Microsoft Defender for Cloud Apps
Cloud and workloads

Anomaly detection policies in Microsoft Defender for Cloud Apps

In brief

The documentation now explains the heuristic and machine-learning baselines, clarifies the seven-day learning period and dynamic threat detection model, updates navigation and terminology, and lists activity by terminated users as a detection.

What Defender admins need to know

Administrators can use the revised guidance to configure, tune, and investigate anomaly detection policies. No action is specified.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Create Defender for Cloud Apps anomaly detection policies

The Microsoft Defender for Cloud Apps anomaly detection policies provide out-of-the-boxbuilt-in user and entity behavioral analytics (UEBA) and machine learning (ML) so that. These policies help you're ready from the outset to run advanced threat detection across your cloud environment.environment right away. Because they're automatically enabled, the new anomaly detection policies immediatelyare turned on by default, they start the process of detecting and collating results,collecting results at once, targeting numerous behavioral anomalies across your usersusers, machines, and the machines and devices connected to your network. In addition, thedevices. The policies also expose more data from the Defender for Cloud Apps detection engine,engine to help you speed up the investigation processinvestigations and contain ongoing threats.

The anomaly detection policies are automatically enabled, but Defender for Cloud Apps has an initial learning period of seven days during which not all anomaly detection alerts are raised. After the initial seven-day learning period,that, as data is collected from your configured API connectors, each session is compared to activity detected over the activity,past month, including when users were active, IP addresses, devices, and so on, detected over the past month and the risk scorescores of these activities. Be aware that it mayData from API connectors might take several hours for data to be available from API connectors. The anomalybecome available.

These detections generated from this analysis are part of the heuristic anomaly detection engine that profiles your environment and triggers alerts with respect tobased on a baseline that was learned onfrom your organization's activity. The anomaly detections also use machine-learning algorithms designed to profile the users and their sign-in patternpatterns to reduce false positives.

Anomalies are detected by scanning user activity. The risk is evaluated by looking at over 30 different risk indicators, grouped into risk factors, as follows:

Based on the policy results, security alerts are triggered. Defender for Cloud Apps looks at every user session on your cloud and alerts you when something happens that is different from the baseline of your organization or from the user's regular activity.

Anomaly detection policies

You can see the anomaly detection policies in the Microsoft Defender Portal,portal by going to Cloud Apps -> Policies -> Policy management. Then choose Anomaly detection policy for the policy type.

:::image type="content" source="media/new-anomaly-detection-policies.png" alt-text="Screenshot showing how to filter anomaly detection policies." lightbox="media/new-anomaly-detection-policies.png":::

The following anomaly detection policies are available:

Impossible travel anomaly detection policy

The Impossible travelThis detection identifies two user activities (in a single or multiple sessions) originating from geographically distant locations within a time period shorter than the time it would have taken the user to travel from the first location to the second, indicating that a different user is using the same credentials. The Impossible travelThis detection uses a machine-learning algorithm that ignores obvious "false positives" contributing to the impossible travel condition, such as VPNs and locations regularly used by other users in the organization. The detection has an initial learning period of seven days during which it learns a new user's activity pattern. The impossible travel detection identifies unusual and impossible user activity between two locations. The activity should be unusual enough to be considered an indicator of compromise and worthy of an alert. To make impossible travel detection work accurately,this work, the detection logic includes different levels of suppression to address scenarios that can trigger false positive,positives, such as VPN activities,activities or activity from cloud providers that don't indicate a physical location. The sensitivity slider allows you to affect the algorithm and define how strict the detection logic is. The higher the sensitivity level, the fewer activities will beare suppressed as part of the detection logic. By adjusting the sensitivity slider,In this way, you can adapt the detection according to your coverage needs and your SNR targets.

Activity from infrequent country detection policycountry/region

The Activity from infrequent countryThis detection considers past activity locations to determine new and infrequent locations. The anomaly detection engine stores information about previous locations used by the user. An alert is triggered when an activity occurs from a location that wasn't recently or never visited by the user. To reduce false positive alerts, the detection suppresses connections that are characterized by common preferences to the user.

Malware detection policy

The MalwareThis detection policy identifies malicious files in your cloud storage, whether they're from your Microsoft apps or third-party apps. Microsoft Defender for Cloud Apps uses Microsoft's threat intelligence to recognize whether certain files that match risks heuristics such as file type and sharing level are associated with known malware attacks and are potentially malicious. This built-in policy is disabled by default. After malicious files are detected, you can then see a list of Infected files. Select the malware file name in the file drawer to open a malware report that provides you with information about the type of malware the file is infected with.

Use the malwarethis detection policy with session policies to control file uploads and downloads in real time.time with session policies.

File Sandboxingsandboxing

By enabling file sandboxing, files that are potentially risky according to their metadata and based on proprietary heuristics to be potentially risky, willare also be sandbox scanned in a safe sandbox environment. The Sandboxsandbox scan maymight detect files that were notweren't detected based on threat intelligence sources.

Defender for Cloud Apps supports "File Sandboxing"file sandboxing malware detection for the following apps:

  • Box
  • Dropbox

Activity from anonymous IP addresses policy

This detection identifies that users were active from an IP address that has been identified as an anonymous proxy IP address. These proxies are used by people who want to hide their device's IP address, and may be used for malicious intent. This detection uses a machine-learning algorithm that reduces "false positives", such as mis-tagged IP addresses that are widely used by users in the organization.

Ransomware activity detection policy

Defender for Cloud Apps extended its ransomware detection capabilities with anomaly detection to ensure more comprehensive coverage against sophisticated ransomware attacks. Using our security research expertise to identify behavioral patterns that reflect ransomware activity, Defender for Cloud Apps ensures holistic and robust protection. For example, a high rate of file uploads or file deletion activities might represent an adverse encryption process. This data is collected in logs received from connected APIs and then combined with learned behavioral patterns and threat intelligence, such as known ransomware extensions. For more information about how Defender for Cloud Apps detects ransomware, see Protecting your organization against ransomware.

Activity performed by terminated user policy

The Activity performed by terminated user detection enables you to identify when a terminated employee continues to perform actions on your SaaS apps. Because data shows that the greatest risk of insider threat comes from employees who left on bad terms, it's important to keep an eye on the activity on accounts from terminated employees. Sometimes, when employees leave a company, their accounts are de-provisioned from corporate apps, but in many cases they still retain access to certain corporate resources. This is even more important when considering privileged accounts, as the potential damage a former admin can do is inherently greater. This detection takes advantage of the Defender for Cloud Apps ability to monitor user behavior across apps, allowing identification of the regular activity of the user, the fact that the account was deleted, and actual activity on other apps. For example, an employee whose Microsoft Entra account was deleted, but still has access to the corporate AWS infrastructure, has the potential to cause large-scale damage.

The detection looks for users whose accounts were deleted in Microsoft Entra ID, but still perform activities in other platforms such as AWS or Salesforce. This is especially relevant for users who use another account (not their primary single sign-on account) to manage resources, since these accounts are often not deleted when a user leaves the company.

This detection enables you to identify when a terminated employee continues to perform actions on your SaaS apps. Because data shows that the greatest risk of insider threat comes from employees who left on bad terms, it's important to keep an eye on the activity on accounts from terminated employees. Sometimes, when employees leave a company, their accounts are deprovisioned from corporate apps, but in many cases they still retain access to certain corporate resources. This is even more important when considering privileged accounts, as the potential damage a former admin can do is inherently greater. This detection takes advantage of the Defender for Cloud Apps ability to monitor user behavior throughout apps, allowing identification of the regular activity of the user, the fact that the account was deleted, and actual activity on other apps. For example, an employee whose Microsoft Entra account was deleted, but still has access to the corporate AWS infrastructure, has the potential to cause large-scale damage.

The detection looks for users whose accounts were deleted in Microsoft Entra ID, but still perform activities in other platforms such as AWS or Salesforce. This is especially relevant for users who use another account (not their primary single sign-on account) to manage resources, since these accounts are often not deleted when a user leaves the company.

Activity from suspicious IP addresses policy

The Activity from suspicious IP addresses detection identifies that users were active from an IP address identified as risky by Microsoft Threat Intelligence. These IP addresses are involved in malicious activities, such as performing password spray, Botnet C&C, and may indicate compromised account. The detection uses a machine-learning algorithm that reduces "false positives", such as mis-tagged IP addresses that are widely used by users in the organization.

Suspicious inbox forwarding policy

The Suspicious inbox forwarding detection looks for suspicious email forwarding rules, for example, if a user created an inbox rule that forwards a copy of all emails to an external address.

Suspicious inbox manipulation rules policy

The Suspicious inbox manipulation rules detection profiles your environment and triggers alerts when suspicious rules that delete or move messages or folders are set on a user's inbox. This may indicate that the user's account is compromised, that messages are being intentionally hidden, and that the mailbox is being used to distribute spam or malware in your organization.

Suspicious email deletion activity policy (Preview)

The Suspicious email deletion activity policy profiles your environment and triggers alerts when a user performs suspicious email deletion activities in a single session. An alert from this policy may indicate that a user's mailboxes are compromised by potential attack vectors such as command-and-control communication (C&C/C2) over email.

Suspicious OAuth app file download activities policy

Scans the OAuth apps connected to your environment and triggers an alert when an app downloads multiple files from Microsoft SharePoint or Microsoft OneDrive in a manner that is unusual for the user. This unusual download behavior may indicate that the user account is compromised.

Unusual ISP for an OAuth app policy

The Unusual ISP for an OAuth app policy profiles your environment and triggers alerts when an OAuth app connects to your cloud applications from an uncommon ISP. An alert from this policy may indicate that an attacker tried to use a legitimate compromised app to perform malicious activities on your cloud applications.

Unusual activities by user policy(by user)

These detections identify users who perform:

These policies look for activities within a single session relative to the learned baseline, which could indicate a breach attempt. These detections use a machine-learning algorithm that profiles users' sign-in patterns and reduces false positives. The detections are part of the heuristic anomaly detection engine that profiles your environment and triggers alerts based on a baseline learned from your organization's activity.

Multiple failed login attempts policy

This detection identifies users thatwho failed multiple login attempts in a single session with respectrelative to the baseline learned,learned baseline, which could indicate on a breach attempt.

Multiple virtual machine deletiondelete VM activities policy

This policy profiles your environment and triggers alerts when users delete multiple VMs in a single session, relative to the baseline in your organization. This might indicate an attempted breach.

Enable automated governance

You can enable automated remediation actions onset up automatic fixes for alerts generated byfrom anomaly detection policies.

  1. SelectOn the name ofPolicies page, select the detection policy in the Policies page.name.
  2. In the Edit anomaly detection policy window that opens,window, under Governance actions set, choose the remediation actions you want for each connected app or for all apps.
  3. Select Update.

Tune anomaly detection policies

To affectYou can tune the anomaly detection engine to suppress or surfaceshow alerts according tobased on your preferences:needs.

In the Impossible Traveltravel policy, you can set the sensitivity slider to determine the level of anomalous behavior needed before an alert is triggered. For example, if you set it toa low or medium, it will suppressmedium setting suppresses Impossible Traveltravel alerts from a user's common locations, and if you set it to high, it will surfacewhile a high setting surfaces such alerts. You can choose from the following sensitivity levels:

  • Low: System, tenant, and user suppressions
  • Medium: System and user suppressions
  • High: Only system suppressions

Where:

Scope anomaly detection policies

Each anomaly detection policy can be independently scoped so that it applies only to the users and groups you want to include and exclude in the policy. For example, you can set the Activity from infrequent countycountry/region detection to ignore a specific user who travels frequently.

To scope an anomaly detection policy:

  1. In the Microsoft Defender Portal,portal, go to Cloud Apps -> Policies -> Policy management. Then choose Anomaly detection policy for the policy type.

  2. Select the policy you want to scope.

  3. Under Scope, change the drop-down from the default setting of All users and groups, to Specific users and groups.

  4. Select Include to specify the users and groups for whoto which this policy will apply.applies. Any user or group not selected here won't be considered a threat and won't generate an alert.

  5. Select Exclude to specify users for whoto which this policy wondoesn't apply. Any user selected here won't be considered a threat and won't generate an alert, even if they're members of groups selected under Include.

    :::image type="content" source="media/anomaly-detection-scoping.png" alt-text="Screenshot that shows how to add scoped access to your anomaly detection policy.":::

Triage anomaly detection alerts

You can triage the various alerts triggered by the new anomaly detection policies quickly and decide which ones need to be taken care of first. To do this,prioritize alerts effectively, you need the context for theeach alert, so you can see the bigger picture and understand whether something malicious is indeed happening.

  1. In the Activity log, you can open an activity to display the Activity drawer. Select User to view the user insights tab. This tab includes information like number of alerts, activities, and where they've connected from, which is important in an investigation.

    :::image type="content" source="media/anomaly-alert-user1.png" alt-text="Screenshot that shows the activity log with the number of anomaly detection alerts." lightbox="media/anomaly-alert-user1.png" :::

  2. For malware malware-infected files, Afterafter files are detected, you can then see a list of Infected files. Select the malware file name in the file drawer to open a malware report that provides you with information about that type ofthe malware the file is infected with.type.

Next steps