MDATP Integration - Unsanctioned Apps - Allow for some users?

Iron Contributor

Hi,

 

I've reviewed the documentation @ https://docs.microsoft.com/en-us/cloud-app-security/governance-discovery in relation to blocking unsanctioned apps - specifically using MDATP on Win10 endpoints.

 

The documentation doesn't mention anything about governance when using MDATP - Is the functionality similar to the integration with Zscaler and iBoss, where once an app is tagged as unsanctioned it is blocked on the endpoint for all users?

 

Is there any way to provide greater granularity to the process - ie allow an app for some users and not for others or is it a binary choice for the entire organisation?

 

Thanks

Paul

25 Replies

@Cristian Calinescu You're right. Sorry, I can't find a solution. :'(

@PJR_CDF 

 

You can find the needed info here: https://docs.microsoft.com/en-us/cloud-app-security/mde-integration

 

Regarding the granular controls - this is not yet supported and is pending user granularity capabilities in MDE.

We will expose parity with MDE indicators in MCAS by allowing scoping blocks based of device groups.

 

Boris

@Boris_Kacevich - That's wonderful news. Looking forward to it. Many thanks.

Thanks, Boris. This is great news as spent most of the afternoon in vein trying to find any granular controls for unsanctioned apps. Do you know specifically when this will be arriving. Is there a preview we can signup for?

Are there any updates regarding this?

@Danny Kadyshevitch hi Danny, have there been any updates in regards to having this functionality in Microsoft Defender for Cloud Apps? Is it still planned or not a priority anymore? Has it already been out and I am unable to find it?