word.cloud.microsoft, excel.cloud.microsoft. powerpoint.cloud.microsoft bypass Conditional Access App Control Enformment

Alexander Alamein 0 Reputation points
2025-07-14T06:03:41.3566667+00:00

Have conditional Access policy, which does the following.

  1. For an Unmanaged Device (Device not in intune)
  2. Allow Access to browser
  3. Use Cloud Access App Control
  4. Block Downloads

This works for the old urls where it routes to ".mcas.ms" to urls and allows for monitoring and blocking downloads in browser sessions.

This doesn't seem to work for when users accessing

  • word.cloud.microsoft
  • excel.cloud.microsoft
  • powerpoint.cloud.microsoft

and in effect allowing them to exfil/bypass download controls.

Is there a solution for this, should I block these apps, I've tried including them in session monitoring, but it doesn't seem to work, has anyone else come across this issue?

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud Apps
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.