Pilot and deploy Microsoft Defender for Cloud Apps
In brief
The article now uses Microsoft Defender instead of Microsoft Defender XDR in its deployment workflow, headings, integration instructions, and descriptions of signal correlation and Sentinel integration.
What Defender admins need to know
No administrator action is stated; review the updated terminology when following the deployment guidance.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Pilot and deploy Microsoft Defender for Cloud Apps
This article provides a workflow for piloting and deploying Microsoft Defender for Cloud Apps in your organization. Use these recommendations to onboard Microsoft Defender for Cloud Apps as part of an end-to-end solution with Microsoft Defender XDR.Defender.
This article assumes you have a production Microsoft 365 tenant and are piloting and deploying Microsoft Defender for Cloud Apps in this environment. This practice will maintain any settings and customizations you configure during your pilot for your full deployment.
Defender for Office 365 contributes to a Zero Trust architecture by helping to prevent or reduce business damage from a breach. For more information, see the Prevent or reduce business damage from a breach business scenario in the Microsoft Zero Trust adoption framework.
End-to-end deployment for Microsoft Defender XDR
This is article 5 of 6 in a series to help you deploy the components of Microsoft Defender XDR, including investigating and responding to incidents.
| Phase | Link |
|---|---|
| A. Start the pilot | Start the pilot |
| B. Pilot and deploy Microsoft Defender |
- Pilot and deploy Defender for Identity - Pilot and deploy Defender for Office 365 - Pilot and deploy Defender for Endpoint - Pilot and deploy Microsoft Defender for Cloud Apps (this article) |
| C. Investigate and respond to threats | Practice incident investigation and response |
Pilot and deploy workflow for Defender for Cloud Apps
Protecting your organization from hackers
Defender for Cloud Apps provides powerful protection on its own. However, when combined with the other capabilities of Microsoft Defender XDR,Defender, Defender for Cloud Apps provides data into the shared signals which together help stop attacks.
Here's an example of a cyber-attack and how the components of Microsoft Defender XDR help detect and mitigate it.
Defender for Cloud Apps detects anomalous behavior like impossible-travel, credential access, and unusual download, file share, or mail forwarding activity and displays these behaviors in the Defender for Cloud Apps. Defender for Cloud Apps also helps prevent lateral movement by hackers and exfiltration of sensitive data.
Microsoft Defender XDR correlates the signals from all the Microsoft Defender components to provide the full attack story.
Defender for Cloud Apps role as a CASB and more
Microsoft Defender for Cloud Apps integrates with Microsoft Defender for Endpoint natively. The integration simplifies roll out of Cloud Discovery, extends Cloud Discovery capabilities beyond your corporate network and enables device-based investigation. This integration reveals cloud apps and services being accessed from IT-managed Windows 10 and Windows 11 devices.
If you've already set up Microsoft Defender for Endpoint, configuring integration with Defender for Cloud Apps is a toggle in Microsoft Defender XDR.Defender. After integration is turned on, you can return to Defender for Cloud Apps and view rich data in the Cloud Discovery Dashboard.
To accomplish these tasks, see Integrate Microsoft Defender for Endpoint with Microsoft Defender for Cloud Apps.
You can integrate Defender for Cloud Apps with Microsoft Sentinel for unified security operations in the Defender portal, or with a generic security information and event management (SIEM) service to enable centralized monitoring of alerts and activities from connected apps. With Microsoft Sentinel, you can more comprehensively analyze security events across your organization and build playbooks for effective and immediate response.
The Defender portal supports unified security operations with Microsoft Sentinel, bringing signals from Defender XDR,Defender, including Defender for Cloud Apps, to Microsoft Sentinel.
For more information, see:
Perform lifecycle management for Defender for Cloud Apps.
Next step for the end-to-end deployment of Microsoft Defender XDR
Continue your end-to-end deployment of Microsoft Defender XDR with Investigate and respond using Microsoft Defender XDR.
@@ -26,13 +26,13 @@ appliesto: # Pilot and deploy Microsoft Defender for Cloud Apps -This article provides a workflow for piloting and deploying Microsoft Defender for Cloud Apps in your organization. Use these recommendations to onboard Microsoft Defender for Cloud Apps as part of an end-to-end solution with Microsoft Defender XDR.+This article provides a workflow for piloting and deploying Microsoft Defender for Cloud Apps in your organization. Use these recommendations to onboard Microsoft Defender for Cloud Apps as part of an end-to-end solution with Microsoft Defender. This article assumes you have a production Microsoft 365 tenant and are piloting and deploying Microsoft Defender for Cloud Apps in this environment. This practice will maintain any settings and customizations you configure during your pilot for your [full deployment](/defender-cloud-apps/get-started). Defender for Office 365 contributes to a Zero Trust architecture by helping to prevent or reduce business damage from a breach. For more information, see the [Prevent or reduce business damage from a breach](/security/zero-trust/adopt/prevent-reduce-business-damage-breach) business scenario in the Microsoft Zero Trust adoption framework. -## End-to-end deployment for Microsoft Defender XDR+## End-to-end deployment for Microsoft Defender This is article 5 of 6 in a series to help you deploy the components of Microsoft Defender XDR, including investigating and responding to incidents. @@ -43,7 +43,7 @@ The articles in this series correspond to the following phases of end-to-end dep | Phase | Link | |---|---| | A. Start the pilot | [Start the pilot](pilot-deploy-overview.md#start-the-pilot)|-| B. Pilot and deploy Microsoft Defender XDR components | - [Pilot and deploy Defender for Identity](pilot-deploy-defender-identity.md) <br><br> - [Pilot and deploy Defender for Office 365](pilot-deploy-defender-office-365.md) <br><br> - [Pilot and deploy Defender for Endpoint](pilot-deploy-defender-endpoint.md) <br><br> - **Pilot and deploy Microsoft Defender for Cloud Apps** (this article) |+| B. Pilot and deploy Microsoft Defender components | - [Pilot and deploy Defender for Identity](pilot-deploy-defender-identity.md) <br><br> - [Pilot and deploy Defender for Office 365](pilot-deploy-defender-office-365.md) <br><br> - [Pilot and deploy Defender for Endpoint](pilot-deploy-defender-endpoint.md) <br><br> - **Pilot and deploy Microsoft Defender for Cloud Apps** (this article) | |C. Investigate and respond to threats | [Practice incident investigation and response](pilot-deploy-investigate-respond.md) | ## Pilot and deploy workflow for Defender for Cloud Apps@@ -79,7 +79,7 @@ Here are the recommended steps for each deployment stage. ### Protecting your organization from hackers -Defender for Cloud Apps provides powerful protection on its own. However, when combined with the other capabilities of Microsoft Defender XDR, Defender for Cloud Apps provides data into the shared signals which together help stop attacks.+Defender for Cloud Apps provides powerful protection on its own. However, when combined with the other capabilities of Microsoft Defender, Defender for Cloud Apps provides data into the shared signals which together help stop attacks. Here's an example of a cyber-attack and how the components of Microsoft Defender XDR help detect and mitigate it. @@ -87,7 +87,7 @@ Here's an example of a cyber-attack and how the components of Microsoft Defender Defender for Cloud Apps detects anomalous behavior like impossible-travel, credential access, and unusual download, file share, or mail forwarding activity and displays these behaviors in the Defender for Cloud Apps. Defender for Cloud Apps also helps prevent lateral movement by hackers and exfiltration of sensitive data. -Microsoft Defender XDR correlates the signals from all the Microsoft Defender components to provide the full attack story.+Microsoft Defender correlates the signals from all the Microsoft Defender components to provide the full attack story. ### Defender for Cloud Apps role as a CASB and more @@ -130,7 +130,7 @@ If you're still having trouble, review [Network requirements](/defender-cloud-ap Microsoft Defender for Cloud Apps integrates with Microsoft Defender for Endpoint natively. The integration simplifies roll out of Cloud Discovery, extends Cloud Discovery capabilities beyond your corporate network and enables device-based investigation. This integration reveals cloud apps and services being accessed from IT-managed Windows 10 and Windows 11 devices. -If you've already set up Microsoft Defender for Endpoint, configuring integration with Defender for Cloud Apps is a toggle in Microsoft Defender XDR. After integration is turned on, you can return to Defender for Cloud Apps and view rich data in the Cloud Discovery Dashboard.+If you've already set up Microsoft Defender for Endpoint, configuring integration with Defender for Cloud Apps is a toggle in Microsoft Defender. After integration is turned on, you can return to Defender for Cloud Apps and view rich data in the Cloud Discovery Dashboard. To accomplish these tasks, see [Integrate Microsoft Defender for Endpoint with Microsoft Defender for Cloud Apps](/defender-cloud-apps/mde-integration). @@ -258,7 +258,7 @@ For more information on advanced hunting in Microsoft Defender for Cloud Apps da You can integrate Defender for Cloud Apps with Microsoft Sentinel for unified security operations in the [Defender portal](/unified-secops-platform/), or with a generic security information and event management (SIEM) service to enable centralized monitoring of alerts and activities from connected apps. With Microsoft Sentinel, you can more comprehensively analyze security events across your organization and build playbooks for effective and immediate response. -The Defender portal supports unified security operations with Microsoft Sentinel, bringing signals from Defender XDR, including Defender for Cloud Apps, to Microsoft Sentinel.+The Defender portal supports unified security operations with Microsoft Sentinel, bringing signals from Defender, including Defender for Cloud Apps, to Microsoft Sentinel. For more information, see: @@ -270,7 +270,7 @@ For more information, see: Perform [lifecycle management for Defender for Cloud Apps](/defender-cloud-apps/lifecycle-management). -## Next step for the end-to-end deployment of Microsoft Defender XDR+## Next step for the end-to-end deployment of Microsoft Defender Continue your end-to-end deployment of Microsoft Defender XDR with [Investigate and respond using Microsoft Defender XDR](pilot-deploy-investigate-respond.md). 