Defender for Cloud Apps policy type selection
Verdict: Access and Session policies are the Conditional Access types; only a Session policy blocks a download in-session. File and activity policies are customisable; malware detection is built-in and cannot be created from scratch.
| Criterion | Access policy | Session policy | Activity policy | File policy | Malware detection policy |
|---|---|---|---|---|---|
| Category | Conditional Access | Conditional Access | Threat detection | Information protection | Threat detection |
| What it does | Allow or block sign-ins in real time | Real-time in-session control, e.g. block a download | Alert on activities you define | Scan files at rest against your filters | Scan cloud files against Microsoft threat intel |
| Custom policy? | Yes | Yes | Yes | Yes | No, ships preconfigured |
Rules
- Access and Session policies are the two Conditional Access policy types; they control sign-in and in-session activity respectively.
- Session policies use Conditional Access App Control to block a download in-session as it happens, with device context such as unmanaged-device detection.
- Malware detection is a built-in threat-detection policy; you enable it and attach an action like quarantine but cannot create it from scratch.
Traps
- File policy scans files at rest via the API and remediates post-event; it cannot block a real-time download.
- Activity policies and anomaly detection sit under threat detection, not Conditional Access.
- There is no Create button for malware detection; the levers are enabling it and attaching a governance action.