MS-102 · Question #498
You have a Microsoft 365 subscription that uses Microsoft Defender for Cloud Apps. You configure a session control policy to block downloads from SharePoint Online sites. Users report that they can st
The correct answer is D. a Conditional Access policy. To enforce session controls from Microsoft Defender for Cloud Apps, such as blocking downloads, an Azure AD Conditional Access policy must be configured to direct relevant user sessions to Defender for Cloud Apps.
Question
You have a Microsoft 365 subscription that uses Microsoft Defender for Cloud Apps. You configure a session control policy to block downloads from SharePoint Online sites. Users report that they can still download files from SharePoint Online sites. You need to ensure that file download is blocked while still allowing users to browse SharePoint Online sites. What should you configure?
Options
- Aan access policy
- Ba data loss prevention (DLP) policy
- Can activity policy
- Da Conditional Access policy
How the community answered
(30 responses)- A23% (7)
- B13% (4)
- C7% (2)
- D57% (17)
Why each option
To enforce session controls from Microsoft Defender for Cloud Apps, such as blocking downloads, an Azure AD Conditional Access policy must be configured to direct relevant user sessions to Defender for Cloud Apps.
An access policy in Defender for Cloud Apps is used to control whether users can access an app at all, or to redirect them to session control, but it doesn't itself block specific in-session activities like downloads without an underlying Conditional Access policy.
A data loss prevention (DLP) policy focuses on identifying, monitoring, and protecting sensitive information across various locations, but it doesn't directly configure session-level controls for cloud apps like blocking downloads via Conditional Access App Control.
An activity policy in Defender for Cloud Apps monitors user activities and can trigger alerts or governance actions, but it is not the mechanism to enforce real-time session controls like blocking downloads based on a Conditional Access trigger.
Microsoft Defender for Cloud Apps' session control policies integrate with Azure AD Conditional Access policies. You must configure an Azure AD Conditional Access policy to 'Use Conditional Access App Control' for the specific app (SharePoint Online) to ensure that user sessions are redirected through Defender for Cloud Apps, allowing its session controls (like blocking downloads) to be enforced.
Concept tested: Defender for Cloud Apps session control integration
Source: https://learn.microsoft.com/en-us/defender-cloud-apps/azca-integration
Topics
Community Discussion
No community discussion yet for this question.