# Account for skipped Graph-only conditions in OAuth app policies

> What happens to Graph-only conditions when app governance evaluates an app using only non-Graph APIs?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-146-account-for-skipped-graph-only-conditions-in-oauth-app-policies/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:29:30+00:00
- Modified: 2026-09-10T00:52:39+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity
- Reading time: 2 minutes

## What you need to know

What happens to Graph-only conditions when app governance evaluates an app using only non-Graph APIs?

## Potentially affected

Custom Microsoft Entra OAuth app-governance policies whose app population includes non-Graph-only applications.

## DSE recommendation

Review condition applicability for each API population before interpreting a custom app policy as one uniform test.

## Article

## Source facts

App governance skips Graph-only policy conditions for applications that access only non-Graph APIs, then evaluates the other conditions. Examples marked Graph only include application or delegated permissions, API access volume and error rate. The normal policy rule requires all specified conditions for an alert, so the documented applicability exception matters. Audit mode evaluates policies without performing configured actions. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-cloud-apps/app-governance-app-policies-create).

## Applicability

Use this review for custom Microsoft Entra OAuth app policies spanning different API permission sets. The question is which conditions actually participate, not whether a skipped condition proves the app passed that test.

## DSE recommendation

Review condition applicability for each API population before interpreting a custom app policy as one uniform test. Have the policy owner identify the Graph-only conditions and explain the remaining decision for non-Graph-only apps. Split the documented review cases where necessary so an alert or its absence can be understood against the applicable conditions. Keep automatic disablement out of the initial experiment.

## Verification

In audit mode, inspect representative authorized apps with Graph access and with only non-Graph access. Compare the applicable conditions and resulting alerts with the intended policy question. Record skipped conditions explicitly instead of labeling them satisfied or failed. Before activating actions, require a reviewer to confirm that each in-scope API population has an understood decision path. Retain the app permission evidence and policy version; this test is not proof that all app behavior is benign.

## Official references

[Microsoft Learn: Custom OAuth app policies](https://learn.microsoft.com/en-us/defender-cloud-apps/app-governance-app-policies-create). Source reviewed September 9, 2026.

## Primary reference

- Name: Create and manage OAuth app policies with app governance - Microsoft Defender for Cloud Apps | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/defender-cloud-apps/app-governance-app-policies-create
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Account for skipped Graph-only conditions in OAuth app policies,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-146-account-for-skipped-graph-only-conditions-in-oauth-app-policies/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
