Continue your lesson
Trace the identity, credential, token, assignment, policy decision, resource, and audit record for each access request.
Block 1 of 3Compare Cloud Discovery · Defender for Cloud Apps connector
Current · 12 min
Compare Cloud Discovery · Defender for Cloud Apps connector
Optional concept notes
Defender for Cloud Apps connector
Connects a supported cloud service through its API for visibility and control.
Cloud Discovery
Analyzes traffic data to identify cloud applications used in the organization.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Block 2 of 3Compare Sanctioned application · OAuth app governance · Defender for Cloud Apps activity policy
18 min
Compare Sanctioned application · OAuth app governance · Defender for Cloud Apps activity policy
Optional concept notes
Sanctioned application
Marks a discovered cloud app as approved for organizational use.
OAuth app governance
Monitors and governs OAuth applications that access Microsoft 365 data.
Defender for Cloud Apps activity policy
Generates alerts or governance actions from matched cloud-app activities.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Block 3 of 3Compare Defender for Cloud Apps session policy · Defender for Cloud Apps access policy · Conditional Access App Control
15 min
Compare Defender for Cloud Apps session policy · Defender for Cloud Apps access policy · Conditional Access App Control
Optional concept notes
Defender for Cloud Apps session policy
Monitors or controls supported app actions through Conditional Access App Control.
Defender for Cloud Apps access policy
Allows or blocks real-time access to a connected cloud application under conditions.
Conditional Access App Control
Routes a supported session through Defender for Cloud Apps for real-time control.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Practice the reasoning here
Use a fictional tenant. Draw one access path, apply least privilege, test an exception, and name the logs that would confirm the result.
- State the expected result before changing or testing anything.
- Name the observation, command, log, or report that would confirm it.
- Explain why the closest alternative does not fit the same requirement.
Check the whole objective
This unlocks objective 3.4 for recall. The latest checkpoint needs 70% or higher; a lower result puts the lesson back near the front of your timeline.