Microsoft Defender for Cloud Apps
Cloud and workloads

View and regulate OAuth app access to sensitive content with app governance | Microsoft Defender for Cloud Apps

In brief

The article now provides more detail on viewing access through app tabs, including Microsoft Entra apps, and simplifies the examples and instructions for configuring the built-in policy or creating a custom policy.

What Defender admins need to know

Administrators can use the clearer guidance to review sensitive-content access and adjust app policy scope or actions.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

View and regulate OAuth app access to sensitive content

App governance lets you quickly identify the Microsoft 365 services apps have accessed and if these apps have accessed content with sensitivity labels. This article explains how to view app access details, review sensitivity label exposure across services like SharePoint, OneDrive, and Exchange Online, and set up policies to regulate access to sensitive content.

View apps that access sensitive content

:::image type="content" source="media/app-governance-visibility-insights-sensitive-content/image7.png" alt-text="Screenshot of the Apps that accessed Microsoft Entra services card.":::

Alternatively,You can also select any of the labelsa label listed under Sensitivity labels access on one ofany app tab, such as the Microsoft Entra apps tabs. Under each service type, app tab. App governance then shows the number ofhow many times the app has accessed the correspondingthat label name in the last 30 days.days for each service type. For example:

:::image type="content" source="media/app-governance-visibility-insights-sensitive-content/sensitive-labels-details.png" alt-text="Screenshot of the Sensitivity labels tab on the Microsoft Entra apps tab.":::

ForIn this example, the screenshot of the Sensitivity labels tab shows that the app accessed content with the sensitivity label Highly confidential content seven times on SharePoint, 15 times on OneDrive, and 25 times on Exchange Online in the last 30 days.

Regulate access to sensitive content

By default, the predefinedThe built-in Access to sensitive data policy triggerssends alerts afterwhen an app accesses sensitive content.

Customize the predefinedYou can change this policy by:to:

  • SelectingSelect Disable app as the policy action to automatically deactivateso that apps that trigger alerts.alerts are turned off.
  • ModifyingChange the policy scope to apply the policy to specific appsinclude or exclude specific apps.

For even more customization options, create a custom policy usingpolicy. Use the condition Sensitivity labels accessed in combinationcondition with other custom policy conditions.

Next step