Microsoft Defender for Cloud Apps
Cloud and workloads

Filter and query activities | Microsoft Defender for Cloud Apps

In brief

The article now explains activity filters, saved queries, investigations, and exports in more detail. It also identifies App connector and App connector analysis as Source filter options and updates screenshot descriptions and metadata.

What Defender admins need to know

Administrators can use the clarified guidance to select sources and work with activity investigations and saved queries.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


title: Filter and query activities | Microsoft Defender for Cloud Apps description: Use activity filters and saved queries in Microsoft Defender for Cloud Apps to investigate events, narrow results, and refine activity searches. ms.date: 06/16/07/03/2026 ms.topic: how-to ms.custom:

  • msecd-doc-authoring-10141016
  • sfi-ga-nochange
  • sfi-image-nochange ai-usage: ai-assisted

This article provides descriptionsdescribes how to use activity filters and instructions forsaved queries in Microsoft Defender for Cloud Apps activity filtersto investigate events, narrow search results, and queries.monitor user and app behavior. You'll learn about the available filter fields, how to create and save custom queries, and how to query or export activities from up to six months back.

Use activity filters

  • Registered ISP - The ISP from which the activity was performed.

  • Source - Search by the source from which the activity was detected. The source can be any of the following:App connector or App connector analysis:

    • App connector - Logs coming directly from the app's API connector.
    • App connector analysis - Defender for Cloud Apps enrichments based on information scanned by the API connector.

To investigate activities older than 30 days, you can navigate to the Activity log and select Investigate 6 months back in the top right-hand corner of the screen:

Screenshot of the Activity log page showing the option to investigate activity from the past six months.

In the Investigate 6 months back view, you can define the filters as you normally would in the Activity Log, with the following differences:

For example:

Screenshot of activity log filters in the six-month investigation view showing fields like Activity ID, Activity type, and IP address.

Export activities six months back

Reports that include private activities are marked with an Eye icon in the reports page.

Icon of an eye indicating that the exported report includes private activities.

Next steps