Microsoft Defender for Cloud Apps
Cloud and workloads

Govern discovered apps using Microsoft Defender for Endpoint

In brief

The page now includes a requirements section, updated screenshots and setting names, clearer scoped-profile instructions, clarified Microsoft Defender for Business device-group behavior, and revised related-content navigation.

What Defender admins need to know

Administrators have clearer configuration guidance and more accurate visual references when setting up app blocking, custom network indicators, and monitored-app warnings.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Prerequisites

Before you begin, make sure you meet the following requirements:

  • One of the following licenses:

    • Defender for Cloud Apps + Endpoint
  1. In the Microsoft Defender Portal, select Settings. Then choose Cloud Apps. Under Cloud Discovery, select Microsoft Defender for Endpoint, and then select Enforce app access.

    Screenshot of Microsoft Defender for Endpoint settings showing the Enforce app access option under Cloud Discovery.

  1. In Microsoft Defender XDR, go to Settings > Endpoints > Advanced features, and then select Custom network indicators. For information about network indicators, see Create indicators for IPs and URLs/domains.

    Enabling custom network indicators allows you to leverage Microsoft Defender Antivirus network protection capabilities to block access to a predefined set of URLs using Defender for Cloud Apps, either by manually sanctioning or unsanctioning apps using app tags or automatically by creating an app discovery policy.

    Screenshot of the Advanced features settings page in Microsoft Defender XDR with the Custom network indicators toggle.

Educate users when accessing blocked apps & customize the block page

  1. In the Alerts dropdown, select Informational.

  2. Under User warnings > Notification URL for blocked apps, enter your URL. For example:

    Screenshot showing configuration of adding custom URL for blocked apps.

Disable informational alerts for unsanctioned app access (Preview)

  1. In the Microsoft Defender Portal, select Settings. Then choose Cloud Apps. Then under Cloud discovery, select Apps tags and go to the Scoped profiles tab.

  2. Select Add profile. The scoped profile sets thewhich entities scopedare included or excluded for blocking/unblocking apps.app blocking or unblocking.

  3. Provide a descriptive profile name and description.

Educate users when accessing risky apps

  1. In the Microsoft Defender Portal, select Settings. Then choose Cloud Apps. Under Cloud Discovery, select Microsoft Defender for Endpoint.

  2. In the Notification URL box, enter your URL.

    Screenshot of Microsoft Defender for Endpoint Cloud Discovery settings showing the Notification URL field for monitored app warnings.

Setting up user bypass duration

  1. In the Microsoft Defender Portal, select Settings. Then choose Cloud Apps. Under Cloud Discovery, select Microsoft Defender for Endpoint.

  2. In the Bypass duration box, enter the duration (hours) of the user bypass.

    Screenshot of Microsoft Defender for Endpoint Cloud Discovery settings showing the Bypass duration field for monitored app warnings.

Monitor applied app controls

[!div class="nextstepaction"] Control cloud apps with policies

Related videoscontent

[!div class="nextstepaction"] Discover and block Shadow IT using Defender for Endpoint