nerdexam
Microsoft

SC-300 · Question #349

You have a Microsoft 365 subscription that uses Microsoft Defender for Cloud Apps. You have multiple third-party apps that access the resources in the subscription. You need to monitor the access of…

The correct answer is C. an OAuth app policy. Explanation An OAuth app policy (Option C) is specifically designed to monitor and control third-party applications that connect to your environment using OAuth authentication - exactly how most third-party apps request access to Microsoft 365 resources. In Microsoft Defender…

Submitted by certguy· Mar 6, 2026Implement access management for apps

Question

You have a Microsoft 365 subscription that uses Microsoft Defender for Cloud Apps. You have multiple third-party apps that access the resources in the subscription. You need to monitor the access of the third-party apps. What should you create?

Options

  • Aan access policy
  • Ban app permission policy
  • Can OAuth app policy
  • Dan endpoint protection policy

How the community answered

(40 responses)
  • A
    5% (2)
  • B
    3% (1)
  • C
    83% (33)
  • D
    10% (4)

Explanation

Explanation

An OAuth app policy (Option C) is specifically designed to monitor and control third-party applications that connect to your environment using OAuth authentication - exactly how most third-party apps request access to Microsoft 365 resources. In Microsoft Defender for Cloud Apps, OAuth app policies allow you to detect and receive alerts when apps request specific permission levels, are used by a certain number of users, or exhibit suspicious behavior.

Why the distractors are wrong:

  • Option A (Access policy) controls real-time session access for users, not third-party app permissions.
  • Option B (App permission policy) is associated with Microsoft Teams app governance, not broad third-party OAuth app monitoring in Defender for Cloud Apps.
  • Option D (Endpoint protection policy) relates to device security through tools like Microsoft Intune/Defender for Endpoint, which is unrelated to app access monitoring.

Memory Tip: Think "OAuth = Other Apps' Access." Whenever the scenario involves third-party apps connecting to your Microsoft 365 resources and you need to monitor or govern their permissions, remember that OAuth is the protocol those apps use - so an OAuth app policy is your tool of choice.

Topics

#Microsoft Defender for Cloud Apps#OAuth applications#App monitoring#Third-party apps

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice