Microsoft Defender for Cloud Apps: Check which policy applied at event

Anonym
2023-02-09T13:06:21+00:00

While trying to upload a file to MS Teams, a client of mine gets a message from Defender for Cloud Apps that the upload has been blocked.

After checking the Cloud Defender policies, I noticed that there are too many policies to identify the one that just got triggered.

Is there a way in MS365 to get which exact policy got applied to user XY at a certain time?

Thanks already for reading and I'll gladly provide more information if needed.

Microsoft 365 und Office | Microsoft 365 Defender | Andere | Windows

Gesperrte Frage. Diese Frage wurde aus der Microsoft-Support-Community migriert. Sie können darüber abstimmen, ob sie hilfreich ist, aber Sie können keine Kommentare oder Antworten hinzufügen oder der Frage folgen.

0 Kommentare Keine Kommentare

1 Antwort

Sortieren nach: Neueste
  1. Anonym
    2023-02-09T13:45:34+00:00

    Hello Ms. M, thanks for coming into forums. I'm also a user like you and I'll be more than happy to help you to the best of my knowledge.

    Yes, you can check which policy was applied to a user in Microsoft Defender for Cloud Apps by reviewing the audit logs.

    To access the audit logs, follow these steps:

    -Go to the Microsoft 365 security center. -Click on the "Threat management" section, and then click on "Audit log search". -In the "Audit log search" page, you can select "Cloud App Security" as the source and then specify the date range and user account to search for events related to Defender for Cloud Apps. -Once the events are displayed, you can look for events related to "File upload blocked" or "Policy applied". These events will include information on which policy was triggered and applied.

    You can also filter the events by policy name to quickly find the specific policy that was triggered.

    Hope this info helps. Feel free to let us know.

    Warm Regards, Myk

    War diese Antwort hilfreich?

    0 Kommentare Keine Kommentare