Microsoft Defender for Cloud Apps
Cloud and workloads

Cloud discovery data anonymization

In brief

The page date and authoring metadata were updated. Wording now identifies Defender for Cloud Apps as generating reports from anonymized data and states that each username resolution action is recorded in the portal’s Audit log.

What Defender admins need to know

Administrators can more clearly understand the reporting process and verify that every username resolution action is audited.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


title: Cloud discovery data anonymization description: This article provides information about how to protect user privacy by anonymizing the usernames in your cloud discovery data. ms.date: 06/16/07/03/2026 ms.topic: how-to ms.reviewer: Mravela ms.custom:

  • msecd-doc-authoring-10141016
  • sfi-ga-blocked
  • sfi-image-nochange ai-usage: ai-assisted
  1. When anonymization is selected, Defender for Cloud Apps parses the traffic log and extracts specific data attributes.

  2. Defender for Cloud Apps replaces the username with an encrypted username.

  3. ItDefender for Cloud Apps then analyzes cloud usage data and generates cloud discovery reports based on the anonymized data.

    Screenshot of the cloud discovery dashboard displaying anonymized usage data.

     ![Screenshot of the resolve dialog prompting for justification before deanonymizing multiple users.](media/anonymize-resolve-dialog.png)
    
  4. TheEach username resolution action is audited in the portal's Audit log.