Microsoft Defender for Cloud Apps
Cloud and workloads

Enrich cloud discovery data with Microsoft Entra usernames

In brief

The article now uses clearer terminology, adds prerequisite guidance, and includes a tip and updated screenshot description for the Microsoft Entra username enrichment option.

What Defender admins need to know

Administrators can use the clarified prerequisites and option description when configuring cloud discovery user enrichment.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Enrich cloud discovery data with Microsoft Entra usernames

Cloud discovery data can now be enriched with Microsoft Entra username data. When you enable this feature,cloud discovery user enrichment, the username,username received in discovery traffic logs,logs is matched and replaced by the Microsoft Entra username. Cloud discovery enrichment enables the following features:

  • You can investigate Shadow IT usage by Microsoft Entra user. The user will be shown with its UPN.
  • You can correlate the Discovered cloud app use with the API collected activities.

Prerequisites

Before you enable user data enrichment, make sure the following prerequisites are met:

EnablingEnable user data enrichment

  1. In the Microsoft Defender Portal, select Settings. Then choose Cloud Apps.

  2. In the User enrichment tab, select Enrich discovered user identifiers with Microsoft Entra ID usernames. This option enables Defender for Cloud Apps to use Microsoft Entra ID data to enrich usernames by default.

    Screenshot that shows enrich Defender for Cloud Apps Discovery with Entra ID usernames.

Next steps

![Screenshot of the User enrichment tab with the option to enrich discovered user identifiers with Microsoft Entra ID usernames.](media/discovery-enrichment.png)

Next steps