Edit

Share via


Manage app policies

Use app governance to manage OAuth policies for Microsoft 365, Google Workspace, and Salesforce.

You might need to manage your app policies as follows to keep up-to-date with your organization's apps, respond to new app-based attacks, and for ongoing changes to your app compliance needs:

  • Create new policies targeted at new apps
  • Change the status of an existing policy (active or disable)
  • Change the conditions of an existing policy
  • Change the actions of an existing policy for auto-remediation of alerts

Editing an app policy configuration

To change the configuration of a user defined app policy:

  1. Select the policy in the policy list, and then select Edit on the app policy pane.

  2. In the Edit policy page, you can make the following changes:

    • Description: Change the description to make it easier to understand the policy's purpose.
    • Severity : Change the severity for your app policy to low, medium, or high.
    • Policy settings: Change the set of apps to which the policy applies. You can also choose to use the existing conditions or modify the conditions
    • Actions: Change the autoremediation action for alerts generated by the policy.
    • Status: Change the policy status.

Screenshot that shows how to edit a user defined policy in the Defender portal.

Deleting an app policy

To delete an app policy, you can:

  • Select the policy in the policy list, and then select Delete on the app policy pane.

An alternative to deleting an app policy is to change its status to disabled. Once disabled, the policy doesn't generate alerts. For example, rather than deleting an app policy for an app with a specific set of conditions that are useful for a future policy, rename the app policy to indicate its usefulness and set its status to disabled.

Next steps

Investigate predefined app policy alerts