---
title: "Configure SaaS apps classification"
canonical: "https://docs.aryaka.com/space/KNOW/529236344/Configure%20SaaS%20apps%20classification"
format: markdown
---
The Aryaka CASB security engines ( SaaS Apps Access Control  and  Tenant Restriction ) enforce user-defined security rules on matched traffic. You can classify applications (for example, Facebook, Instagram, and Gmail), applications suites (for example, Microsoft 365 and Google Workspace), and organizations (for example, Meta Platforms, Inc., Alphabet Inc., and Microsoft Corporation) as sanctioned or unsanctioned. These classifications can be used by the SaaS Apps Access Control security engine to determine whether to permit or deny traffic.  The SaaS Apps Classification page allows you to classify applications as sanctioned or unsanctioned. This classification can then be used by the SaaS Apps Access Control security engine to determine the action to take on matched traffic. This is a global classification that applies to all of your sites. Follow the procedures in this topic to configure SaaS apps classification for your sites.  To configure SaaS apps classification Login to MyAryaka. The Home page appears. Click  Security  >  CASB  in the left navigation pane. The CASB page appears. Click  Manage  in the SaaS Apps Classification tile. The SaaS Apps Classification page appears and displays the Apps, Suites, and Orgs tabs. The Apps tab is open by default. Click the tab for which you want to modify the current classification. The page displays a list of sanctioned and unsanctioned applications, suites, or organizations. Note:  This procedure describes the Apps tab, but the instructions are the same for each tab. Click the  Edit  icon. The SaaS Apps Classification page appears in edit mode.  In the Sanctioned SaaS Applications pane, do one or more of the following: Click the red  X  in the Action column of an application to remove it from the Sanctioned SaaS Applications list. Click the blue  arrow  in the Action column of an application to move it to the Unsanctioned SaaS Applications list. Click  Move All to Unsanctioned List  to move all applications in the Sanctioned SaaS Application list to the Unsanctioned SaaS Applications list.  Click  Add  and complete the following procedure to add applications to the Sanctioned SaaS Application list: Click one or more applications you want to add to the Sanctioned SaaS Applications list. The selected entities are highlighted in green and display a check. Click  Add Selected . The selected applications are displayed in the Sanctioned SaaS Applications list.  In the Unsanctioned SaaS Applications pane, do one or more of the following: Click the red  X  in the Action column of an application to remove it from the Unsanctioned SaaS Applications list. Click the blue  arrow  in the Action column of an application to move it to the Sanctioned SaaS Applications list. Click  Move All to Sanctioned List  to move all applications in the Unsanctioned SaaS Application list to the Sanctioned SaaS Applications list.  Click  Add  and complete the following procedure to add applications to the Unsanctioned SaaS Application list: Click one or more applications you want to add to the Unsanctioned SaaS Applications list. The selected entities are highlighted in green and display a check. Click  Add Selected . The selected applications are displayed in the Unsanctioned SaaS Applications list.  (Optional) Click one of the other tabs and complete steps 6-7 to make additional changes. Click  Submit . You are prompted to select one of the following options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. When your update is activated, your SaaS apps classification configuration is saved.  Related topics CASB Configure site-level security features Security engine rulesets Configure a SaaS Apps Access Control ruleset Configure a Tenant Restriction ruleset