Loading...

Safeguarding your OAuth apps with App Governance

Safeguarding your OAuth apps with App Governance

In today's cloud-connected world, organizations rely heavily on SaaS applications to streamline operations and improve productivity. However, this has increased reliance on cloud services which exposes organizations to potential security threats. Among these threats are OAuth applications, which can be vulnerable due to insecure implementation, frequently misconfigured permissions, relying on user consent granting permissions to third-party apps and allowing lateral movement to bad actors that can lead to phishing.  

 

App governance provides an essential layer of defense to help you to protect and improve the security posture of your OAuth enabled apps. Back in April, we announced that App governance will be included in Microsoft Defender for Cloud Apps, at no additional cost. We also did a walkthrough and overview of the features in our latest webinar.

 

Today, we will share how easy it is to deploy and the immediate value it provides in your SaaS Security strategy.

 

What are the benefits of App governance?

 

Visibility into suspicious app activities: Malicious OAuth applications can be used to spread spam and laterally move to gain further access to your environment. App governance helps prevent these types of attacks and others like consent phishing by giving you visibility into your connected apps, enabling you to detect and remediate any suspicious behavior or unauthorized apps.

 

Improving app compliance posture: App governance enables you to assess the compliance posture of apps in your environment. By providing insights into app permissions, usage, and risks, you can make informed decisions about which apps to allow or block. It also helps you to identify potential compliance issues that need to be addressed to enhance the overall compliance posture in your organization. Additionally, App governance integrates with Microsoft Purview Information Protection enabling you to maintain a unified compliance strategy across your applications and services.

 

How do I start using App governance?

 

App governance can be easily enabled in Microsoft 365 Defender. To opt-in, navigate to the Microsoft 365 Defender settings > Cloud Apps > App Governance > Service status > Enable “Use app governance” toggle bar. If you are using a trial license, then you will still need to follow these steps to continue using App governance.

 

GregWiselka_0-1685633877041.png

Figure 1. How to opt-in to App Governance

 

Where do I start?

 

Once App governance is enabled, the best place to start is the dashboard. It provides an overview of your organization's connected apps, privilege levels, and usage patterns. The dashboard identifies the number of connected apps, high risk and overprivileged apps. It also provides information on data usage and sensitive labels accessed. The latest incidents section makes it easy and actionable for you to identify the latest threat detection and policy-based alerts in their environment.

 

GregWiselka_1-1685633877055.png

Figure 2. App governance dashboard

 

The apps list shows you an overview of OAuth apps registered with Azure Active Directory in your environment, along with their registration data, privilege levels and usage data along with enriched app insights such as publisher name and certification status.

 

GregWiselka_2-1685633877068.png

Figure 3. Apps list.

 

App governance will provide insights into anomalous behavior, the number of users, the volume of data transferred, sensitivity labels accessed by an app, permissions and latest activity. From all apps, select an app to see the insights.  

 

GregWiselka_3-1685633877073.png

Figure 4. App usage details.

 

How can I leverage the out of the box policies?

 

Once you enable App governance in your tenant, you automatically benefit from out of the box predefined policies. These policies enable you to monitor app behavior, detect anomalies, and take automated remediation actions. There will be no impact on your users after turning on App governance and enabling predefined policies unless the policy is set to “Disable app.”

 

GregWiselka_4-1685633877077.png

Figure 5. App governance policies.

 

Lastly, App governance alerts are unified with Microsoft 365 Defender incidents and are correlated with other security workloads and suspicious activities in your environment.

 

GregWiselka_5-1685633877083.png

Figure 6. Review Incidents.

 

App governance is an essential tool for organizations looking to safeguard their SaaS applications and maintain a robust security posture. With its ease of deployment, predefined policies, and comprehensive dashboard, it empowers you to detect and remediate malicious OAuth applications By providing visibility, insights, and automated remediation capabilities, App governance ensures that you stay ahead of potential threats and maintain a secure environment.

Published on:

Learn more
Microsoft 365 Defender Blog articles
Microsoft 365 Defender Blog articles

Microsoft 365 Defender Blog articles

Share post:

Related posts

Monthly news - November 2024

Microsoft Defender XDRMonthly newsNovember 2024 Edition This is our monthly "What's new" blog post, summarizing product updates and v...

1 year ago

Monthly news - August 2024

Microsoft Defender XDRMonthly newsAugust 2024 Edition This is our monthly "What's new" blog post, summarizing product updates and var...

1 year ago

Defender for Identity: the critical role of identities in automatic attack disruption

In today's digital landscape, cyber-threats are becoming increasingly sophisticated and frequent. Advanced attacks are often multi-workload an...

1 year ago

New Security Copilot skill: Identity Summary

“Can you summarize Defender insights about this user over the last two days?” Microsoft’s latest innovation for Copilot for Security, sim...

1 year ago

Demystify potential data leaks with Insider Risk Management insights in Defender XDR

In today's complex security landscape, understanding and mitigating data exfiltration risks is more critical than ever. Earlier this year, we ...

1 year ago

Monthly news - October 2024

Microsoft Defender XDRMonthly newsOctober 2024 Edition This is our monthly "What's new" blog post, summarizing product updates and va...

1 year ago

AI-Driven Guided Response for SOCs with Microsoft Copilot for Security

In today's evolving cybersecurity landscape, security operation centers (SOCs) are constantly bombarded with incidents ranging from minor aler...

1 year ago

Identity Summary: New Security Copilot skill within Defender XDR

“Can you summarize Defender insights about this user over the last two days?” Microsoft’s latest innovation for Copilot for Security, sim...

1 year ago

Detecting browser anomalies to disrupt attacks early

Detecting browser anomalies is crucial for early identification and prevention of cyber threats, preventing data breaches and attacks by monit...

1 year ago

Microsoft Defender for Identity: the critical role of identities in automatic attack disruption

In today's digital landscape, cyber-threats are becoming increasingly sophisticated and frequent. Advanced attacks are often multi-workload an...

1 year ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.