Turn on app governance in Microsoft Defender for Cloud Apps
In brief
The guide updates metadata, clarifies licensing, prerequisite, and role headings, and revises references from Microsoft Defender XDR to the Defender portal and Microsoft Defender.
What Defender admins need to know
Use the updated section names and portal terminology when following the guide; no administrator action is specified.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Before you start, verify that you satisfy the following prerequisites:
Microsoft Defender for Cloud Apps must be present in your account as either a standalone product or as part of the various licensing requirements packages.
If you aren't already a Defender for Cloud Apps customer, you can sign up for a free trial.
Your organization's billing address must be in a region other than Singapore, Poland, Italy, Qatar, Israel, Spain, Mexico and Taiwan.
Turn on app governance
If your organization satisfies the app governance prerequisites, go to Microsoft Defender XDR > Settings > Cloud Apps > App governance and select Use app governance. For example:
:::image type="content" source="media/app-governance-get-started/app-governance-service-status2.png" alt-text="Screenshot of the App governance toggle in Microsoft Defender XDR." lightbox="media/app-governance-get-started/app-governance-service-status2.png":::
:::image type="content" source="media/app-governance-get-started/app-governance-service-status.png" alt-text="Screenshot of the App governance waitlist option." lightbox="media/app-governance-get-started/app-governance-service-status.png":::
Licensing requirements
App governance is available to organizations with a valid Defender for Cloud Apps license. For more information, see the Microsoft 365 licensing datasheet.
RolesRequired roles
You must have at least one of these roles to turn on app governance:
For more information about each role, see Administrator role permissions.
@@ -1,10 +1,10 @@ --- title: Turn on app governance in Microsoft Defender for Cloud Apps-ms.date: 06/16/2026+ms.date: 07/03/2026 ms.topic: how-to ms.reviewer: anandd512 description: Get started with app governance capabilities to govern your apps in Microsoft Defender for Cloud Apps.-ms.custom: sfi-ga-nochange, msecd-doc-authoring-1014+ms.custom: sfi-ga-nochange, msecd-doc-authoring-1016 ai-usage: ai-assisted --- @@ -16,7 +16,7 @@ This article describes how to turn on Microsoft Defender for Cloud Apps app gove Before you start, verify that you satisfy the following prerequisites: -- Microsoft Defender for Cloud Apps must be present in your account as either a standalone product or as part of the various [license](#licensing) packages.+- Microsoft Defender for Cloud Apps must be present in your account as either a standalone product or as part of the various [licensing requirements](#licensing) packages. If you aren't already a Defender for Cloud Apps customer, you can [sign up for a free trial](https://www.microsoft.com/security/business/cloud-apps-defender). @@ -25,13 +25,13 @@ Before you start, verify that you satisfy the following prerequisites: - Your organization's billing address must be in a region **other than** Singapore, Poland, Italy, Qatar, Israel, Spain, Mexico and Taiwan. > [!IMPORTANT]-> Connect to Microsoft 365 connector to get visibility into activities and specific resources accessed by OAuth apps in the Microsoft Defender XDR advanced hunting blade. This will enhance your ability to investigate and respond to certain threat detection policy alerts generated by app governance.+> Connect to Microsoft 365 connector to get visibility into activities and specific resources accessed by OAuth apps in the Defender portal advanced hunting blade. This will enhance your ability to investigate and respond to certain threat detection policy alerts generated by app governance. > > Learn how to [connect to the Microsoft 365 connector](/defender-cloud-apps/protect-office-365). ## Turn on app governance -If your organization satisfies the [prerequisites](#prerequisites), go to [Microsoft Defender XDR > Settings > Cloud Apps > App governance](https://security.microsoft.com/cloudapps/settings) and select **Use app governance**. For example:+If your organization satisfies the [app governance prerequisites](#prerequisites), go to [Microsoft Defender XDR > Settings > Cloud Apps > App governance](https://security.microsoft.com/cloudapps/settings) and select **Use app governance**. For example: :::image type="content" source="media/app-governance-get-started/app-governance-service-status2.png" alt-text="Screenshot of the App governance toggle in Microsoft Defender XDR." lightbox="media/app-governance-get-started/app-governance-service-status2.png"::: @@ -48,11 +48,13 @@ For example: :::image type="content" source="media/app-governance-get-started/app-governance-service-status.png" alt-text="Screenshot of the App governance waitlist option." lightbox="media/app-governance-get-started/app-governance-service-status.png"::: -## Licensing+<a name="licensing"></a>+## Licensing requirements App governance is available to organizations with a valid Defender for Cloud Apps license. For more information, see the [Microsoft 365 licensing datasheet](https://aka.ms/M365EnterprisePlans). -## Roles+<a name="roles"></a>+## Required roles You must have at least one of these roles to turn on app governance: @@ -78,7 +80,7 @@ The following table lists the app governance capabilities for each role. For more information about each role, see [Administrator role permissions](/azure/active-directory/roles/permissions-reference). > [!NOTE]-> App governance alerts won't flow to Microsoft Defender XDR or show up in app governance until you have provisioned both Defender for Cloud Apps and Microsoft Defender XDR by accessing their respective portals at least once.+> App governance alerts won't flow to Microsoft Defender or show up in app governance until you have provisioned both Defender for Cloud Apps and Microsoft Defender by accessing their respective portals at least once. > > The Cloud App Security Admin role grants permissions turn on app governance for Microsoft Defender for Cloud Apps. However, this role doesn't grant access to view or manage app governance capabilities. To view or manage app governance capabilities, you must also have one of the other roles listed in the table below. > 