Eine integrierte Bedrohungsschutzlösung, die entwickelt wurde, um Cyberbedrohungen in Microsoft 365-Diensten zu erkennen, zu untersuchen und darauf zu reagieren.
Hello Ms. M, thanks for coming into forums. I'm also a user like you and I'll be more than happy to help you to the best of my knowledge.
Yes, you can check which policy was applied to a user in Microsoft Defender for Cloud Apps by reviewing the audit logs.
To access the audit logs, follow these steps:
-Go to the Microsoft 365 security center. -Click on the "Threat management" section, and then click on "Audit log search". -In the "Audit log search" page, you can select "Cloud App Security" as the source and then specify the date range and user account to search for events related to Defender for Cloud Apps. -Once the events are displayed, you can look for events related to "File upload blocked" or "Policy applied". These events will include information on which policy was triggered and applied.
You can also filter the events by policy name to quickly find the specific policy that was triggered.
Hope this info helps. Feel free to let us know.
Warm Regards, Myk