Microsoft Defender for Cloud Apps
Cloud and workloads

Generic SIEM integration

In brief

The documentation states that existing Defender for Cloud Apps SIEM agents continue functioning until November 2025. It also confirms that new SIEM agents cannot be configured and that Microsoft Sentinel agent integration remains supported in preview.

What Defender admins need to know

Administrators using existing SIEM agents should note the November 2025 timeframe; the update does not state that immediate action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Integrate Defender for Cloud Apps with a generic SIEM

As part of our ongoing convergence process across Microsoft Defender workloads, Microsoft Defender for Cloud Apps SIEM agents will be deprecated starting November 2025.

Existing Microsoft Defender for Cloud Apps SIEM agents will continue to function as is until that time.November 2025. As of June 19, 2025, no new SIEM agents can be configured, but Microsoft Sentinel agent integration (Preview), will remain supported and can still be added.

We recommend transitioning to APIs that support the management of activities and alerts data from multiple workloads. These APIs enhance security monitoring and management and offer additional capabilities using data from multiple Microsoft Defender workloads.

You can integrate Microsoft Defender for Cloud Apps with your generic SIEM server to enable centralized monitoring of alerts and activities from connected apps. As new activities and events are supported by connected apps, visibility into themthose activities and events is then rolled out into Microsoft Defender for Cloud Apps. Integrating with a SIEM service allows you to better protect your cloud applications while maintaining your usual security workflow, automating security procedures, and correlating between cloud-based and on-premises events. The Microsoft Defender for Cloud Apps SIEM agent runs on your server and pulls alerts and activities from Microsoft Defender for Cloud Apps and streams them into the SIEM server.

When you first integrate your SIEM with Defender for Cloud Apps, activities and alerts from the last two days will be forwarded to the SIEM and all activities and alerts (based on the alerts and activities filters you configure during SIEM setup) from then on. If you disable this featureSIEM integration for an extended period,period and then re-enable,enable it, the past two days of alerts and activities are forwarded and then all alerts and activities from then on.

Additional integration solutions include:

Generic SIEM integration architecture

The SIEM agent is deployed in your organization's network. When deployed and configured, itthe SIEM agent pulls the data types that were configured (alerts and activities) using Defender for Cloud Apps RESTful APIs. The SIEM agent then sends the alerts and activities data is then sent over an encrypted HTTPS channel on port 443.

Once the SIEM agent retrieves the data from Defender for Cloud Apps, it sends the Syslog messages to your local SIEM. Defender for Cloud Apps uses the network configurations you provided during the setup (TCP or UDP with a custom port).

  1. In your Syslog/SIEM server, make sure you see activities and alerts arriving from Defender for Cloud Apps.

RegeneratingRegenerate your token

If you lose the token, you can always regenerate it by selecting the three dots at the end of the row for the SIEM agent in the table. Select Regenerate token to get a new token.

Screenshot of SIEM settings option to regenerate the agent token.

EditingEdit your SIEM agent

To edit the SIEM agent, select the three dots at the end of the row for the SIEM agent in the table, and select Edit. If you edit the SIEM agent, you don't need to rerun the .jar file, it updates automatically.

Screenshot of SIEM settings option to edit the integration configuration.

DeletingDelete your SIEM agent

To delete the SIEM agent, select the three dots at the end of the row for the SIEM agent in the table, and select Delete.