What's changed: Created SC-300 Chapter 4 (Domain 3: workload identity selection/managed identities (system/user-assigned)/service principals/gMSA; enterprise apps (SSO/Application Proxy/app-role assignment/consent policies/admin consent workflow); app registrations (redirect URIs/secret-certificate-federated credentials/delegated-application permissions/app roles); Defender for Cloud Apps (cloud discovery/Cloud app catalog/OAuth app policies/CA app control/access-session policies)).
4.4Managing app access with Defender for Cloud Apps
Understand Microsoft Defender for Cloud Apps (CASB): cloud discovery, connected apps, app-enforced restrictions, Conditional Access app control, access/session policies, OAuth app policies, and the Cloud app catalog.
Microsoft Defender for Cloud Apps (CASB) gives visibility and control over app "usage": discovering SaaS shadow IT and controlling in-session actions (downloads, etc.).
4.4.1Cloud discovery and OAuth app governance
Cloud discovery finds and risk-scores employees’ shadow-IT SaaS from firewall/proxy logs or Defender for Endpoint integration, and you sanction/unsanction via the Cloud app catalog. OAuth app policies then detect/revoke excessive or abused permissions of third-party apps users consented to (operationally complementing the previous section’s consent governance).
4.4.2Conditional Access app control and session policies
Conditional Access app control integrates CA with Defender for Cloud Apps to control sessions in real time via proxy. You can create access policies (allow/block sign-in) and session policies (control in-session actions: block download/copy, apply labels, monitor). Fine requirements like "from unmanaged devices allow view-only and block download" are met with session policies, not CA alone.
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

