[D 5.2] App Governance: The OAuth Consent Control Plane

App governance is where you see the OAuth grants your users made and switch off the dangerous ones. The consent-phishing control plane, and what it hands to identity and to the capstone.

App governance is where you see the OAuth grants your users made and switch off the dangerous ones. The consent-phishing control plane, and what it hands to identity and to the capstone.

Discovery is only half the job. How Defender for Cloud Apps sees the shadow-IT and shadow-AI estate and turns an unsanctioned tag into a real block through Defender for Endpoint, with no infrastructure to stand up.

What Defender for Cloud Apps actually is in 2026: five durable pillars, a licensing spine with one useful asymmetry, and the file-protection pillar leaving for Purview in January 2027.

A reproducible walkthrough: turn on collaboration protection and close the download door, make the Safe Links rewrite decision explicit, and set the anti-phishing engine to act, with self-tests that prove each engine is live.

A reproducible walkthrough: enable and scope the Standard preset, populate the impersonation lists by hand, carve one custom exception, and wire quarantine notifications, validated end to end.

Prevention is bought once. Operations is the part that never stops, and it is where Defender for Office 365 either earns its place or gathers dust.

Three engines do the real catching, and each hides one decision that matters more than the rest. Teams is now inside the same blast radius.

The mail policy layer is a precedence order, not a pile of settings, and the first policy to match a user wins outright. Knowing which policy speaks for whom is the whole discipline.