Skip to content

SecOps - 41080 - Conditional Access App Control session policies are enforced for sensitive cloud apps - #1481

Merged
Thomas Detzner (tdetzner) merged 3 commits into
devfrom
SEC-41080
Aug 5, 2026
Merged

SecOps - 41080 - Conditional Access App Control session policies are enforced for sensitive cloud apps#1481
Thomas Detzner (tdetzner) merged 3 commits into
devfrom
SEC-41080

Conversation

@Manoj-Kesana

Copy link
Copy Markdown
Collaborator

No description provided.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a new SecOps assessment (Test ID 41080) to validate that Conditional Access App Control (Defender for Cloud Apps session controls) is enforced for targeted cloud applications, and provides report output plus remediation documentation.

Changes:

  • Introduces Test-Assessment-41080 PowerShell test that queries enabled Conditional Access policies and evaluates sessionControls.cloudAppSecurity.
  • Generates a markdown table report with deep links to Conditional Access policies in the Entra portal.
  • Adds accompanying markdown documentation with remediation resources for the assessment.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.

File Description
src/powershell/tests/Test-Assessment.41080.ps1 New assessment implementation: Graph query, evaluation logic, and markdown report output for CA App Control session policies.
src/powershell/tests/Test-Assessment.41080.md New assessment documentation and remediation links; contains the %TestResult% placeholder for report injection.

Comment thread src/powershell/tests/Test-Assessment.41080.ps1
Comment thread src/powershell/tests/Test-Assessment.41080.ps1
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
@Manoj-Kesana
Manoj Kesana (Manoj-Kesana) marked this pull request as ready for review August 4, 2026 16:55
@Manoj-Kesana Manoj Kesana (Manoj-Kesana) added the ready for review PR is ready for review and merging label Aug 4, 2026

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Manoj Kesana (@Manoj-Kesana) Please, address my feedback.

Comment thread src/powershell/tests/Test-Assessment.41080.ps1 Outdated
Comment thread src/powershell/tests/Test-Assessment.41080.ps1 Outdated

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@tdetzner
Thomas Detzner (tdetzner) merged commit 54a7759 into dev Aug 5, 2026
2 checks passed
@Manoj-Kesana
Manoj Kesana (Manoj-Kesana) deleted the SEC-41080 branch August 5, 2026 12:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ready for review PR is ready for review and merging

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants