Keeps watch over OAuth apps registered in Microsoft Entra ID, Google or Salesforce on behalf of Defender for Cloud Apps: it reports what permissions and data each app uses, and flags or limits those that look dangerous.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains App governance in context, with comparison tables and the common traps.
Terms in this definition
- OVER
Gives a T-SQL window function its window: PARTITION BY, ORDER BY and, if wanted, a ROWS or RANGE frame. Rankings and running totals can then be worked out while every row is kept.
- OAuth
An authorisation standard allowing software to act for someone. In Azure Pipelines, choosing it for a GitHub service connection ties the connection to your own GitHub account; for integrations with Azure DevOps APIs, Microsoft Entra ID OAuth is the right choice.
- Microsoft Entra ID
Cloud identity service from Microsoft, previously named Azure AD, which provides the tenant behind Microsoft 365 and Azure.
- AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.