Prerequisite for Microsoft Defender for Cloud Apps Session Policy

Answer Correct answer: C — You must create a Conditional Access policy in the Microsoft Entra admin center to enable Conditional Access App Control, which allows Defender for Cloud Apps to monitor and control user sessions.

You have a Microsoft 365 E5 subscription. You need to be able to create a Microsoft Defender for Cloud Apps session policy. What should you do first?

  1. From the Microsoft 365 Defender portal, select User monitoring.
  2. From the Microsoft 365 Defender portal, select App onboarding/maintenance.
  3. From the Microsoft Entra admin center, create a Conditional Access policy. Correct Answer
  4. From the Microsoft 365 Defender portal, create a continuous report.

Community Votes

C
60%
B
40%

60% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the dependency chain: session policies are not standalone but rely on the infrastructure provided by Conditional Access App Control (CAAC). The trap is assuming app onboarding is the immediate step before creating the policy itself.

To enable session policies in Microsoft Defender for Cloud Apps, you must first establish a Conditional Access policy in the Entra admin center. This prerequisite ensures that user traffic is redirected through the proxy for real-time monitoring and control.

Many candidates select 'App onboarding/maintenance' because they believe connecting the application is the primary administrative task. However, without an active Conditional Access policy to route traffic, the session policy has no mechanism to enforce controls.

Community Discussion (5 comments)

csi_2025 👍 1 Selected: C
The wording of the question doesn't mention that a new App is to be monitored but that you need to be able to create a session policy. For that you definitely have to create a CA Policy.
rvln7 👍 1 Selected: B
I think that we should onboard it firs, so B
Oskarma 👍 1 Selected: C
This policy serves as the foundation for redirecting user sessions through Conditional Access App Control, allowing you to monitor and control user activities in real-time.
northgaterebel 👍 4 Selected: C
In order for your session policy to work, you must also have a Microsoft Entra ID Conditional Access policy, which creates the permissions to control traffic. https://learn.microsoft.com/en-us/defender-cloud-apps/session-policy-aad
Btn26 👍 3 Selected: B
The correct first step is B. From the Microsoft 365 Defender portal, select App onboarding/maintenance. This step is necessary to connect the app to Microsoft Defender for Cloud Apps before you can create a session policy.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Creating a Conditional Access policy is the mandatory first step because it enables Conditional Access App Control (CAAC). As noted by northgaterebel, "In order for your session policy to work, you must also have a Microsoft Entra ID Conditional Access policy." The CA policy defines the conditions under which users are redirected through the Defender for Cloud Apps proxy. Without this redirection infrastructure, the session policy cannot inspect or modify traffic in real-time.

Why the Other Options Are Wrong

Option B (App onboarding) is a necessary configuration step but is not the functional prerequisite for the policy logic to operate; you can onboard apps without enabling session control if no CA policy exists to trigger it. Option A (User monitoring) provides visibility but does not grant the permissions to control traffic flows required for session policies. Option D (Continuous report) is a reporting feature unrelated to the enforcement engine.

Community Comment Notes

Users like csi_2025 highlighted that the question focuses on the capability to create the policy, which inherently requires the CA foundation. Others like Oskarma emphasized that the CA policy serves as the "foundation for redirecting user sessions," confirming that the technical dependency lies with Entra ID rather than the Defender portal's app management screen.

Official Reference

Exam Strategy

When asked about 'session policies' in Defender for Cloud Apps, immediately look for 'Conditional Access'. These two components are tightly coupled; one cannot function effectively without the other. Always identify the underlying traffic routing mechanism before selecting configuration steps.

Frequently Asked Questions

Why is app onboarding not the first step?

App onboarding connects the service, but session policies require a Conditional Access policy to route traffic through the proxy for inspection. Without CA, session policies cannot enforce controls.

Can I create a session policy without Conditional Access?

No. Session policies rely on Conditional Access App Control (CAAC) to intercept and analyze network traffic. The CA policy is the gateway that makes session inspection possible.

Related Analysis

Practice All SC-300 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-300 Practice Test →

← Back to SC-300 Study Guide