Microsoft Defender for Cloud Apps
Cloud and workloads

Investigate accounts from connected apps

In brief

The article now explains how to view and use the Cloud application accounts inventory, investigate accounts, filter by account type, and take actions. It also updates headings, anchors, screenshot descriptions, and metadata.

What Defender admins need to know

Administrators can use the revised guidance to find account investigation, filtering, and action details more easily.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Investigate accounts from connected apps

Microsoft Defender for Cloud Apps shows you account information from your connected applications. This article explains how to view and use the Cloud application accounts inventory to investigate accounts, filter by account type, and take actions on accounts from connected apps.

After you connect an app using the App connector, Defender for Cloud Apps reads account data including permissions, group memberships, aliases, and app usage.

When Defender for Cloud Apps detects a new account in a connected app, for example through activities or file sharing, it adds the account to the accounts list. This lets you see activity from people outside the organization in your cloud apps.

  • View which accounts are included in each user group.
  • See which apps are accessed by each account and which apps are deleted for specific accounts.

Screenshot of the Cloud application accounts tab showing account details, filters, and available actions.

AccountsUse account filters

The Cloud application accounts tab includes predefined filters for common scenarios. You can also turn on the Advanced filters toggle to filter by additional attributes or create conditions such as "does not equal".

  • Account name: Filter by specific accounts.

  • Affiliation: Internal or external. Set internal accounts under Settings by defining the IP address range of your organization. Admin accounts are marked with a red tie icon.

    Icon indicating an admin account, shown as a red tie.

  • App: Filter by any connected app used by accounts in your organization.

  • Groups: Filter by members of user groups in Defender for Cloud Apps, both built-in and imported user groups.

  • Show Admins only: Filter for admin accounts only.

Additional actions for cloud application accounts

You can take additional actions from the Cloud application accounts tab. Select the three dots at the end of an account's row to view options such as viewing related activities and incidents. Select the account row to see other accounts related to the same user.