SC-300 - Plan and Implement Workload Identities - Section 3.6

Implement Conditional Access app control, access policies, and session policies in Microsoft Defender for Cloud Apps.

Configure Conditional Access app control in Microsoft Defender for Cloud Apps to proxy app sessions and enforce access policies and session policies at runtime. Apply application-enforced restrictions and real-time monitoring to block downloads, watermark content, or cut off sessions when risk is detected mid-session.

application-enforced restrictionsConditional Access app controlaccess policiessession policiesreal-time monitoring

Practice question for this objective

Free samplePlan and Implement Workload Identitieshard

A team wants to bring a non-Microsoft SaaS application that supports single sign-on with Microsoft Entra ID under session policy control in Microsoft Defender for Cloud Apps. The app is not on the list of automatically onboarded apps. What is the correct way to make this app eligible for Conditional Access app control session policies?

  • AAdd the app to a dynamic application group in Microsoft Entra ID so Defender for Cloud Apps automatically begins proxying its sessions.
  • BConnect the app to Defender for Cloud Apps using its API connector so the recorded session traffic is automatically routed through the reverse proxy.
  • CCreate a Conditional Access policy with the use Conditional Access app control session control, then onboard the app in Defender for Cloud Apps as a custom app. Correct
  • DEnable application-enforced restrictions for the app so Defender for Cloud Apps can substitute its own session policy in place of the app's native limits.
An app needs a Conditional Access app control session control plus onboarding in Defender for Cloud Apps before session policies can govern it. To bring a single sign-on SaaS app under session policies, you create a Conditional Access policy that applies the use Conditional Access app control session control and then onboard the app in Microsoft Defender for Cloud Apps as a catalogue or custom app, which establishes the reverse proxy. Group membership, API connectors, and application-enforced restrictions each serve other purposes and do not create the inline proxy session policies require.

Why A is wrong: Application grouping does not exist as a mechanism that auto-enables proxying, and membership in any group does not connect an app to the Conditional Access app control reverse proxy.

Why B is wrong: App connectors use vendor APIs for visibility and governance of data at rest and do not establish the inline reverse proxy that session policies depend on.

Why C is correct: Session policies require both a Conditional Access policy that routes the app through app control and the app being onboarded in Defender for Cloud Apps, which is how a non-featured SAML or OpenID Connect app becomes proxied.

Why D is wrong: Application-enforced restrictions push limited controls to the app itself and only suit Microsoft 365 services, so they neither onboard the app for proxying nor support custom session policies.

See more SC-300 practice questions, answers explained.

More in this domain

Back to all Plan and Implement Workload Identities objectives, or the SC-300 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.