Unsanctioned Apps - Scoped Profile Tab

Copper Contributor

All,

 

I am trying to test blocking of unsanctioned cloud apps and I have created a group for testing since I do not want to enforce this for all users. 

 

When I go to Settings>Cloud Apps>App tags I do not see the scoped profile tab at all so I can only select the test group to enforce the blocking of unsanctioned apps. 

In this article you will see the option for scoped profile tab: 

Govern discovered apps using Microsoft Defender for Endpoint - Microsoft Defender for Cloud Apps | M...

In the screenshot below is the option I do not see. I have checked my roles and I have global admin roles as well as other security roles for Defender portal. 


Capture.PNG

6 Replies
This feature only applies to device groups, from Defender for Endpoint.
Have you created any Device Groups in Defender for Endpoint, before going into the Cloud App settings?
https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/machine-groups?view=o365-...

@Bosanac89

@Douglas Santos 

 

I've also got this issue. According to the same article posted by Bosanac89: https://learn.microsoft.com/en-us/defender-cloud-apps/mde-govern#blocking-apps

 

Step 1 says:
1. In the Microsoft 365 Defender portal, select Settings. Then choose Cloud Apps. Then under Cloud discovery, select Apps tags and go to the Scoped profiles tab.

 

This tab does not exist:

PlatinumCat_0-1697116105553.png

 

We are fully licensed, Defender for Endpoint preview features are switched on, both prerequisites are met (from: https://learn.microsoft.com/en-us/defender-cloud-apps/mde-govern#how-to-enable-cloud-app-blocking-wi...), device groups created and active (for a long time before trying to implement a scoped profile).  DfE is integrated with DfCA and vice versa.

 

This option simply does not exist where it is supposed to.  Has it been disabled or moved?  Is there another way to implement exclusions for app blocking via unsanctioned apps? (e.g. based on tags, users, groups, ip addresses, or devices?)

Yes I have. The groups were created weeks prior to trying to manage unsanctioned apps. I am still working with MS support and have not found a resolution to this issue.
I got the issue resolved with MS support.

1. Go to Settings>Cloud Apps>Microsoft Defender for Endpoint
2. Check the box to enforce app access
3. Then go to app tags and you will see the scoped profile tab

@Bosanac89 Since you've already verified having the appropriate admin roles and licenses enabled, my suspicion is there may be some prerequisite not yet met for that scoped profile tab to appear. I know you enabled the Defender for Endpoint preview features already, but there could be an additional configuration step needed to activate that capability.

 

Rather than repeating suggestions you've already tried from other community members, I would recommend opening a support case directly with Microsoft if you haven't already. Explain precisely what steps you've taken and what options you expect to see but don't. The engineers and product team there would have the best insight on whether a bug, missing prerequisite, or something else is preventing that scoped profile tab from showing up.

Same here, it took 24 hours after checking this box, but it did eventually appear