GuideInformationCybersecurity

Do not expect a Monitor only Cloud Apps session policy to record file activity

Does the Monitor only session-control type observe downloads as well as sign-ins?

Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.
DSE visual intelligenceCyber defenseGuide · 2 min read
Executive summary

What you need to know

Does the Monitor only session-control type observe downloads as well as sign-ins?

Potentially affected

Defender for Cloud Apps session policies for applications onboarded to Conditional Access app control.

DSE recommendation

Translate the required observation into the appropriate session-control type instead of choosing Monitor only from its name.

Source facts

Defender for Cloud Apps’ Monitor only session-control type monitors Login activity only. Microsoft’s guidance uses a file-download or file-upload control with the Audit action when those activities need observation without a block. Session policies also require a corresponding Microsoft Entra Conditional Access policy to control the traffic. Microsoft Learn.

Applicability

This is a choice of session-control type for an already onboarded application. It does not describe all Cloud Apps telemetry or guarantee that a user’s entire session will be recorded. Keep the desired file observation separate from a decision to block it.

DSE recommendation

Translate the required observation into the appropriate session-control type instead of choosing Monitor only from its name. Write down the exact upload or download scenario, application and user scope that the pilot should reveal. Inspect the selected action so an observation exercise does not unintentionally become a blocking change. Review other matching session policies before interpreting the user experience.

Verification

Use an approved test account and harmless file, end existing sessions, and authenticate again before exercising the selected scenario. Compare the observed activity and policy report with the intended file action rather than accepting a successful sign-in as sufficient evidence. If behavior is more restrictive than expected, check the other matching policies: Microsoft states that the more restrictive session policy wins. Retain the tested scenario and actual outcome without claiming observation of activities outside its scope.

Official references

Microsoft Learn: Cloud Apps session policies. Source reviewed September 9, 2026.

Primary reference

Review the official source

Create session policies - Microsoft Defender for Cloud Apps | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE