SharePoint Online in Monitor Mode is blocking REST requests in SPFx solutions. What can I do?

%3CLINGO-SUB%20id%3D%22lingo-sub-1573904%22%20slang%3D%22en-US%22%3ESharePoint%20Online%20in%20Monitor%20Mode%20is%20blocking%20REST%20requests%20in%20SPFx%20solutions.%20What%20can%20I%20do%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1573904%22%20slang%3D%22en-US%22%3E%3CP%3ESuddenly%2C%20I'm%20being%20redirected%20and%20told%20via%20splash%20screen%20that%20I'm%20being%20monitored.%20It%20looks%20like%20this%26nbsp%3B%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-markdown%22%3E%3CCODE%3EAccess%20to%20Microsoft%20SharePoint%20Online%20is%20monitored.%0A%0AFor%20improved%20security%2C%20your%20organization%20allows%20access%20to%20Microsoft%20SharePoint%20Online%20in%20monitor%20mode.%20Access%20is%20only%20available%20from%20a%20web%20browser.%20Continue%20to%20Microsoft%20SharePoint%20Online%3C%2FCODE%3E%3C%2FPRE%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHere%20are%20the%20relevant%20docs%3A%26nbsp%3B-ERR%3AREF-NOT-FOUND-%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fsharepoint%2Ftroubleshoot%2Fadministration%2Faccess-to-sharepoint-online-is-monitored%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fsharepoint%2Ftroubleshoot%2Fadministration%2Faccess-to-sharepoint-online-is-monitored%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIssue%3A%20This%20completely%20blocks%20affected%20users%20from%20using%20custom%20apps.%20Any%20SharePoint%20REST%20request%20is%20blocked%20by%20a%20403%20Access%20Denied%20error.%20I've%20poked%20around%20the%20security%20settings%20as%20described%20in%20the%20above%20linked%20docs%2C%20but%20there%20really%20isn't%20much%20detail.%20It%20mentions%20%22finding%20the%20affected%20user%20and%20disabling%20monitoring%22%3A%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-markdown%22%3E%3CCODE%3ETo%20disable%20monitoring%2C%20you%20have%20to%20browse%20to%20the%20Microsoft%20Cloud%20App%20Security%20page%2C%20select%20the%20activity%20log%2C%20and%20then%20search%20for%20the%20affected%20users.%20After%20you%20locate%20the%20policy%2C%20you%20can%20either%20disable%20the%20policy%20or%20remove%20the%20users%20from%20the%20group%20so%20that%20the%20policy%20no%20longer%20affects%20them.%3C%2FCODE%3E%3C%2FPRE%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EI%20see%20no%20option%20to%20do%20this%20anywhere.%3C%2FSTRONG%3E%20At%20this%20point%20I%20can't%20even%20prove%20this%20is%20the%20direct%20cause%2C%20I'm%20only%20assuming%20because%20the%20issue%20seemed%20to%20occur%20after%20I've%20been%20notified%20I'm%20being%20monitored.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EQuestions%3A%3C%2FP%3E%3CP%3E-How%20can%20I%20turn%20off%20monitoring%20and%20is%20it%20the%20right%20thing%20to%20do%3F%3C%2FP%3E%3CP%3E-Can%20anyone%20confirm%20that%20a%20policy%20being%20triggered%20is%20actually%20what's%20blocking%20my%20REST%20requests%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20help%20is%20appreciated.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1573904%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EDeveloper%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESharePoint%20Online%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Highlighted
Visitor

Suddenly, I'm being redirected and told via splash screen that I'm being monitored. It looks like this 

Access to Microsoft SharePoint Online is monitored.

For improved security, your organization allows access to Microsoft SharePoint Online in monitor mode. Access is only available from a web browser. Continue to Microsoft SharePoint Online

 

 

Here are the relevant docs: https://docs.microsoft.com/en-us/sharepoint/troubleshoot/administration/access-to-sharepoint-online-...

 

Issue: This completely blocks affected users from using custom apps. Any SharePoint REST request is blocked by a 403 Access Denied error. I've poked around the security settings as described in the above linked docs, but there really isn't much detail. It mentions "finding the affected user and disabling monitoring": 

 

To disable monitoring, you have to browse to the Microsoft Cloud App Security page, select the activity log, and then search for the affected users. After you locate the policy, you can either disable the policy or remove the users from the group so that the policy no longer affects them.

 

 

I see no option to do this anywhere. At this point I can't even prove this is the direct cause, I'm only assuming because the issue seemed to occur after I've been notified I'm being monitored.

 

Questions:

-How can I turn off monitoring and is it the right thing to do?

-Can anyone confirm that a policy being triggered is actually what's blocking my REST requests?

 

Any help is appreciated.

0 Replies