SC-300 · Question #251
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Cloud Apps. You need to identify which users access Facebook from their devices and browsers. The solution must minimize…
The correct answer is A. From the Microsoft 365 Defender portal, unsanction Facebook. Explanation Unsanctioning Facebook in the Microsoft 365 Defender portal tags it as a blocked/monitored app, which causes Defender for Cloud Apps to automatically generate Shadow IT discovery reports - revealing which users are accessing Facebook from their devices and browsers…
Question
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Cloud Apps. You need to identify which users access Facebook from their devices and browsers. The solution must minimize administrative effort. What should you do first?
Options
- AFrom the Microsoft 365 Defender portal, unsanction Facebook.
- BCreate a Defender for Cloud Apps access policy.
- CCreate an app configuration policy in Microsoft Intune.
- DCreate a Conditional Access policy.
How the community answered
(21 responses)- A81% (17)
- B10% (2)
- C5% (1)
- D5% (1)
Explanation
Explanation
Unsanctioning Facebook in the Microsoft 365 Defender portal tags it as a blocked/monitored app, which causes Defender for Cloud Apps to automatically generate Shadow IT discovery reports - revealing which users are accessing Facebook from their devices and browsers with minimal configuration effort. Option B (an Access Policy) is incorrect because access policies control conditional access to sanctioned apps and require more setup, not just identification of usage. Option C (an Intune app configuration policy) manages app settings on enrolled devices but doesn't provide visibility into browser-based Facebook access. Option D (a Conditional Access policy) can block or control access but is a more complex solution and doesn't directly identify which users are accessing the app the way unsanctioning does in Cloud App Discovery.
Memory Tip: Think of unsanctioning = shining a spotlight - when you mark an app as unsanctioned in Defender for Cloud Apps, you're telling the system "watch this," which triggers automatic monitoring and discovery reports. Always unsanction first to identify, then enforce controls later.
Topics
Community Discussion
No community discussion yet for this question.