{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-191-do-not-expect-a-monitor-only-cloud-apps-session-policy-to-record-file-activity/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-191-do-not-expect-a-monitor-only-cloud-apps-session-policy-to-record-file-activity/",
        "slug": "dse-20260909-191-do-not-expect-a-monitor-only-cloud-apps-session-policy-to-record-file-activity",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-191-do-not-expect-a-monitor-only-cloud-apps-session-policy-to-record-file-activity/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-191-do-not-expect-a-monitor-only-cloud-apps-session-policy-to-record-file-activity.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-191-do-not-expect-a-monitor-only-cloud-apps-session-policy-to-record-file-activity/"
        },
        "title": "Do not expect a Monitor only Cloud Apps session policy to record file activity",
        "summary": "Does the Monitor only session-control type observe downloads as well as sign-ins?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:28:45+00:00",
        "modified_at": "2026-09-10T00:55:36+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 243,
        "potentially_affected": "Defender for Cloud Apps session policies for applications onboarded to Conditional Access app control.",
        "dse_recommendation": "Translate the required observation into the appropriate session-control type instead of choosing Monitor only from its name.",
        "primary_source": {
            "name": "Create session policies - Microsoft Defender for Cloud Apps | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-cloud-apps/session-policy-aad",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Defender for Cloud Apps&#8217; Monitor only session-control type monitors Login activity only. Microsoft&#8217;s guidance uses a file-download or file-upload control with the Audit action when those activities need observation without a block. Session policies also require a corresponding Microsoft Entra Conditional Access policy to control the traffic. <a href=\"https://learn.microsoft.com/en-us/defender-cloud-apps/session-policy-aad\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>This is a choice of session-control type for an already onboarded application. It does not describe all Cloud Apps telemetry or guarantee that a user&#8217;s entire session will be recorded. Keep the desired file observation separate from a decision to block it.</p>\n<h2>DSE recommendation</h2>\n<p>Translate the required observation into the appropriate session-control type instead of choosing Monitor only from its name. Write down the exact upload or download scenario, application and user scope that the pilot should reveal. Inspect the selected action so an observation exercise does not unintentionally become a blocking change. Review other matching session policies before interpreting the user experience.</p>\n<h2>Verification</h2>\n<p>Use an approved test account and harmless file, end existing sessions, and authenticate again before exercising the selected scenario. Compare the observed activity and policy report with the intended file action rather than accepting a successful sign-in as sufficient evidence. If behavior is more restrictive than expected, check the other matching policies: Microsoft states that the more restrictive session policy wins. Retain the tested scenario and actual outcome without claiming observation of activities outside its scope.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-cloud-apps/session-policy-aad\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Cloud Apps session policies</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nDefender for Cloud Apps’ Monitor only session-control type monitors Login activity only. Microsoft’s guidance uses a file-download or file-upload control with the Audit action when those activities need observation without a block. Session policies also require a corresponding Microsoft Entra Conditional Access policy to control the traffic. Microsoft Learn.\nApplicability\nThis is a choice of session-control type for an already onboarded application. It does not describe all Cloud Apps telemetry or guarantee that a user’s entire session will be recorded. Keep the desired file observation separate from a decision to block it.\nDSE recommendation\nTranslate the required observation into the appropriate session-control type instead of choosing Monitor only from its name. Write down the exact upload or download scenario, application and user scope that the pilot should reveal. Inspect the selected action so an observation exercise does not unintentionally become a blocking change. Review other matching session policies before interpreting the user experience.\nVerification\nUse an approved test account and harmless file, end existing sessions, and authenticate again before exercising the selected scenario. Compare the observed activity and policy report with the intended file action rather than accepting a successful sign-in as sufficient evidence. If behavior is more restrictive than expected, check the other matching policies: Microsoft states that the more restrictive session policy wins. Retain the tested scenario and actual outcome without claiming observation of activities outside its scope.\nOfficial references\nMicrosoft Learn: Cloud Apps session policies. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nDefender for Cloud Apps’ Monitor only session-control type monitors Login activity only. Microsoft’s guidance uses a file-download or file-upload control with the Audit action when those activities need observation without a block. Session policies also require a corresponding Microsoft Entra Conditional Access policy to control the traffic. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-cloud-apps/session-policy-aad).\n\n## Applicability\n\nThis is a choice of session-control type for an already onboarded application. It does not describe all Cloud Apps telemetry or guarantee that a user’s entire session will be recorded. Keep the desired file observation separate from a decision to block it.\n\n## DSE recommendation\n\nTranslate the required observation into the appropriate session-control type instead of choosing Monitor only from its name. Write down the exact upload or download scenario, application and user scope that the pilot should reveal. Inspect the selected action so an observation exercise does not unintentionally become a blocking change. Review other matching session policies before interpreting the user experience.\n\n## Verification\n\nUse an approved test account and harmless file, end existing sessions, and authenticate again before exercising the selected scenario. Compare the observed activity and policy report with the intended file action rather than accepting a successful sign-in as sufficient evidence. If behavior is more restrictive than expected, check the other matching policies: Microsoft states that the more restrictive session policy wins. Retain the tested scenario and actual outcome without claiming observation of activities outside its scope.\n\n## Official references\n\n[Microsoft Learn: Cloud Apps session policies](https://learn.microsoft.com/en-us/defender-cloud-apps/session-policy-aad). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-191-do-not-expect-a-monitor-only-cloud-apps-session-policy-to-record-file-activity/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-191-do-not-expect-a-monitor-only-cloud-apps-session-policy-to-record-file-activity/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-191-do-not-expect-a-monitor-only-cloud-apps-session-policy-to-record-file-activity/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Do not expect a Monitor only Cloud Apps session policy to record file activity",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-191-do-not-expect-a-monitor-only-cloud-apps-session-policy-to-record-file-activity/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-191-do-not-expect-a-monitor-only-cloud-apps-session-policy-to-record-file-activity/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-191-do-not-expect-a-monitor-only-cloud-apps-session-policy-to-record-file-activity/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-191-do-not-expect-a-monitor-only-cloud-apps-session-policy-to-record-file-activity/",
                "headline": "Do not expect a Monitor only Cloud Apps session policy to record file activity",
                "description": "Does the Monitor only session-control type observe downloads as well as sign-ins?",
                "abstract": "Does the Monitor only session-control type observe downloads as well as sign-ins?",
                "articleBody": "Source facts\nDefender for Cloud Apps’ Monitor only session-control type monitors Login activity only. Microsoft’s guidance uses a file-download or file-upload control with the Audit action when those activities need observation without a block. Session policies also require a corresponding Microsoft Entra Conditional Access policy to control the traffic. Microsoft Learn.\nApplicability\nThis is a choice of session-control type for an already onboarded application. It does not describe all Cloud Apps telemetry or guarantee that a user’s entire session will be recorded. Keep the desired file observation separate from a decision to block it.\nDSE recommendation\nTranslate the required observation into the appropriate session-control type instead of choosing Monitor only from its name. Write down the exact upload or download scenario, application and user scope that the pilot should reveal. Inspect the selected action so an observation exercise does not unintentionally become a blocking change. Review other matching session policies before interpreting the user experience.\nVerification\nUse an approved test account and harmless file, end existing sessions, and authenticate again before exercising the selected scenario. Compare the observed activity and policy report with the intended file action rather than accepting a successful sign-in as sufficient evidence. If behavior is more restrictive than expected, check the other matching policies: Microsoft states that the more restrictive session policy wins. Retain the tested scenario and actual outcome without claiming observation of activities outside its scope.\nOfficial references\nMicrosoft Learn: Cloud Apps session policies. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:28:45+00:00",
                "dateModified": "2026-09-10T00:55:36+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-191-do-not-expect-a-monitor-only-cloud-apps-session-policy-to-record-file-activity/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-191-do-not-expect-a-monitor-only-cloud-apps-session-policy-to-record-file-activity/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Do not expect a Monitor only Cloud Apps session policy to record file activity"
                },
                "articleSection": [
                    "Cybersecurity"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    }
                ],
                "wordCount": 243,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Create session policies - Microsoft Defender for Cloud Apps | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-cloud-apps/session-policy-aad"
                }
            }
        ]
    }
}