Microsoft Defender for Cloud Apps
Cloud and workloads

Protect your Microsoft 365 environment | Microsoft Defender for Cloud Apps

In brief

The article adds Microsoft Entra integration and connection-prerequisite guidance, refines threat-related wording, and clarifies that the service principal API must be enabled for Malware detection and response support. Logs may take 24–72 hours to arrive afterward.

What Defender admins need to know

Administrators connecting Microsoft 365 should verify that the service principal API is enabled and plan for the stated logging delay.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

How Defender for Cloud Apps helps protect your Microsoft 365 environment

Microsoft 365 is a productivity suite that provides tools for cloud file storage, collaboration, business intelligence (BI), and customer relationship management (CRM). Microsoft 365 helps users share documents within your organization and with external partners in a streamlined and efficient way. Using Microsoft 365 might expose your sensitive data not only internally, but also to external collaborators, or even worse make it publicly available via a shared link. SuchThese data exposure incidents might occur due to a malicious actor,actor or by an unaware employee. Microsoft 365 also provides a large third-party app eco-system to help boost productivity. Using thesethird-party apps in Microsoft 365 can expose your organization to the risk of malicious apps or use of apps with excessive permissions.

Connecting Microsoft 365 to Defender for Cloud Apps gives you improved insights into your users' activities. Defender for Cloud Apps helps detect threats using machine learning based anomaly detections and information protection detections, such as detecting external information sharing. Defender for Cloud Apps also applies automated remediation controls and detects threats from enabled third-party apps in your organization.

Main threats to your Microsoft 365 environment

Key threats to your Microsoft 365 environment include:

  • Compromised accounts and insider threats
  • Data leakage |User governance|
    • Notify user on alert (via Microsoft Entra ID)
    • Require user to sign in again (via Microsoft Entra ID)
    • Confirm user compromised (via Microsoft Entra ID)
    • Suspend user (via Microsoft Entra ID)
    Note: The Require user to sign in again, Confirm user compromised, and Suspend user actions aren't supported for guest users.| |OAuth app governance|
    • Revoke OAuth app permission
    |

For more information about remediating threats from connected cloud apps, see Governing connected apps.

Protect Microsoft 365 in real time

Defender for Cloud Apps supports the legacy Microsoft 365 Dedicated Platform and the latest offerings of Microsoft 365 services, commonly referred as the vNext release family of Microsoft 365.

In some cases, a service in the vNext service release family differs slightly at the administrative and management levels from the standard multi-tenant Microsoft 365 service offering.

How audit logging works with Defender for Cloud Apps

How Microsoft Entra integration works

Microsoft Entra integration has the following behaviors and limitations:

  • If your Microsoft Entra ID is set to automatically sync with the users in your Active Directory on-premises environment the settings in the on-premises environment override the Microsoft Entra settings and use of the Suspend user governance action is reverted.

  • For Microsoft Entra sign-in activities, Defender for Cloud Apps only surfaces interactive sign-in activities and sign-in activities from legacy protocols such as ActiveSync.

Prerequisites

Before you connect Microsoft 365 to Defender for Cloud Apps, make sure the following prerequisites are met:

  • To enable file monitoring of Microsoft 365 files, you must sign in with a Microsoft Entra account that has an appropriate administrator role, such as Application Administrator or Cloud Application Administrator. For more information, see Microsoft Entra built-in roles.

  • You must have at least one assigned Microsoft 365 license to connect Microsoft 365 to Defender for Cloud Apps.

  • You must enable auditing in Power BI to get the logs from there. Once auditing is enabled, Defender for Cloud Apps starts getting the logs (with a delay of 24-72 hours).

  • You must enable auditing in Dynamics 365 to get the logs from there. Once auditing is enabled, Defender for Cloud Apps starts getting the logs (with a delay of 24-72 hours).

  • You must enable the service principal API to get Malware detection and response support (the service principal API is enabled by default). Once the service principal API is enabled, Defender for Cloud Apps starts getting the logs (with a delay of 24-72 hours).

To connect Microsoft 365 to Defender for Cloud Apps: