Microsoft Defender for Cloud Apps
Cloud and workloads

SaaS Security Initiative in Microsoft Defender XDR

In brief

The article now emphasizes SSPM recommendations organized into 12 metrics, adds prerequisite guidance, and updates instructions for accessing, prioritizing, and tracking recommendations in the Defender portal.

What Defender admins need to know

Administrators can use the revised navigation and guidance to review metrics, target scores, connector coverage, and remediation steps. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Use the SaaS Security Initiative in Defender for Cloud Apps

This article shows you how to view and prioritize SaaS security recommendations in Microsoft Defender XDR by using the SaaS Security Initiative. Before you start, make sure you meet the prerequisites.

Overview of the SaaS Security Initiative

The SaaS Security Initiative provides a centralized place for software as a service (SaaS) security best practices, so that organizations can manage and prioritize security recommendations effectively. By focusing on the most impactful metrics, organizations can enhance their SaaS security posture.

The SaaS Security Initiative serves asis the main hub for SaaS security posture management (SSPM). It consolidatesgives you a central place to manage software as a service (SaaS) security best practices.

The initiative groups best-practice recommendationstips into 12 measurable metrics. TheseYou can use these metrics facilitateto rank and act on security tasks. Focus on the management and prioritization of a large number ofmetrics with the most impact to improve your SaaS security recommendations.posture.

How to use the SaaS Security Initiative

Prerequisites

Before you view SaaS Security Initiativethese recommendations, ensure that the following prerequisites are met:make sure you meet these requirements:

  • Your organization must have Microsoft Defender for Cloud Apps licenses.
  • The app for which you want to view security recommendationscheck must be connected to Defender for Cloud Apps. For information about connectingTo learn how to connect apps and about which of the app connectors provide security recommendations,tips, see Connect apps to get visibility and control with Microsoft Defender for Cloud Apps.

View SaaS Security Initiative recommendations

To view SaaS Security Initiative recommendations, perform the following steps:

  1. In Microsoftthe Defender XDR,portal, go to Exposure Management and select Initiatives.
  2. Select the SaaS Security initiative, and then select Open Initiative Page.

The page that appears lists the 12 metrics that categorize hundreds of best-practice recommendations.

:::image type="content" source="media\saas-securty-initiative\screenshot-of-the-saas-security-initiative-home-page.png" alt-text="Screenshot of the SaaS Security Initiative home page." lightbox="media\saas-securty-initiative\screenshot-of-the-saas-security-initiative-home-page.png":::

We recommendStart with the metrics that you prioritize metrics withhave the highest Impact on Initiative Score level. This composite measure considers bothscore combines the Weight value of each recommendation anditem with the percentageshare of Non-Compliant recommendations.items.

To effectively monitortrack progress, set a target score value for your organization's security posture. ThisUse this target will serve as a benchmark for improvement and help track advancementsto measure gains over time.

For instance,example, to gain visibility into all best-practice recommendations that pertain toreview tips for privileged access withinin SaaS applications,apps, select the metric labeled Missing Best Practices to Secure Privileged Access in SaaS Apps. You can thenThen select any of the Non-Compliant recommendationsitem to accesssee the associated remediationfix steps.

Related resources for SaaS Security Initiative

The following information can help you interpretUse these resources to understand and extendbuild on the initiative results:

  • Each metric includes a list of associatedlists its linked app connectors. The list encourages organizations to enableEnable more connectors to get broader coverage. To see tips for enhanced visibility. If you're interested in recommendations fora specific applications,app, go to the Security recommendations tab and filter by the relevant application.that app.
  • To learn more about Microsoft Security Exposure Management initiatives, see Review security initiatives.