Investigate apps discovered by Microsoft Defender for Endpoint | Microsoft Defender for Cloud Apps
In brief
The article clarifies Cloud Discovery navigation, integration context, network-event descriptions, and unsanctioned-app investigation steps. Headings, portal terminology, metadata, and screenshot descriptions were also updated.
What Defender admins need to know
Administrators following the article will have clearer labels and navigation for locating device timelines, network events, and unsanctioned-app alerts.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
In the Microsoft Defender portal, under Cloud Apps, select Cloud Discovery > Dashboard.
At the top of theCloud Discovery Dashboard page, select Defender-managed endpoints. The Defender-managed endpoints stream contains data from any operating systems mentioned in Defender for Cloud Apps integration prerequisites.
At the top of the Cloud Discovery dashboard, you'll see the number of discovered devices added after the integration.Defender for Endpoint and Defender for Cloud Apps integration was configured.
- Select the Devices tab.
Defender for Cloud Apps can discover Shadow IT network events detected from Defender for Endpoint devices that are working in the same environment as a network proxy. For example, if your Windows 10 endpoint device is in the same environment as ZScalar, Defender for Cloud Apps can discover Shadow IT applications via the Win10 Endpoint Users stream.
Investigate device network events in Microsoft Defender XDR
Network events are timeline records of device connections captured by Defender for Endpoint that help you investigate app-related activity on specific devices.
- In the Microsoft Defender Portal, under Cloud Apps, select Cloud Discovery. Then select the Devices tab.
- Select the machine you want to investigate and then in the top-left select View in Microsoft Defender for Endpoint.
- In the Defender portal, under Assets -> Devices > {selected device}, select Timeline.
- Under Filters, select Network events.
- Investigate the device's network events as required.
Investigate app usage in Microsoft Defender XDR with advanced hunting

Investigate unsanctioned apps in Microsoft Defender
Every attempt to access an unsanctioned app triggers an alert in the Defender portal with in-depth details about the entire session. The alert details enable you to perform deeper investigations into attempts to access unsanctioned apps, as well as providing additional relevant information for use in endpoint device investigation.
Sometimes, access to an unsanctioned app isn't blocked, either because the endpoint device isn't configured correctly or if the enforcement policy hasn't yet propagated to the endpoint. When access to an unsanctioned app isn't blocked because of endpoint misconfiguration or policy propagation delays, Defender for Endpoint administrators receive an alert in the Defender portal that the unsanctioned app wasn't blocked.

@@ -1,10 +1,10 @@ --- title: Investigate apps discovered by Microsoft Defender for Endpoint | Microsoft Defender for Cloud Apps description: Learn how to use Microsoft Defender for Cloud Apps to investigate Microsoft Defender for Endpoint discovered devices, network events, and app usage.-ms.date: 06/16/2026+ms.date: 07/03/2026 ms.topic: how-to ms.reviewer: Mravela-ms.custom: sfi-image-nochange, msecd-doc-authoring-1014+ms.custom: sfi-image-nochange, msecd-doc-authoring-1016 ai-usage: ai-assisted --- @@ -22,9 +22,9 @@ After you integrate Defender for Endpoint with Defender for Cloud Apps, investig 1. In the Microsoft Defender portal, under **Cloud Apps**, select **Cloud Discovery** > **Dashboard**. -1. At the top of the page, select **Defender-managed endpoints**. The Defender-managed endpoints stream contains data from any operating systems mentioned in Defender for Cloud Apps [integration prerequisites](mde-integration.md#prerequisites).+1. At the top of the **Cloud Discovery Dashboard** page, select **Defender-managed endpoints**. The Defender-managed endpoints stream contains data from any operating systems mentioned in Defender for Cloud Apps [integration prerequisites](mde-integration.md#prerequisites). - At the top of the Cloud Discovery dashboard, you'll see the number of discovered devices added after the integration.+ At the top of the Cloud Discovery dashboard, you'll see the number of discovered devices added after the Defender for Endpoint and Defender for Cloud Apps integration was configured. 1. Select the **Devices** tab. @@ -53,7 +53,9 @@ As with any other cloud discovery source, you can export the data from the **Def Defender for Cloud Apps can discover Shadow IT network events detected from Defender for Endpoint devices that are working in the same environment as a network proxy. For example, if your Windows 10 endpoint device is in the same environment as ZScalar, Defender for Cloud Apps can discover Shadow IT applications via the **Win10 Endpoint Users** stream. -## Investigate device network events in Microsoft Defender XDR+## Investigate device network events in Microsoft Defender++Network events are timeline records of device connections captured by Defender for Endpoint that help you investigate app-related activity on specific devices. >[!NOTE] >Network events should be used to investigate discovered apps and not used to debug missing data.@@ -62,11 +64,11 @@ Use the following steps to gain more granular visibility on device's network act 1. In the Microsoft Defender Portal, under **Cloud Apps**, select **Cloud Discovery**. Then select the **Devices** tab. 1. Select the machine you want to investigate and then in the top-left select **View in Microsoft Defender for Endpoint**.-1. In Microsoft Defender XDR, under **Assets** -> **Devices** > {selected device}, select **Timeline**.+1. In the Defender portal, under **Assets** -> **Devices** > {selected device}, select **Timeline**. 1. Under **Filters**, select **Network events**. 1. Investigate the device's network events as required. -+ ## Investigate app usage in Microsoft Defender XDR with advanced hunting @@ -88,13 +90,13 @@ Use the following steps to gain more granular visibility on device's network act  -## Investigate unsanctioned apps in Microsoft Defender XDR+## Investigate unsanctioned apps in Microsoft Defender -Every attempt to access an unsanctioned app triggers an alert in Microsoft Defender XDR with in-depth details about the entire session. The alert details enable you to perform deeper investigations into attempts to access unsanctioned apps, as well as providing additional relevant information for use in endpoint device investigation.+Every attempt to access an unsanctioned app triggers an alert in the Defender portal with in-depth details about the entire session. The alert details enable you to perform deeper investigations into attempts to access unsanctioned apps, as well as providing additional relevant information for use in endpoint device investigation. -Sometimes, access to an unsanctioned app isn't blocked, either because the endpoint device isn't configured correctly or if the enforcement policy hasn't yet propagated to the endpoint. When access to an unsanctioned app isn't blocked because of endpoint misconfiguration or policy propagation delays, Defender for Endpoint administrators receive an alert in Microsoft Defender XDR that the unsanctioned app wasn't blocked.+Sometimes, access to an unsanctioned app isn't blocked, either because the endpoint device isn't configured correctly or if the enforcement policy hasn't yet propagated to the endpoint. When access to an unsanctioned app isn't blocked because of endpoint misconfiguration or policy propagation delays, Defender for Endpoint administrators receive an alert in the Defender portal that the unsanctioned app wasn't blocked. -+ > [!NOTE] > 