In this article, we will explore Microsoft Defender for Cloud Apps, focusing on its initial setup, baseline configuration, and key requirements.

Introduction

Microsoft Defender for Cloud Apps is implemented as a Cloud Access Security Broker (CASB), providing visibility into user and application activity within Microsoft 365. It enables the detection of suspicious behaviour, supports investigation of potential security incidents, and facilitates the application of remediation controls where required.

Defender for Cloud Apps Portal

Microsoft Defender for Cloud Apps is available inside the Microsoft Defender portal https://security.microsoft.com

Figure 1 Cloud Apps in Microsoft Defender Portal

Data Collection by Defender for Cloud Apps

Microsoft Defender for Cloud Apps gathers data from the configured cloud applications and data sources. This collection includes:

  • Network data
  • OAuth app configuration and usage
  • Audits on cloud app usage by users and other apps
  • File metadata and content
  • System settings and policies
  • User and group configurations

Data Storage Location

Defender for Cloud Apps operates in the Microsoft Azure data centers in the following geographical regions:

Customer provisioning locationData storage location
Customers whose tenants are provisioned in the United StatesUnited States
Customers whose tenants are provisioned in the European Union or the United KingdomThe European Union or the United Kingdom, depending on service availability.
Customers whose tenants are provisioned in any other regionThe United States and/or a data center in the region that’s nearest to the location of where the customer’s Microsoft Entra tenant has been provisioned.

Table 1 Data Storage Location

Find the Location

Defender for Cloud Apps tenant location in the Microsoft Defender portal can be found in Settings > Cloud Apps > About > Region

Figure 2 Data Location

Data Retention

Data from Microsoft Defender for Cloud Apps is retained for up to 180 days, and is visible across the portal.

Data Sharing

Defender for Cloud Apps shares data, including customer data, with other Microsoft products that the customer has licensed.

  • Microsoft Defender
  • Microsoft Defender for Cloud
  • Microsoft Sentinel
  • Microsoft Defender for Endpoint
  • Microsoft Security Exposure Management
  • Microsoft Purview
  • Microsoft Entra ID Protection

Network Requirements

List of URLs and IP addresses that are required for Microsoft Defender for Cloud Apps can be found at https://learn.microsoft.com/en-us/defender-cloud-apps/network-requirements

Required Role to complete the Setup

To configure Defender for Cloud Apps, you need to have at least Security Administrator rights in Microsoft Entra ID or Microsoft 365.

Dependency: Entra ID Applications

Microsoft Defender for Cloud Apps relies on specific Microsoft Entra ID applications to operate correctly. Do not disable these applications within Microsoft Entra ID.

  • Microsoft Defender for Cloud Apps – APIs (or API Connectors (1st Party)) (ID: 972bb84a-1d27-4bd3-8306-6b8e57679e8c)
  • Microsoft Defender for Cloud Apps – Customer Experience (ID: ac6dbf5e-1087-4434-beb2-0ebf7bd1b883)
  • Microsoft Defender for Cloud Apps – Information Protection (ID: 9ba4f733-be8f-4112-9c4a-e3b417c44e7d)
  • Microsoft Defender for Cloud Apps – MIP Server (ID: 0858ddce-8fca-4479-929b-4504feeed95e)
  • Microsoft Defender for Cloud Apps – Data Loss Prevention – SPO (ID: 71559765-2fa9-4207-b59f-a8bd85269d4a)

Defender for Cloud Apps environment Setup

Setting up Microsoft Defender for Cloud Apps is simple and friendly! You start by entering your organisation and environment details. Then, you can define your managed domains to easily track your internal users. If you’d like, you can also include your company logo to personalise your setup—making it feel even more like your own space.

Figure 3 Defender for Cloud Apps environment Details

Notifications

Templates and Sender

Defender for Cloud Apps notifications are sent by a pre-configured email ID, no-reply@cloudappsecurity.com

Microsoft deprecated the custom email settings feature.

Figure 4 Cloud Apps Email settings

Admin Notifications

Admin notifications specific to Defender for Cloud Apps can be set up in the Microsoft Defender portal under the Microsoft Defender XDR Email notifications section. Presently, the notifications area includes three types: Incidents, Actions, and Threat Analytics.

Figure 5 XDR Email Notifications

Figure 6 Incident Notifications Settings

Figure 7 Actions Notifications Settings

Connect Apps

To enable instant visibility, protection, and governance for the necessary applications, they must be linked with Defender for Cloud Apps via App Connectors. Once you establish a connection with an application, you will gain enhanced visibility, enabling you to investigate activities, files, and accounts associated with the applications within your cloud environment.

Figure 8 App Connectors for Cloud Apps

File Monitoring

Enabling file monitoring in Microsoft Defender for Cloud Apps allows the platform to scan, classify, and protect sensitive files stored in connected cloud services (such as SharePoint, OneDrive, or Google Drive). Its main goal is to enforce data loss prevention (DLP), identify risks of external or public data sharing, and detect compliance issues or malware within cloud files.

To enable protection for Microsoft 365 files, you must enable Defender for Cloud Apps file monitoring.

Figure 8 Enable File Monitoring

In the next blog, we will see some example sessions and Access Control policies.

Leave a comment

The Author

My name is Meyyalazhan Venkatachalam, and I have over 20 years of experience in IT. I currently work as a Technical Architect. My areas of specialization include Intune, SCCM, M365 Security, PKI, Entra/Azure, and related technologies.