nerdexam
Microsoft

SC-300 · Question #48

Hotspot Question You have a Microsoft 365 tenant. Sometimes, users use external, third-party applications that require limited access to the Microsoft 365 data of the respective user. The users…

The correct answer is Tool to use:: Microsoft Defender for Cloud Apps; Policy type to create:: OAuth app. This question tests your knowledge of configuring Microsoft Defender for Cloud Apps (formerly MCAS) app governance policies to detect when registered Azure AD applications gain excessive permissions to users' mailboxes.

Submitted by certguy· Mar 6, 2026Implement access management for apps

Question

Hotspot Question You have a Microsoft 365 tenant. Sometimes, users use external, third-party applications that require limited access to the Microsoft 365 data of the respective user. The users register the applications in Azure Active Directory (Azure AD). You need to receive an alert if a registered application gains read and write access to the users' email. What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Answer:

Exhibit

SC-300 question #48 exhibit

Answer Area

  • Tool to use:Microsoft Defender for Cloud Apps
    Azure AD Identity ProtectionIdentity GovernanceMicrosoft Defender for Cloud AppsMicrosoft Endpoint Manager
  • Policy type to create:OAuth app
    App discoveryApp protectionConditional accessOAuth appSign-in riskUser risk

How the community answered

(1 responses)
  • Microsoft Endpoint Manager|OAuth app
    100% (1)

Explanation

This question tests your knowledge of configuring Microsoft Defender for Cloud Apps (formerly MCAS) app governance policies to detect when registered Azure AD applications gain excessive permissions to users' mailboxes.

Approach. To receive an alert when a registered application gains read and write access to users' email, you should use Microsoft Defender for Cloud Apps (Microsoft Defender for Cloud Apps > App governance or Cloud App Security). Specifically, you need to create an App policy under App governance that monitors OAuth apps registered in Azure AD. You would configure the policy to trigger when an app requests or is granted Mail.ReadWrite (or similar Mail permissions) scopes, and set the action to generate an alert. This leverages App Governance's ability to track OAuth application permissions and alert administrators when suspicious or high-risk permission scopes - such as full mailbox read/write - are granted to third-party registered applications.

Concept tested. The core concept tested is Microsoft Defender for Cloud Apps App Governance (OAuth app policies), which monitors third-party OAuth applications registered in Azure AD for excessive or sensitive permission scopes such as Mail.ReadWrite. Administrators must understand how to create policy-based alerts triggered by specific OAuth permission grants to protect organizational data from over-privileged third-party apps.

Reference. https://learn.microsoft.com/en-us/defender-cloud-apps/app-governance-app-policies-overview

Topics

#Defender for Cloud Apps#OAuth app policy#app permissions#email access

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice