What Should You Do First for App1 Access Policy in Defender for Cloud Apps?
You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps. You register a cloud app named App1 in Microsoft Entra ID. You need to create an access policy for App1. What should you do first?
Community Votes
73% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests the prerequisite for a Defender for Cloud Apps access policy, and the common trap is confusing API-based app connectors with session-control onboarding via Conditional Access App Control.
Microsoft Defender for Cloud Apps access policies require Conditional Access App Control, not an API app connector. This page establishes that deploying Conditional Access App Control to App1 is the correct first step for an MS-102 access policy.
Most candidates choose D (configure an app connector) because app connectors are the usual first step for API visibility, but they are not required for real-time access policies.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Microsoft Defender for Cloud Apps access policies are real-time session policies that depend on Conditional Access App Control (CAAC). When you register App1 in Microsoft Entra ID, you must deploy CAAC to it so that authentication traffic can be proxied and evaluated by Defender for Cloud Apps. Only after CAAC is deployed can you create an access policy that blocks or allows sessions based on conditions. The app connector path is for API-based visibility and does not provide the session interception required for access policies. Therefore, deploying CAAC is the prerequisite first step.Why the Other Options Are Wrong
Creating an app tag (B) is used for filtering and grouping apps after onboarding, not for enabling access policies. Adding a SIEM agent (C) integrates Defender for Cloud Apps alerts with a SIEM, which is unrelated to creating an access policy for a specific app. Configuring an app connector (D) is the correct first step for activity and file policies that rely on API data, but it does not enable real-time session control; an access policy needs CAAC. Because the question specifically asks for an access policy, D is a distractor that many candidates select by habit.Community Comment Notes
The comments show a split: the vote majority picked D, but deeper explanations favor A. wafferrr wrote that app connectors are "not required for access policies," pointing to the real prerequisite. JohnDoe47 described registering an app in Entra, adding a Conditional Access App Control policy, and then creating an access policy with "Automatic Entra ID onboarding" — demonstrating that no app connector was needed. GetEsn shared the official get-started link, which reinforces the CAAC onboarding path. These learner notes support the conclusion that Conditional Access App Control is the first step.Official Reference
Exam Strategy
For MS-102, distinguish between API app connectors (for activity and file policies) and Conditional Access App Control (for access and session policies). If the question mentions an app registered in Entra ID and an access policy, look for Conditional Access App Control deployment as the prerequisite.
Frequently Asked Questions
Why is configuring an app connector not the first step for an App1 access policy?
App connectors provide API-based activity and file visibility; access policies need real-time session control, which requires Conditional Access App Control instead.
Does registering App1 in Microsoft Entra ID automatically onboard it to Defender for Cloud Apps?
No, Entra ID registration alone is not enough; you must deploy Conditional Access App Control to App1 before creating an access policy.
Related Analysis
Practice All MS-102 Questions
Access 111 questions with complete answers and detailed explanations.
View Full MS-102 Practice Test →