Collections organize applications
A My Apps collection organizes applications a user can already access. It does not replace assignments or business roles. In a fictional project, the team publishes a Funds Operations collection for shift staff, but one person sees only two of four applications. Compare that person’s access with collection configuration and visibility requirements. Do not grant an administrative role to fix presentation. Delivery acceptance should check both navigation and an authorized operation inside each required application, with ownership of any missing assignment recorded.
Redirect URI and sign-in errors
The request redirect URI must match an allowed address in the application registration. AADSTS50011 points to that match and does not establish missing API consent. In a fictional release, the new HTTPS callback changes the return path. Check client ID, tenant, the address actually sent, and environment configuration, including path case. Correct the approved application-registration contract and test again. Adding broad or wrong-environment addresses creates risk and hides drift. Keep evidence without copying tokens or secrets into the support ticket.
Control a session activity
In Defender for Cloud Apps, control type and action determine the effect. To test inspected downloads without blocking, use the corresponding control with Audit and suitable filters. Monitor only follows Login activity; it is not a complete rehearsal of every action. In a fictional pilot, the team wants to prevent selected file downloads in an integrated application. Confirm onboarding, scope, and logs before enabling Block for the approved population. Repeat the test operation and check the result in both client behavior and telemetry.
Alerts and actions for OAuth applications
An app governance policy defines population, conditions, and actions. Raising an alert and disabling an application are different outcomes; configure the action explicitly. In a fictional scenario, a financial reconciliation integration starts using elevated permissions outside its usual schedule. The team investigates the owner, approved change, and actual usage before automating containment across applications. An alerting pilot can expose legitimate exceptions. Record escalation criteria, batch impact, and recovery so the security decision also accounts for service continuity and accountable ownership.
After a release, the callback requests /signin-v2 while registration contains /signin-v1. Correlate the request with the correct registration before changing consent.
Common pitfalls
Collection as authorization; consent as a callback fix; Audit as Block; alert as disablement.
Related topics: Tenant, scope, and objects · Hybrid identity and partners · Methods and emergency access
Separate navigation, authentication, authorization, and session actions.
Reference: Redirect URI matching · SC-300 objectives effective 2026-04-27; product documentation reviewed 2026-10-01; 2026-10-28 English update compared separately