring credentials more easily? Microsoft Entra ID includes recommendations to help you identify such apps, and theapps. The App governance page in Microsoft Defender provides an app hygiene feature suite that includeswith controls and insights on unused apps, unused credentials, and expiring credentials.
TheseApp hygiene features enable automatic control over theseflagged apps and provide extra app behavior context to help you determine the risk these apps poseeach app poses in your environment.
Watch this video for a brief explanation of the app hygiene features for unused apps, unused credentials, and expiring credentials:
App governance provides customizable policies for unused apps, apps with unused credentials, and apps with expiring credentials.
For example, create a policy to automatically disable any app that hasn’t been used in the past 90 days, has high privilege permissions, and can access priority accounts in Microsoft 365. Like all app governance alerts, these alerts are aggregated into incidents in your Microsoft Defender XDR alerts queue and flow to Advanced hunting and Microsoft Sentinel.
For example:The following image shows an example of policy conditions for an app hygiene policy:
:::image type="content" source="media/app-governance/edit-policy-conditions.png" alt-text="Screenshot of the Edit policy conditions page.":::
By staying on top ofClean up unused apps and expiring or unused app credentials and cleaning upto keep your SaaS app inventory,inventory lean. This helps you aren't only optimizing app usagecut SaaS spend and SaaS spend, but also, more importantly, keepingreduce your app attack surface in check.surface.
Next steps
@@ -1,11 +1,11 @@ --- title: Secure OAuth apps with app governance hygiene features | Microsoft Defender for Cloud Apps-ms.date: 06/16/2026+ms.date: 07/03/2026 ms.topic: how-to description: Use app governance hygiene features to identify unused apps, manage unused credentials, and review expiring credentials in Microsoft Defender. ms.reviewer: anandd512 ai-usage: ai-assisted-ms.custom: msecd-doc-authoring-1014+ms.custom: msecd-doc-authoring-1016 --- @@ -14,9 +14,9 @@ ms.custom: msecd-doc-authoring-1014 > [!NOTE] > Management of unused credentials and expiring credentials is available to app governance customers with a Microsoft Entra Workload ID Premium license. For more information, see [What are workload identities?](/azure/active-directory/workload-identities/workload-identities-overview) -Have you ever wanted to see the apps that your organization owns but isn't using, but didn't know how to? Or clean up unused or expiring credentials more easily? Microsoft Entra ID includes recommendations to help you identify such apps, and the **App governance** page in Microsoft Defender provides an app hygiene feature suite that includes controls and insights on unused apps, unused credentials, and expiring credentials. +Have you ever wanted to find apps that your organization owns but doesn't use? Or clean up unused or expiring credentials more easily? Microsoft Entra ID includes recommendations to help you identify such apps. The **App governance** page in Microsoft Defender provides an app hygiene feature suite with controls and insights on unused apps, unused credentials, and expiring credentials. -These features enable automatic control over these apps and provide extra app behavior context to help you determine the risk these apps pose in your environment.+App hygiene features enable automatic control over flagged apps and provide extra behavior context to help you determine the risk each app poses in your environment. Watch this video for a brief explanation of the app hygiene features for unused apps, unused credentials, and expiring credentials: @@ -38,13 +38,13 @@ App governance allows you to sort and filter on app last used date, credential u App governance provides customizable policies for unused apps, apps with unused credentials, and apps with expiring credentials. -For example, create a policy to automatically disable any app that hasn’t been used in the past 90 days, has high privilege permissions, and can access [priority accounts in Microsoft 365](/microsoft-365/admin/setup/priority-accounts). Like all app governance alerts, these alerts are aggregated into incidents in your Microsoft Defender XDR alerts queue and flow to Advanced hunting and Microsoft Sentinel.+For example, create a policy to automatically disable any app that hasn’t been used in the past 90 days, has high privilege permissions, and can access [priority accounts in Microsoft 365](/microsoft-365/admin/setup/priority-accounts). Like all app governance alerts, these alerts are aggregated into incidents in your Defender alerts queue and flow to Advanced hunting and Microsoft Sentinel. -For example:+The following image shows an example of policy conditions for an app hygiene policy: :::image type="content" source="media/app-governance/edit-policy-conditions.png" alt-text="Screenshot of the Edit policy conditions page."::: -By staying on top of unused apps and expiring or unused app credentials and cleaning up your SaaS app inventory, you aren't only optimizing app usage and SaaS spend, but also, more importantly, keeping your app attack surface in check.+Clean up unused apps and expiring credentials to keep your SaaS app inventory lean. This helps you cut SaaS spend and reduce your app attack surface. ## Next steps 