Microsoft Defender for Cloud Apps
Troubleshooting

Troubleshoot access and session controls for admins | Microsoft Defender for Cloud Apps

In brief

The guide now explains how to determine whether Conditional Access App Control or Defender for Endpoint caused a block, and how to use sign-in logs, the Defender activity log, policy settings, and the Admin View toolbar to investigate.

What Defender admins need to know

Administrators can use these steps to identify the blocking policy or setting and diagnose access issues.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Troubleshooting access and session controls for admin users

Issue type Issues
Unexpected website blocksIdentify the policy or control that blocked access
Network condition issues Network errors when navigating to a browser page

Slow sign-ins

More considerations for network conditions
Device identification issues Misidentified Intune Compliant or Microsoft Entra hybrid joined devices

Client certificates aren't prompting when expected

Client certificates aren't prompting when expected
Client certificates are prompting at every sign-in

More considerations for device identification
Issues when onboarding an app App doesn't appear on the conditional access app control apps page

App status: Continue Setup Can't configure controls for native apps

Request session control option appears
Issues when creating access and session policies In Conditional Access policies, you can't see the conditional access app control option

Error message when creating a policy: You don't have any apps deployed with conditional access app control

Can't create session policies for an app

Can't choose Inspection Method: Data Classification Service

Can't choose Action: Protect

More considerations for onboarding apps
Diagnose and troubleshoot with the Admin View toolbar Bypass proxy session

Record a session

Add domains for your app

Troubleshoot an unexpected website block

When a user sees This website is blocked by your organization, first determine whether Conditional Access App Control enforced the block:

If neither indicator is present and the entire website or domain is blocked, the block might come from an app marked as Unsanctioned and enforced by Defender for Endpoint. For more information, see Govern discovered apps using Defender for Endpoint.

To identify the Conditional Access App Control policy that caused the block:

  1. In the Microsoft Entra sign-in logs, open the affected sign-in and review the Conditional Access details. Identify the Conditional Access policy that applied the Use Conditional Access App Control session control. For more information, see View applied Conditional Access policies in sign-in logs.

  2. On the Activity log page in the Microsoft Defender portal at https://security.microsoft.com/cloudapps/activity-log, filter by the affected user, app, and time of the block. Open the blocked activity to identify the access or session policy that matched. For more information, see Investigate activities in Defender for Cloud Apps.

  3. Review the matched policy's users, apps, device tags, locations, and other conditions. An access or session policy with no app filter applies to all apps enabled for Conditional Access App Control.

  4. If no policy explains the block, review the Default behavior setting for service disruptions. A setting of Block access can block sessions when normal policy enforcement isn't available.

  5. To confirm that the proxy caused the problem, use the Admin View toolbar and select Bypass experience. If bypassing restores access, review the policy conditions before you re-enable enforcement. You can also record the session to provide diagnostic information to Microsoft Support.

Network condition issues

Common network condition issues you might encounter include: