Microsoft Defender for Cloud Apps
Cloud and workloads

Integrate Microsoft Sentinel with Microsoft Defender for Cloud Apps

In brief

The Microsoft Sentinel integration page now states that SIEM agents are deprecated and that the Microsoft Sentinel integration (Preview) remains supported. It also adds a dedicated integration section.

What Defender admins need to know

Administrators using SIEM agents should review their integration strategy and the supported Microsoft Sentinel option.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Set up Microsoft Sentinel integration for Defender for Cloud Apps (Preview)

Integrate Microsoft Defender for Cloud Apps with Microsoft Sentinel

Integrating with Microsoft Sentinel

Use the following steps to integrate Defender for Cloud Apps with Microsoft Sentinel.

  1. In the Microsoft Defender Portal, select Settings > Cloud Apps.

  2. Under System, select SIEM agents > Add SIEM agent > Sentinel. For example: To get started:

  3. In Power BI, import queries from Microsoft Sentinel for Defender for Cloud Apps data. For more information, see Import Azure Monitor log data into Power BI.

  4. Install the Defender for Cloud Apps Shadow IT Discovery app and connect it to your discovery log data to view the built-in Shadow IT Discovery dashboard. To connect the app, open it in Power BI, select Connect, enter your Microsoft Sentinel workspace ID, and then sign in. For detailed steps, see Connect the Defender for Cloud Apps Shadow IT Discovery app.