Microsoft Defender for Cloud Apps
Cloud and workloads

Integrate Microsoft Defender for Cloud Apps with external security solutions

In brief

The article title and description now emphasize integrations with threat intelligence, MDM/MTD, and UEBA solutions. It also clarifies the UEBA and Microsoft Entra ID Protection context for risky-user policies and adds a support heading.

What Defender admins need to know

No administrator action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Additional integrations with external solutions

  • UEBA solutions
    You can use multiple UEBA solutions to cater for different workloads and scenarios, where each UEBA solution relies on multiple data sources to identify suspicious and anomalous user behavior. Additionally, external UEBA solutions can be integrated with Microsoft's security ecosystem through Microsoft Entra ID Protection.

    Once integrated,an external UEBA solution is integrated with Microsoft Entra ID Protection, policies can be used to identify risky users, apply adaptive controls, and automatically remediate dangerous users by setting the user's risk level to high. Once a user is set to high, the relevant policy actions are enforced, such as resetting a user's password, requiring MFA authentication, or forcing a user to use a managed device.

    Defender for Cloud Apps allows security teams to automatically or manually confirm a user as compromised to ensure fast remediation of compromised users.

    For more information, see How does Microsoft Entra ID use my risk feedback.

Get support

If you run into any problems, we're here to help. To get assistance or support for your product issue, please open a support ticket.