AdvancedMDCA-SESS-001

Microsoft Defender for Cloud Apps — Session Policy Masterclass

Control real-time user sessions and govern SaaS data flows with Defender for Cloud Apps

Conditional Access gets users to the door — Defender for Cloud Apps session policies control what they do once inside. This masterclass trains engineers to implement session controls, access policies, and activity policies that protect sensitive data in SaaS applications, manage shadow IT risk, and govern OAuth application sprawl — with direct application to Copilot data governance, APRA CPS 234 cloud controls, and ASD Essential Eight application hardening.

16 hours (2 days intensive)
New course
Certificate Included
Microsoft Defender for Cloud Apps — Session Policy Masterclass

At a Glance

Who it's for

  • Identity and security engineers who completed the Conditional Access Workshop and need session control depth
  • Compliance officers governing SaaS application usage and OAuth application sprawl
  • Security architects designing Copilot data governance controls
  • CASB practitioners transitioning to or consolidating on Microsoft Defender for Cloud Apps

Course Details

Duration:16 hours (2 days intensive)
Format:Live online masterclass — 2 days intensive with a shared Microsoft 365 E5 Security lab
Next intake:September 2026 — register your interest at educ4te.com
Alignment:Aligned to ASD Essential Eight Maturity Level 2 (Application Control, User Application Hardening) and APRA CPS 234 cloud third-party risk management obligations

Course Overview

Microsoft Defender for Cloud Apps (formerly MCAS) is the cloud access security broker (CASB) embedded in the Microsoft 365 E5 Security stack. This masterclass moves past the basics of app discovery and goes deep into the operational configuration that makes Defender for Cloud Apps a genuine data governance tool: Conditional Access App Control session policies that proxy SaaS sessions and enforce real-time controls, activity policies that alert on or block risky actions within sanctioned apps, access policies for unmanaged devices, and the OAuth app governance feature that manages consent and permissions for third-party applications. In the Australian context, session policies and OAuth governance are increasingly referenced in APRA CPS 234 cloud service risk assessments and in ACSC Essential Eight Application Control implementation guidance for cloud-delivered applications.

What You'll Learn

Configure Conditional Access App Control to proxy SaaS sessions through Defender for Cloud Apps
Implement session policies: block download, block cut/copy/paste, require step-up authentication on sensitive content
Configure access policies for unmanaged and non-compliant devices with real-time session inspection
Build activity policies that alert or block risky user actions within sanctioned SaaS applications
Implement OAuth app governance: review, approve, and revoke third-party app permissions at scale
Run a shadow IT discovery assessment and build an app sanction and unsanction workflow
Configure Defender for Cloud Apps integration with Microsoft Purview sensitivity labels for file governance
Produce an application governance evidence pack aligned to APRA CPS 234 and Essential Eight controls

Course Curriculum

Module 1: Shadow IT Discovery and App Governance Foundation

4 hours
  • Defender for Cloud Apps architecture: discovery, proxy, and API-based connectors
  • Shadow IT discovery: log collection from firewalls, proxies, and Defender for Endpoint integration
  • App catalogue and risk scores: evaluating SaaS applications against GDPR, SOC 2, and APRA CPS 234 criteria
  • App sanctioning and tagging: building an approved and unsanctioned app registry
  • App connectors: configuring API access for Microsoft 365, Salesforce, Box, ServiceNow, and other sanctioned apps

Module 2: Conditional Access App Control — Session Policies

6 hours
  • Conditional Access App Control architecture: how the reverse proxy works and browser session requirements
  • Onboard applications to App Control: Microsoft 365, Salesforce, and custom SAML apps
  • Session policies: monitor only, block download, block upload, and require step-up MFA on sensitive content
  • File inspection: content inspection policies using sensitive information types and sensitivity labels
  • Protect sensitive data on unmanaged devices: access policies scoping download controls by device compliance state

Module 3: Activity Policies and OAuth App Governance

4 hours
  • Activity policies: detect and alert on risky user behaviours within sanctioned SaaS apps
  • Anomaly detection policies: impossible travel, ransomware activity, and mass download alerts
  • OAuth App Governance: review third-party app permissions, set publisher verification requirements, revoke overscoped consents
  • OAuth policy automation: auto-revoke apps that exceed permissions or access non-sanctioned data sources
  • APRA CPS 234 application risk evidence: shadow IT reports, OAuth governance posture, and app compliance scoring

Module 4: Advanced Integration and Governance Evidence Pack

2 hours
  • Microsoft Purview sensitivity label integration: govern cloud files using labels from within Defender for Cloud Apps
  • Microsoft Sentinel integration: stream Defender for Cloud Apps alerts for SOC investigation and SOAR response
  • Copilot data governance: using session policies to prevent Copilot from accessing unsanctioned SaaS data sources
  • Governance evidence pack: App Control policy exports, OAuth review reports, and shadow IT assessment for APRA CPS 234
  • Capstone: design a session policy framework for an Australian financial services or healthcare organisation

Who Should Attend

  • Identity and security engineers extending Conditional Access into real-time session control
  • Security architects designing SaaS and Copilot data governance controls
  • CASB practitioners consolidating onto Microsoft Defender for Cloud Apps from a third-party broker
  • Compliance officers governing shadow IT and OAuth application sprawl
  • Risk and assurance staff in APRA-regulated entities building CPS 234 third-party evidence
  • SOC engineers triaging Defender for Cloud Apps alerts in Microsoft Sentinel

Prerequisites

Before enrolling, please ensure you meet these requirements:

  • • Completion of the Microsoft Entra Conditional Access Workshop (CA-WS-001) or equivalent production CA experience
  • • Microsoft 365 E5 or Microsoft 365 E5 Security licence — Defender for Cloud Apps is included
  • • Application Administrator or Security Administrator role in the Microsoft 365 tenant
  • • At least one third-party SaaS application in use for the session policy labs (Salesforce, Box or similar)
  • • Working understanding of SAML and OpenID Connect single sign-on flows

Delivery, Format and Logistics

Delivery Mode

Live online masterclass — 2 days intensive with a shared Microsoft 365 E5 Security lab

Maximum 10 participants — lab environment with Microsoft 365 E5 Security

What You'll Need

  • Completion of Microsoft Entra Conditional Access Workshop (CA-WS-001) or equivalent CA production experience
  • Microsoft 365 E5 or Microsoft 365 E5 Security licence (Defender for Cloud Apps is included)
  • At least one third-party SaaS application in use for session policy lab exercises (Salesforce, Box, or similar)
  • Application administrator or Security Administrator role in the Microsoft 365 tenant

What You'll Receive

  • 16 hours of instructor-led masterclass sessions capped at 10 participants
  • Step-by-step SAML application onboarding lab for Conditional Access App Control
  • Session, access and activity policy templates you can adapt to your tenant
  • OAuth app governance review workflow and auto-revoke policy configurations
  • Shadow IT discovery assessment method with app sanction and unsanction registry template
  • Capstone: a session policy framework for an Australian financial services or healthcare scenario
  • APRA CPS 234 application governance evidence pack template
  • Recorded sessions for 6 months and a certificate of completion

Frequently Asked Questions

Not Ready to Enrol?

Join our mailing list to receive updates about courses, resources, and cybersecurity insights tailored for Australian organisations.

By subscribing, you agree to receive email updates from Educ4te. You can unsubscribe at any time. We respect your privacy and will never share your information.

$799AUD
$999EARLY BIRD

Early-bird rate — apply your promo code at checkout.

1

Secure payment via Stripe · Promo codes accepted

Next Intake

September 2026 — register your interest at educ4te.com

Format

Live online masterclass — 2 days intensive with a shared Microsoft 365 E5 Security lab

Group & Enterprise Options

Discounted rates available for teams of 3+ delegates. Contact us for in-house delivery options.

What's Included

  • 16 hours of instructor-led masterclass sessions capped at 10 participants
  • Step-by-step SAML application onboarding lab for Conditional Access App Control
  • Session, access and activity policy templates you can adapt to your tenant
  • OAuth app governance review workflow and auto-revoke policy configurations
  • Shadow IT discovery assessment method with app sanction and unsanction registry template
  • Capstone: a session policy framework for an Australian financial services or healthcare scenario
  • APRA CPS 234 application governance evidence pack template
  • Recorded sessions for 6 months and a certificate of completion

Have questions about this course?