Microsoft Defender for Cloud Apps
Cloud and workloads

Investigate apps discovered by Microsoft Defender for Endpoint | Microsoft Defender for Cloud Apps

In brief

The article clarifies Cloud Discovery navigation, integration context, network-event descriptions, and unsanctioned-app investigation steps. Headings, portal terminology, metadata, and screenshot descriptions were also updated.

What Defender admins need to know

Administrators following the article will have clearer labels and navigation for locating device timelines, network events, and unsanctioned-app alerts.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  1. In the Microsoft Defender portal, under Cloud Apps, select Cloud Discovery > Dashboard.

  2. At the top of theCloud Discovery Dashboard page, select Defender-managed endpoints. The Defender-managed endpoints stream contains data from any operating systems mentioned in Defender for Cloud Apps integration prerequisites.

At the top of the Cloud Discovery dashboard, you'll see the number of discovered devices added after the integration.Defender for Endpoint and Defender for Cloud Apps integration was configured.

  1. Select the Devices tab.

Defender for Cloud Apps can discover Shadow IT network events detected from Defender for Endpoint devices that are working in the same environment as a network proxy. For example, if your Windows 10 endpoint device is in the same environment as ZScalar, Defender for Cloud Apps can discover Shadow IT applications via the Win10 Endpoint Users stream.

Investigate device network events in Microsoft Defender XDR

Network events are timeline records of device connections captured by Defender for Endpoint that help you investigate app-related activity on specific devices.

  1. In the Microsoft Defender Portal, under Cloud Apps, select Cloud Discovery. Then select the Devices tab.
  2. Select the machine you want to investigate and then in the top-left select View in Microsoft Defender for Endpoint.
  3. In the Defender portal, under Assets -> Devices > {selected device}, select Timeline.
  4. Under Filters, select Network events.
  5. Investigate the device's network events as required.

Screenshot of the Microsoft Defender XDR device timeline filtered to show network events for the selected device.

Investigate app usage in Microsoft Defender XDR with advanced hunting

![Screenshot of Advanced hunting query results in Microsoft Defender XDR showing network events for the investigated app domains.](media/mde-advanced-hunting.png)

Investigate unsanctioned apps in Microsoft Defender

Every attempt to access an unsanctioned app triggers an alert in the Defender portal with in-depth details about the entire session. The alert details enable you to perform deeper investigations into attempts to access unsanctioned apps, as well as providing additional relevant information for use in endpoint device investigation.

Sometimes, access to an unsanctioned app isn't blocked, either because the endpoint device isn't configured correctly or if the enforcement policy hasn't yet propagated to the endpoint. When access to an unsanctioned app isn't blocked because of endpoint misconfiguration or policy propagation delays, Defender for Endpoint administrators receive an alert in the Defender portal that the unsanctioned app wasn't blocked.

Screenshot of a Microsoft Defender XDR alert indicating that access to an unsanctioned app was detected but not blocked on an endpoint device.