{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-511-check-predefined-app-policy-state-before-claiming-its-detection-is-enabled/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-511-check-predefined-app-policy-state-before-claiming-its-detection-is-enabled/",
        "slug": "dse-20260909-511-check-predefined-app-policy-state-before-claiming-its-detection-is-enabled",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-511-check-predefined-app-policy-state-before-claiming-its-detection-is-enabled/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-511-check-predefined-app-policy-state-before-claiming-its-detection-is-enabled.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-511-check-predefined-app-policy-state-before-claiming-its-detection-is-enabled/"
        },
        "title": "Check predefined app-policy state before claiming its detection is enabled",
        "summary": "Can a predefined OAuth app policy remain visible in Defender after Microsoft has disabled it?",
        "format": {
            "slug": "briefing",
            "name": "Briefing"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:23:25+00:00",
        "modified_at": "2026-09-10T02:11:17+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 250,
        "potentially_affected": "App governance environments reviewing the documented predefined OAuth app policies and their effective state.",
        "dse_recommendation": "Reconcile the intended detection register with each policy's actual enabled or disabled state before asserting coverage.",
        "primary_source": {
            "name": "Investigate predefined OAuth app policy alerts with app governance - Microsoft Defender for Cloud Apps | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-cloud-apps/app-governance-investigate-predefined-policies",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft documents several predefined app-governance policies that remain visible but disabled: increased data use by an overprivileged or highly privileged app, unusual activity involving priority-account consent, and access to sensitive data. The documentation describes an optional Activate action for administrators who decide to continue using them. It also says predefined anomaly policies are nondeterministic and trigger on behavior that departs from normal patterns. <a href=\"https://learn.microsoft.com/en-us/defender-cloud-apps/app-governance-investigate-predefined-policies\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>This check concerns the documented policies&#8217; state, not the presence of all app-governance protection. A row in a policy list is different from an enabled detection, and an enabled anomaly policy is not a promise that every contrived test will create an alert.</p>\n<h2>DSE recommendation</h2>\n<p>Reconcile the intended detection register with each policy&#8217;s actual enabled or disabled state before asserting coverage. Ask the security owner to review why an optional policy is needed and what evidence would support retaining it. Do not reactivate every visible disabled policy simply to make an inventory count increase. Record deliberate exclusions and alternative coverage without describing either as an observed detection result.</p>\n<h2>Verification</h2>\n<p>Capture the relevant policy names and effective states from the intended tenant. Compare them with the monitoring plan and investigate unexplained differences. If an owner approves activation, verify the saved state and review subsequent operational evidence without promising deterministic alert generation. Keep the policy-state check separate from investigation of a particular application&#8217;s behavior or a claim that the application is safe.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-cloud-apps/app-governance-investigate-predefined-policies\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Predefined OAuth app policy alerts</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nMicrosoft documents several predefined app-governance policies that remain visible but disabled: increased data use by an overprivileged or highly privileged app, unusual activity involving priority-account consent, and access to sensitive data. The documentation describes an optional Activate action for administrators who decide to continue using them. It also says predefined anomaly policies are nondeterministic and trigger on behavior that departs from normal patterns. Microsoft Learn.\nApplicability\nThis check concerns the documented policies’ state, not the presence of all app-governance protection. A row in a policy list is different from an enabled detection, and an enabled anomaly policy is not a promise that every contrived test will create an alert.\nDSE recommendation\nReconcile the intended detection register with each policy’s actual enabled or disabled state before asserting coverage. Ask the security owner to review why an optional policy is needed and what evidence would support retaining it. Do not reactivate every visible disabled policy simply to make an inventory count increase. Record deliberate exclusions and alternative coverage without describing either as an observed detection result.\nVerification\nCapture the relevant policy names and effective states from the intended tenant. Compare them with the monitoring plan and investigate unexplained differences. If an owner approves activation, verify the saved state and review subsequent operational evidence without promising deterministic alert generation. Keep the policy-state check separate from investigation of a particular application’s behavior or a claim that the application is safe.\nOfficial references\nMicrosoft Learn: Predefined OAuth app policy alerts. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft documents several predefined app-governance policies that remain visible but disabled: increased data use by an overprivileged or highly privileged app, unusual activity involving priority-account consent, and access to sensitive data. The documentation describes an optional Activate action for administrators who decide to continue using them. It also says predefined anomaly policies are nondeterministic and trigger on behavior that departs from normal patterns. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-cloud-apps/app-governance-investigate-predefined-policies).\n\n## Applicability\n\nThis check concerns the documented policies’ state, not the presence of all app-governance protection. A row in a policy list is different from an enabled detection, and an enabled anomaly policy is not a promise that every contrived test will create an alert.\n\n## DSE recommendation\n\nReconcile the intended detection register with each policy’s actual enabled or disabled state before asserting coverage. Ask the security owner to review why an optional policy is needed and what evidence would support retaining it. Do not reactivate every visible disabled policy simply to make an inventory count increase. Record deliberate exclusions and alternative coverage without describing either as an observed detection result.\n\n## Verification\n\nCapture the relevant policy names and effective states from the intended tenant. Compare them with the monitoring plan and investigate unexplained differences. If an owner approves activation, verify the saved state and review subsequent operational evidence without promising deterministic alert generation. Keep the policy-state check separate from investigation of a particular application’s behavior or a claim that the application is safe.\n\n## Official references\n\n[Microsoft Learn: Predefined OAuth app policy alerts](https://learn.microsoft.com/en-us/defender-cloud-apps/app-governance-investigate-predefined-policies). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-511-check-predefined-app-policy-state-before-claiming-its-detection-is-enabled/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-511-check-predefined-app-policy-state-before-claiming-its-detection-is-enabled/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-511-check-predefined-app-policy-state-before-claiming-its-detection-is-enabled/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Check predefined app-policy state before claiming its detection is enabled",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-511-check-predefined-app-policy-state-before-claiming-its-detection-is-enabled/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-511-check-predefined-app-policy-state-before-claiming-its-detection-is-enabled/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-511-check-predefined-app-policy-state-before-claiming-its-detection-is-enabled/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-511-check-predefined-app-policy-state-before-claiming-its-detection-is-enabled/",
                "headline": "Check predefined app-policy state before claiming its detection is enabled",
                "description": "Can a predefined OAuth app policy remain visible in Defender after Microsoft has disabled it?",
                "abstract": "Can a predefined OAuth app policy remain visible in Defender after Microsoft has disabled it?",
                "articleBody": "Source facts\nMicrosoft documents several predefined app-governance policies that remain visible but disabled: increased data use by an overprivileged or highly privileged app, unusual activity involving priority-account consent, and access to sensitive data. The documentation describes an optional Activate action for administrators who decide to continue using them. It also says predefined anomaly policies are nondeterministic and trigger on behavior that departs from normal patterns. Microsoft Learn.\nApplicability\nThis check concerns the documented policies’ state, not the presence of all app-governance protection. A row in a policy list is different from an enabled detection, and an enabled anomaly policy is not a promise that every contrived test will create an alert.\nDSE recommendation\nReconcile the intended detection register with each policy’s actual enabled or disabled state before asserting coverage. Ask the security owner to review why an optional policy is needed and what evidence would support retaining it. Do not reactivate every visible disabled policy simply to make an inventory count increase. Record deliberate exclusions and alternative coverage without describing either as an observed detection result.\nVerification\nCapture the relevant policy names and effective states from the intended tenant. Compare them with the monitoring plan and investigate unexplained differences. If an owner approves activation, verify the saved state and review subsequent operational evidence without promising deterministic alert generation. Keep the policy-state check separate from investigation of a particular application’s behavior or a claim that the application is safe.\nOfficial references\nMicrosoft Learn: Predefined OAuth app policy alerts. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:23:25+00:00",
                "dateModified": "2026-09-10T02:11:17+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-511-check-predefined-app-policy-state-before-claiming-its-detection-is-enabled/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-511-check-predefined-app-policy-state-before-claiming-its-detection-is-enabled/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Check predefined app-policy state before claiming its detection is enabled"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Briefing",
                    "Information priority"
                ],
                "genre": "Briefing",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 250,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Investigate predefined OAuth app policy alerts with app governance - Microsoft Defender for Cloud Apps | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-cloud-apps/app-governance-investigate-predefined-policies"
                }
            }
        ]
    }
}