Microsoft Defender for Cloud Apps
Cloud and workloads

Configure activity monitoring to protect user privacy

In brief

The article now provides expanded guidance for configuring privacy groups, granting admins permission to view private activities, and viewing those activities in the activity log. Wording, headings, image descriptions, anchors, and audit-log explanations were also refined.

What Defender admins need to know

Administrators have clearer instructions for managing private activities and understanding that viewing them is audited and recorded in the governance log.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Configure activity monitoring to protect user privacy

Learn how to configure activity privacy in Microsoft Defender for Cloud Apps to monitor users while complying with your organization's privacy regulations. This article covers how to set up privacy user groups, assign admin permissions to view private activities, and view those activities in the activity log.

Activity privacy overview

Microsoft Defender for Cloud Apps allows enterprises to granularly determine which users they want to monitor based on group membership. Activity privacy will enable you to follow your organization's compliance regulations without compromising user privacy. Activity privacy is achieved by allowing you to monitor users while maintaining their privacy by hiding their activities in the activity log. Only authorized admins can choose to view these private activities, with each instance being audited in the governance log.

Configure activity privacy user groups

You may have users in Defender for Cloud Apps that you want to monitor, but, due to compliance regulations, you need to limit the people who can do so. Activity privacy lets you define a user group for which the activities performed by members of that group will be hidden by default.

To configure your user privacy groups, you must first import user groups to Defender for Cloud Apps. By default, you'll see the following groups:

  1. In the Add user groups dialog, under Select user groups, select all the groups you want to make private in Defender for Cloud Apps, then select Add.

    Screenshot of the Add user groups dialog for selecting groups to make private in Defender for Cloud Apps.

Assign admins permission to view private activities

To grant specific admins permission to view private activities, follow these steps:

  1. In the Microsoft Defender Portal, in the left-hand menu, select Permissions.

  2. Under Cloud Apps, choose Activity Privacy Permissions.

  3. In the Add admin permission dialog, enter the admin's UPN or email address and select Add permission.

    Screenshot of the dialog for granting admins permission to view private activities.

\ No newline at end

View private activities

Once an admin has been granted the appropriate permission to view private activities, the admin can choose to see those activities in the activity log.

View private activities in the activity log

  1. In the Activity log page, to the right of filethe activity table, select Table settings, and then select Show private activities.

    Screenshot of the Activity log settings control used to open privacy viewing settings.

  2. In the Show private activities dialog, select OK to confirm that you understand that showing private activities is being audited. Once confirmed, the private activities are shown in the activity log, and the action of showing private activities is recorded in the governance log.

\ No newline at end of file If you run into any problems, we're here to help. To get assistance or support for your product issue, please contact Microsoft Defender XDR support. \ No newline at end of file