Which Defender for Cloud Apps Policy Blocks Printing from App1?

Implement and manage Microsoft Defender for Cloud Apps Implement and manage secure access
Answer Correct answer: B — Create a session policy in Microsoft Defender for Cloud Apps to block User1 from printing from App1 when Conditional Access App Control is deployed.

You have a Microsoft 365 E5 subscription that contains a user named User1. You have a Conditional Access policy applied to a cloud-based app named App1. App1 has Conditional Access App Control deployed. You need to create a Microsoft Defender for Cloud Apps policy to block User1 from printing from App1. Which type of policy should you create?

  1. activity policy
  2. session policy Correct Answer
  3. OAuth app policy
  4. Cloud Discovery anomaly detection policy

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests whether you know that Conditional Access App Control requires a session policy for real-time in-session actions like print blocking, while activity, OAuth app, and Cloud Discovery anomaly policies serve different purposes.

This MS-102 question asks which Microsoft Defender for Cloud Apps policy blocks a user from printing from an app protected by Conditional Access App Control. The correct choice is a session policy (B), which can enforce real-time print blocking inside the proxied session.

A common mistake is choosing an activity policy because it sounds like it governs user activity, but activity policies detect and alert rather than block printing in real time.

Community Discussion (4 comments)

7d01a47 👍 7 Selected: B
Designed to control user sessions for cloud applications. It allows you to enforce restrictions based on user actions during a session, including blocking specific activities like printing. Since App1 has Conditional Access App Control deployed, you can leverage session policies to monitor and control user activities in real-time.
0b29bdf 👍 5
B. session policy
Hamouda1 👍 1 Selected: B
B. session policy / Correct answer
Mpalonopsaro 👍 3 Selected: B
https://learn.microsoft.com/en-us/defender-cloud-apps/session-policy-aad

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A session policy in Microsoft Defender for Cloud Apps is the only policy type that can apply real-time controls to a cloud app session proxied by Conditional Access App Control. Because App1 already has Conditional Access App Control deployed, User1's session is routed through Defender for Cloud Apps, where a session policy can block actions such as printing. The question asks specifically to block printing, which is a session control, not a post-event detection. The official Microsoft Learn documentation for session policies confirms they can block downloads, uploads, copy/paste, and print actions. Therefore B is correct.

Why the Other Options Are Wrong

An activity policy (A) is used to detect and alert on user activities after they occur, or to apply governance actions like suspend user — it is not the policy type used to block printing inside a live app session. An OAuth app policy (C) governs the permissions and consent of OAuth applications connecting to Microsoft 365; it has nothing to do with blocking print from a specific app session. A Cloud Discovery anomaly detection policy (D) monitors Cloud Discovery logs for unusual usage of discovered apps, such as spikes in traffic or rare IP addresses, and cannot enforce session controls. None of these interact with Conditional Access App Control to stop a print action.

Community Comment Notes

The community consensus is unanimous: all voters chose B. As one learner (7d01a47) explained, session policies are "Designed to control user sessions for cloud applications" and let you "enforce restrictions based on user actions during a session" and block actions "including blocking specific activities like printing." Mpalonopsaro pointed directly to the Microsoft Learn session-policy-aad documentation, and Hamouda1 and 0b29bdf also selected B. Those comments align with the official behavior, reinforcing that a session policy is the correct policy type here.

Official Reference

Exam Strategy

When a question says Conditional Access App Control is deployed and asks about blocking an in-app action like printing, immediately map it to session policy. Activity policies detect rather than block, so do not let the word "activity" pull you toward them.

Frequently Asked Questions

Why is a session policy correct instead of an activity policy for blocking printing?

A session policy can enforce real-time controls like block printing inside the proxied App1 session, whereas an activity policy is for detecting or alerting on activities after they occur.

Do OAuth app policy or Cloud Discovery anomaly detection policy fit this scenario?

No. OAuth app policies govern app permissions and consent, while Cloud Discovery anomaly detection policies flag unusual shadow IT usage; neither blocks printing from a Conditional Access App Control session.

Related Analysis

Practice All MS-102 Questions

Access 111 questions with complete answers and detailed explanations.

View Full MS-102 Practice Test →

← Back to MS-102 Study Guide