Microsoft Defender for Cloud Apps
Cloud and workloads

View discovered apps on the Cloud discovery dashboard | Microsoft Defender for Cloud Apps

In brief

The page updates metadata, clarifies unsanctioning and blocking discovered apps, restates the discovered-subdomain support cutoff, renames the cloud discovery data section, and reformats related links.

What Defender admins need to know

Administrators get clearer action wording and navigation; the page reiterates that discovered subdomains have no support after December 31, 2025.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

To dive deeper in to cloud discovery data, use the filters to check for risky or commonly used apps.

For example, if you want to identify commonly used, risky cloud storage and collaboration apps, use the Discovered apps page to filter for the apps you want. Then, unsanction or block discovered apps those apps as follows:

  1. In the Microsoft Defender portal, under Cloud Apps, select Cloud discovery. Then choose the Discovered apps tab.

    :::image type="content" source="media/discovered-app-filters.png" alt-text="Screenshot of discovered app filters." lightbox="media/discovered-app-filters.png":::

After the results are filtered, unsanction and block discovered apps the filtered apps by using the bulk action checkbox to unsanction all of those apps in one action. Once the apps are unsanctioned, use a blocking script to block those apps from being used in your environment.

You also might want to identify specific app instances that are in use by investigating the discovered subdomains. For example, differentiate between different SharePoint sites:

:::image type="content" source="media/discovered-apps/subdomains-image.png" alt-text="Subdomain filter.":::

DeletingDelete cloud discovery data

We recommend deleting cloud discovery data in the following cases:

Next steps

[!div class="nextstepaction"]

[!div class="nextstepaction"]

  • Configure automatic log upload for continuous reports

  • [!div class="nextstepaction"]

  • Work with cloud discovery data

  • [!div class="nextstepaction"]

  • Discover apps with Defender for Endpoint integration