Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Note
Management of unused credentials and expiring credentials is available to app governance customers with a Microsoft Entra Workload ID Premium license. For more information, see What are workload identities?
Have you ever wanted to find apps that your organization owns but doesn't use? Or clean up unused or expiring credentials more easily? Microsoft Entra ID includes recommendations to help you identify such apps. The App governance page in Microsoft Defender provides an app hygiene feature suite with controls and insights on unused apps, unused credentials, and expiring credentials.
App hygiene features enable automatic control over flagged apps and provide extra behavior context to help you determine the risk each app poses in your environment.
Watch this video for a brief explanation of the app hygiene features for unused apps, unused credentials, and expiring credentials:
Review app insights
App governance allows you to sort and filter on app last used date, credential unused since, and credential expiration date. You can export the filtered app list for easy reporting and triage across your organization.
Due to data history or app scope constraints, some apps show Over 30 days ago in the Last used or Credential unused since column. These apps haven't signed in the last 30 days, but we don't currently have an exact last sign-in date.
Apps that don't have a last sign-in date or credential expiration date available have Not available in the respective column.
Apps with No credentials in the Credential unused since or Credential expiration column don’t have any credentials assigned to the app.
Create app hygiene policies
App governance provides customizable policies for unused apps, apps with unused credentials, and apps with expiring credentials.
For example, create a policy to automatically disable any app that hasn’t been used in the past 90 days, has high privilege permissions, and can access priority accounts in Microsoft 365. Like all app governance alerts, these alerts are aggregated into incidents in your Defender alerts queue and flow to Advanced hunting and Microsoft Sentinel.
The following image shows an example of policy conditions for an app hygiene policy:
Clean up unused apps and expiring credentials to keep your SaaS app inventory lean. This helps you cut SaaS spend and reduce your app attack surface.