SaaS Security Initiative in Microsoft Defender XDR
In brief
The article now emphasizes SSPM recommendations organized into 12 metrics, adds prerequisite guidance, and updates instructions for accessing, prioritizing, and tracking recommendations in the Defender portal.
What Defender admins need to know
Administrators can use the revised navigation and guidance to review metrics, target scores, connector coverage, and remediation steps. No action is required.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Use the SaaS Security Initiative in Defender for Cloud Apps
This article shows you how to view and prioritize SaaS security recommendations in Microsoft Defender XDR by using the SaaS Security Initiative. Before you start, make sure you meet the prerequisites.
Overview of the SaaS Security Initiative
The SaaS Security Initiative provides a centralized place for software as a service (SaaS) security best practices, so that organizations can manage and prioritize security recommendations effectively. By focusing on the most impactful metrics, organizations can enhance their SaaS security posture.
The SaaS Security Initiative serves asis the main hub for SaaS security posture management (SSPM). It consolidatesgives you a central place to manage software as a service (SaaS) security best practices.
The initiative groups best-practice recommendationstips into 12 measurable metrics. TheseYou can use these metrics facilitateto rank and act on security tasks. Focus on the management and prioritization of a large number ofmetrics with the most impact to improve your SaaS security recommendations.posture.
How to use the SaaS Security Initiative
Prerequisites
Before you view SaaS Security Initiativethese recommendations, ensure that the following prerequisites are met:make sure you meet these requirements:
- Your organization must have Microsoft Defender for Cloud Apps licenses.
- The app
for whichyou want toview security recommendationscheck must be connected to Defender for Cloud Apps.For information about connectingTo learn how to connect apps andaboutwhichof the appconnectors provide securityrecommendations,tips, see Connect apps to get visibility and control with Microsoft Defender for Cloud Apps.
View SaaS Security Initiative recommendations
To view SaaS Security Initiative recommendations, perform the following steps:
- In
Microsoftthe DefenderXDR,portal, go to Exposure Management and select Initiatives. - Select the SaaS Security initiative, and then select Open Initiative Page.
The page that appears lists the 12 metrics that categorize hundreds of best-practice recommendations.
:::image type="content" source="media\saas-securty-initiative\screenshot-of-the-saas-security-initiative-home-page.png" alt-text="Screenshot of the SaaS Security Initiative home page." lightbox="media\saas-securty-initiative\screenshot-of-the-saas-security-initiative-home-page.png":::
We recommendStart with the metrics that you prioritize metrics withhave the highest Impact on Initiative Score level. This composite measure considers bothscore combines the Weight value of each recommendation anditem with the percentageshare of Non-Compliant recommendations.items.
To effectively monitortrack progress, set a target score value for your organization's security posture. ThisUse this target will serve as a benchmark for improvement and help track advancementsto measure gains over time.
For instance,example, to gain visibility into all best-practice recommendations that pertain toreview tips for privileged access withinin SaaS applications,apps, select the metric labeled Missing Best Practices to Secure Privileged Access in SaaS Apps. You can thenThen select any of the Non-Compliant recommendationsitem to accesssee the associated remediationfix steps.
Related resources for SaaS Security Initiative
The following information can help you interpretUse these resources to understand and extendbuild on the initiative results:
- Each metric
includes a list of associatedlists its linked app connectors.The list encourages organizations to enableEnable more connectors to get broader coverage. To see tips forenhanced visibility. If you're interested in recommendations fora specificapplications,app, go to the Security recommendations tab and filter bythe relevant application.that app. - To learn more about Microsoft Security Exposure Management initiatives, see Review security initiatives.
@@ -1,20 +1,22 @@ --- title: SaaS Security Initiative in Microsoft Defender XDR-description: Learn how to use the SaaS Security Initiative in Microsoft Defender XDR.+description: View and prioritize SaaS security posture management (SSPM) recommendations using the 12 metrics in the SaaS Security Initiative in Microsoft Defender XDR. ms.topic: how-to-ms.date: 06/16/2026+ms.date: 07/03/2026 ms.reviewer: iidogGedanken-ms.custom: sfi-image-nochange, msecd-doc-authoring-1014+ms.custom: sfi-image-nochange, msecd-doc-authoring-1016 ai-usage: ai-assisted --- # Use the SaaS Security Initiative in Defender for Cloud Apps +This article shows you how to view and prioritize SaaS security recommendations in Microsoft Defender XDR by using the SaaS Security Initiative. Before you start, make sure you meet the [prerequisites](#prerequisites).+ ## Overview of the SaaS Security Initiative -The SaaS Security Initiative provides a centralized place for software as a service (SaaS) security best practices, so that organizations can manage and prioritize security recommendations effectively. By focusing on the most impactful metrics, organizations can enhance their SaaS security posture.+The SaaS Security Initiative is the main hub for SaaS security posture management (SSPM). It gives you a central place to manage software as a service (SaaS) security best practices. -The SaaS Security Initiative serves as the main hub for SaaS security posture management (SSPM). It consolidates best-practice recommendations into 12 measurable metrics. These metrics facilitate the management and prioritization of a large number of security recommendations.+The initiative groups best-practice tips into 12 metrics. You can use these metrics to rank and act on security tasks. Focus on the metrics with the most impact to improve your SaaS security posture. ## How to use the SaaS Security Initiative @@ -24,32 +26,32 @@ Watch the following video for an overview of how to use the SaaS Security Initia ## Prerequisites -Before you view SaaS Security Initiative recommendations, ensure that the following prerequisites are met:+Before you view these recommendations, make sure you meet these requirements: - Your organization must have Microsoft Defender for Cloud Apps licenses.-- The app for which you want to view security recommendations must be connected to Defender for Cloud Apps. For information about connecting and about which of the app connectors provide security recommendations, see [Connect apps to get visibility and control with Microsoft Defender for Cloud Apps](enable-instant-visibility-protection-and-governance-actions-for-your-apps.md).+- The app you want to check must be connected to Defender for Cloud Apps. To learn how to connect apps and which connectors provide security tips, see [Connect apps to get visibility and control with Microsoft Defender for Cloud Apps](enable-instant-visibility-protection-and-governance-actions-for-your-apps.md). ## View SaaS Security Initiative recommendations To view SaaS Security Initiative recommendations, perform the following steps: -1. In Microsoft Defender XDR, go to **Exposure Management** and select **Initiatives**.+1. In the Defender portal, go to **Exposure Management** and select **Initiatives**. 1. Select the **SaaS Security** initiative, and then select **Open Initiative Page**. The page that appears lists the 12 metrics that categorize hundreds of best-practice recommendations. :::image type="content" source="media\saas-securty-initiative\screenshot-of-the-saas-security-initiative-home-page.png" alt-text="Screenshot of the SaaS Security Initiative home page." lightbox="media\saas-securty-initiative\screenshot-of-the-saas-security-initiative-home-page.png"::: -We recommend that you prioritize metrics with the highest **Impact on Initiative Score** level. This composite measure considers both the **Weight** value of each recommendation and the percentage of **Non-Compliant** recommendations.+Start with the metrics that have the highest **Impact on Initiative Score** level. This score combines the **Weight** of each item with the share of **Non-Compliant** items. -To effectively monitor progress, set a **target score** value for your organization's security posture. This target will serve as a benchmark for improvement and help track advancements over time.+To track progress, set a **target score** for your security posture. Use this target as a benchmark to measure gains over time. -For instance, to gain visibility into all best-practice recommendations that pertain to privileged access within SaaS applications, select the metric labeled **Missing Best Practices to Secure Privileged Access in SaaS Apps**. You can then select any of the **Non-Compliant** recommendations to access the associated remediation steps.+For example, to review tips for privileged access in SaaS apps, select **Missing Best Practices to Secure Privileged Access in SaaS Apps**. Then select any **Non-Compliant** item to see the fix steps. <a name="additional-information"></a> ## Related resources for SaaS Security Initiative -The following information can help you interpret and extend the initiative results:+Use these resources to understand and build on the initiative results: -- Each metric includes a list of associated app connectors. The list encourages organizations to enable more connectors for enhanced visibility. If you're interested in recommendations for specific applications, go to the **Security recommendations** tab and filter by the relevant application.+- Each metric lists its linked app connectors. Enable more connectors to get broader coverage. To see tips for a specific app, go to the **Security recommendations** tab and filter by that app. - To learn more about Microsoft Security Exposure Management initiatives, see [Review security initiatives](/security-exposure-management/initiatives). 