Prerequisite for Microsoft Defender for Cloud Apps Session Policy
You have a Microsoft 365 E5 subscription. You need to be able to create a Microsoft Defender for Cloud Apps session policy. What should you do first?
Community Votes
60% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the dependency chain: session policies are not standalone but rely on the infrastructure provided by Conditional Access App Control (CAAC). The trap is assuming app onboarding is the immediate step before creating the policy itself.
To enable session policies in Microsoft Defender for Cloud Apps, you must first establish a Conditional Access policy in the Entra admin center. This prerequisite ensures that user traffic is redirected through the proxy for real-time monitoring and control.
Many candidates select 'App onboarding/maintenance' because they believe connecting the application is the primary administrative task. However, without an active Conditional Access policy to route traffic, the session policy has no mechanism to enforce controls.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Creating a Conditional Access policy is the mandatory first step because it enables Conditional Access App Control (CAAC). As noted by northgaterebel, "In order for your session policy to work, you must also have a Microsoft Entra ID Conditional Access policy." The CA policy defines the conditions under which users are redirected through the Defender for Cloud Apps proxy. Without this redirection infrastructure, the session policy cannot inspect or modify traffic in real-time.Why the Other Options Are Wrong
Option B (App onboarding) is a necessary configuration step but is not the functional prerequisite for the policy logic to operate; you can onboard apps without enabling session control if no CA policy exists to trigger it. Option A (User monitoring) provides visibility but does not grant the permissions to control traffic flows required for session policies. Option D (Continuous report) is a reporting feature unrelated to the enforcement engine.Community Comment Notes
Users like csi_2025 highlighted that the question focuses on the capability to create the policy, which inherently requires the CA foundation. Others like Oskarma emphasized that the CA policy serves as the "foundation for redirecting user sessions," confirming that the technical dependency lies with Entra ID rather than the Defender portal's app management screen.Official Reference
Exam Strategy
When asked about 'session policies' in Defender for Cloud Apps, immediately look for 'Conditional Access'. These two components are tightly coupled; one cannot function effectively without the other. Always identify the underlying traffic routing mechanism before selecting configuration steps.
Frequently Asked Questions
Why is app onboarding not the first step?
App onboarding connects the service, but session policies require a Conditional Access policy to route traffic through the proxy for inspection. Without CA, session policies cannot enforce controls.
Can I create a session policy without Conditional Access?
No. Session policies rely on Conditional Access App Control (CAAC) to intercept and analyze network traffic. The CA policy is the gateway that makes session inspection possible.
Related Analysis
Practice All SC-300 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-300 Practice Test →