Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft SC-300 Exam - Topic 1 Question 129 Discussion

You have a Microsoft 365 E5 subscription.Users authorize third-party cloud apps to access their data.You need to configure an alert that will be triggered when an app requires high permissions and is authorized by more than 20 users.Which type of policy should you create in the Microsoft Defender for Cloud Apps portal?
B) OAuth app policy
A) anomaly detection policy
C) access policy
D) activity policy

Microsoft SC-300 Exam - Topic 1 Question 129 Discussion

Actual exam question for Microsoft's SC-300 exam
Question #: 129
Topic #: 1
[All SC-300 Questions]

You have a Microsoft 365 E5 subscription.

Users authorize third-party cloud apps to access their data.

You need to configure an alert that will be triggered when an app requires high permissions and is authorized by more than 20 users.

Which type of policy should you create in the Microsoft Defender for Cloud Apps portal?

Show Suggested Answer Hide Answer
Suggested Answer: B

According to Microsoft Defender for Cloud Apps documentation and the SC-300 study guide, an OAuth app policy monitors third-party applications that request access to Microsoft 365 data through Microsoft Graph API permissions. These apps can request delegated or application permissions. When an app is authorized by many users and requests high permissions such as Calendars.ReadWrite, it can introduce security risks.

Defender for Cloud Apps allows administrators to create OAuth app policies to generate alerts when an app:

Requires high permissions (e.g., read/write to mailboxes, calendars, or files).

Is authorized by more than a specified number of users (for example, more than 20).

This matches the requirement in the question exactly. Other policy types (anomaly detection, access, or activity) monitor user or session behavior, not app consent behavior.

As per Microsoft's documentation:

''Use OAuth app policies to detect risky OAuth apps, monitor application permissions, and alert when apps are authorized by an unusual number of users or request excessive permissions.''


Contribute your Thoughts:

0/2000 characters
Cory
4 days ago
But we need to specifically monitor app authorizations. B) is more targeted.
upvoted 0 times
...
Carla
9 days ago
I’m not so sure. A) anomaly detection policy could also work for unusual activity.
upvoted 0 times
...
Stanford
14 days ago
Agreed! OAuth app policy makes sense for tracking high permissions.
upvoted 0 times
...
Dacia
19 days ago
I think B) OAuth app policy is the right choice. It focuses on app permissions.
upvoted 0 times
...
Tricia
25 days ago
But what if the app is legit? Shouldn't we be cautious?
upvoted 0 times
...
Antonio
30 days ago
I agree, OAuth makes the most sense here.
upvoted 0 times
...
Arlette
1 month ago
Wait, can you really set alerts for that? Sounds risky!
upvoted 0 times
...
Marti
1 month ago
I think it's more of an anomaly detection policy.
upvoted 0 times
...
Nilsa
2 months ago
Definitely an OAuth app policy!
upvoted 0 times
...
Launa
2 months ago
I agree, OAuth seems like the right choice here.
upvoted 0 times
...
Johnna
2 months ago
No way, it has to be an anomaly detection policy!
upvoted 0 times
...
Alpha
2 months ago
Surprised this isn't more straightforward.
upvoted 0 times
...
Louann
2 months ago
I think access policy could work too.
upvoted 0 times
...
Domingo
2 months ago
Definitely an OAuth app policy!
upvoted 0 times
...
Garry
3 months ago
I feel like access policies could be relevant here, but I can't recall if they specifically handle the number of users authorizing apps.
upvoted 0 times
...
Arthur
3 months ago
This sounds similar to a question we had about monitoring app access, and I think the right choice was an anomaly detection policy, but I'm confused about the user count aspect.
upvoted 0 times
...
Desmond
3 months ago
I remember practicing with activity policies, but I don't think they specifically target app permissions like this question asks.
upvoted 0 times
...
Nina
4 months ago
I think we might need to create an OAuth app policy since it deals with third-party app permissions, but I'm not entirely sure.
upvoted 0 times
...

Save Cancel