A tool that provides visibility, control, and threat protection for cloud-based applications and services
Hi Kashif Hasnain,
When Outlook Web sends a notification with a deep link (e.g., "Go to file"), the MDCA reverse proxy rewrites the
URL. During this URL rewriting, the deep link context (the specific file path/anchor) maybe lost, causing the user to
land on the SharePoint homepage instead of the specific document. Refer: https://learn.microsoft.com/en-us/defender-cloud-apps/caac-known-issues#context-loss-limitations
Recommendations:
- Use Microsoft Edge with in-browser protection – Edge users get direct in-browser protection without the reverse
proxy, so deep links are preserved (though Edge also has its own deep link limitation when switching profiles).
- Scope session policies more precisely – If managed devices are already compliant (Intune/Hybrid Azure AD
joined), consider excluding managed devices from the session policy and only applying it to unmanaged devices.
Managed devices already have endpoint-level protections (Defender for Endpoint DLP).
- Use Access Policy instead of Session Policy for managed devices – Apply session controls only to unmanaged
devices, and use access policies or Endpoint DLP for managed ones.
If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.