logo
search
Data Protection Issues

Configure Microsoft Defender Session Policies to Block Copy and Paste on macOS

Phi Hung VoPhi Hung Vo Oct 9, 2026 868 views

Question details

An organization needs to prevent users from copying sensitive information from Microsoft 365 web applications and pasting it into native macOS applications like Notepad.

How to Configure Microsoft Defender Session Policies to Block Copy and Paste on macOS
Product
Microsoft Defender for Cloud Apps
Device & OS
macOS
Scenario
Securing sensitive organizational data in Microsoft 365 web applications accessed on macOS devices to prevent data exfiltration.
Observed behavior
Users can currently copy data from Microsoft 365 web apps and freely paste it into local macOS applications, which needs to be restricted via policy.
Before you start

Ensure you have global administrator or security administrator privileges in the Microsoft Defender Portal and Microsoft Entra ID. It is highly recommended to test session policies with a small pilot group of macOS users before applying them organization-wide.

Solution 1Recommended

Configure a Block Copy and Paste Session Policy in Defender

Use Microsoft Defender for Cloud Apps to create a session policy that actively monitors and restricts clipboard actions (like copy and paste) within connected web applications.

Session policies allow real-time session-level monitoring and control over cloud apps. To block copy and paste, you must route your Microsoft 365 web app traffic through Conditional Access App Control.

Ensure your macOS devices and the browsers being used (such as Edge or Safari) are supported and properly configured in your Entra ID Conditional Access policies.

1
Access the Defender Portal

Sign in to the Microsoft Defender Portal (security.microsoft.com) using your administrator credentials and navigate to 'Cloud Apps' in the side menu.

2
Create a New Session Policy

Go to 'Policies' > 'Policy management'. Click on 'Create policy' and select 'Session policy' from the dropdown menu.

3
Select the Appropriate Template

In the policy creation screen, select the 'Block copy/paste' template if available, or choose 'Control data download (with inspection)' and manually configure the session control type to monitor clipboard activities.

4
Configure the Block Action

Under the 'Actions' section, set the policy action to 'Block'. You can also customize the message that appears to the macOS user when their copy/paste action is blocked.

5
Scope and Save the Policy

Set the policy filters to target macOS devices and specifically apply it to Microsoft 365 web apps. Click 'Create' to save and enable the policy for your pilot group.

Configure a Block Copy and Paste Session Policy in Defender
Testing Required: Session policies require precise device compliance conditions and browser support. Always validate the copy-and-paste controls thoroughly before a full production deployment.
Free Microsoft Office alternative

Looking for a Lightweight, Secure Alternative to Microsoft Office?

If you are managing complex administrative policies in Microsoft 365 and looking for a hassle-free, lightweight alternative for local document editing on macOS, consider WPS Office. It provides robust offline capabilities, ensuring data stays on your device while offering excellent compatibility with mainstream document formats.

  1. 1. Visit the WPS Website: Go to the official WPS Office website and navigate to the macOS download section.
  2. 2. Download the Installer: Click the 'Free Download' button to get the lightweight macOS installation package.
  3. 3. Install and Edit: Run the installer and open WPS Office to immediately start editing your Word, Excel, and PowerPoint files.
Highly compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Lightweight installation tailored for seamless performance on macOS.Familiar user interface requiring zero learning curve for transitioning teams.Powerful offline editing capabilities to keep sensitive data local when needed.
QA img-9

Frequently Asked Questions

Which web browsers on macOS support Defender session policies?

Defender for Cloud Apps session policies generally support major browsers like Microsoft Edge, Google Chrome, and Apple Safari. Traffic must be routed through Conditional Access App Control for the restrictions to take effect.

Does blocking copy and paste in web apps affect native desktop applications like Word for Mac?

No, session policies specifically target web applications accessed via a browser. To prevent data leakage from native desktop applications on macOS, you need to configure Endpoint Data Loss Prevention (Endpoint DLP) or Microsoft Intune app protection policies.

Can I test the block copy/paste policy without affecting all users?

Yes. When creating your Conditional Access policy in Entra ID that routes traffic to Defender for Cloud Apps, you can scope the policy to a specific 'Pilot Group' or set of test users before rolling it out to the entire organization.