SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload▸ View skill file▾ Hide skill file
---
name: Defender for Cloud Apps Session Controls Review
description: Reviews Microsoft Defender for Cloud Apps Conditional Access App Control session policies, identifies SaaS applications lacking real-time session protection, and recommends session policy coverage for regulated and high-risk apps.
---
# Defender for Cloud Apps Session Controls Review
> **TL;DR:** This skill audits Conditional Access App Control session policies in Microsoft Defender for Cloud Apps to identify sanctioned SaaS applications with no real-time session protection — download blocks, DLP scanning, or copy-paste restrictions — and produces a prioritised onboarding plan for high-risk apps.
## What does the Defender for Cloud Apps session controls review examine?
Microsoft Defender for Cloud Apps Conditional Access App Control (CAAC) proxies user sessions to sanctioned SaaS applications, enabling real-time controls: blocking downloads of sensitive files, preventing copy-paste of labelled content, watermarking downloaded documents, and running DLP policies against uploads. Many organisations deploy MDCA without enabling session controls for any application beyond the default Microsoft 365 apps, leaving regulated SaaS platforms — SharePoint on unmanaged devices, Salesforce, ServiceNow — without a data exfiltration layer. This skill enumerates all applications onboarded to CAAC, identifies sanctioned apps that are still unprotected, reviews the active session policies and their scope, and benchmarks the configuration against the recommended CAAC baseline for Australian regulated industries.
## When should you run this skill?
- "Review our MDCA session control configuration"
- "Which apps have Conditional Access App Control enabled?"
- "Find SaaS apps with no download protection"
- "Audit Defender for Cloud Apps session policies"
- "Prepare CASB session control evidence for IRAP"
- "Block downloads from unmanaged devices for Salesforce"
## How this skill works, step by step
1. Open the Microsoft Defender portal → Cloud Apps → Connected apps → Conditional Access App Control apps
2. Export the list of apps onboarded to CAAC (app name, onboard method: automatic or manual, status: active/inactive)
3. In Policies → Session policies, export all session policies with name, scope (all users / specific groups), app targets, action type (monitor, block download, block copy-paste, DLP scan, watermark), enabled/disabled status
4. For each sanctioned app in the cloud app catalogue, check whether a session policy is targeted to it
5. Identify apps in the following categories that lack session controls:
- Cloud storage and collaboration (SharePoint, Box, Dropbox, Google Workspace)
- CRM and ERP (Salesforce, ServiceNow, SAP)
- Development platforms (GitHub, Jira, Confluence)
- Any app rated High risk in the Defender for Cloud Apps risk catalogue
6. For each unprotected app, determine the recommended session policy action based on data type and regulatory obligation
7. Score priority for onboarding: High (handles PROTECTED/Highly Confidential data or in scope of PSPF/APRA), Medium (commercial-in-confidence data), Low (general business data)
## Output format
| App | CAAC Onboarded | Session Policy | Policy Action | Unmanaged Device Coverage | Priority | Recommendation |
| --- | --- | --- | --- | --- | --- | --- |
| Salesforce | Yes | None | — | None | High | Add download-block policy for sensitive records |
| SharePoint Online | Yes | Download block | Block + DLP | Yes | — | Compliant |
| Box | No | None | — | None | High | Onboard to CAAC, add download-block |
Summary:
- Apps onboarded to CAAC: N
- Apps with active session policies: N
- High-priority apps lacking session controls: N
- DLP scanning active in sessions: Yes/No
- Recommended for immediate onboarding: N apps
## Scope and safety
Read-only — this skill does NOT:
- Create or modify session policies
- Block or redirect user sessions
- Access session content (file contents, user keystrokes)
- Onboard applications to CAAC (requires Conditional Access policy update)
## Licensing and permissions
### Licences and add-ons
| Capability used | Minimum licence |
| --- | --- |
| Microsoft Defender for Cloud Apps CAAC and session policies | Microsoft Defender for Cloud Apps (included in Microsoft 365 E5 or E5 Security) |
| Conditional Access App Control (proxy enforcement) | Microsoft Entra ID P1 + Defender for Cloud Apps |
### Least-privilege roles
- Cloud App Security Administrator (read session policies and CAAC configuration)
- Security Reader (read-only review of Defender portal CAAC settings)
### Microsoft Graph permissions (read-only)
- Session policy data is accessed through the Microsoft Defender portal and the MDCA REST API
- `CloudApp-Discovery.Read.All` (MDCA API scope) — read cloud app and session policy configuration
## Sources and compliance
- [Protect apps with Microsoft Defender for Cloud Apps Conditional Access App Control](https://learn.microsoft.com/en-us/defender-cloud-apps/proxy-intro-aad)
- [Deploy session and access controls with CAAC (Microsoft Learn)](https://learn.microsoft.com/en-us/defender-cloud-apps/proxy-deployment-aad)
- Supports Essential Eight ML2 evidence for Control 7 (user application hardening — real-time session DLP)
- Aligns with APRA CPS 234 Information Security requirements for third-party SaaS data controls
- Pair with MDCA Policy Coverage Audit for a complete CASB governance picture
- Output in Australian English
How to use this skill
- Get the file. Download or copy the
SKILL.mdfrom the panel above. - Load it into your host:
- Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
- Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
- Any chat host — paste the file contents as your prompt.
- Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions below.
- Provide your tenant scope and run it (a site, a collection, or the whole tenant).
- Review the report and action the risk-ranked recommendations.
This skill is read-only by default — it inspects and reports, and never changes your tenant.
Defender for Cloud Apps Session Controls Review
TL;DR: This skill audits Conditional Access App Control session policies in Microsoft Defender for Cloud Apps to identify sanctioned SaaS applications with no real-time session protection — download blocks, DLP scanning, or copy-paste restrictions — and produces a prioritised onboarding plan for high-risk apps.
What does the Defender for Cloud Apps session controls review examine?
Microsoft Defender for Cloud Apps Conditional Access App Control (CAAC) proxies user sessions to sanctioned SaaS applications, enabling real-time controls: blocking downloads of sensitive files, preventing copy-paste of labelled content, watermarking downloaded documents, and running DLP policies against uploads. Many organisations deploy MDCA without enabling session controls for any application beyond the default Microsoft 365 apps, leaving regulated SaaS platforms — SharePoint on unmanaged devices, Salesforce, ServiceNow — without a data exfiltration layer. This skill enumerates all applications onboarded to CAAC, identifies sanctioned apps that are still unprotected, reviews the active session policies and their scope, and benchmarks the configuration against the recommended CAAC baseline for Australian regulated industries.
When should you run this skill?
- “Review our MDCA session control configuration”
- “Which apps have Conditional Access App Control enabled?”
- “Find SaaS apps with no download protection”
- “Audit Defender for Cloud Apps session policies”
- “Prepare CASB session control evidence for IRAP”
- “Block downloads from unmanaged devices for Salesforce”
How this skill works, step by step
- Open the Microsoft Defender portal → Cloud Apps → Connected apps → Conditional Access App Control apps
- Export the list of apps onboarded to CAAC (app name, onboard method: automatic or manual, status: active/inactive)
- In Policies → Session policies, export all session policies with name, scope (all users / specific groups), app targets, action type (monitor, block download, block copy-paste, DLP scan, watermark), enabled/disabled status
- For each sanctioned app in the cloud app catalogue, check whether a session policy is targeted to it
- Identify apps in the following categories that lack session controls:
- Cloud storage and collaboration (SharePoint, Box, Dropbox, Google Workspace)
- CRM and ERP (Salesforce, ServiceNow, SAP)
- Development platforms (GitHub, Jira, Confluence)
- Any app rated High risk in the Defender for Cloud Apps risk catalogue
- For each unprotected app, determine the recommended session policy action based on data type and regulatory obligation
- Score priority for onboarding: High (handles PROTECTED/Highly Confidential data or in scope of PSPF/APRA), Medium (commercial-in-confidence data), Low (general business data)
Output format
| App | CAAC Onboarded | Session Policy | Policy Action | Unmanaged Device Coverage | Priority | Recommendation |
|---|---|---|---|---|---|---|
| Salesforce | Yes | None | — | None | High | Add download-block policy for sensitive records |
| SharePoint Online | Yes | Download block | Block + DLP | Yes | — | Compliant |
| Box | No | None | — | None | High | Onboard to CAAC, add download-block |
Summary:
- Apps onboarded to CAAC: N
- Apps with active session policies: N
- High-priority apps lacking session controls: N
- DLP scanning active in sessions: Yes/No
- Recommended for immediate onboarding: N apps
Scope and safety
Read-only — this skill does NOT:
- Create or modify session policies
- Block or redirect user sessions
- Access session content (file contents, user keystrokes)
- Onboard applications to CAAC (requires Conditional Access policy update)
Licensing and permissions
Licences and add-ons
| Capability used | Minimum licence |
|---|---|
| Microsoft Defender for Cloud Apps CAAC and session policies | Microsoft Defender for Cloud Apps (included in Microsoft 365 E5 or E5 Security) |
| Conditional Access App Control (proxy enforcement) | Microsoft Entra ID P1 + Defender for Cloud Apps |
Least-privilege roles
- Cloud App Security Administrator (read session policies and CAAC configuration)
- Security Reader (read-only review of Defender portal CAAC settings)
Microsoft Graph permissions (read-only)
- Session policy data is accessed through the Microsoft Defender portal and the MDCA REST API
CloudApp-Discovery.Read.All(MDCA API scope) — read cloud app and session policy configuration
Sources and compliance
- Protect apps with Microsoft Defender for Cloud Apps Conditional Access App Control
- Deploy session and access controls with CAAC (Microsoft Learn)
- Supports Essential Eight ML2 evidence for Control 7 (user application hardening — real-time session DLP)
- Aligns with APRA CPS 234 Information Security requirements for third-party SaaS data controls
- Pair with MDCA Policy Coverage Audit for a complete CASB governance picture
- Output in Australian English