Creating a Conditional Access policy first to enable Defender for Cloud Apps session control

Topic 5
Answer Correct answer: D — A Conditional Access policy using Conditional Access App Control is the prerequisite that routes the session to Defender for Cloud Apps session control.

You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1. You need to enable Microsoft Defender for Cloud Apps session control for Site1. Which type of policy should you create first?

  1. access
  2. session
  3. app governance
  4. Conditional Access Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Defender for Cloud Apps session policies act on sessions that are already routed through Conditional Access App Control; the Conditional Access policy is the prerequisite that sends the user session to Defender for Cloud Apps.

To enable Microsoft Defender for Cloud Apps session control for a SharePoint Online site, you first create a Conditional Access policy that uses Conditional Access App Control, which routes the session through Defender for Cloud Apps for real-time monitoring and control.

Creating a session policy directly — a Defender for Cloud Apps session policy has no effect until a Conditional Access policy sends the relevant session through App Control, so the Conditional Access policy must come first.

Community Discussion (3 comments)

MCWDSR 👍 5 Selected: D
To enable Microsoft Defender for Cloud Apps session control for your SharePoint Online site (Site1), you should create a Conditional Access policy (D) first. This policy will allow you to enforce session controls and integrate with Microsoft Defender for Cloud Apps to monitor and control user activities in real-time1. Create session policies - Microsoft Defender for Cloud Apps
a_kto_to 👍 1 Selected: D
ChatGTP: The correct answer is: ✅ D. Conditional Access 💡 Explanation: To enable Microsoft Defender for Cloud Apps (MDCA) session control (e.g., for monitoring or restricting user activity in real time) for a SharePoint Online site, the first thing you need to do is: ➤ Create a Conditional Access policy …with "Use Conditional Access App Control" enabled.
HAjouz 👍 3 Selected: D
Correct answer is D 100%

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Defender for Cloud Apps session control is applied to sessions that are routed through Conditional Access App Control. The first step is therefore to create a Conditional Access policy (scoped to the SharePoint Online site and users) that sets the session control to 'Use Conditional Access App Control', which then lets a Defender for Cloud Apps session policy monitor and control the session.

Why the Other Options Are Wrong

Creating a session policy (B) before the Conditional Access policy routes sessions does nothing, because no session is being sent to App Control yet. An access policy (A) governs access decisions, not real-time session monitoring. App governance (C) manages app permissions and is unrelated to session control.

Community Comment Notes

The community is unanimous (D 100). MCWDSR (5 likes) and HAjouz confirm that a Conditional Access policy with Conditional Access App Control enabled is the first step before Defender for Cloud Apps session policies take effect.

Official Reference

Related Analysis

Practice All SC-200 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-200 Practice Test →

← Back to SC-200 Study Guide