Forum Discussion

Felix87's avatar
Felix87
Copper Contributor
Feb 17, 2026

McasShadowItReporting / Cloud Discovery in Azure Sentinel

Hi!

I´m trying to Query the McasShadowItReporting Table, for Cloud App DISCOVERYs


The Table is empty at the moment, the connector is warning me that the Workspace is onboarded to Unified Security Operations Platform
So I cant activate it here

 

I cant mange it via https://security.microsoft.com/, too 

The Documentation ( https://learn.microsoft.com/en-us/defender-cloud-apps/siem-sentinel#integrating-with-microsoft-sentinel ) 

Leads me to the SIEM Integration, which is configured for (for a while) 

 


I wonder if something is misconfigured here and why there is no log ingress / how I can query them  

No RepliesBe the first to reply