Integrate Microsoft Defender for Endpoint
In brief
The page metadata was updated, and the integration section now introduces prerequisites and describes the integration’s capabilities more clearly.
What Defender admins need to know
No administrator action is required.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Integrate Microsoft Defender for Endpoint with Microsoft Defender for Cloud Apps
Prerequisites
Before you configure the integration, make sure you meet the following prerequisites:
Microsoft Defender for Cloud Apps license
Devices must be onboarded to Microsoft Defender for Endpoint
On its own, Defender for Cloud Apps collects logs from your endpoints using either logs you upload or by configuring automatic log upload. The out-of-the-box integration enables you to take advantage of the logs Defender for Endpoint's agent creates when it runs on Windows and monitors network transactions. Use these Defender for Endpoint network transaction logs for Shadow IT discovery across the Windows devices on your network.
The integration doesn't require extra deployment steps or routing or mirroring traffic from your endpoints, and works as follows:endpoints. It provides the following capabilities:
- Logs from your endpoints that are sent to Defender for Cloud Apps provide user and device information for traffic activities. Pairing device context with the username provides a full picture across your network enabling you to determine which user did which activity from which device.
- When you identify a risky user, check the devices that the user accessed to detect potential risks. If you identify a risky device, check all the users who used it to detect further potential risks.
@@ -1,11 +1,11 @@ --- title: Integrate Microsoft Defender for Endpoint description: This article describes how to integrate Microsoft Defender for Endpoint with Defender for Cloud Apps for enhanced visibility into Shadow IT and risk management.-ms.date: 06/16/2026+ms.date: 07/03/2026 ms.topic: how-to ms.reviewer: Mravela ai-usage: ai-assisted-ms.custom: msecd-doc-authoring-1014+ms.custom: msecd-doc-authoring-1016 --- # Integrate Microsoft Defender for Endpoint with Microsoft Defender for Cloud Apps@@ -19,6 +19,8 @@ The out-of-the-box integration between Microsoft Defender for Cloud Apps and Mic ## Prerequisites +Before you configure the integration, make sure you meet the following prerequisites:+ - Microsoft Defender for Cloud Apps license - Devices must be onboarded to [Microsoft Defender for Endpoint](/defender-endpoint/onboard-client)@@ -52,7 +54,7 @@ The out-of-the-box integration between Microsoft Defender for Cloud Apps and Mic On its own, Defender for Cloud Apps collects logs from your endpoints using either [logs you upload](create-snapshot-cloud-discovery-reports.md) or by [configuring automatic log upload](discovery-docker.md). The out-of-the-box integration enables you to take advantage of the logs Defender for Endpoint's agent creates when it runs on Windows and monitors network transactions. Use these Defender for Endpoint network transaction logs for Shadow IT discovery across the Windows devices on your network. -The integration doesn't require extra deployment steps or routing or mirroring traffic from your endpoints, and works as follows:+The integration doesn't require extra deployment steps or routing or mirroring traffic from your endpoints. It provides the following capabilities: - **Logs from your endpoints that are sent to Defender for Cloud Apps provide user and device information for traffic activities**. Pairing device context with the username provides a full picture across your network enabling you to determine which user did which activity from which device. - **When you identify a risky user, check the devices that the user accessed to detect potential risks**. If you identify a risky device, check all the users who used it to detect further potential risks. 