Microsoft Defender for Cloud Apps
Cloud and workloads

Investigate cloud app risks and suspicious activity

In brief

The documentation now consistently refers to policy violations and clarifies that administrators should determine appropriate remediation steps after suspending a user.

What Defender admins need to know

Administrators get clearer guidance when reviewing alerts and deciding on containment or remediation.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Investigate cloud app risks and suspicious activity

After Microsoft Defender for Cloud Apps runs in your cloud environment, you'll need a stage of learning and investigating. Learn to use the Microsoft Defender for Cloud Apps tools to gain a deeper understanding of what's happening in your cloud environment. Based on your particular environment and how it's being used, you can identify the requirements for protecting your organization from risk. This article describes how to do an investigation to get a better understanding of your cloud environment.

Tag apps as sanctioned or unsanctioned

An important step to understanding your cloud is to tag apps as sanctioned or unsanctioned. After you sanction an app, you can filter for apps that aren't sanctioned and start migration to sanctioned apps of the same app category.

  1. In the Microsoft Defender Portal, go to Incidents & alerts -> Alerts and view the alert about the policy violation.

  2. If you see that the alert looks like a real policy violation, you want to contain risk or remediate the policy violation.

    To contain risk, you can send the user a notification to ask if the policy violation was intentional and if the user was aware of it.

    You can also drill down into the alert and suspend the user until you can figure out what needs to be done.determine the appropriate remediation steps.

  3. If the event is allowed and isn't likely to recur, you can dismiss the alert.