Microsoft Defender for Cloud Apps - Simply Explained
Microsoft Defender for Cloud Apps is Microsoft's Cloud Access Security Broker (CASB) that helps organizations discover, monitor, and protect the cloud applications employees use every day. In this episode of Microsoft Knowledge Nuggets, Mirko Peters explains Defender for Cloud Apps in simple terms, showing how organizations can gain visibility into cloud usage, detect risky behavior, and protect sensitive business data across Microsoft 365 and thousands of third-party SaaS applications.
You'll learn how Defender for Cloud Apps discovers Shadow IT, assesses the security of cloud services, and continuously monitors user activity for suspicious behavior. The episode explains core capabilities including Cloud Discovery, app governance, SaaS Security Posture Management (SSPM), threat detection, OAuth app protection, adaptive access controls, and data loss prevention (DLP). It also covers how the platform integrates with Microsoft Defender XDR, Microsoft Entra ID, Microsoft Purview, Microsoft Sentinel, and Microsoft 365 to provide a unified security experience across identities, endpoints, applications, and data.
The episode explores practical enterprise scenarios such as detecting unsanctioned cloud applications, preventing sensitive data from being shared externally, identifying compromised user accounts, controlling risky third-party app permissions, and enforcing real-time session controls for unmanaged devices. You'll also discover how Defender for Cloud Apps supports a Zero Trust security strategy by continuously verifying access, monitoring cloud activity, and helping security teams respond to threats before they become major incidents.
In today's digital landscape, you face increasing challenges in securing cloud applications. Microsoft Defender for Cloud Apps serves as a vital security solution, protecting your sensitive data and ensuring compliance with regulations. This platform empowers you to monitor and manage the cloud applications your organization uses, reducing risks associated with unapproved services. Understanding its features and setup is crucial for maximizing its effectiveness. For instance, 95% of users rate Microsoft Defender with 4 or 5 stars, showcasing its reliability in enhancing your security posture.
Key Takeaways
- Microsoft Defender for Cloud Apps protects sensitive data and ensures compliance with regulations.
- Cloud applications enhance productivity but can introduce risks like shadow IT, which can lead to security vulnerabilities.
- Advanced threat detection features help identify suspicious activities and potential threats in real-time.
- Data Loss Prevention (DLP) safeguards sensitive information from leaks and helps maintain compliance with industry regulations.
- Cloud discovery allows organizations to identify unauthorized applications and assess their risks effectively.
- Setting up Microsoft Defender involves accessing the Microsoft 365 Admin Center and following a setup wizard.
- Flexible subscription plans are available, allowing organizations to choose the level of protection that fits their needs.
- Regular updates and enhancements improve the platform's features, ensuring effective management of cloud security.
Cloud Apps Overview

Importance of Cloud Apps
Cloud apps have become essential in modern business operations. They enhance productivity and streamline processes, allowing you to work more efficiently. Here are some common types of cloud applications you might encounter:
- Serverless computing
- Container-based computing
- Server-based computing
- DevOps
- Managed cloud protection
- Disaster recovery services
These applications contribute significantly to your organization's digital transformation. They offer various benefits, including:
| Benefit | Description |
|---|---|
| Data Security and Reliability | Cloud services invest in advanced security measures, ensuring data safety and business continuity. |
| Improved Collaboration | Enables seamless data sharing and real-time communication, enhancing teamwork across departments. |
| Cost-Efficient | Reduces expenses related to on-premises infrastructure, allowing better resource allocation. |
| Accelerated Time to Market | Provides quick access to necessary resources, reducing time for project initiation and innovation. |
| Automation Opportunities | Automates routine tasks, improving efficiency and allowing focus on strategic initiatives. |
Risks of Shadow IT
While cloud apps offer numerous advantages, they also introduce risks, particularly through shadow IT. Shadow IT occurs when employees use unauthorized applications without IT approval. This practice can lead to serious security vulnerabilities. According to a study, 11% of all cyber incidents in organizations are linked to unauthorized shadow IT applications. This statistic highlights the significant impact of shadow IT on security breaches.
The main risks associated with using unauthorized cloud applications include:
- Data exfiltration, as sensitive files may be uploaded to personal accounts without oversight.
- Compliance risks arise from unapproved processing of data, which can result in severe fines under regulations like GDPR and HIPAA.
- OAuth-enabled applications can bypass traditional security measures, allowing unauthorized access to corporate data without detection.
- Shadow IT can lead to redundant licensing costs, as different departments may purchase similar tools independently.
- It accounts for a significant portion of IT spending, estimated at 30 to 40% in large enterprises, which generates risk alongside productivity.
Understanding these risks is crucial for maintaining a secure cloud environment. By recognizing the importance of cloud apps and the dangers of shadow IT, you can take proactive steps to safeguard your organization’s data.
Features of Microsoft Defender

Microsoft Defender for Cloud Apps offers a range of powerful features designed to enhance your organization's security posture. These features help you monitor, protect, and manage your cloud applications effectively.
Threat Detection
One of the standout features of Microsoft Defender for Cloud Apps is its advanced threat detection capabilities. This tool utilizes User and Entity Behavior Analytics (UEBA) and machine learning to identify suspicious activity and potential threats. You can detect various types of threats, including:
- Compromised accounts
- Insider threats
- Data leakage
- Malicious third-party apps
- Malware
- Phishing
- Ransomware
- Risks related to unmanaged devices
With anomaly detection policies, you can monitor user behavior and identify unusual activities. This proactive approach allows you to respond quickly to potential cyber threats. The platform also provides unified threat detection across Microsoft and third-party cloud services, ensuring comprehensive protection.
Data Loss Prevention
Data loss prevention (DLP) is another critical feature of Microsoft Defender for Cloud Apps. This functionality helps you safeguard sensitive information from accidental or malicious leaks. The platform allows you to implement real-time security measures that monitor user activity and enforce controls. For example, you can block downloads of sensitive documents from unmanaged devices.
Key capabilities of DLP include:
- File Policies: Automate processes using cloud provider APIs to enforce DLP for sensitive content shared publicly.
- Monitoring: Track any file type based on over 20 metadata filters, such as access level and file type.
- Alerts: Set alerts for specific actions, such as publicly shared files or files containing sensitive information.
These features empower you to maintain compliance with industry regulations like GDPR and HIPAA. Microsoft Defender for Cloud Apps helps you identify compliance issues and assess your compliance posture effectively.
Cloud Discovery
Cloud discovery is essential for managing your organization's cloud environment. Microsoft Defender for Cloud Apps enables you to discover and identify shadow IT, which refers to unauthorized applications used by employees. The process involves several steps:
- Discover and identify Shadow IT: Run cloud discovery to see what's happening in your network.
- Identify the risk levels of your apps: Use the Defender for Cloud Apps catalog to assess risks associated with discovered apps.
- Evaluate compliance: Check if the apps meet your organization's compliance standards.
- Analyze usage: Investigate how and who is using the apps to determine their necessity and risk.
- Identify alternative apps: Find safer apps that comply with your organization's policies.
- Manage your apps: Create custom app tags for monitoring and manage discovered apps using Microsoft Entra Gallery.
With the ability to identify over 31,000 cloud applications, Microsoft Defender for Cloud Apps provides comprehensive visibility into your cloud environment. This visibility allows you to make informed decisions about application usage and security.
Setting Up Microsoft Defender for Cloud Apps
Setting up Microsoft Defender for Cloud Apps involves a few essential steps. You need to ensure that your organization meets specific prerequisites before installation. Follow these steps to get started:
Installation Steps
- Access the Microsoft 365 Admin Center: Log in to your Microsoft 365 account and navigate to the Admin Center.
- Select Security: In the left-hand menu, click on "Security" to access security-related features.
- Choose Microsoft Defender for Cloud Apps: Locate and select Microsoft Defender for Cloud Apps from the list of available services.
- Follow the Setup Wizard: The setup wizard will guide you through the installation process. Follow the prompts to complete the installation.
- Assign Roles: Ensure that the appropriate roles are assigned to users who will manage the application. Refer to the table below for the required roles.
| Role Type | Required Role(s) |
|---|---|
| Read/Write Access | Any read or write role |
| Configuration Change | Global Administrator, Security Administrator, or Cloud App Administrator |
| Defender for Cloud Apps Role | Global Administrator |
Configuration Settings
After installation, you must configure Microsoft Defender for Cloud Apps to optimize its security features. Here are some recommended configuration settings:
- App Discovery Configuration: Set up App Discovery to identify unsanctioned cloud apps in your environment.
- Data Loss Prevention (DLP) Setup: Enable built-in DLP templates to automatically detect sensitive data.
- Session Control Deployment: Use session controls to manage user actions within SaaS apps, especially from unmanaged devices.
- Security Policy Customization: Fine-tune default policies to meet specific industry requirements and risk tolerance.
- Alert Integration and Response Planning: Integrate alerts into existing systems for unified incident response.
By following these steps and configurations, you can effectively set up Microsoft Defender for Cloud Apps. This setup will help you manage security risks and protect sensitive data across your cloud applications.
Pricing for Microsoft Defender
Subscription Plans
Microsoft Defender for Cloud Apps offers flexible subscription plans tailored to meet various organizational needs. These plans allow you to choose the level of protection that aligns with your budget and security requirements. Here are the key options available:
- Basic Plan: This plan provides essential features for small to medium-sized businesses. It includes basic threat detection and data loss prevention capabilities.
- Standard Plan: This option adds advanced threat detection and cloud discovery features. It is suitable for organizations that require more comprehensive security measures.
- Premium Plan: This plan includes all features from the Standard Plan, plus enhanced compliance tools and advanced analytics. It is ideal for larger enterprises with complex security needs.
Each plan is designed to scale with your organization, ensuring you only pay for what you need.
Cost Comparison
When comparing Microsoft Defender for Cloud Apps to other leading cloud security solutions, you will find some notable differences. Here are a few points to consider:
- Setup Costs: Microsoft Defender for Cloud Apps generally has higher setup costs compared to Cisco Cloudlock, which offers a more budget-friendly initial setup. This can be a significant factor for organizations with limited budgets.
- Ongoing Expenses: While Microsoft Defender for Cloud Apps may have higher initial costs, it provides robust features that can lead to a higher return on investment (ROI) over time. Netskope also offers multiple pricing options, but specific pricing details are not readily available.
- Ease of Use: The ease of administration can impact your overall experience. Microsoft Defender for Cloud Apps integrates seamlessly with other Microsoft security tools, which may simplify management for organizations already using Microsoft products.
When evaluating your options, consider factors such as initial costs, implementation expenses, ongoing maintenance, and the overall impact on your security posture. This comprehensive approach will help you make an informed decision that best suits your organization's needs.
Recent Updates and Enhancements
New Features
Microsoft Defender for Cloud Apps has recently introduced several new features that significantly enhance your organization's security posture. These updates focus on improving visibility and control over cloud applications. Here are some key enhancements:
| Enhancement Description | Benefit to Security Posture |
|---|---|
| Inclusion of OAuth applications in attack path mapping | Visualizes potential exploitation paths, aiding in risk mitigation. |
| Centralized Applications page for SaaS and OAuth apps | Streamlines monitoring and management, enhancing visibility and control. |
| Visibility into origins of OAuth apps | Allows proactive review of external apps, improving security. |
| New Permissions filter and export capabilities | Facilitates identification of apps with specific permissions, enhancing oversight. |
| Enhanced privilege level classification for API permissions | Improves monitoring of apps with powerful permissions, reducing risk. |
These features empower you to manage risks more effectively. By visualizing potential threats and streamlining application management, you can take proactive steps to protect sensitive data.
User Experience Improvements
In addition to new features, Microsoft Defender for Cloud Apps has made significant user experience improvements. These enhancements aim to simplify navigation and increase efficiency. You will notice a more intuitive interface that allows for quicker access to essential tools. The centralized dashboard provides a comprehensive overview of your cloud environment, making it easier to monitor application usage and security status.
The future roadmap for Microsoft Defender for Cloud Apps includes exciting developments. Here’s a look at what to expect:
| Aspect | Details |
|---|---|
| Expansion | Microsoft Purview DLP will expand to Google, AWS, and Salesforce by September 2026. |
| Key Questions | Important questions include the ability to inspect content, support for custom sensitive information types, and actions available for policies. |
| Licensing and Administration | Clarification on required licenses and roles for connector authorization is needed. |
| Migration Guidance | Guidance on policy mapping and automated assessment tools for transitioning from Defender for Cloud Apps file policies is essential. |
| Preview Feedback | Real-world performance metrics during the preview phase will be critical for assessing the effectiveness of the connectors. |
| Overall Goal | The aim is to create a cross-cloud data security control plane that effectively manages security across various applications and platforms. |
These updates and enhancements reflect Microsoft’s commitment to providing you with the tools necessary to secure your cloud applications effectively. By staying informed about these changes, you can leverage the full potential of Microsoft Defender for Cloud Apps to protect your organization.
Microsoft Defender for Cloud Apps plays a crucial role in securing your cloud environment. Its key features provide significant benefits, including:
| Key Features | Benefits |
|---|---|
| Visibility into cloud app usage | Helps organizations monitor and manage application usage effectively. |
| Protection of sensitive data | Ensures that critical information is safeguarded against unauthorized access. |
| Threat detection | Identifies potential security threats in real-time, allowing for prompt response. |
| Integration with Microsoft ecosystem | Provides a seamless experience and enhances overall security posture. |
By adopting Microsoft Defender for Cloud Apps, you empower your organization with enterprise-grade cloud defense. This tool not only enhances your ability to operate safely in the cloud but also supports compliance with data protection regulations.
To maximize its effectiveness, consider these recommendations:
- Complete basic setup and organizational details.
- Connect your priority cloud apps.
- Enable Cloud Discovery to map shadow IT.
- Configure access and session policies.
- Turn on app governance for OAuth monitoring.
Taking these steps will help you protect sensitive data and maintain compliance effectively.
FAQ
What is Microsoft Defender for Cloud Apps?
Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that helps you monitor and protect cloud applications. It provides visibility into app usage, detects threats, and enforces security policies.
How does Cloud Discovery work?
Cloud Discovery identifies unauthorized applications used by your employees. It assesses risk levels, evaluates compliance, and analyzes usage to help you manage shadow IT effectively.
Can I integrate Microsoft Defender with other Microsoft tools?
Yes, Microsoft Defender for Cloud Apps integrates seamlessly with other Microsoft security tools, such as Microsoft Entra ID and Microsoft Defender for Endpoint, enhancing your overall security posture.
What are the subscription plans available?
Microsoft Defender for Cloud Apps offers three subscription plans: Basic, Standard, and Premium. Each plan provides different features tailored to meet your organization's security needs.
How does Data Loss Prevention (DLP) work?
DLP in Microsoft Defender for Cloud Apps helps you protect sensitive information from leaks. It monitors user activity, enforces controls, and alerts you to potential compliance issues.
What types of threats can Microsoft Defender detect?
Microsoft Defender can detect various threats, including compromised accounts, insider threats, data leakage, malware, and phishing attempts. It uses advanced analytics to identify suspicious activities.
Is training required to use Microsoft Defender for Cloud Apps?
While no formal training is required, familiarizing yourself with the platform's features and settings will help you maximize its effectiveness. Microsoft provides resources and documentation to assist you.
How often are updates released for Microsoft Defender?
Microsoft regularly updates Microsoft Defender for Cloud Apps to enhance features and improve security. Staying informed about these updates ensures you leverage the latest capabilities for your organization.
🚀 Want to be part of m365.fm?
Then stop just listening… and start showing up.
👉 Connect with me on LinkedIn and let’s make something happen:
- 🎙️ Be a podcast guest and share your story
- 🎧 Host your own episode (yes, seriously)
- 💡 Pitch topics the community actually wants to hear
- 🌍 Build your personal brand in the Microsoft 365 space
This isn’t just a podcast — it’s a platform for people who take action.
🔥 Most people wait. The best ones don’t.
👉 Connect with me on LinkedIn and send me a message:
"I want in"
Let’s build something awesome 👊
1
00:00:00,000 --> 00:00:03,640
Welcome to another episode of Microsoft Knowledge Nuggets on M365.
2
00:00:03,640 --> 00:00:05,320
FM, I'm your host, Mirko Peters.
3
00:00:05,320 --> 00:00:07,720
Today's topic is one that almost everyone is heard of,
4
00:00:07,720 --> 00:00:09,840
but very few people actually understand.
5
00:00:09,840 --> 00:00:11,600
Microsoft Defender for Cloud Apps.
6
00:00:11,600 --> 00:00:14,440
It sounds like another security product you're supposed to buy,
7
00:00:14,440 --> 00:00:16,240
configure, and then forget about.
8
00:00:16,240 --> 00:00:19,360
But here's the thing, most businesses have no idea which Cloud Apps
9
00:00:19,360 --> 00:00:21,640
their employees are actually using, and I mean no idea.
10
00:00:21,640 --> 00:00:23,360
You probably know about the official ones.
11
00:00:23,360 --> 00:00:26,400
The Microsoft 365 subscription, maybe Salesforce or Dropbox
12
00:00:26,400 --> 00:00:27,760
if IT gave the green light.
13
00:00:27,800 --> 00:00:29,960
But what about the other ones, the free file sharing side,
14
00:00:29,960 --> 00:00:31,640
someone in Accounting Found last week,
15
00:00:31,640 --> 00:00:33,960
the AI writing tool, the marketing team started using
16
00:00:33,960 --> 00:00:36,120
without telling anyone, the project management app
17
00:00:36,120 --> 00:00:38,120
that just showed up on someone's browser one day,
18
00:00:38,120 --> 00:00:39,800
those are the apps you don't know about.
19
00:00:39,800 --> 00:00:41,800
And they're the ones that cause real problems.
20
00:00:41,800 --> 00:00:43,920
By the end of this episode, you'll understand
21
00:00:43,920 --> 00:00:46,320
what Defender for Cloud Apps actually is,
22
00:00:46,320 --> 00:00:49,360
why it matters for your business, and how it works.
23
00:00:49,360 --> 00:00:51,400
Without needing to touch a single setting.
24
00:00:51,400 --> 00:00:54,280
This is a plain English overview, no technical deep dives,
25
00:00:54,280 --> 00:00:55,920
no admin console walkthroughs,
26
00:00:55,960 --> 00:00:57,960
just the big picture explained clearly.
27
00:00:57,960 --> 00:01:00,000
So grab your coffee and let's dive in.
28
00:01:00,000 --> 00:01:03,280
The blind spot in your cloud, here's what actually happens every single day.
29
00:01:03,280 --> 00:01:05,720
Employees in your organization sign up for cloud services
30
00:01:05,720 --> 00:01:08,160
without telling anyone, they do it because it's faster.
31
00:01:08,160 --> 00:01:11,280
They need to send a large file, so they use a free file sharing app.
32
00:01:11,280 --> 00:01:13,000
They want to collaborate on a document,
33
00:01:13,000 --> 00:01:15,600
so they create an account on some online whiteboard tool.
34
00:01:15,600 --> 00:01:17,240
They hear about a new AI assistant,
35
00:01:17,240 --> 00:01:19,600
so they sign up and start feeding it company data.
36
00:01:19,600 --> 00:01:20,960
Let me give you a concrete example.
37
00:01:20,960 --> 00:01:24,720
Imagine someone in marketing needs to send a large presentation to a client.
38
00:01:24,760 --> 00:01:28,000
The file is too big for email, so they search for free file transfer
39
00:01:28,000 --> 00:01:29,360
and pick the first result.
40
00:01:29,360 --> 00:01:30,800
They upload the presentation,
41
00:01:30,800 --> 00:01:34,400
which contains next quarter's pricing strategy and share the link done.
42
00:01:34,400 --> 00:01:35,400
Problem solved, right?
43
00:01:35,400 --> 00:01:36,240
Not quite.
44
00:01:36,240 --> 00:01:39,320
That free file sharing app might not have any security controls,
45
00:01:39,320 --> 00:01:42,320
no encryption, no audit trail, no data retention policy.
46
00:01:42,320 --> 00:01:45,680
The company behind it might be based in a country with weak data protection laws.
47
00:01:45,680 --> 00:01:49,040
And once that file is uploaded, you have no idea who accesses it,
48
00:01:49,040 --> 00:01:51,880
where it gets downloaded, or whether it gets forwarded to someone else.
49
00:01:51,880 --> 00:01:54,640
This is what security experts call shadow IT.
50
00:01:54,680 --> 00:01:58,320
In plain English, shadow IT means using software or services at work
51
00:01:58,320 --> 00:02:00,400
without the IT department knowing about it.
52
00:02:00,400 --> 00:02:01,800
And it's more common than you think.
53
00:02:01,800 --> 00:02:02,880
So why should you care?
54
00:02:02,880 --> 00:02:04,000
Three big reasons.
55
00:02:04,000 --> 00:02:08,480
First, data leakage, your sensitive information ends up on service you don't control.
56
00:02:08,480 --> 00:02:10,280
Second, compliance violations.
57
00:02:10,280 --> 00:02:13,440
If you're subject to regulations like GDPR or HIPAA,
58
00:02:13,440 --> 00:02:17,040
using an app that doesn't meet those standards puts you in violation.
59
00:02:17,040 --> 00:02:18,680
Third, unknown risk.
60
00:02:18,680 --> 00:02:21,320
Every unapproved app is a potential entry point for an attacker
61
00:02:21,320 --> 00:02:23,760
because you can't protect what you can't see.
62
00:02:23,800 --> 00:02:25,960
The old way of solving this was impossible.
63
00:02:25,960 --> 00:02:27,680
You couldn't see what you couldn't control.
64
00:02:27,680 --> 00:02:29,720
You might block certain websites at the firewall,
65
00:02:29,720 --> 00:02:33,360
but employees working from home on their phones were just bypass those restrictions.
66
00:02:33,360 --> 00:02:35,640
You might ask people to only use approved apps,
67
00:02:35,640 --> 00:02:38,440
but that relied on everyone following the rules, which they didn't.
68
00:02:38,440 --> 00:02:41,640
And even if they did, new apps appeared every day that you never knew about.
69
00:02:41,640 --> 00:02:42,440
So what do you do?
70
00:02:42,440 --> 00:02:44,480
You need a tool that actually sees what's happening,
71
00:02:44,480 --> 00:02:46,680
a tool designed to shine a light on the shadows
72
00:02:46,680 --> 00:02:49,400
that's exactly what Defender for Cloud Apps is built to do.
73
00:02:49,400 --> 00:02:51,120
What is Defender for Cloud Apps?
74
00:02:51,120 --> 00:02:53,000
What exactly is Defender for Cloud Apps?
75
00:02:53,040 --> 00:02:54,320
Here's the simplest definition.
76
00:02:54,320 --> 00:02:58,640
It's a security guard that watches every connection between your users and the Cloud Apps they use.
77
00:02:58,640 --> 00:03:01,960
Checks who's using what flags anything suspicious.
78
00:03:01,960 --> 00:03:05,720
The technical name is Cloud Access Security Broker or CSB.
79
00:03:05,720 --> 00:03:07,120
But we're sticking with plain English.
80
00:03:07,120 --> 00:03:08,000
Think of it this way.
81
00:03:08,000 --> 00:03:10,160
Your business is a building with lots of doors.
82
00:03:10,160 --> 00:03:12,280
Each Cloud app is one of those doors.
83
00:03:12,280 --> 00:03:13,240
Some are safe.
84
00:03:13,240 --> 00:03:15,800
They lead to well-lit rooms with security cameras.
85
00:03:15,800 --> 00:03:17,400
Others lead to dark alleys.
86
00:03:17,400 --> 00:03:19,360
Defender for Cloud Apps stands at each door,
87
00:03:19,360 --> 00:03:21,400
checks who's coming in, what they're carrying,
88
00:03:21,440 --> 00:03:23,120
and whether they should be there at all.
89
00:03:23,120 --> 00:03:24,240
So what does it actually do?
90
00:03:24,240 --> 00:03:26,840
It finds every Cloud app being used in your company,
91
00:03:26,840 --> 00:03:28,400
whether you approved it or not,
92
00:03:28,400 --> 00:03:31,120
tells you how risky each app is based on security features,
93
00:03:31,120 --> 00:03:33,440
compliance certifications and legal policies,
94
00:03:33,440 --> 00:03:37,000
watches how people use those apps and flags on usual activity.
95
00:03:37,000 --> 00:03:39,000
And if something's dangerous, it can block it.
96
00:03:39,000 --> 00:03:41,080
Defender for Cloud Apps doesn't work alone.
97
00:03:41,080 --> 00:03:43,160
It's part of the Microsoft Defender suite,
98
00:03:43,160 --> 00:03:45,000
a collection of security tools,
99
00:03:45,000 --> 00:03:48,120
shares information with Defender for Endpoint for Device Protection,
100
00:03:48,160 --> 00:03:51,640
connects to Microsoft Enter ID for user identity management.
101
00:03:51,640 --> 00:03:54,120
Integrates with Microsoft Sentinel for enterprise security,
102
00:03:54,120 --> 00:03:56,280
but for now, just know it's one piece of a bigger system
103
00:03:56,280 --> 00:03:57,720
protecting your entire environment.
104
00:03:57,720 --> 00:04:00,800
That's the big picture, but how does it actually find those hidden apps?
105
00:04:00,800 --> 00:04:02,600
That's where Cloud Discovery comes in.
106
00:04:02,600 --> 00:04:04,880
Cloud Discovery, seeing the invisible.
107
00:04:04,880 --> 00:04:07,920
So how does Defender for Cloud Apps find those hidden apps?
108
00:04:07,920 --> 00:04:09,520
Through a feature called Cloud Discovery.
109
00:04:09,520 --> 00:04:11,040
It does exactly what it sounds like.
110
00:04:11,040 --> 00:04:14,240
Discovers every Cloud app in use across your organization,
111
00:04:14,240 --> 00:04:15,960
whether IT approved it or not.
112
00:04:16,000 --> 00:04:18,760
There are two ways this works and it depends on your license.
113
00:04:18,760 --> 00:04:21,320
The full version integrates directly with Microsoft Defender
114
00:04:21,320 --> 00:04:23,280
for Endpoint on your company devices.
115
00:04:23,280 --> 00:04:26,840
One setup, Cloud Discovery runs continuously and automatically.
116
00:04:26,840 --> 00:04:28,480
Reports everything it finds.
117
00:04:28,480 --> 00:04:31,720
Every app someone accesses, every login, every file upload,
118
00:04:31,720 --> 00:04:32,960
constant monitoring.
119
00:04:32,960 --> 00:04:35,520
The business premium version is different, less seamless.
120
00:04:35,520 --> 00:04:37,000
Instead of automatic integration,
121
00:04:37,000 --> 00:04:39,920
you upload log files from your firewall or network proxy,
122
00:04:39,920 --> 00:04:43,480
export traffic logs, upload them to Defender and it analyzes them.
123
00:04:43,520 --> 00:04:46,320
It gives you a snapshot of what apps were accessed during that period.
124
00:04:46,320 --> 00:04:48,080
Not a live feed, but it still works.
125
00:04:48,080 --> 00:04:50,600
For many small businesses, it's the only option.
126
00:04:50,600 --> 00:04:52,920
Once Cloud Discovery is running, you get a dashboard.
127
00:04:52,920 --> 00:04:55,080
Shows total apps used across your organization.
128
00:04:55,080 --> 00:04:57,600
How many users accessed them, which IP addresses?
129
00:04:57,600 --> 00:04:59,160
How much traffic they generated?
130
00:04:59,160 --> 00:05:02,120
You can filter by risk level, category, location or user.
131
00:05:02,120 --> 00:05:03,400
See exactly what's happening.
132
00:05:03,400 --> 00:05:04,640
Here's a real scenario.
133
00:05:04,640 --> 00:05:08,160
You discover 10 people in your company are using a file sharing app
134
00:05:08,160 --> 00:05:10,800
hosted in a country with weak data protection laws.
135
00:05:10,800 --> 00:05:12,520
You didn't approve it, nobody asked.
136
00:05:12,560 --> 00:05:15,600
But now you know, before Cloud Discovery, that app was invisible.
137
00:05:15,600 --> 00:05:16,680
Now you see it clearly.
138
00:05:16,680 --> 00:05:18,400
That visibility changes everything.
139
00:05:18,400 --> 00:05:20,200
You stop guessing and start knowing.
140
00:05:20,200 --> 00:05:23,640
And once you know, you can do something about it.
141
00:05:23,640 --> 00:05:26,120
The app catalog, risk scoring made simple.
142
00:05:26,120 --> 00:05:27,360
So you found all those apps.
143
00:05:27,360 --> 00:05:29,160
Now you need to know which ones are safe.
144
00:05:29,160 --> 00:05:30,720
That's where the app catalog steps in.
145
00:05:30,720 --> 00:05:34,120
Microsoft has already checked over 31,000 cloud apps
146
00:05:34,120 --> 00:05:35,880
against more than 90 risk factors.
147
00:05:35,880 --> 00:05:36,880
That's a lot of homework.
148
00:05:36,880 --> 00:05:39,200
Each app gets a risk score from 0 to 10.
149
00:05:39,200 --> 00:05:39,960
10 is the safest.
150
00:05:39,960 --> 00:05:41,600
0 means stay far away.
151
00:05:41,640 --> 00:05:42,880
What exactly are they checking?
152
00:05:42,880 --> 00:05:43,560
Three things.
153
00:05:43,560 --> 00:05:45,400
First, security features.
154
00:05:45,400 --> 00:05:47,000
Does the app support encryption?
155
00:05:47,000 --> 00:05:49,320
Does it offer multi factor authentication?
156
00:05:49,320 --> 00:05:50,600
Does it keep an audit trail?
157
00:05:50,600 --> 00:05:52,440
Second, compliance certifications.
158
00:05:52,440 --> 00:05:56,680
Is it certified for ISO 27001, SOC2 or GDPR?
159
00:05:56,680 --> 00:05:57,920
Third, legal policies.
160
00:05:57,920 --> 00:05:59,320
Who owns the data you store there?
161
00:05:59,320 --> 00:06:00,640
What happens if you stop paying?
162
00:06:00,640 --> 00:06:02,320
What privacy protections exist?
163
00:06:02,320 --> 00:06:04,920
Think of it like a restaurant health inspection school.
164
00:06:04,920 --> 00:06:07,360
You wouldn't eat at a place with a score of 2 out of 10.
165
00:06:07,360 --> 00:06:08,200
Same logic here.
166
00:06:08,200 --> 00:06:10,840
You want to know the kitchen is clean before your employees eat there.
167
00:06:10,880 --> 00:06:13,440
Once you know an app's score, you have three choices.
168
00:06:13,440 --> 00:06:14,600
You can sanction it.
169
00:06:14,600 --> 00:06:16,160
That means you approve it for use.
170
00:06:16,160 --> 00:06:18,560
You can un-sanction it and that blocks it completely.
171
00:06:18,560 --> 00:06:19,720
Or you can monitor it.
172
00:06:19,720 --> 00:06:20,880
Let people keep using it.
173
00:06:20,880 --> 00:06:23,360
But watch it closely and maybe show a warning that says
174
00:06:23,360 --> 00:06:25,840
this app hasn't been reviewed for security.
175
00:06:25,840 --> 00:06:27,560
The catalog updates continuously.
176
00:06:27,560 --> 00:06:29,200
New apps get added all the time.
177
00:06:29,200 --> 00:06:30,520
And as Microsoft learns more,
178
00:06:30,520 --> 00:06:32,760
maybe the app gets a new security certification
179
00:06:32,760 --> 00:06:34,800
or a data breach reveals a vulnerability.
180
00:06:34,800 --> 00:06:36,720
The risk score updates automatically.
181
00:06:36,720 --> 00:06:38,560
So you never work with stale information.
182
00:06:38,560 --> 00:06:40,280
Discovery gives you visibility.
183
00:06:40,320 --> 00:06:42,000
The catalog gives you context.
184
00:06:42,000 --> 00:06:44,600
Together they tell you what's out there and how risky it is.
185
00:06:44,600 --> 00:06:46,760
But knowing isn't the same as doing.
186
00:06:46,760 --> 00:06:48,160
The real power comes next.
187
00:06:48,160 --> 00:06:49,960
Automated protection.
188
00:06:49,960 --> 00:06:51,480
Policies and threat detection.
189
00:06:51,480 --> 00:06:52,880
So you've discovered the apps.
190
00:06:52,880 --> 00:06:54,080
You've checked their risk scores.
191
00:06:54,080 --> 00:06:54,800
Now what?
192
00:06:54,800 --> 00:06:57,400
Defender for Cloud Apps comes with built-in policies
193
00:06:57,400 --> 00:06:59,880
that watch for suspicious behavior automatically.
194
00:06:59,880 --> 00:07:01,240
You don't need to configure much.
195
00:07:01,240 --> 00:07:03,080
The system already knows what to look for.
196
00:07:03,080 --> 00:07:05,080
Let me give you some examples of what it detects.
197
00:07:05,080 --> 00:07:05,880
Impossible travel.
198
00:07:05,880 --> 00:07:07,200
This one is straightforward.
199
00:07:07,240 --> 00:07:10,320
Imagine a user logs in from New York at 9 a.m.
200
00:07:10,320 --> 00:07:13,400
Then 10 minutes later, the same user logs in from Tokyo.
201
00:07:13,400 --> 00:07:14,320
That's impossible.
202
00:07:14,320 --> 00:07:16,680
You can't get from New York to Tokyo in 10 minutes.
203
00:07:16,680 --> 00:07:17,680
So something is wrong.
204
00:07:17,680 --> 00:07:19,440
Either someone stole that user's password
205
00:07:19,440 --> 00:07:20,560
or they're using a VPN
206
00:07:20,560 --> 00:07:22,400
that makes it look like they're somewhere they're not.
207
00:07:22,400 --> 00:07:23,880
Either way, Defender flags it.
208
00:07:23,880 --> 00:07:25,320
Mass downloads or deletions.
209
00:07:25,320 --> 00:07:27,480
If someone suddenly downloads hundreds of files
210
00:07:27,480 --> 00:07:29,720
from SharePoint or OneDrive, that's unusual.
211
00:07:29,720 --> 00:07:31,960
If they delete a bunch of data all at once,
212
00:07:31,960 --> 00:07:32,800
that's also unusual.
213
00:07:32,800 --> 00:07:34,760
These could be signs of a disgruntled employee
214
00:07:34,800 --> 00:07:37,720
about to leave or an attacker trying to steal or destroy data
215
00:07:37,720 --> 00:07:38,960
before they get caught.
216
00:07:38,960 --> 00:07:40,640
Logins from risky IP addresses.
217
00:07:40,640 --> 00:07:42,760
Some IP addresses are known to be dangerous.
218
00:07:42,760 --> 00:07:44,800
They might belong to countries under sanctions.
219
00:07:44,800 --> 00:07:47,120
They might be associated with known hacking groups.
220
00:07:47,120 --> 00:07:49,280
When a login comes from one of these addresses,
221
00:07:49,280 --> 00:07:51,080
Defender raises an alert.
222
00:07:51,080 --> 00:07:52,920
Suspicious email forwarding rules.
223
00:07:52,920 --> 00:07:54,640
This is a common hacker tactic.
224
00:07:54,640 --> 00:07:56,920
They compromise an email account and set up a rule
225
00:07:56,920 --> 00:08:00,240
that forwards all incoming messages to an external address.
226
00:08:00,240 --> 00:08:03,120
That way they can read every email that person receives
227
00:08:03,160 --> 00:08:05,120
without logging into their account again.
228
00:08:05,120 --> 00:08:07,840
Defender can spot when a new forwarding rule is created
229
00:08:07,840 --> 00:08:09,160
and flag it immediately.
230
00:08:09,160 --> 00:08:10,920
How does it know what's normal and what's not?
231
00:08:10,920 --> 00:08:13,800
It uses something called user and entity behavior analytics,
232
00:08:13,800 --> 00:08:15,160
UEBA for short.
233
00:08:15,160 --> 00:08:17,680
The system learns what normal looks like for each person
234
00:08:17,680 --> 00:08:18,840
in your organization.
235
00:08:18,840 --> 00:08:21,040
It watches their patterns over time.
236
00:08:21,040 --> 00:08:23,400
Where they log in from, what time of day they work,
237
00:08:23,400 --> 00:08:25,240
how many files they typically access.
238
00:08:25,240 --> 00:08:28,560
Once it understands the baseline, it can spot deviations.
239
00:08:28,560 --> 00:08:29,960
And when it does, it takes action.
240
00:08:29,960 --> 00:08:32,640
The system can automatically respond in several ways.
241
00:08:32,680 --> 00:08:34,480
It can send an alert to the IT team.
242
00:08:34,480 --> 00:08:35,800
It can suspend the user's account.
243
00:08:35,800 --> 00:08:38,360
It can block the suspicious activity entirely.
244
00:08:38,360 --> 00:08:40,360
You decide how aggressive you want to be.
245
00:08:40,360 --> 00:08:43,160
You can also create custom policies for your specific needs.
246
00:08:43,160 --> 00:08:44,920
Maybe you want to be alerted any time someone
247
00:08:44,920 --> 00:08:47,600
from the finance team accesses files after midnight.
248
00:08:47,600 --> 00:08:50,200
Maybe you want to block all downloads from a particular app.
249
00:08:50,200 --> 00:08:51,760
You can build those rules yourself.
250
00:08:51,760 --> 00:08:53,240
Here's a real world scenario.
251
00:08:53,240 --> 00:08:55,760
A busy executive gets an email that looks legitimate.
252
00:08:55,760 --> 00:08:57,880
They click a link, their credentials get stolen.
253
00:08:57,880 --> 00:09:00,640
Within minutes, the attacker logs in from a different country.
254
00:09:00,640 --> 00:09:02,640
Defender spots the impossible travel
255
00:09:02,640 --> 00:09:05,200
checks the IP address against known threat databases
256
00:09:05,200 --> 00:09:07,120
and automatically disables the account.
257
00:09:07,120 --> 00:09:08,600
The IT team gets an alert.
258
00:09:08,600 --> 00:09:10,240
The executive gets a notification.
259
00:09:10,240 --> 00:09:12,760
The attacker stopped before any real damage happens.
260
00:09:12,760 --> 00:09:16,000
Policies cover threats, but what about protecting the data itself?
261
00:09:16,000 --> 00:09:17,840
Data protection and access control.
262
00:09:17,840 --> 00:09:19,680
So policies catch suspicious behavior,
263
00:09:19,680 --> 00:09:22,000
but Defender also protects the data itself.
264
00:09:22,000 --> 00:09:24,880
The files and documents your employees work with every day.
265
00:09:24,880 --> 00:09:27,160
Defender monitors file sharing to stop sensitive data
266
00:09:27,160 --> 00:09:28,640
from leaving your organization
267
00:09:28,640 --> 00:09:30,920
and it hooks into Microsoft Information Protection.
268
00:09:30,960 --> 00:09:33,760
The system behind those sensitivity labels you've seen.
269
00:09:33,760 --> 00:09:37,000
Confidential, internal only, highly confidential.
270
00:09:37,000 --> 00:09:38,440
Based on what a file contains,
271
00:09:38,440 --> 00:09:40,680
Defender can apply those labels automatically.
272
00:09:40,680 --> 00:09:41,480
Here's an example.
273
00:09:41,480 --> 00:09:43,720
Someone tries to share a confidential document
274
00:09:43,720 --> 00:09:44,920
to their personal email.
275
00:09:44,920 --> 00:09:48,040
They're working from home and want to finish something on their personal laptop.
276
00:09:48,040 --> 00:09:50,600
Defender spots the attempt and blocks the share entirely
277
00:09:50,600 --> 00:09:53,760
or applies a label that makes the file unreadable outside the company.
278
00:09:53,760 --> 00:09:55,720
Either way, that document stays protected.
279
00:09:55,720 --> 00:09:57,520
You also get conditional access app control,
280
00:09:57,520 --> 00:09:59,840
which gives you real time controls inside apps.
281
00:09:59,880 --> 00:10:03,120
You can block, cut, copy, paste, downloads, even printing.
282
00:10:03,120 --> 00:10:06,760
So if someone accesses a sensitive app from an unmanaged device,
283
00:10:06,760 --> 00:10:08,080
like their personal phone,
284
00:10:08,080 --> 00:10:09,680
you can restrict what they're allowed to do
285
00:10:09,680 --> 00:10:11,640
without cutting off access completely.
286
00:10:11,640 --> 00:10:14,440
And it works with both Microsoft apps and non-Microsoft apps.
287
00:10:14,440 --> 00:10:18,520
Google workspace, Salesforce, Box AWS, Defender Connects to all of them
288
00:10:18,520 --> 00:10:19,560
through API connectors.
289
00:10:19,560 --> 00:10:23,680
So whether your team is an outlook or Gmail, one drive or Google drive,
290
00:10:23,680 --> 00:10:25,480
you get the same protection.
291
00:10:25,480 --> 00:10:27,160
One more thing, OAuth app management.
292
00:10:27,200 --> 00:10:31,120
OAuth is the tech that lets third party apps request permission to your data.
293
00:10:31,120 --> 00:10:34,120
You know when you sign into a site with your Google or Microsoft account
294
00:10:34,120 --> 00:10:37,920
and it asks for permission to read your email or access your files, that's OAuth?
295
00:10:37,920 --> 00:10:40,640
Defender can detect when an app asks for too many permissions,
296
00:10:40,640 --> 00:10:44,440
maybe a simple note-taking app wants access to your entire one drive.
297
00:10:44,440 --> 00:10:45,440
That's suspicious.
298
00:10:45,440 --> 00:10:47,640
Defender flags it and lets you revoke those permissions.
299
00:10:47,640 --> 00:10:51,200
So you've got discovery, risk assessment, thread detection and data protection.
300
00:10:51,200 --> 00:10:52,600
But none of this works alone.
301
00:10:52,600 --> 00:10:55,280
Defender for cloud apps fits into a bigger picture.
302
00:10:55,320 --> 00:10:59,440
And understanding how it connects to everything else is where the real power lies.
303
00:10:59,440 --> 00:11:04,280
How it connects to everything else, you might wonder, can Defender for cloud apps work on its own?
304
00:11:04,280 --> 00:11:09,040
Yes, it can, but the real power comes from how it connects to the rest of the Microsoft security world.
305
00:11:09,040 --> 00:11:12,640
Defender for cloud apps is part of the Microsoft Defender XDR suite.
306
00:11:12,640 --> 00:11:17,400
XDR stands for Extended Detection and Response, basically a set of security tools that share information.
307
00:11:17,400 --> 00:11:21,440
Defender for endpoint protects devices, Defender for Office 365 protects email,
308
00:11:21,440 --> 00:11:23,920
Defender for Identity protects user accounts,
309
00:11:23,960 --> 00:11:26,320
and Defender for Cloud Apps protects cloud apps.
310
00:11:26,320 --> 00:11:30,760
Together they form a unified system where each tool feeds data to the others.
311
00:11:30,760 --> 00:11:33,680
Defender for cloud apps shares data with Microsoft Sentinel,
312
00:11:33,680 --> 00:11:37,720
Microsoft's enterprise level seam, security information and event management.
313
00:11:37,720 --> 00:11:40,600
Sentinel collects logs from across your entire organization,
314
00:11:40,600 --> 00:11:43,000
servers, firewalls, applications, everything.
315
00:11:43,000 --> 00:11:46,400
When Defender spots something suspicious, it sends that info to Sentinel.
316
00:11:46,400 --> 00:11:48,600
Sentinel then correlates it with other events.
317
00:11:48,600 --> 00:11:52,280
The same IP that accessed a risky cloud app also tried to log into a server,
318
00:11:52,280 --> 00:11:53,840
Sentinel connects those dots.
319
00:11:53,880 --> 00:11:56,760
Integration with Microsoft, EntraID is just as important.
320
00:11:56,760 --> 00:11:59,720
EntraID manages who your users are and what they can access.
321
00:11:59,720 --> 00:12:02,840
Defender uses that identity info to understand who's doing what.
322
00:12:02,840 --> 00:12:04,440
When it detects a compromised account,
323
00:12:04,440 --> 00:12:07,640
it can tell EntraID to block that user's access immediately,
324
00:12:07,640 --> 00:12:09,600
no waiting for a human to respond.
325
00:12:09,600 --> 00:12:12,960
It also connects to Defender for Endpoint, which runs on company devices.
326
00:12:12,960 --> 00:12:15,280
That's how cloud discovery works in the full version.
327
00:12:15,280 --> 00:12:19,080
Defender for Endpoints sees every website and app a user visits on their work computer
328
00:12:19,080 --> 00:12:22,720
and sends that data to Defender for cloud apps, which builds your discovery dashboard.
329
00:12:22,760 --> 00:12:26,240
Without this connection, you're stuck manually uploading firewall logs
330
00:12:26,240 --> 00:12:28,160
and there's integration with Power Automate,
331
00:12:28,160 --> 00:12:29,840
Microsoft's automation platform.
332
00:12:29,840 --> 00:12:33,200
You can create playbooks, automated response workflows.
333
00:12:33,200 --> 00:12:35,920
When Defender detects a threat, it triggers a Power Automate flow
334
00:12:35,920 --> 00:12:38,000
that sends a notification to a Teams channel,
335
00:12:38,000 --> 00:12:41,040
creates a helpdesk ticket and suspends the user's account
336
00:12:41,040 --> 00:12:42,960
all without anyone lifting a finger.
337
00:12:42,960 --> 00:12:46,760
So once a suspicious event can trigger actions across multiple tools,
338
00:12:46,760 --> 00:12:49,120
an impossible travel detection in Defender for cloud apps
339
00:12:49,120 --> 00:12:50,880
can block the user in EntraID,
340
00:12:50,920 --> 00:12:54,040
alert the security team and Teams and log the incident in Sentinel.
341
00:12:54,040 --> 00:12:56,120
Everything works together.
342
00:12:56,120 --> 00:12:57,760
Now, licenses matter.
343
00:12:57,760 --> 00:13:01,160
With Microsoft 365 Business Premium, you get a limited version.
344
00:13:01,160 --> 00:13:03,520
You can upload firewall logs for cloud discovery
345
00:13:03,520 --> 00:13:06,240
and use the app catalog to check risk scores,
346
00:13:06,240 --> 00:13:09,120
but you don't get automatic integration with Defender for Endpoint
347
00:13:09,120 --> 00:13:10,680
and some advanced features are missing.
348
00:13:10,680 --> 00:13:15,400
For the full version, you need Microsoft 365 e5 or an EMS e5 add-on.
349
00:13:15,400 --> 00:13:19,200
That's where continuous monitoring, real-time session controls and full automation come in.
350
00:13:19,200 --> 00:13:20,320
That's how everything connects.
351
00:13:20,360 --> 00:13:22,480
So what does it take to get started?
352
00:13:22,480 --> 00:13:24,360
Getting started in plain terms.
353
00:13:24,360 --> 00:13:27,960
You don't need to be a security expert to start using Defender for cloud apps.
354
00:13:27,960 --> 00:13:30,760
You can begin without configuring a single policy.
355
00:13:30,760 --> 00:13:32,560
The best approach is to start small.
356
00:13:32,560 --> 00:13:35,200
Learn what you're dealing with, then gradually add controls.
357
00:13:35,200 --> 00:13:38,480
Phase one is visibility, just turn on cloud discovery and see what's out there.
358
00:13:38,480 --> 00:13:42,280
If you have Business Premium, upload your firewall logs and get a snapshot.
359
00:13:42,280 --> 00:13:45,320
If you have e5, enable the Defender for Endpoint integration
360
00:13:45,320 --> 00:13:46,800
and watch the data flow in.
361
00:13:46,800 --> 00:13:48,920
Don't block anything yet, don't sanction anything yet.
362
00:13:48,960 --> 00:13:51,600
Just look, you'll probably be surprised by what you find.
363
00:13:51,600 --> 00:13:53,440
Phase two is policy definition.
364
00:13:53,440 --> 00:13:56,160
Now that you know which apps are in use, decide what to do.
365
00:13:56,160 --> 00:13:59,600
Use the app catalog to check risk scores, sanction the safe ones,
366
00:13:59,600 --> 00:14:02,160
un-sanction the dangerous ones, set the rest to monitored,
367
00:14:02,160 --> 00:14:05,320
then create a few alert policies for the most obvious threats.
368
00:14:05,320 --> 00:14:09,160
Impossible travel, logins from risky countries, mass downloads.
369
00:14:09,160 --> 00:14:10,280
Phase three is enforcement.
370
00:14:10,280 --> 00:14:12,200
This is where you start actively blocking things,
371
00:14:12,200 --> 00:14:16,680
implement session policies that restrict what users can do on unmanaged devices.
372
00:14:16,720 --> 00:14:19,800
Set up automated responses that suspend compromised accounts.
373
00:14:19,800 --> 00:14:23,400
Connect Defender to Power Automate so Alerts Trigger Real Actions.
374
00:14:23,400 --> 00:14:24,880
Phase four is optimization.
375
00:14:24,880 --> 00:14:27,160
Security isn't something you set once and forget.
376
00:14:27,160 --> 00:14:28,840
Review your alerts regularly.
377
00:14:28,840 --> 00:14:31,680
Tune your policies based on what you see.
378
00:14:31,680 --> 00:14:33,880
Get feedback from users who get blocked.
379
00:14:33,880 --> 00:14:36,560
Sometimes legitimate work gets caught by mistake.
380
00:14:36,560 --> 00:14:38,280
Adjust and improve over time.
381
00:14:38,280 --> 00:14:41,920
If you're not sure where to start, just look at the cloud discovery dashboard.
382
00:14:41,920 --> 00:14:44,160
Even a single snapshot from your firewall logs
383
00:14:44,160 --> 00:14:46,400
will show you apps you didn't know existed.
384
00:14:46,440 --> 00:14:47,640
That alone is worth the effort.
385
00:14:47,640 --> 00:14:49,560
The biggest risk isn't the apps you know about.
386
00:14:49,560 --> 00:14:50,640
It's the ones you don't.
387
00:14:50,640 --> 00:14:53,320
Defender for Cloud Apps turns those blind spots into something
388
00:14:53,320 --> 00:14:55,160
you can actually see and manage.
389
00:14:55,160 --> 00:14:57,200
So here's what Defender for Cloud Apps gives you.
390
00:14:57,200 --> 00:14:58,240
Four things.
391
00:14:58,240 --> 00:15:01,160
Visibility into every cloud app your employees use.
392
00:15:01,160 --> 00:15:03,720
Risk assessment to tell you which ones are safe.
393
00:15:03,720 --> 00:15:06,560
Threat detection that spots suspicious behavior automatically
394
00:15:06,560 --> 00:15:09,720
and data protection that keeps your sensitive files from leaking out.
395
00:15:09,720 --> 00:15:11,760
The real value isn't any single feature.
396
00:15:11,760 --> 00:15:14,640
It's that the tool turns blind spots into manageable risks.
397
00:15:14,680 --> 00:15:17,160
You go from not knowing what's happening to having a complete picture
398
00:15:17,160 --> 00:15:19,040
you can actually act on. Here's your challenge.
399
00:15:19,040 --> 00:15:22,240
If you have access to Microsoft 365, open the Defender portal
400
00:15:22,240 --> 00:15:24,040
and check your own cloud discovery report.
401
00:15:24,040 --> 00:15:26,440
Even if it's empty, you'll understand what's possible.
402
00:15:26,440 --> 00:15:28,160
And if you find something unexpected,
403
00:15:28,160 --> 00:15:30,080
you'll see exactly why this tool matters.
404
00:15:30,080 --> 00:15:33,640
In our next episode, we'll look at how to create your first security policy,
405
00:15:33,640 --> 00:15:36,200
the practical steps to start protecting your environment.
406
00:15:36,200 --> 00:15:38,480
Subscribe on your favorite podcast platform
407
00:15:38,480 --> 00:15:41,680
and share this with someone who's trying to make sense of cloud security.
Founder of m365.fm, m365.show and m365con.net
Mirko Peters is a Microsoft 365 expert, content creator, and founder of m365.fm, a platform dedicated to sharing practical insights on modern workplace technologies. His work focuses on Microsoft 365 governance, security, collaboration, and real-world implementation strategies.
Through his podcast and written content, Mirko provides hands-on guidance for IT professionals, architects, and business leaders navigating the complexities of Microsoft 365. He is known for translating complex topics into clear, actionable advice, often highlighting common mistakes and overlooked risks in real-world environments.
With a strong emphasis on community contribution and knowledge sharing, Mirko is actively building a platform that connects experts, shares experiences, and helps organizations get the most out of their Microsoft 365 investments.