Microsoft Defender for Cloud Apps
Cloud and workloads

Create cloud discovery policies

In brief

The article now includes expanded introductory guidance, clearer wording for saved organization-wide alert defaults, updated metadata, and more descriptive screenshot alt text.

What Defender admins need to know

Administrators can more easily understand how to reuse default alert settings and apply policies to continuous reports. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Create cloud discovery policies

You can create app discovery policies to alert you when new apps are detected. Defender for Cloud Apps also searches all the logs in your cloud discovery for anomalies. This article explains how to create and configure app discovery policies to monitor newly discovered apps, and how to use cloud discovery anomaly detection to identify unusual usage patterns in your environment.

Creating an app discovery policy

- Uploaded data
  1. Set a Daily alert limit under Alerts. Select if the alert is sent as an email. Then provide email addresses as needed.

    • Selecting Save alert settings as the default for your organization enables future policies to use the setting.these alert settings.
    • If you have a default setting,alert settings saved for your organization, you can select Use your organization's default settings.
  2. Select Governance actions to apply when an app matches this policy. It can tag policies as Sanctioned, Unsanctioned, Monitored, or a custom tag.

  3. Under Apply to choose whether this policy applies All continuous reports or Specific continuous reports. Select whether the policy applies to Users, IP addresses, or both.

    :::image type="content" source="media/apply-to-continous-reports.png" alt-text="Screenshot showing howof Apply to apply file polcies tosettings for an app discovery policy with options for all or specific continouscontinuous reports and filters for users and IP addresses." lightbox="media/apply-to-continous-reports.png":::

  1. Select the dates during which the anomalous activity occurred to trigger the alert under Raise alerts only for suspicious activities occurring after date.

  2. Set a Daily alert limit under Alerts. Select if the alert is sent as an email. Then provide email addresses as needed.

    • Selecting Save alert settings as the default for your organization enables future policies to use these alert settings.
    • If you have default alert settings saved for your organization, you can select Use your organization's default settings.
  3. Select Create.