Microsoft Defender for Cloud Apps
Cloud and workloads

US Government offerings

In brief

The page date changed to August 7, 2026. The documented list now retains only app metadata associated with a known phishing campaign; three other examples were removed.

What Defender admins need to know

Review internal references that rely on the previous examples.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Microsoft Defender for Cloud Apps for US Government offerings

  • App performed drive enumeration

  • App redirects to phishing URL by exploiting OAuth redirection vulnerability

  • App with bad URL reputation

  • App with suspicious OAuth scope made graph calls to read email and created inbox rule

  • App impersonating a Microsoft logo

  • App is associated with a typosquatted domain

  • App metadata associated with known phishing campaign

  • App metadata associated with previously flagged suspicious apps