What you need to know
What happens to Graph-only conditions when app governance evaluates an app using only non-Graph APIs?
Potentially affected
Custom Microsoft Entra OAuth app-governance policies whose app population includes non-Graph-only applications.
DSE recommendation
Review condition applicability for each API population before interpreting a custom app policy as one uniform test.
Source facts
App governance skips Graph-only policy conditions for applications that access only non-Graph APIs, then evaluates the other conditions. Examples marked Graph only include application or delegated permissions, API access volume and error rate. The normal policy rule requires all specified conditions for an alert, so the documented applicability exception matters. Audit mode evaluates policies without performing configured actions. Microsoft Learn.
Applicability
Use this review for custom Microsoft Entra OAuth app policies spanning different API permission sets. The question is which conditions actually participate, not whether a skipped condition proves the app passed that test.
DSE recommendation
Review condition applicability for each API population before interpreting a custom app policy as one uniform test. Have the policy owner identify the Graph-only conditions and explain the remaining decision for non-Graph-only apps. Split the documented review cases where necessary so an alert or its absence can be understood against the applicable conditions. Keep automatic disablement out of the initial experiment.
Verification
In audit mode, inspect representative authorized apps with Graph access and with only non-Graph access. Compare the applicable conditions and resulting alerts with the intended policy question. Record skipped conditions explicitly instead of labeling them satisfied or failed. Before activating actions, require a reviewer to confirm that each in-scope API population has an understood decision path. Retain the app permission evidence and policy version; this test is not proof that all app behavior is benign.
Official references
Microsoft Learn: Custom OAuth app policies. Source reviewed September 9, 2026.
Review the official source
Create and manage OAuth app policies with app governance - Microsoft Defender for Cloud Apps | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE