Skillplan M365 Checklist
2026-07-20 19:35
M365
Microsoft 365 Security Checklist
de
en
fr
it
System Online
← Back to sections
Mitigation Controls · Section 13 of 17
Defender for Cloud Apps
Assessment Progress
0
/ 136 items
0%
Fulfillment so far
0
/ 0 controls
0%
Explain this control
Enable Cloud Discovery (Shadow IT) reports using Defender for Endpoint or a network log feed.
Not Fulfilled
Fulfilled
Accepted
Configure App Governance policies to alert on overprivileged OAuth applications.
Not Fulfilled
Fulfilled
Accepted
Require admin consent for any OAuth app requesting access to mail, files, or directory data.
Not Fulfilled
Fulfilled
Accepted
Configure session policies on approved SaaS apps (Salesforce, Box, ServiceNow) to block download to unmanaged devices.
Not Fulfilled
Fulfilled
Accepted
Connect at least one SaaS app via the App Connector for richer alerts than network-log discovery alone.
Not Fulfilled
Fulfilled
Accepted
Set anomaly detection policies (impossible travel, mass download, ransomware activity) to alert and auto-respond.
Not Fulfilled
Fulfilled
Accepted
Review the OAuth app inventory monthly; revoke consent for apps with no business use.
Not Fulfilled
Fulfilled
Accepted
Integrate Defender for Cloud Apps with Conditional Access App Control to enforce session-based restrictions.
Not Fulfilled
Fulfilled
Accepted
Save and Continue →