GuideInformationCybersecurity

Account for skipped Graph-only conditions in OAuth app policies

What happens to Graph-only conditions when app governance evaluates an app using only non-Graph APIs?

Governed cloud identity system with connected service and lifecycle nodes.
DSE visual intelligenceIdentity & cloudGuide · 2 min read
Executive summary

What you need to know

What happens to Graph-only conditions when app governance evaluates an app using only non-Graph APIs?

Potentially affected

Custom Microsoft Entra OAuth app-governance policies whose app population includes non-Graph-only applications.

DSE recommendation

Review condition applicability for each API population before interpreting a custom app policy as one uniform test.

Source facts

App governance skips Graph-only policy conditions for applications that access only non-Graph APIs, then evaluates the other conditions. Examples marked Graph only include application or delegated permissions, API access volume and error rate. The normal policy rule requires all specified conditions for an alert, so the documented applicability exception matters. Audit mode evaluates policies without performing configured actions. Microsoft Learn.

Applicability

Use this review for custom Microsoft Entra OAuth app policies spanning different API permission sets. The question is which conditions actually participate, not whether a skipped condition proves the app passed that test.

DSE recommendation

Review condition applicability for each API population before interpreting a custom app policy as one uniform test. Have the policy owner identify the Graph-only conditions and explain the remaining decision for non-Graph-only apps. Split the documented review cases where necessary so an alert or its absence can be understood against the applicable conditions. Keep automatic disablement out of the initial experiment.

Verification

In audit mode, inspect representative authorized apps with Graph access and with only non-Graph access. Compare the applicable conditions and resulting alerts with the intended policy question. Record skipped conditions explicitly instead of labeling them satisfied or failed. Before activating actions, require a reviewer to confirm that each in-scope API population has an understood decision path. Retain the app permission evidence and policy version; this test is not proof that all app behavior is benign.

Official references

Microsoft Learn: Custom OAuth app policies. Source reviewed September 9, 2026.

Primary reference

Review the official source

Create and manage OAuth app policies with app governance - Microsoft Defender for Cloud Apps | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE