Study guide
Technical reference and lesson notes
Purpose of This Lesson
Microsoft Defender for Cloud Apps helps security teams discover, monitor, govern, and remediate cloud application use. Its primary SOC value is gaining visibility into sanctioned and unsanctioned applications, reducing shadow IT, and applying controls to cloud sessions and sensitive data.
The product was previously called Microsoft Cloud App Security. Older documentation, exam materials, and operational runbooks may still use that name.
Key Concepts
Cloud access security broker capabilities
Defender for Cloud Apps provides cloud access security broker (CASB) capabilities as a cloud service rather than as a hardware appliance inserted into the network. It can receive activity information from endpoints, firewalls, proxies, and connected cloud applications.
Its capabilities include:
- Discovering cloud applications that users access.
- Assessing application risk and identifying unsanctioned services.
- Monitoring user activity and cloud data movement.
- Generating alerts and reports for policy violations or anomalous activity.
- Applying session controls to selected cloud applications.
- Supporting compliance and sensitive-data governance.
- Providing remediation actions through policies and connected services.
Cloud Discovery
Cloud Discovery identifies the applications being used in the organization by analyzing traffic or activity logs. This helps answer questions such as:
- Which SaaS applications are employees using?
- Are users storing corporate files in services that have not been approved?
- Which applications present unacceptable security or compliance risk?
- Is application use different for office users, remote users, and mobile users?
Discovery is especially important for finding shadow IT: cloud services adopted by users without formal approval from IT or security.
Discovery data can come from supported firewalls and proxies, endpoint-related activity, and imported log files. For older or unsupported network devices, an organization may need to export and transform logs before importing them.
App connectors
An app connector establishes an API-based connection between Defender for Cloud Apps and a supported cloud application. Connectors allow the service to obtain information from, and in some cases perform governance actions in, applications such as approved business SaaS platforms.
For example, an organization might connect a business file-sharing service so that security teams can monitor activity and apply governance to corporate accounts. An app connector is different from Cloud Discovery: discovery identifies applications in use, while a connector integrates with a specific application for deeper visibility or control.
Conditional Access App Control
Conditional Access App Control applies session-level controls to cloud applications. It can be used when the organization needs to monitor or restrict activities such as:
- Downloading a sensitive file.
- Uploading information to an unapproved destination.
- Sharing a document externally.
- Using a personal account instead of the organization’s managed account.
This capability can operate through a reverse-proxy session path. The user may still access the application, but selected activities can be monitored or blocked according to policy. The exact behavior depends on the application, identity configuration, session policy, and integration in use.
Policies and remediation
Defender for Cloud Apps policies can detect risky behavior, suspicious activity, policy violations, and sensitive-data handling. Depending on the policy and integration, a response may include an alert, report, notification, or remediation action.
A useful policy design separates:
- Detection: What behavior or data condition should be identified?
- Scope: Which users, applications, devices, and locations are affected?
- Action: Should the system alert, block, restrict, notify, or remediate?
- Evidence: What activity, file, identity, or application details must be retained for investigation?
Microsoft Security Operations Context
Defender for Cloud Apps is most useful when treated as part of a wider Microsoft security workflow rather than as an isolated product.
- Microsoft Defender XDR: Relevant alerts and incidents may be correlated with identity, endpoint, email, and other Microsoft security signals.
- Microsoft Entra ID: Identity and access conditions help distinguish managed business access from personal or unmanaged account use.
- Microsoft Purview capabilities: Sensitivity labels, classification, and compliance controls provide context for determining whether a file or activity is sensitive.
- Firewalls and proxies: Network telemetry can feed Cloud Discovery, including traffic from devices that are not directly managed by Microsoft security products.
- SOC operations: Analysts use discovered application activity to validate policy violations, investigate possible data exposure, and coordinate remediation with IT, identity, privacy, and compliance teams.
The product can monitor users working from office networks as well as users operating away from on-premises firewalls and proxies, provided the relevant endpoint, identity, application, or session integration is configured.
Exam-Relevant Takeaways
- Defender for Cloud Apps is the current name for the product formerly known as Cloud App Security.
- It provides CASB capabilities without requiring a physical CASB appliance.
- Cloud Discovery identifies cloud applications in use and supports shadow-IT investigations.
- App connectors integrate Defender for Cloud Apps with specific cloud applications for deeper visibility and governance.
- Conditional Access App Control is used for session-based monitoring and control of cloud application activities.
- Policies can detect risky behavior, violations, suspicious activity, and sensitive-data handling.
- Firewalls and proxies can provide discovery logs; unsupported devices may require exported and imported logs.
- Application governance should distinguish sanctioned applications from unsanctioned applications.
- Sensitive-data controls work with classification, sensitivity labels, and Microsoft 365 compliance capabilities.
- A policy can generate an alert or initiate remediation; detection and prevention are not the same design choice.
Tool / Feature Decision Guide
| Requirement | Best-fit capability | Why |
|---|---|---|
| Determine which SaaS applications employees are using | Cloud Discovery | Analyzes activity or network logs to identify applications and usage patterns |
| Integrate a known business application for deeper management | App connector | Creates an application-specific integration for visibility and governance |
| Monitor or restrict actions during a cloud session | Conditional Access App Control | Applies session controls such as blocking or restricting selected activities |
| Prevent or identify use of unapproved cloud storage | Cloud Discovery plus policy controls | Discovery establishes the facts; policies can alert or restrict activity when configured |
| Protect a sensitive document from external sharing | Data-aware policy and session control | Uses sensitivity or classification context to enforce an appropriate action |
| Ingest visibility from a network appliance | Supported firewall or proxy integration | Sends activity logs to the service for discovery and analysis |
| Work with an unsupported legacy appliance | Log export/import or a compatible custom process | Preserves discovery value when direct integration is unavailable |
Common Exam Traps
- Cloud Discovery is not the same as an app connector. Discovery finds applications from activity data; a connector integrates with a particular application.
- A CASB does not have to be a physical network appliance. Defender for Cloud Apps is a cloud service that can receive data from multiple sources.
- Visibility does not automatically mean prevention. Discovering personal Dropbox use does not by itself block it; an appropriate identity, session, or application policy must be configured.
- Conditional Access App Control is about session activity. It is the relevant choice when the requirement is to monitor or restrict what a user does inside a cloud application.
- Sanctioned and unsanctioned are governance classifications. They describe whether an application is approved for organizational use, not whether the application is inherently malicious.
- Compliance context is not a replacement for investigation. A sensitive-data alert still requires validation of the user, file, destination, business justification, and actual exposure.
- Imported logs may provide less immediate control than a supported integration. Log ingestion can improve visibility, but it may not provide the same real-time enforcement capabilities as a configured session or application integration.
Real-World SOC Analyst Notes
Triage shadow-IT findings carefully
An unsanctioned application is not automatically a security incident. Confirm what data was accessed, whether the account is corporate or personal, whether data was uploaded or shared, and whether the service is prohibited or merely not yet reviewed.
Preserve evidence before remediation
Before blocking access, revoking sharing, or removing content, capture the relevant alert, user, application, file, timestamp, destination, policy, and available activity details. Coordinate with legal, privacy, compliance, and business owners when the data may be regulated.
Use graduated controls
A mature rollout often begins with discovery and alert-only policies. After false positives and business requirements are understood, the organization can introduce restrictions for high-confidence cases. Broad blocking can disrupt legitimate work and encourage users to find less visible workarounds.
Review policy scope and permissions
Session controls and remediation can affect an entire user population or application. Validate pilot groups, exclusions, service accounts, administrative roles, and change-control approval before enabling a tenant-wide action.
Treat application risk as contextual
An application’s risk score or classification is an input to triage, not the final verdict. Consider the application’s data handling, authentication model, contractual status, regulatory impact, user population, and observed behavior.
Coordinate ownership
The SOC may identify the activity, but remediation may belong to identity, endpoint, network, application, compliance, or data-governance teams. Document the handoff and the expected validation step after the control is applied.
Quick Reference Summary
- Defender for Cloud Apps is Microsoft’s CASB-oriented service for cloud application visibility and control.
- The former product name was Microsoft Cloud App Security.
- Cloud Discovery maps application use from activity and network logs.
- App connectors provide deeper integration with selected cloud applications.
- Conditional Access App Control governs activities within cloud sessions.
- Policies can detect, alert, restrict, and remediate depending on configuration and integration.
- Use sensitivity and classification context when evaluating data movement.
- Use discovery to understand the problem before selecting a blocking or remediation strategy.
Flashcards
Q: An organization wants to identify every SaaS application employees use, including services that IT never approved. Which Defender for Cloud Apps capability should be evaluated first?
A: Cloud Discovery. It analyzes activity or network logs to identify applications, usage, and potential shadow IT.
Q: When should an app connector be chosen instead of relying only on Cloud Discovery?
A: Use an app connector when a known cloud application requires deeper, application-specific visibility or governance. Discovery identifies use; the connector integrates with the selected application.
Q: What is the current product name for Microsoft Cloud App Security?
A: Microsoft Defender for Cloud Apps. Older documentation may still use the former name, Cloud App Security.
Q: A policy must restrict external sharing of a document containing sensitive information during a user’s cloud session. Which capability is most relevant?
A: Conditional Access App Control, combined with data sensitivity or classification context and an appropriate policy action. It is designed for monitoring or controlling activities within cloud application sessions.
Q: Does finding an unsanctioned application automatically block the application?
A: No. Discovery provides visibility and risk information. Blocking or restricting use requires a separately configured policy and an applicable identity, application, or session control.
Q: What is the key distinction between a sanctioned and an unsanctioned application?
A: A sanctioned application is approved for organizational use; an unsanctioned application is not approved or is outside the organization’s governance standard. Unsanctioned does not automatically mean malicious.
Q: How can firewall and proxy systems contribute to Defender for Cloud Apps?
A: Supported devices can send activity logs for Cloud Discovery. Older or unsupported devices may require log export and import instead of a direct integration.
Q: What is a major limitation of relying on imported logs from an unsupported device?
A: Imported logs can provide visibility, but they may not provide the same immediacy or enforcement capabilities as a supported integration or session-control deployment.
Q: Which capability is most directly associated with reducing shadow IT?
A: Cloud Discovery, followed by governance policies that classify, alert on, or restrict discovered applications and activities.
Q: Why should a SOC analyst preserve evidence before applying remediation to a cloud activity?
A: Remediation may change or remove the original state. Recording the alert, user, application, file, timestamps, destination, and policy supports investigation, escalation, and compliance review.
Q: What does Conditional Access App Control primarily govern?
A: It governs selected actions within a cloud application session, such as downloading, uploading, or sharing data, when the required integrations and policies are configured.
Q: A discovery alert reports that a user accessed personal and business versions of a storage service. What should the analyst validate first?
A: Validate the account type, data accessed or transferred, policy applicability, and whether the personal service is prohibited. Do not assume that access alone proves data loss.
Q: Why should sensitive-data policies be tested with a pilot group before broad enforcement?
A: Classification and activity signals can produce false positives, and tenant-wide restrictions can disrupt legitimate work. A pilot helps tune scope, exclusions, and actions safely.
Practice Questions
Question 1
A security team wants to learn which cloud applications employees are using before deciding which services to approve or block. Which capability should they use?
A. App connectors only
B. Cloud Discovery
C. Conditional Access App Control only
D. Sensitivity labels only
Correct answer: B. Cloud Discovery
Cloud Discovery is designed to identify applications and usage from activity or network logs. App connectors and session controls are useful after the organization understands which applications require deeper integration or enforcement.
Question 2
An organization has approved business OneDrive accounts but wants to prevent users from transferring corporate documents through personal cloud-storage accounts. Which approach best matches the requirement?
A. Use Cloud Discovery only and assume detection blocks access
B. Configure suitable identity and session/application policies, using Conditional Access App Control where supported
C. Create an app connector for every website discovered
D. Disable all cloud applications for every user
Correct answer: B. Configure suitable identity and session/application policies, using Conditional Access App Control where supported
Discovery can reveal the behavior, but prevention requires an enforcement policy and the appropriate integration. A blanket shutdown is excessive and does not represent a precise SOC response.
Question 3
A firewall is not directly supported for Defender for Cloud Apps integration, but the SOC still needs application-usage visibility. What is the most appropriate next step?
A. Abandon Cloud Discovery entirely
B. Export the firewall logs and import them using a compatible process
C. Replace the firewall immediately without validating requirements
D. Use sensitivity labels as a substitute for network telemetry
Correct answer: B. Export the firewall logs and import them using a compatible process
The lesson identifies log export and import as an option for older or unsupported devices. The SOC should also recognize that this may provide less immediate control than a supported integration.
Question 4
A policy identifies that a sensitive document was shared externally through an approved SaaS application. What should the analyst do first?
A. Treat the application as malicious and block it for everyone
B. Delete the document immediately without preserving evidence
C. Validate the user, document sensitivity, sharing destination, business context, and policy details
D. Ignore the alert because the application is sanctioned
Correct answer: C. Validate the user, document sensitivity, sharing destination, business context, and policy details
A sanctioned application can still be misused, and a sensitive-data alert requires contextual investigation. Preserve evidence and coordinate remediation according to the organization’s data and compliance procedures.
Question 5
Which statement best compares Cloud Discovery with an app connector?
A. Cloud Discovery controls sessions, while an app connector only collects firewall logs
B. Cloud Discovery identifies applications in use, while an app connector provides deeper integration with a selected application
C. Both capabilities are identical names for the same feature
D. An app connector is required before any cloud application can be discovered
Correct answer: B. Cloud Discovery identifies applications in use, while an app connector provides deeper integration with a selected application
This distinction is a common exam decision point: discovery maps the environment, while connectors support application-specific visibility and governance.