Microsoft Defender for Cloud Apps
Architecture and deployment

Deploy conditional access app control for any web app using AD FS

In brief

The instructions now specify using the AD FS SingleSignOnService Location from the federation metadata and explicitly require a Microsoft Defender for Cloud Apps license. They also clarify which values are needed when configuring the relying party trust.

What Defender admins need to know

Administrators setting up this integration should use the updated AD FS SSO URL and confirm the required license is available.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Deploy conditional access app control for any web app using Active Directory Federation Services (AD FS) as the identity provider (IdP)

Prerequisites

  • Your organization must have the following licenses to usefor conditional access app control:

    • A pre-configured AD FSActive Directory Federation Services (AD FS) environment
    • A Microsoft Defender for Cloud Apps license
  • An existing AD FS single sign-on configurationsetup for the app using thethat uses SAML 2.0 authentication protocol

  1. Back in the Defender for Cloud Apps IDENTITY PROVIDER page, click Next to proceed.

  2. On the IDENTITY PROVIDER details page, select Fill in data manually, do the following, and then click Next.

    • For the Single sign-on service URL, enter the AD FS SingleSignOnService Location you noted from the federation metadata file in Step 3.
    • Select Upload identity provider's SAML certificate and upload the certificate file you downloaded earlier.

    Screenshot of the Defender for Cloud Apps identity provider page with fields for the SSO service URL and SAML certificate.

  3. On the EXTERNAL CONFIGURATION page, make a note of the following information, and then click Next. You'll need the single sign-on URL and the attributes and values when configuring the AD FS relying party trust and updating the app.

    • Defender for Cloud Apps single sign-on URL
    • Defender for Cloud Apps attributes and values

Complete the wizard to enable routing through conditional access app control.

  • Back in the Defender for Cloud Apps APP CHANGES page, click Finish. After completing the wizard, all associated login requests to the configured app will be routed through conditional access app control.

Related content