Microsoft Defender for Cloud Apps: Check which policy applied at event

Diskutiere und helfe bei Microsoft Defender for Cloud Apps: Check which policy applied at event im Bereich Microsoft Office im Windows Info bei einer Lösung; While trying to upload a file to MS Teams, a client of mine gets a message from Defender for Cloud Apps that the upload has been blocked.After checking... Dieses Thema im Forum "Microsoft Office" wurde erstellt von Ms. Merlo, 9. Februar 2023.

  1. Ms. Merlo
    Ms. Merlo Gast

    Microsoft Defender for Cloud Apps: Check which policy applied at event


    While trying to upload a file to MS Teams, a client of mine gets a message from Defender for Cloud Apps that the upload has been blocked.After checking the Cloud Defender policies, I noticed that there are too many policies to identify the one that just got triggered.Is there a way in MS365 to get which exact policy got applied to user XY at a certain time? Thanks already for reading and I'll gladly provide more information if needed.
     
  2. Myk Ylaya Win User

    Microsoft Defender for Cloud Apps: Check which policy applied at event

    Hello Ms. M, thanks for coming into forums. I'm also a user like you and I'll be more than happy to help you to the best of my knowledge.

    Yes, you can check which policy was applied to a user in Microsoft Defender for Cloud Apps by reviewing the audit logs.

    To access the audit logs, follow these steps:

    -Go to the Microsoft 365 security center.
    -Click on the "Threat management" section, and then click on "Audit log search".
    -In the "Audit log search" page, you can select "Cloud App Security" as the source and then specify the date range and user account to search for events related to Defender for Cloud Apps.
    -Once the events are displayed, you can look for events related to "File upload blocked" or "Policy applied". These events will include information on which policy was triggered and applied.

    You can also filter the events by policy name to quickly find the specific policy that was triggered.

    Hope this info helps. Feel free to let us know.

    Warm Regards,
    Myk
  3. Martin_Gasser CH Win User

    Microsoft Office Home & Student 2016 for Mac

    Hi John

    After I've applied all of the updates for Office 2016 for Mac, this error no longer occurs.
    It was a bit complicated to find the update in the app (Reg Help, check for updates)

    But now everything works fine. Thanks for the support.

    Best regards Martin
  4. Ezzati Win User

    Microsoft Defender 365

    Hi,
    Happy new year and Thanks for reply and information.
    What I am trying to do is deactivating Microsoft 365 defender for some email addresses(10-15 emails). Because I have to test the performance of another anti spam tool. Currently 365 defender works for all email addresses and it does not allow me to check other one.
    Thank you
  5. Ravikumar Vadamalai Win User

    Microsoft Defender 365

    Hello,

    Greetings for the day!
    I’m an Independent Advisor and Microsoft user like you. Thanks for posting the query here at this forum.

    Are you using the Microsoft Defender in Office 365 for any on-premises or cloud mailboxes ?

    The following are the primary ways you can use Defender for Office 365 for message protection:

    1. In a Defender for Office 365 filtering-only scenario, Defender for Office 365 provides cloud-based email protection for your on-premises Exchange Server environment or any other on-premises SMTP email solution.

    2. Defender for Office 365 can be enabled to protect Exchange Online cloud-hosted mailboxes.

    3. In a hybrid deployment, Defender for Office 365 can be configured to protect your messaging environment and control mail routing when you have a mix of on-premises and cloud mailboxes with Exchange Online Protection for inbound email filtering.

    Please find the details below.
    https://learn.microsoft.com/en-us/o...dvanced-threat-protection-service-description

    Incase if you want to exclude any particular program in Windows device from Microsoft defender,

    1. Select Start , then open Settings . Under Privacy & security , select Virus & threat protection.

    2. Under Virus & threat protection settings, select Manage settings, and then under Exclusions, select Add or remove exclusions.

    3. Select Add an exclusion, and then select from files, folders, file types, or process. A folder exclusion will apply to all subfolders within the folder as well.
    https://support.microsoft.com/windows/811816c0-4dfd-af4a-47e4-c301afe13b26

    Hope this information helps. Please feel free to get back if you have any questions.

    Thank you!
    Ravikumar
    Help the next person who has this issue by indicating if this reply solved your problem. Click Yes or No below.
  6. Desislava Dimova MSF Win User

    Wird eine inaktive und leere Mailbox automatisch aus einer In-Place Hold entfernt?

    Hallo Peter Ess,



    Bedanke mich für die Erläuterung :)



    Was mit den Elementen nach dem 365 Tag passiert hängt von der Aufbewahrungsrichtlinie ab.



    What happens when the hold duration expires?



    When the hold duration expires for a mailbox item in the Recoverable Items folder, the item is permanently deleted (purged) from the inactive mailbox. If there is no duration specified for the hold placed on the inactive mailbox, items in the Recoverable
    Items folder are never purged (unless the hold duration for the inactive mailbox is changed).



    Is retention policy still processed on inactive mailboxes?



    If a retention policy was applied to a mailbox when it was made inactive, the deletion policies (which are retention tags configured with a Delete retention action) will continue to be processed on the inactive mailbox. That means items that are tagged with
    a deletion policy are moved to the Recoverable Items folder when the retention period expires. Those items are then purged from the inactive mailbox when the hold duration for an item expires.



    Conversely, any archive policies (which are retention tags configured with a MoveToArchive retention action) that are included in the retention policy assigned to an inactive mailbox are ignored. That means items in an inactive mailbox that are tagged with
    an archive policy remain in the primary mailbox when the retention period expires. They're not moved to the archive mailbox or to the Recoverable Items folder in the archive mailbox. Because a user can't sign in to an inactive mailbox, there's no reason to
    consume datacenter resources to process archive policies.



    Quelle:
    Change the hold duration for an inactive mailbox in Exchange Online




    Für weitere Fragen stehe ich gerne zur Verfügung.



    Mit freundlichen Grüßen,



    Desislava Dimova



    Microsoft Office 365 Support Engineer
  7. User Advert


    Hi,

    willkommen im Windows Forum!
Thema:

Microsoft Defender for Cloud Apps: Check which policy applied at event - Microsoft Office

Die Seite wird geladen...

Microsoft Defender for Cloud Apps: Check which policy applied at event - Similar Threads - Microsoft Defender for

Forum Datum

Computerabsturz Kernel event tracing kernel security check failure

Computerabsturz Kernel event tracing kernel security check failure: Hallo,mein PC stürzt jedes mal ab wenn ich ein spiel spiele, nach so 5 min.Der PC ist schon 7 Jahre alt, also könnte es auch daran liegen, aber ich will mir keinen neuen kaufen, wenn ich nicht...
Apps 7. Dezember 2023

Computerabsturz Kernel event tracing kernel security check failure

Computerabsturz Kernel event tracing kernel security check failure: Hallo,mein PC stürzt jedes mal ab wenn ich ein spiel spiele, nach so 5 min.Der PC ist schon 7 Jahre alt, also könnte es auch daran liegen, aber ich will mir keinen neuen kaufen, wenn ich nicht...
Games und Spiele 7. Dezember 2023

Kündigung von Microsoft 365 Apps for Business

Kündigung von Microsoft 365 Apps for Business: Liebes Forum,gerne würden wir ein Abo vom Microsoft 365 Apps für Business kündigen. Leider haben wir aber kein Zugriff mehr auf dieses Konto bzw. weiß ich nicht, auf welches Konto dieses Abo...
Microsoft Office 24. Mai 2023

Microsoft 365 Apps for Enterprise nicht lizenziert

Microsoft 365 Apps for Enterprise nicht lizenziert: Wie lizenziere ich office?
Microsoft Office 4. März 2023

Wechsel von Apps for Enterprise auf Apps for Business

Wechsel von Apps for Enterprise auf Apps for Business: Hallo Community,aufgrund einer Lizenzänderung haben wir den Fehler gemacht und diversen Mitarbeitern Lizenzen von Apps for Enterprise entzogen und Lizenzen Apps for Business zugeteilt.Das war Ende...
Microsoft Office 16. Februar 2022

Outlook Microsoft 365 Apps for Business

Outlook Microsoft 365 Apps for Business: Version 16.0.13001.20266 Seit einigen Wochen funktioniert die Option, die Übermittlung einer E-Mail zu verzögern, nicht mehr korrekt. Vorgehen: Neue Mail erstellen, Mail verfassen, im Register...
Microsoft Office 22. Juli 2020

Microsoft Solitaire Event

Microsoft Solitaire Event: Hallo,mein Laptop war für 2 Wochen in der Reparatur. Nachdem ich es wiederbekommen habe,waren die Event (Nicht die Herausforderungen) nicht mehr vorhanden. Gibt es keine Events mehr??
Games und Spiele 8. November 2017
Microsoft Defender for Cloud Apps: Check which policy applied at event solved
  1. Diese Seite verwendet Cookies, um Inhalte zu personalisieren, diese deiner Erfahrung anzupassen und dich nach der Registrierung angemeldet zu halten.
    Auf dieser Website werden Cookies für die Zugriffsanalyse und Anzeigenmessung verwendet.
    Wenn du dich weiterhin auf dieser Seite aufhältst, akzeptierst du unseren Einsatz von Cookies.