Microsoft Defender for Cloud Apps
Cloud and workloads

Integrate Microsoft Defender for Endpoint

In brief

The page metadata was updated, and the integration section now introduces prerequisites and describes the integration’s capabilities more clearly.

What Defender admins need to know

No administrator action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Integrate Microsoft Defender for Endpoint with Microsoft Defender for Cloud Apps

Prerequisites

Before you configure the integration, make sure you meet the following prerequisites:

On its own, Defender for Cloud Apps collects logs from your endpoints using either logs you upload or by configuring automatic log upload. The out-of-the-box integration enables you to take advantage of the logs Defender for Endpoint's agent creates when it runs on Windows and monitors network transactions. Use these Defender for Endpoint network transaction logs for Shadow IT discovery across the Windows devices on your network.

The integration doesn't require extra deployment steps or routing or mirroring traffic from your endpoints, and works as follows:endpoints. It provides the following capabilities:

  • Logs from your endpoints that are sent to Defender for Cloud Apps provide user and device information for traffic activities. Pairing device context with the username provides a full picture across your network enabling you to determine which user did which activity from which device.
  • When you identify a risky user, check the devices that the user accessed to detect potential risks. If you identify a risky device, check all the users who used it to detect further potential risks.