SC-300 - Plan and Implement Workload Identities (25% of the exam) - Section 3.5

Manage and monitor app access using Microsoft Defender for Cloud Apps discovery and connected apps.

Use Microsoft Defender for Cloud Apps cloud discovery and the Cloud app catalog to identify shadow IT and assess app risk. Connect sanctioned apps and apply OAuth app policies and app governance controls to detect and restrict excessive or anomalous OAuth permissions.

cloud discoveryconnected appsOAuth app policiesCloud app catalogapp governance

Practice question for this objective

Free samplePlan and Implement Workload Identitieshard

A Conditional Access policy must place a SaaS application under Microsoft Defender for Cloud Apps so that session policies can monitor and control activity in real time. After selecting the target app and users, which session control inside the Conditional Access policy actually routes the user's session through the Defender for Cloud Apps reverse proxy?

  • AThe Sign-in frequency session control set to a short interval so the session is re-evaluated often enough for Defender for Cloud Apps to take over
  • BThe Persistent browser session control set to never persistent so each new browser session is redirected into the Defender for Cloud Apps proxy
  • CThe Use Conditional Access App Control session control, configured to use custom policy, which redirects the session to Defender for Cloud Apps Correct
  • DThe Customise continuous access evaluation session control, which streams session events to Defender for Cloud Apps for real-time policy matching
The Use Conditional Access App Control session control redirects a session to the Defender for Cloud Apps reverse proxy so session policies can apply. Conditional Access app control depends on the Use Conditional Access App Control session control, which redirects the targeted session to the Defender for Cloud Apps reverse proxy; only then can session policies inspect and control in-session activity, which sign-in frequency, persistent browser, and continuous access evaluation cannot do.

Why A is wrong: Sign-in frequency only forces periodic reauthentication; it never hands the session to the Defender for Cloud Apps proxy and so cannot enable session policies.

Why B is wrong: Persistent browser session only governs whether the sign-in stays signed in across browser restarts and has no role in routing traffic through the proxy.

Why C is correct: The Use Conditional Access App Control session control is what redirects the session to the Defender for Cloud Apps reverse proxy, where the configured session policies are then evaluated.

Why D is wrong: Continuous access evaluation handles near real-time token revocation between Microsoft services and does not proxy or hand the session to Defender for Cloud Apps.

See more SC-300 practice questions, answers explained.

Exam traps in Plan and Implement Workload Identities

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-300 bank for this domain.

  • Onboard the app to Conditional Access app control so its live sessions are routed through the reverse proxy.

    Why it is wrong: Conditional Access app control governs real-time session activity through a reverse proxy, which is tempting, but it cannot scan files already at rest or read the app's native API logs.

  • The activity log, which records each individual user action performed inside the connected applications.

    Why it is wrong: The activity log shows per-user actions in connected apps, which is useful for investigation, but it holds no standardised security attribute scoring for app selection.

  • An activity policy that flags any interactive sign-in from an anonymous IP address range.

    Why it is wrong: An activity policy inspects user activities such as sign-ins, which is tempting, but it does not evaluate the permission scope or publisher of consented OAuth apps.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.