← SC-300: identity, access, and operations
10 / 11 · 40 MIN

Applications, sessions, and OAuth governance

Diagnose callbacks and control application actions with explicit scope.

Collections organize applications

A My Apps collection organizes applications a user can already access. It does not replace assignments or business roles. In a fictional project, the team publishes a Funds Operations collection for shift staff, but one person sees only two of four applications. Compare that person’s access with collection configuration and visibility requirements. Do not grant an administrative role to fix presentation. Delivery acceptance should check both navigation and an authorized operation inside each required application, with ownership of any missing assignment recorded.

Redirect URI and sign-in errors

The request redirect URI must match an allowed address in the application registration. AADSTS50011 points to that match and does not establish missing API consent. In a fictional release, the new HTTPS callback changes the return path. Check client ID, tenant, the address actually sent, and environment configuration, including path case. Correct the approved application-registration contract and test again. Adding broad or wrong-environment addresses creates risk and hides drift. Keep evidence without copying tokens or secrets into the support ticket.

Control a session activity

In Defender for Cloud Apps, control type and action determine the effect. To test inspected downloads without blocking, use the corresponding control with Audit and suitable filters. Monitor only follows Login activity; it is not a complete rehearsal of every action. In a fictional pilot, the team wants to prevent selected file downloads in an integrated application. Confirm onboarding, scope, and logs before enabling Block for the approved population. Repeat the test operation and check the result in both client behavior and telemetry.

Alerts and actions for OAuth applications

An app governance policy defines population, conditions, and actions. Raising an alert and disabling an application are different outcomes; configure the action explicitly. In a fictional scenario, a financial reconciliation integration starts using elevated permissions outside its usual schedule. The team investigates the owner, approved change, and actual usage before automating containment across applications. An alerting pilot can expose legitimate exceptions. Record escalation criteria, batch impact, and recovery so the security decision also accounts for service continuity and accountable ownership.

IN PRACTICE

After a release, the callback requests /signin-v2 while registration contains /signin-v1. Correlate the request with the correct registration before changing consent.

Common pitfalls

Collection as authorization; consent as a callback fix; Audit as Block; alert as disablement.

Related topics: Tenant, scope, and objects · Hybrid identity and partners · Methods and emergency access

Take this idea with you

Separate navigation, authentication, authorization, and session actions.

Create account

Reference: Redirect URI matching · SC-300 objectives effective 2026-04-27; product documentation reviewed 2026-10-01; 2026-10-28 English update compared separately