Configure Microsoft Defender Session Policies to Block Copy and Paste on macOS
Question details
An organization needs to prevent users from copying sensitive information from Microsoft 365 web applications and pasting it into native macOS applications like Notepad.

- Product
- Microsoft Defender for Cloud Apps
- Device & OS
- macOS
- Scenario
- Securing sensitive organizational data in Microsoft 365 web applications accessed on macOS devices to prevent data exfiltration.
- Observed behavior
- Users can currently copy data from Microsoft 365 web apps and freely paste it into local macOS applications, which needs to be restricted via policy.
Ensure you have global administrator or security administrator privileges in the Microsoft Defender Portal and Microsoft Entra ID. It is highly recommended to test session policies with a small pilot group of macOS users before applying them organization-wide.
Configure a Block Copy and Paste Session Policy in Defender
Use Microsoft Defender for Cloud Apps to create a session policy that actively monitors and restricts clipboard actions (like copy and paste) within connected web applications.
Session policies allow real-time session-level monitoring and control over cloud apps. To block copy and paste, you must route your Microsoft 365 web app traffic through Conditional Access App Control.
Ensure your macOS devices and the browsers being used (such as Edge or Safari) are supported and properly configured in your Entra ID Conditional Access policies.
Sign in to the Microsoft Defender Portal (security.microsoft.com) using your administrator credentials and navigate to 'Cloud Apps' in the side menu.
Go to 'Policies' > 'Policy management'. Click on 'Create policy' and select 'Session policy' from the dropdown menu.
In the policy creation screen, select the 'Block copy/paste' template if available, or choose 'Control data download (with inspection)' and manually configure the session control type to monitor clipboard activities.
Under the 'Actions' section, set the policy action to 'Block'. You can also customize the message that appears to the macOS user when their copy/paste action is blocked.
Set the policy filters to target macOS devices and specifically apply it to Microsoft 365 web apps. Click 'Create' to save and enable the policy for your pilot group.

Seek Specialist Guidance on Microsoft Q&A
Since configuring session policies for specific OS environments can involve complex Entra ID routing, escalating to Microsoft specialists ensures accurate setup.
Looking for a Lightweight, Secure Alternative to Microsoft Office?
If you are managing complex administrative policies in Microsoft 365 and looking for a hassle-free, lightweight alternative for local document editing on macOS, consider WPS Office. It provides robust offline capabilities, ensuring data stays on your device while offering excellent compatibility with mainstream document formats.
- 1. Visit the WPS Website: Go to the official WPS Office website and navigate to the macOS download section.
- 2. Download the Installer: Click the 'Free Download' button to get the lightweight macOS installation package.
- 3. Install and Edit: Run the installer and open WPS Office to immediately start editing your Word, Excel, and PowerPoint files.

Frequently Asked Questions
Which web browsers on macOS support Defender session policies?
Defender for Cloud Apps session policies generally support major browsers like Microsoft Edge, Google Chrome, and Apple Safari. Traffic must be routed through Conditional Access App Control for the restrictions to take effect.
Does blocking copy and paste in web apps affect native desktop applications like Word for Mac?
No, session policies specifically target web applications accessed via a browser. To prevent data leakage from native desktop applications on macOS, you need to configure Endpoint Data Loss Prevention (Endpoint DLP) or Microsoft Intune app protection policies.
Can I test the block copy/paste policy without affecting all users?
Yes. When creating your Conditional Access policy in Entra ID that routes traffic to Defender for Cloud Apps, you can scope the policy to a specific 'Pilot Group' or set of test users before rolling it out to the entire organization.




