View and regulate OAuth app access to sensitive content with app governance | Microsoft Defender for Cloud Apps
In brief
The article now provides more detail on viewing access through app tabs, including Microsoft Entra apps, and simplifies the examples and instructions for configuring the built-in policy or creating a custom policy.
What Defender admins need to know
Administrators can use the clearer guidance to review sensitive-content access and adjust app policy scope or actions.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
View and regulate OAuth app access to sensitive content
App governance lets you quickly identify the Microsoft 365 services apps have accessed and if these apps have accessed content with sensitivity labels. This article explains how to view app access details, review sensitivity label exposure across services like SharePoint, OneDrive, and Exchange Online, and set up policies to regulate access to sensitive content.
View apps that access sensitive content
:::image type="content" source="media/app-governance-visibility-insights-sensitive-content/image7.png" alt-text="Screenshot of the Apps that accessed Microsoft Entra services card.":::
Alternatively,You can also select any of the labelsa label listed under Sensitivity labels access on one ofany app tab, such as the Microsoft Entra apps tabs. Under each service type, app tab. App governance then shows the number ofhow many times the app has accessed the correspondingthat label name in the last 30 days.days for each service type. For example:
:::image type="content" source="media/app-governance-visibility-insights-sensitive-content/sensitive-labels-details.png" alt-text="Screenshot of the Sensitivity labels tab on the Microsoft Entra apps tab.":::
ForIn this example, the screenshot of the Sensitivity labels tab shows that the app accessed content with the sensitivity label Highly confidential content seven times on SharePoint, 15 times on OneDrive, and 25 times on Exchange Online in the last 30 days.
Regulate access to sensitive content
By default, the predefinedThe built-in Access to sensitive data policy triggerssends alerts afterwhen an app accesses sensitive content.
Customize the predefinedYou can change this policy by:to:
SelectingSelect Disable app as thepolicyactionto automatically deactivateso that apps that triggeralerts.alerts are turned off.ModifyingChange the policy scope toapply the policy to specific appsinclude or exclude specific apps.
For even more customization options, create a custom policy usingpolicy. Use the condition Sensitivity labels accessed in combinationcondition with other custom policy conditions.
Next step
@@ -1,16 +1,16 @@ --- title: View and regulate OAuth app access to sensitive content with app governance | Microsoft Defender for Cloud Apps-ms.date: 06/16/2026+ms.date: 07/03/2026 ms.topic: how-to description: Identify which Microsoft 365 services apps access and determine whether they have accessed content protected with sensitivity labels. ms.reviewer: anandd512-ms.custom: sfi-image-nochange, msecd-doc-authoring-1014+ms.custom: sfi-image-nochange, msecd-doc-authoring-1016 ai-usage: ai-assisted --- # View and regulate OAuth app access to sensitive content -App governance lets you quickly identify the Microsoft 365 services apps have accessed and if these apps have accessed content with sensitivity labels.+App governance lets you quickly identify the Microsoft 365 services apps have accessed and if these apps have accessed content with sensitivity labels. This article explains how to view app access details, review sensitivity label exposure across services like SharePoint, OneDrive, and Exchange Online, and set up policies to regulate access to sensitive content. <a name="view-apps"></a> ## View apps that access sensitive content@@ -19,22 +19,22 @@ To view apps that have accessed data across Microsoft 365 services, select **Vie :::image type="content" source="media/app-governance-visibility-insights-sensitive-content/image7.png" alt-text="Screenshot of the Apps that accessed Microsoft Entra services card."::: -Alternatively, select any of the labels listed under **Sensitivity labels access** on one of the apps tabs. Under each service type, app governance shows the number of times the app has accessed the corresponding label name in the last 30 days. For example:+You can also select a label listed under **Sensitivity labels access** on any app tab, such as the **Microsoft Entra apps** tab. App governance then shows how many times the app accessed that label in the last 30 days for each service type. For example: :::image type="content" source="media/app-governance-visibility-insights-sensitive-content/sensitive-labels-details.png" alt-text="Screenshot of the Sensitivity labels tab on the Microsoft Entra apps tab."::: -For example, the screenshot of the Sensitivity labels tab shows that the app accessed content with the sensitivity label *Highly confidential* seven times on SharePoint, 15 times on OneDrive, and 25 times on Exchange Online in the last 30 days.+In this example, the app accessed *Highly confidential* content seven times on SharePoint, 15 times on OneDrive, and 25 times on Exchange Online in the last 30 days. ## Regulate access to sensitive content -By default, the predefined **Access to sensitive data** policy triggers alerts after an app accesses sensitive content.+The built-in **Access to sensitive data** policy sends alerts when an app accesses sensitive content. -Customize the predefined policy by:+You can change this policy to: -- Selecting **Disable app** as the policy action to automatically deactivate apps that trigger alerts.-- Modifying the policy scope to apply the policy to specific apps or exclude specific apps.+- Select **Disable app** as the action so that apps that trigger alerts are turned off.+- Change the policy scope to include or exclude specific apps. -For even more customization options, create a custom policy using the condition **Sensitivity labels accessed** in combination with [custom policy conditions](app-governance-app-policies-create.md#custom-policies).+For more options, create a custom policy. Use the **Sensitivity labels accessed** condition with other [custom policy conditions](app-governance-app-policies-create.md#custom-policies). ## Next step 