Accounts |
File |
Remove user's collaborations |
Remove all the collaborations of a specific user for any files - good for people leaving the company. |
Box, Google Workspace |
Accounts |
Account |
Unsuspend user |
Unsuspends the user |
Google Workspace, Box, Office, Salesforce |
Accounts |
Account |
Account settings |
Takes you to the account settings page in the specific app (for example, inside Salesforce). |
All apps -One Drive and SharePoint settings are configured from within Office. |
Accounts |
File |
Transfer all files ownership |
On an account, you transfer one user's files to all be owned by a new person you select. The previous owner becomes an editor and can no longer change sharing settings. The new owner will receive an email notification about the change of ownership. |
Google Workspace |
Accounts, Activity policy |
Account |
Suspend user |
Sets user to have no access and no ability to sign in. If they're logged in when you set this action, they're immediately locked out. |
Google Workspace, Box, Office, Salesforce |
Activity policy, Accounts |
Account |
Require user to sign in again |
Revokes all refresh tokens and session cookies issues to applications by the user. This action will prevent access to any of the organization's data and will force the user to sign into all applications again. |
Google Workspace, Office |
Activity policy, Accounts |
Account |
Confirm user compromised |
Set the user's risk level to high. This causes the relevant policy actions defined in Microsoft Entra ID to be enforced. |
Office |
Activity policy, Accounts |
Account |
Revoke admin privileges |
Revokes privileges for an admin account. For example, setting an activity policy that revokes admin privileges after 10 failed login attempts. |
Google Workspace |
App dashboard > App permissions |
Permissions |
Unban app |
In Google and Salesforce: remove the banning from the app and allow users to give permissions to the third-party app with their Google or Salesforce. In Microsoft 365: restores the permissions of the third-party app's to Office. |
Google Workspace, Salesforce, Office |
App dashboard > App permissions |
Permissions |
Disable app permissions |
Revoke a third-party app's permissions to Google, Salesforce, or Office. This is a one-time action that will occur on all existing permissions, but won't prevent future connections. |
Google Workspace, Salesforce, Office |
App dashboard > App permissions |
Permissions |
Enable app permissions |
Grant a third-party app's permissions to Google, Salesforce, or Office. This is a one-time action that will occur on all existing permissions, but won't prevent future connections. |
Google Workspace, Salesforce, Office |
App dashboard > App permissions |
Permissions |
Ban app |
In Google and Salesforce: revoke a third-party app's permissions to Google or Salesforce and ban it from receiving permissions in the future. In Microsoft 365: doesn't allow the permission of third-party apps to access Office, but doesn't revoke them. |
Google Workspace, Salesforce, Office |
App dashboard > App permissions |
Permissions |
Revoke app |
Revoke a third-party app's permissions to Google or Salesforce. This is a one-time action that will occur on all existing permissions, but won't prevent future connections. |
Google Workspace, Salesforce |
App dashboard > App permissions |
Account |
Revoke user from app |
You can revoke specific users when clicking on the number under Users. The screen will display the specific users and you can use the X to delete permissions for any user. |
Google Workspace, Salesforce |
Discover > Discovered Apps/IP addresses/Users |
Cloud discovery |
Export discovery data |
Creates a CSV from the discovery data. |
Discovery |
File policy |
File |
Trash |
Moves the file in the user's trash. |
Box, Dropbox, Google Drive, OneDrive, SharePoint, Cisco Webex (Permanently delete) |
File Policy |
File |
Notify last file editor |
Sends an email to notify the last person who edited the file that it violates a policy. |
Google Workspace, Box |
File Policy |
File |
Notify file owner |
Sends an email to the file owner, when a file violates a policy. In Dropbox, if no owner is associated with a file, the notification will be sent to the specific user you set. |
All apps |
File Policy, Activity Policy |
File, Activity |
Notify specific users |
Sends an email to notify specific users about a file that violates a policy. |
All apps |
File policy and Activity policy |
File, Activity |
Notify user |
Sends an email to users to notify them that something they did or a file they own violates a policy. You can add a custom notification to let them know what the violation was. |
All |
File policy and Files |
File |
Remove editors' ability to share |
In Google Drive, the default editor permissions of a file allow sharing as well. This governance action restricts this option and restricts file sharing to the owner. |
Google Workspace |
File policy and Files |
File |
Put in admin quarantine |
Removes any permissions from the file and moves the file to a quarantine folder in a location for the admin. This action enables the admin to review the file and remove it. |
Microsoft 365 SharePoint, OneDrive for Business, Box |
File policy and Files |
File |
Apply sensitivity label |
Applies a Microsoft Purview Information Protection sensitivity label to files automatically based on the conditions set in the policy. |
Box, One Drive, Google Workspace, SharePoint |
File policy and Files |
File |
Remove sensitivity label |
Removes a Microsoft Purview Information Protection sensitivity label from files automatically based on the conditions set in the policy. You can remove labels only if they do not include protection, and they were applied from within Defender for Cloud Apps, not labels applied directly in Information Protection. |
Box, One Drive, Google Workspace, SharePoint |
File policy, Activity policy, Alerts |
App |
Require users to sign in again |
You can require users to sign in again to all Microsoft 365 and Microsoft Entra apps as a quick and effective remediation for suspicious user activity alerts and compromised accounts. You can find the new governance in the policy settings and the alert pages, next to the Suspend user option. |
Microsoft 365, Microsoft Entra ID |
Files |
File |
Restore from user quarantine |
Restores a user from being quarantined. |
Box |
Files |
File |
Grant read permissions to myself |
Grants read permissions for the file for yourself so you can access the file and understand if it has a violation or not. |
Google Workspace |
Files |
File |
Allow editors to share |
In Google Drive, the default editor permission of a file allows sharing as well. This governance action is the opposite of Remove editor's ability to share and enables the editor to share the file. |
Google Workspace |
Files |
File |
Protect |
Protect a file with Microsoft Purview by applying an organization template. |
Microsoft 365 (SharePoint and OneDrive) |
Files |
File |
Revoke read permissions form myself |
Revokes read permissions for the file for yourself, useful after granting yourself permission to understand if a file has a violation or not. |
Google Workspace |
Files, File policy |
File |
Transfer file ownership |
Changes the owner - in the policy you choose a specific owner. |
Google Workspace |
Files, File policy |
File |
Reduce public access |
This action enables you to set publicly available files to be available only with a shared link. |
Google Workspace |
Files, File policy |
File |
Remove a collaborator |
Removes a specific collaborator from a file. |
Google Workspace, Box, One Drive, SharePoint |
Files, File policy |
File |
Make private |
Only Site Admins can access the file, all shares are removed. |
Google Workspace, One Drive, SharePoint |
Files, File policy |
File |
Remove external users |
Removes all external collaborators - outside the domains configured as internal in Settings. |
Google Workspace, Box, One Drive, SharePoint |
Files, File policy |
File |
Grant read permission to domain |
Grants read permissions for the file to the specified domain for your entire domain or a specific domain. This action is useful if you want to remove public access after granting access to the domain of people who need to work on it. |
Google Workspace |
Files, File policy |
File |
Put in user quarantine |
Removes all permissions from the file and moves the file to a quarantine folder under the user's root drive. This action allows the user to review the file and move it. If it's manually moved back, the file sharing isn't restored. |
Box, One Drive, SharePoint |
Files |
File |
Expire shared link |
Set an expiration date for a shared link after which it will no longer be active. |
Box |
Files |
File |
Change sharing link access level |
Changes the access level of the shared link between company only, collaborators only, and public. |
Box |
Files, File policy |
File |
Remove public access |
If a file was yours and you put it in public access, it becomes accessible to anyone else configured with access to the file (depending on what kind of access the file had). |
Google Workspace |
Files, File policy |
File |
Remove direct shared link |
Removes a link that is created for the file that is public but only shared with specific people. |
Box, Dropbox |
Settings> Cloud Discovery settings |
Cloud discovery |
Recalculate cloud discovery scores |
Recalculates the scores in the Cloud app catalog after a score metric change. |
Discovery |
Settings> Cloud Discovery settings > Manage data views |
Cloud discovery |
Create custom cloud discovery filter data view |
Creates a new data view for a more granular view of the discovery results. For example, specific IP ranges. |
Discovery |
Settings> Cloud Discovery settings > Delete data |
Cloud discovery |
Delete cloud discovery data |
Deletes all the data collected from discovery sources. |
Discovery |
Settings> Cloud Discovery settings > Upload logs manually/Upload logs automatically |
Cloud discovery |
Parse cloud discovery data |
Notification that all the log data was parsed. |
Discovery |