nerdexam
Microsoft

SC-300 · Question #199

You have a Microsoft 365 E5 subscription. Users authorize third-party cloud apps to access their data. You need to configure an alert that will be triggered when an app requires high permissions and i

The correct answer is B. OAuth app policy. In addition to the existing investigation of OAuth apps connected to your environment, you can set permission policies so that you get automated notifications when an OAuth app meets certain criteria. For example, you can automatically be alerted when there are apps that require

Submitted by yousef_jo· Mar 6, 2026Implement access management for apps

Question

You have a Microsoft 365 E5 subscription. Users authorize third-party cloud apps to access their data. You need to configure an alert that will be triggered when an app requires high permissions and is authorized by more than 20 users. Which type of policy should you create in the Microsoft Defender for Cloud Apps portal?

Options

  • Aanomaly detection policy
  • BOAuth app policy
  • Caccess policy
  • Dactivity policy

How the community answered

(29 responses)
  • A
    7% (2)
  • B
    76% (22)
  • C
    3% (1)
  • D
    14% (4)

Explanation

In addition to the existing investigation of OAuth apps connected to your environment, you can set permission policies so that you get automated notifications when an OAuth app meets certain criteria. For example, you can automatically be alerted when there are apps that require a high permission level and were authorized by more than 50 users. https://learn.microsoft.com/en-us/defender-cloud-apps/app-permission-policy

Topics

#OAuth app policy#Defender for Cloud Apps#third-party app risk#permission scope

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice