Microsoft Defender for Cloud Apps
Cloud and workloads

Protect your Mural environment | Microsoft Defender for Cloud Apps

In brief

The documentation now states that the Activity performed by terminated user policy requires Microsoft Entra ID as the identity provider and that Mural audit-log ingestion is delayed by 48 hours. It also includes wording, heading, and navigation updates.

What Defender admins need to know

Administrators should account for the identity-provider prerequisite and 48-hour delay when configuring and monitoring Mural in Defender for Cloud Apps.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

How Microsoft Defender for Cloud Apps helps protect your Mural environment (Preview)

Mural is an online workspace that enables distributed, cross-functionalwhere teams can organize and collaboratework together on projects. Mural holds criticalkey data offor your organization, and that exposurewhich makes it a target for malicious actors.

ConnectingWhen you connect Mural to Defender for Cloud Apps givesApps, you improved insightsget better visibility into your users' activities and providesuser activity. You also get threat detection usingwith machine learning based anomaly detections.

Main threats to your Mural environment

Connecting Mural without adequate protection exposes your organization to the following threats:

Control Mural with policies

The following table lists theYou can use these policy types you can use to monitor and control Mural:Mural.

TypeName
Built-in anomaly detection policyActivity from anonymous IP addresses
Type Name
Built-in anomaly detection policy Activity from anonymous IP addresses
Activity from infrequent country
Activity from suspicious IP addresses
Impossible travel
Activity performed by terminated user (requires Microsoft Entra ID as IdP)
Multiple failed login attempts
Activity policy BuiltBuild a customizedcustom policy by usingwith the Mural Audit Log API.

For more information about creating policies, see Create a policy.

Automate governance controls

In addition to monitoring for potential threats, youYou can also apply and automate the followingthese Mural governance actions to remediatefix detected threats:

Type Action
User governance Notify user on alert (via Microsoft Entra ID)
Require user to sign in again (via Microsoft Entra ID)
Suspend user (via Microsoft Entra ID)

ForTo learn more information about remediatingfixing threats from apps, see Governing connected apps.

Connect Mural to Microsoft Defender for Cloud Apps

This section providesThe following instructions for connectingexplain how to connect Microsoft Defender for Cloud Apps to your existing Mural account using the App Connector APIs. This connection gives you visibility into and control over Mural usage.

Prerequisites

  • A Mural enterprise account.
  • You must be signed-in as an admin to Mural.

To connectConnect Mural to Defender for Cloud Apps

Perform the following steps to connect Mural to Defender for Cloud Apps:

  1. In the connection wizard, enter your instance name, and then select Next.
  2. Paste the API key you copied from the Mural portal and then select Submit.

OnceAfter the connection is successfully established, Defender for Cloud Apps starts fetching Mural audit logs. SinceBecause Mural's API logs are delayed by 48 hours, the audit log ingestion tointo Defender for Cloud Apps is similarly delayed.also delayed by 48 hours.