Microsoft Defender for Cloud Apps — Session Policy Masterclass
Control real-time user sessions and govern SaaS data flows with Defender for Cloud Apps
Conditional Access gets users to the door — Defender for Cloud Apps session policies control what they do once inside. This masterclass trains engineers to implement session controls, access policies, and activity policies that protect sensitive data in SaaS applications, manage shadow IT risk, and govern OAuth application sprawl — with direct application to Copilot data governance, APRA CPS 234 cloud controls, and ASD Essential Eight application hardening.

At a Glance
Who it's for
- Identity and security engineers who completed the Conditional Access Workshop and need session control depth
- Compliance officers governing SaaS application usage and OAuth application sprawl
- Security architects designing Copilot data governance controls
- CASB practitioners transitioning to or consolidating on Microsoft Defender for Cloud Apps
Course Details
Course Overview
Microsoft Defender for Cloud Apps (formerly MCAS) is the cloud access security broker (CASB) embedded in the Microsoft 365 E5 Security stack. This masterclass moves past the basics of app discovery and goes deep into the operational configuration that makes Defender for Cloud Apps a genuine data governance tool: Conditional Access App Control session policies that proxy SaaS sessions and enforce real-time controls, activity policies that alert on or block risky actions within sanctioned apps, access policies for unmanaged devices, and the OAuth app governance feature that manages consent and permissions for third-party applications. In the Australian context, session policies and OAuth governance are increasingly referenced in APRA CPS 234 cloud service risk assessments and in ACSC Essential Eight Application Control implementation guidance for cloud-delivered applications.
What You'll Learn
Course Curriculum
Module 1: Shadow IT Discovery and App Governance Foundation
4 hours- Defender for Cloud Apps architecture: discovery, proxy, and API-based connectors
- Shadow IT discovery: log collection from firewalls, proxies, and Defender for Endpoint integration
- App catalogue and risk scores: evaluating SaaS applications against GDPR, SOC 2, and APRA CPS 234 criteria
- App sanctioning and tagging: building an approved and unsanctioned app registry
- App connectors: configuring API access for Microsoft 365, Salesforce, Box, ServiceNow, and other sanctioned apps
Module 2: Conditional Access App Control — Session Policies
6 hours- Conditional Access App Control architecture: how the reverse proxy works and browser session requirements
- Onboard applications to App Control: Microsoft 365, Salesforce, and custom SAML apps
- Session policies: monitor only, block download, block upload, and require step-up MFA on sensitive content
- File inspection: content inspection policies using sensitive information types and sensitivity labels
- Protect sensitive data on unmanaged devices: access policies scoping download controls by device compliance state
Module 3: Activity Policies and OAuth App Governance
4 hours- Activity policies: detect and alert on risky user behaviours within sanctioned SaaS apps
- Anomaly detection policies: impossible travel, ransomware activity, and mass download alerts
- OAuth App Governance: review third-party app permissions, set publisher verification requirements, revoke overscoped consents
- OAuth policy automation: auto-revoke apps that exceed permissions or access non-sanctioned data sources
- APRA CPS 234 application risk evidence: shadow IT reports, OAuth governance posture, and app compliance scoring
Module 4: Advanced Integration and Governance Evidence Pack
2 hours- Microsoft Purview sensitivity label integration: govern cloud files using labels from within Defender for Cloud Apps
- Microsoft Sentinel integration: stream Defender for Cloud Apps alerts for SOC investigation and SOAR response
- Copilot data governance: using session policies to prevent Copilot from accessing unsanctioned SaaS data sources
- Governance evidence pack: App Control policy exports, OAuth review reports, and shadow IT assessment for APRA CPS 234
- Capstone: design a session policy framework for an Australian financial services or healthcare organisation
Who Should Attend
- Identity and security engineers extending Conditional Access into real-time session control
- Security architects designing SaaS and Copilot data governance controls
- CASB practitioners consolidating onto Microsoft Defender for Cloud Apps from a third-party broker
- Compliance officers governing shadow IT and OAuth application sprawl
- Risk and assurance staff in APRA-regulated entities building CPS 234 third-party evidence
- SOC engineers triaging Defender for Cloud Apps alerts in Microsoft Sentinel
Prerequisites
Before enrolling, please ensure you meet these requirements:
- • Completion of the Microsoft Entra Conditional Access Workshop (CA-WS-001) or equivalent production CA experience
- • Microsoft 365 E5 or Microsoft 365 E5 Security licence — Defender for Cloud Apps is included
- • Application Administrator or Security Administrator role in the Microsoft 365 tenant
- • At least one third-party SaaS application in use for the session policy labs (Salesforce, Box or similar)
- • Working understanding of SAML and OpenID Connect single sign-on flows
Delivery, Format and Logistics
Delivery Mode
Live online masterclass — 2 days intensive with a shared Microsoft 365 E5 Security lab
Maximum 10 participants — lab environment with Microsoft 365 E5 Security
What You'll Need
- Completion of Microsoft Entra Conditional Access Workshop (CA-WS-001) or equivalent CA production experience
- Microsoft 365 E5 or Microsoft 365 E5 Security licence (Defender for Cloud Apps is included)
- At least one third-party SaaS application in use for session policy lab exercises (Salesforce, Box, or similar)
- Application administrator or Security Administrator role in the Microsoft 365 tenant
What You'll Receive
- 16 hours of instructor-led masterclass sessions capped at 10 participants
- Step-by-step SAML application onboarding lab for Conditional Access App Control
- Session, access and activity policy templates you can adapt to your tenant
- OAuth app governance review workflow and auto-revoke policy configurations
- Shadow IT discovery assessment method with app sanction and unsanction registry template
- Capstone: a session policy framework for an Australian financial services or healthcare scenario
- APRA CPS 234 application governance evidence pack template
- Recorded sessions for 6 months and a certificate of completion
Frequently Asked Questions
Not Ready to Enrol?
Join our mailing list to receive updates about courses, resources, and cybersecurity insights tailored for Australian organisations.
Early-bird rate — apply your promo code at checkout.
Secure payment via Stripe · Promo codes accepted
Next Intake
September 2026 — register your interest at educ4te.com
Format
Live online masterclass — 2 days intensive with a shared Microsoft 365 E5 Security lab
Group & Enterprise Options
Discounted rates available for teams of 3+ delegates. Contact us for in-house delivery options.
What's Included
- 16 hours of instructor-led masterclass sessions capped at 10 participants
- Step-by-step SAML application onboarding lab for Conditional Access App Control
- Session, access and activity policy templates you can adapt to your tenant
- OAuth app governance review workflow and auto-revoke policy configurations
- Shadow IT discovery assessment method with app sanction and unsanction registry template
- Capstone: a session policy framework for an Australian financial services or healthcare scenario
- APRA CPS 234 application governance evidence pack template
- Recorded sessions for 6 months and a certificate of completion
Have questions about this course?