Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Use app governance with Microsoft Defender for Cloud Apps in the Defender portal to:
Monitor the threat alerts generated by built-in app governance detection methods for malicious app activities and policy-based alerts generated by active app policies that you create.
These alerts can indicate anomalies in app activity and when noncompliant, malicious, or risky apps are used. You can also use patterns in alerts to create new app policies or modify the settings of existing policies for more restrictive actions.
Remediate alerts, either manually after investigation, or automatically through the action settings on active app policies.
Supported roles
For more information, see App governance administrator roles.
View alerts
App governance generates alerts using various mechanisms. Threat detection alerts use built-in, machine-learning-driven detection rules to find malicious app attributes and activities. Policy-based alerts are triggered either by predefined policies or user-defined policies.
To view the latest incidents associated with these alerts, go to the App governance > Overview tab in Microsoft Defender XDR.
For example:
On the Overview tab, the Latest alerts section lists the most recent alerts. You can use these recent alerts to quickly see the current app alert activity for your tenant.
To see all of the alerts, select the Alerts tab.
Alerts page
App governance alerts are listed with all other Microsoft Defender XDR alerts. To find them, filter for "App governance" as the service source.
For example:
Monitor and respond to apps with unusual data usage
App governance provides data usage information that can help you identify unwanted and potentially malicious app activity.
Data usage card
The Data usage card provides total data usage over time, highlighting sudden spikes in total upload and download activity of all apps that access Microsoft 365 resources.
This card provides usage information separately for various resources, such as files and email, so you can pinpoint the resources that apps might be misusing.
App details pane
Located on the right of an apps tab when you select an app, an app details pane provides app-specific data usage information by resource type and upload and download patterns over time.
Policy conditions
Create policies that automatically flag and deactivate apps whose data usage matches the following conditions:
- Data usage: The total number of downloads and uploads exceeds your specified threshold
- Data usage trend: The percentage increase in the total number of downloads and uploads compared to the previous day reaches your specified threshold
Monitoring unusual data usage can help detect:
- Sudden spikes in application activity.
- Potential misuse of applications accessing Microsoft 365 data.
- Applications that might be transferring unusually large volumes of data.