Loading...

Protect your sensitive data against malicious apps

Protect your sensitive data against malicious apps

Protecting sensitive content is a top priority for security and compliance administrators across all organizations. With Microsoft Purview Information Protection, you have the ability to track and regulate user access to content with sensitivity labels. However, with the accelerated adoption of apps and the evolution of our threat landscape, administrators need to ensure that the same protection of the sensitivity content available to users is also available to the apps running in their organization.

 

We wanted to share more details around the recent feature rollout for insights and remediation for sensitive content identified by Microsoft Purview Information Protection labels in the Microsoft Defender for Cloud Apps add-on, App governance. Enterprise admins now have visibility into the workloads that these apps access and whether they access sensitive data in these workloads.

 

With predefined and custom policies, admins are alerted about apps that have attempted to access sensitive data. Moreover, App governance can automatically deactivate noncompliant apps. App governance provides additional app-specific context for allowing or disallowing access to sensitive data. It provides security administrators with more insights into related app activity and the ability to automatically regulate apps.   

 

Overview of the insights and remediation for sensitive content feature:

 

  1. Insights about data access on Microsoft 365: We provide insights on how much content—sensitive or not—is being accessed through 3rd-party and line-of-business (LOB) OAuth apps on SharePoint (sites, files), OneDrive, Exchange Online, and Teams.  
     
    Avahidnia_4-1672877999783.png 

 

  1. Insights on sensitive content: We provide insights on OAuth apps that access various types of sensitive data as identified by Information Protection sensitivity labels on SharePoint (sites, files), OneDrive, Exchange Online, and Teams.  

 

Avahidnia_5-1672877999789.png

 

  1. Policies for monitoring & auto-remediation: We added a new policy condition to flag apps that access sensitive data. This new condition can be combined to track access to sensitive data by apps with other risky attributes. Security admins can choose to configure policies so that apps are automatically deactivated based on their risk tolerance. 
  2. Integration with Secure Score: We released a predefined policy that security admins can use to quickly boost their visibility and control over noncompliant apps accessing sensitive data. With a corresponding Secure Score recommendation, security admins can harden their security posture with the right policy. 

As organizations continue to implement new capabilities for SaaS app protection, it is critical to maintain a strong data loss prevention strategy. With the app governance insights and remediation for sensitive content feature, companies will be able to get deeper protection for apps accessing data on behalf of another application.

 

Get Started

App governance is an add-on feature for Microsoft Defender for Cloud Apps.

Published on:

Learn more
Need help with this product?

We can help you with Protect your sensitive data against malicious apps

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

Microsoft 365 Defender Blog articles
Microsoft 365 Defender Blog articles

Microsoft 365 Defender Blog articles

Share post:

Related posts

Monthly news - November 2024

Microsoft Defender XDRMonthly newsNovember 2024 Edition This is our monthly "What's new" blog post, summarizing product updates and v...

1 year ago

Monthly news - August 2024

Microsoft Defender XDRMonthly newsAugust 2024 Edition This is our monthly "What's new" blog post, summarizing product updates and var...

1 year ago

Defender for Identity: the critical role of identities in automatic attack disruption

In today's digital landscape, cyber-threats are becoming increasingly sophisticated and frequent. Advanced attacks are often multi-workload an...

1 year ago

New Security Copilot skill: Identity Summary

“Can you summarize Defender insights about this user over the last two days?” Microsoft’s latest innovation for Copilot for Security, sim...

1 year ago

Demystify potential data leaks with Insider Risk Management insights in Defender XDR

In today's complex security landscape, understanding and mitigating data exfiltration risks is more critical than ever. Earlier this year, we ...

1 year ago

Monthly news - October 2024

Microsoft Defender XDRMonthly newsOctober 2024 Edition This is our monthly "What's new" blog post, summarizing product updates and va...

1 year ago

AI-Driven Guided Response for SOCs with Microsoft Copilot for Security

In today's evolving cybersecurity landscape, security operation centers (SOCs) are constantly bombarded with incidents ranging from minor aler...

1 year ago

Identity Summary: New Security Copilot skill within Defender XDR

“Can you summarize Defender insights about this user over the last two days?” Microsoft’s latest innovation for Copilot for Security, sim...

1 year ago

Detecting browser anomalies to disrupt attacks early

Detecting browser anomalies is crucial for early identification and prevention of cyber threats, preventing data breaches and attacks by monit...

1 year ago

Microsoft Defender for Identity: the critical role of identities in automatic attack disruption

In today's digital landscape, cyber-threats are becoming increasingly sophisticated and frequent. Advanced attacks are often multi-workload an...

1 year ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.