Defender for Cloud Apps policy type selection

Verdict: Access and Session policies are the Conditional Access types; only a Session policy blocks a download in-session. File and activity policies are customisable; malware detection is built-in and cannot be created from scratch.

CriterionAccess policySession policyActivity policyFile policyMalware detection policy
CategoryConditional AccessConditional AccessThreat detectionInformation protectionThreat detection
What it doesAllow or block sign-ins in real timeReal-time in-session control, e.g. block a downloadAlert on activities you defineScan files at rest against your filtersScan cloud files against Microsoft threat intel
Custom policy?YesYesYesYesNo, ships preconfigured

Rules

Traps