Microsoft Defender for Cloud Apps
Cloud and workloads

View your OAuth app details with app governance | Microsoft Defender for Cloud Apps

In brief

The article adds descriptive tab headings and anchors, clarifies role and admin-consent terminology, expands Exchange Web Services (EWS), and standardizes descriptions of app detail tabs.

What Defender admins need to know

Administrators can more easily link to and interpret app governance details; no action is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Prerequisites

Your sign-in account must have one of the required app governance roles to view app governance data.

View the apps in your tenant

Company administrators can use the Disable app and Enable app controls in the details pane to enable or disable an app.

Review app details on the Summary tab

ShowsThe Summary tab shows more data about the app, such as the date first consented and the App ID. To see the properties of the app as registered in Microsoft Entra ID, select View in Microsoft Entra ID.

:::image type="content" source="media/app-governance-visibility-insights-view-apps/app-governance-app-summary.png" alt-text="Screenshot of an app details pane with the Summary tab showing." lightbox="media/app-governance-visibility-insights-view-apps/app-governance-app-summary.png":::

Review risk details on the Risk score tab

ShowsThe Risk score tab shows a 1-100 risk score for the app, where higher values mean greater risk. The risk score helps you quickly prioritize which apps need attention first. The Risk scoretab also shows the risk summary, including the factors behind the app's risk score.

:::image type="content" source="media/app-governance-visibility-insights-view-apps/app-governance-app-risk-score.png" alt-text="Screenshot of an app details pane with the Risk score tab showing." lightbox="media/app-governance-visibility-insights-view-apps/app-governance-app-risk-score.png":::

Review app connections on the Graph tab

The Graph tab shows a visual identity graph that illustrates how the app connects to other entities in your organization, like users, resources, SaaS workloads, and critical assets. Select any node or edge in the graph to open a details pane with deeper context. When applicable, the graph details pane also shows attack paths involving the selected nodes or edges. To explore further, select View in map below the graph to open the full Attack Map experience in a new window.

The graph can also surface the AI agent behind an app. For OAuth apps tied to Microsoft Copilot Studio agents, expand the OAuth app node to view the connected agent.

:::image type="content" source="media/app-governance-visibility-insights-view-apps/app-governance-app-graph.png" alt-text="Screenshot of an app details pane with the Graph tab showing." lightbox="media/app-governance-visibility-insights-view-apps/app-governance-app-graph.png":::

Review app activity on the Data usage tab

The Data usage tab shows a graph of data usage over time, for Exchange, SharePoint, OneDrive, and Teams resources via Microsoft Graph and Exchange Web Services (EWS) APIs. The Data usage tab supports filtering usage insights by priority accounts only.

:::image type="content" source="media/app-governance-visibility-insights-view-apps/app-governance-app-data-usage.png" alt-text="Screenshot of the Data usage tab." lightbox="media/app-governance-visibility-insights-view-apps/app-governance-app-data-usage.png":::

Review user access on the Users tab

The Users tab shows a list of users who are using the app, whether they're a priority account, and the amount of data downloaded and uploaded.

If an app has been granted admin consent (approved for the entire organization by an administrator), the Total consented users are all users in the tenant.

:::image type="content" source="media/app-governance-visibility-insights-view-apps/app-governance-app-users.png" alt-text="Screenshot of an app details pane with the Users tab showing." lightbox="media/app-governance-visibility-insights-view-apps/app-governance-app-users.png":::

Review app permissions on the Permissions tab

The Permissions tab shows a summary and list of the Graph API and legacy permissions granted to the app, consent type, privilege level, and whether they're in use. This also shows the Microsoft Entra roles granted to the app, including its type (built-in or custom), privilege level, and whether it grants tenant-wide access. Select a role to view its granular permissions, descriptions, and privilege levels.

For more information, see the Microsoft Graph permissions reference.

Review sensitivity labels on the Sensitivity labels tab

ShowsThe Sensitivity labels tab shows how frequently items with certain sensitivity labels were accessed by the app on Microsoft 365.

:::image type="content" source="media/app-governance-visibility-insights-view-apps/app-governance-app-sensitive-labels-details.png" alt-text="Screenshot of the Sensitivity labels tab." lightbox="media/app-governance-visibility-insights-view-apps/app-governance-app-sensitive-labels-details.png":::