Microsoft Defender for Cloud Apps
Cloud and workloads

Secure OAuth apps with app governance hygiene features | Microsoft Defender for Cloud Apps

In brief

The documentation now uses clearer wording for finding unused apps and managing unused or expiring credentials, adds an example image of app hygiene policy conditions, and updates metadata.

What Defender admins need to know

Administrators can use the revised guidance and example when creating app hygiene policies.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Have you ever wanted to see thefind apps that your organization owns but isndoesn't using, but didn't know how to?use? Or clean up unused or expiring credentials more easily? Microsoft Entra ID includes recommendations to help you identify such apps, and theapps. The App governance page in Microsoft Defender provides an app hygiene feature suite that includeswith controls and insights on unused apps, unused credentials, and expiring credentials.

TheseApp hygiene features enable automatic control over theseflagged apps and provide extra app behavior context to help you determine the risk these apps poseeach app poses in your environment.

Watch this video for a brief explanation of the app hygiene features for unused apps, unused credentials, and expiring credentials:

App governance provides customizable policies for unused apps, apps with unused credentials, and apps with expiring credentials.

For example, create a policy to automatically disable any app that hasn’t been used in the past 90 days, has high privilege permissions, and can access priority accounts in Microsoft 365. Like all app governance alerts, these alerts are aggregated into incidents in your Microsoft Defender XDR alerts queue and flow to Advanced hunting and Microsoft Sentinel.

For example:The following image shows an example of policy conditions for an app hygiene policy:

:::image type="content" source="media/app-governance/edit-policy-conditions.png" alt-text="Screenshot of the Edit policy conditions page.":::

By staying on top ofClean up unused apps and expiring or unused app credentials and cleaning upto keep your SaaS app inventory,inventory lean. This helps you aren't only optimizing app usagecut SaaS spend and SaaS spend, but also, more importantly, keepingreduce your app attack surface in check.surface.

Next steps