MDCA Session policy Deep link issue

Kashif Hasnain 0 Reputation points
2025-12-08T06:08:29.3166667+00:00

We have enabled the MDCA session policy to inspect download, cut, copy and paste from Managed as well as Non-managed devices. For managed devices what we have seen is when a user gets a notification on his/her Outlook web regarding a comment put by colleague of a shared document, when the user clicks on that "go to file" link to reviwe the comments . MDCA does not route the session directly to the file; instead, the user lands on the SharePoint homepage

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud Apps
0 comments No comments

1 answer

Sort by: Oldest
  1. Catherine Kyalo 3,180 Reputation points Microsoft Employee
    2026-04-14T15:01:33.9066667+00:00

    Hi Kashif Hasnain,

    When Outlook Web sends a notification with a deep link (e.g., "Go to file"), the MDCA reverse proxy rewrites the

    URL. During this URL rewriting, the deep link context (the specific file path/anchor) maybe lost, causing the user to

    land on the SharePoint homepage instead of the specific document. Refer: https://learn.microsoft.com/en-us/defender-cloud-apps/caac-known-issues#context-loss-limitations

    Recommendations:

    1. Use Microsoft Edge with in-browser protection – Edge users get direct in-browser protection without the reverse

    proxy, so deep links are preserved (though Edge also has its own deep link limitation when switching profiles).

    1. Scope session policies more precisely – If managed devices are already compliant (Intune/Hybrid Azure AD

    joined), consider excluding managed devices from the session policy and only applying it to unmanaged devices.

    Managed devices already have endpoint-level protections (Defender for Endpoint DLP).

    1. Use Access Policy instead of Session Policy for managed devices – Apply session controls only to unmanaged

    devices, and use access policies or Endpoint DLP for managed ones.

    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

     

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.