How to view all „marked approved“ apps?

Sascha Josephs 1 Reputation point
2025-09-18T06:43:21.8433333+00:00

Hello everybody, within a incident in Defender XDR, I see an Oauth app as suspicious. The application is an internal development and therefore trustworthy. In the "attack story" of the Incident, I called up the "App Page" and declared the application as „marked approved“. The app is an enterprise app that does not have an admin or user consent, nor a connection to an M365 app. This means that it does not appear under Cloud App / App Governance. Now my question is how can I display all „marked approved“ apps? I marked several App in the past and need now a list of them. Thanks in advance for the support

User's image

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud Apps
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Catherine Kyalo 2,620 Reputation points Microsoft Employee
    2025-09-19T08:48:14.42+00:00

    Hi Josephs,

    Did you already attempt to check under Assets> Applications? https://learn.microsoft.com/en-us/defender-cloud-apps/applications-inventory#navigate-to-the-applications-page

    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.


  2. Sascha Josephs 1 Reputation point
    2025-10-08T13:24:08.0166667+00:00

    my summary :
    • App registration/Service Principal without connection to Microsoft366, Google or Salesforce is recognized as an Oaut app in the incident but is not listed in the Governance app.

    • The App Page for this type of Oauth Apps can only be opened within the incident.

    • There is no query for Status Approved in KQL (OAuthAppInfo), only Enabled or Disabled

    • No reference to Approved found via Powershell.

    • With the Object ID you can find the app in Defender / Assets / Identities, but also no "Approved" note.

    • There is no notice in Entra ID / Enterprise Apps either

    Guess it's just an internal classification in the Defender Incident that isn't really listed anywhere.
    Manual documentation is probably the current solution.
    Consultants, Copilot and GPT coudn't help either ;-)

    I appreciate any advises.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.