Creating a Conditional Access policy first to enable Defender for Cloud Apps session control
You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1. You need to enable Microsoft Defender for Cloud Apps session control for Site1. Which type of policy should you create first?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Defender for Cloud Apps session policies act on sessions that are already routed through Conditional Access App Control; the Conditional Access policy is the prerequisite that sends the user session to Defender for Cloud Apps.
To enable Microsoft Defender for Cloud Apps session control for a SharePoint Online site, you first create a Conditional Access policy that uses Conditional Access App Control, which routes the session through Defender for Cloud Apps for real-time monitoring and control.
Creating a session policy directly — a Defender for Cloud Apps session policy has no effect until a Conditional Access policy sends the relevant session through App Control, so the Conditional Access policy must come first.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Defender for Cloud Apps session control is applied to sessions that are routed through Conditional Access App Control. The first step is therefore to create a Conditional Access policy (scoped to the SharePoint Online site and users) that sets the session control to 'Use Conditional Access App Control', which then lets a Defender for Cloud Apps session policy monitor and control the session.Why the Other Options Are Wrong
Creating a session policy (B) before the Conditional Access policy routes sessions does nothing, because no session is being sent to App Control yet. An access policy (A) governs access decisions, not real-time session monitoring. App governance (C) manages app permissions and is unrelated to session control.Community Comment Notes
The community is unanimous (D 100). MCWDSR (5 likes) and HAjouz confirm that a Conditional Access policy with Conditional Access App Control enabled is the first step before Defender for Cloud Apps session policies take effect.Official Reference
Related Analysis
Practice All SC-200 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-200 Practice Test →