# Check predefined app-policy state before claiming its detection is enabled

> Can a predefined OAuth app policy remain visible in Defender after Microsoft has disabled it?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-511-check-predefined-app-policy-state-before-claiming-its-detection-is-enabled/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:23:25+00:00
- Modified: 2026-09-10T02:11:17+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Briefing
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Can a predefined OAuth app policy remain visible in Defender after Microsoft has disabled it?

## Potentially affected

App governance environments reviewing the documented predefined OAuth app policies and their effective state.

## DSE recommendation

Reconcile the intended detection register with each policy's actual enabled or disabled state before asserting coverage.

## Article

## Source facts

Microsoft documents several predefined app-governance policies that remain visible but disabled: increased data use by an overprivileged or highly privileged app, unusual activity involving priority-account consent, and access to sensitive data. The documentation describes an optional Activate action for administrators who decide to continue using them. It also says predefined anomaly policies are nondeterministic and trigger on behavior that departs from normal patterns. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-cloud-apps/app-governance-investigate-predefined-policies).

## Applicability

This check concerns the documented policies’ state, not the presence of all app-governance protection. A row in a policy list is different from an enabled detection, and an enabled anomaly policy is not a promise that every contrived test will create an alert.

## DSE recommendation

Reconcile the intended detection register with each policy’s actual enabled or disabled state before asserting coverage. Ask the security owner to review why an optional policy is needed and what evidence would support retaining it. Do not reactivate every visible disabled policy simply to make an inventory count increase. Record deliberate exclusions and alternative coverage without describing either as an observed detection result.

## Verification

Capture the relevant policy names and effective states from the intended tenant. Compare them with the monitoring plan and investigate unexplained differences. If an owner approves activation, verify the saved state and review subsequent operational evidence without promising deterministic alert generation. Keep the policy-state check separate from investigation of a particular application’s behavior or a claim that the application is safe.

## Official references

[Microsoft Learn: Predefined OAuth app policy alerts](https://learn.microsoft.com/en-us/defender-cloud-apps/app-governance-investigate-predefined-policies). Source reviewed September 9, 2026.

## Primary reference

- Name: Investigate predefined OAuth app policy alerts with app governance - Microsoft Defender for Cloud Apps | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/defender-cloud-apps/app-governance-investigate-predefined-policies
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check predefined app-policy state before claiming its detection is enabled,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-511-check-predefined-app-policy-state-before-claiming-its-detection-is-enabled/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
