Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRHard
An organization uses Microsoft Defender for Cloud Apps (MDCAS) to monitor cloud application usage. They have identified several unapproved cloud storage applications being used by employees. They want to prevent sensitive corporate data from being uploaded to these unapproved cloud storage apps, while still allowing access to sanctioned cloud apps. Which MDCAS control should be configured to enforce this policy?
- AFile policy
- BCloud Discovery policy
- CActivity policy
- DSession policy
Show answer & explanationAnswer & explanation
Correct answer: D. Session policy
Session policies in MDCAS are used to control activities within sessions, including preventing uploads or downloads of sensitive data to/from unapproved applications in real-time, while still allowing access for other activities. This directly addresses the requirement to prevent sensitive data uploads to unapproved apps.
Why the other options are wrong
- A. File policies can scan files at rest or as they are uploaded/downloaded, but 'session policy' provides more granular, real-time control over the 'upload' action itself within a session to unapproved apps.
- B. Cloud Discovery policies identify and categorize cloud apps, but do not enforce real-time controls on data uploads.
- C. Activity policies detect specific activities, but 'session policies' provide the real-time, inline control to *prevent* an action like 'upload' to unapproved apps.
MDCAS Session Policies
MDCAS Session Policies allow real-time control over user sessions in cloud apps, enabling actions like blocking uploads/downloads of sensitive data, or monitoring specific activities.
- Enforces control during an active session.
- Can block specific actions (e.g., upload, download, copy/paste).
- Integrates with Conditional Access App Control.
Memory trick: To control what happens *during* a session, you need a 'Session' policy, like a traffic cop for your cloud apps.