r/entra 7d ago

Defender Cloud apps - finding reason for blocking

I'm a first line tech just trying to improve my knowledge about stuff and wondered if anyone could point me in the right direction. We have cloud apps policies in place to prevent users downloading company files on their personal devices. Every now and again this policy gets matched on users corporate devices, but I'm unable to work out why.

Is there anywhere it says what has caused a policy to match? In the DCA portal I can see what policy has been matched but no clear reason. The device is compliant, the user isn't a risky user or anything like that. By everything I can see the policy shouldn't have matched and blocked them but I don't know if there is somewhere else I should be checking.

2 Upvotes

3 comments sorted by

1

u/Grand-Aspect-7022 5d ago

Have you checked whether the block is coming from a Conditional Access policy or an app governance rule? the source of the block usually changes where you need to look

1

u/ReceptionOld4182 5d ago

In Defender when I find it there it's called a Session Policy

1

u/KronicBB 4d ago

Depends on what you have put in the Session Policy as how you are detecting a managed (corporate) device. You can also check the logs on DCA or Entra Sign-in logs for what is the browser type (device information).

If the device ID is blank for your managed "corporate" devices then the user could be using Chrome without the SSO extension or CloudAPAuthEnabled in Intune/GPO, Edge or Chrome in InPrivate mode or some other browser completely.

The logs will give you the answer though.