Event details
If you're interested in learning more about Defender for Cloud Apps and have any questions around our SaaS capabilities or on SaaS Security in general, join our Ask Me Anything event to get your questions answered by our product experts!
An AMA is a live text-based online event similar to an "Ask Me Anything," on Reddit. This AMA gives you the opportunity to connect with members of the Defender for Cloud Apps product group who will be on hand to answer your questions and listen to feedback.
Feel free to post your questions about Defender for Cloud Apps anytime in the comments beforehand!
72 Comments
- JHandlerCopper ContributorWill we receive a link to download this AMA afterwards?
- Trevor_Rusher
Community Manager
Hi Jonathan! This event page will live on Tech Community under the same link in perpetuity, so feel free to bookmark it for reference!
- SMAC1157Copper ContributorIs the Defender for Mac sensor able to send the network cloud discovery data into MDCA as well? Right now seeing just Win10 with no other reports. Is it likely a Defender for Mac configuration issue?
- Itai_Cohen
Microsoft
Defender for Cloud Apps send cloud discovery data from Microsoft Defender for Endpoint to Microsoft Defender for Cloud Apps via Windows devices (Windows 10 and above). Note although we currently don't Discover MacOS traffic coming from Defender for Endpoint, we are able to block/warn on MacOS devices. We've heard a lot of feedback around the need for discovery on MacOS devices via Microsoft Defender for Endpoint. It is high on our list and and is something we are actively looking into. Stay tuned for updates on this!- SMAC1157Copper ContributorThanks!
- tanyaerringtonjonesCopper ContributorHello! I am a Business Architect, covering - data, technology and also applications. Where do I start, as a lead architect, on designing the blueprint for SaaS security based on Azure?
- Nir Hendler
Microsoft
Hey Tanya, My recommendation is that you start with reviewing more about the product overview and top SaaS Security use cases: https://learn.microsoft.com/en-us/defender-cloud-apps/what-is-defender-for-cloud-apps & https://securityhub.transform.microsoft.com/download/8aced378-e9d5-4647-8968-034239b63688- JonathanHoppCopper ContributorHow does one access the security hub? I just tried logging in with my corporate creds and I'm getting a Not Authorized message. Not sure what the requirements are to access Security Hub?
- cliffcorneyCopper ContributorGreat question Tanya, it's always a challenge to know where and how to begin.
- tanyaerringtonjonesCopper ContributorYes indeed. I think now with Microsoft 365 Defender - this is leverage for the client - to have a dashboard to detect vulnerabilities etc.
- Simona_Balabanova
Microsoft
Could you please elaborate on the value of app governance add-on as I know that an overview of the delegated permissions to applications can be downloaded from Azure AD, too, but without any cost?
- WendyLiuFormer Employee
The app governance add on provides much more info beyond just delegated permissions. Our value aligns to three pillars:
- Deep visibility & insights into app configuration & high-risk behaviors. Such as priority account access, sensitivity label access, what permissions are in use/not, how much data is being accessed and tailored KQL queries, and more
- Policy-driven governance for Azure-connected apps to meet security & compliance mandates for data access. Such as generate an alert for overprivileged apps, or set up a custom policy to automatically shut down apps that have accessed sensitivity labeled data for a particular workload over a particular threshold data volume
- Comprehensive ML-based detection & remediation of unusual app activity. We offer in built detections based on previously seen attack patterns. You can see a list of our active detections here https://learn.microsoft.com/en-us/defender-cloud-apps/app-governance-anomaly-detection-alerts
- WendyLiuFormer EmployeeIn case you'd like to learn more about the capabilities I mentioned above you can also take a look at our documentation! The trial user guide is a good place to start https://aka.ms/AppGTrialGuide
- grantnelCopper ContributorHey there! Is there any plan to add additional governance actions in cloud apps such as AWS, GCP, GitHub, etc.? We're currently using Trellix's CASB and it has the ability to quarantine sensitive files based on an exact data match. We'd love to migrate this to Microsoft but there isn't the ability to do so natively.
- Dan Michelson
Microsoft
Thanks Grant. It will be great to get more details about the entire need. We are prioritizing more capabilities to all the supported SaaS apps connectors. If there is a specific need, please share it with me directly. For cloud workloads like AWS we have different efforts that are covering them. The question from our side to you will be about the way you use them. Are you looking for a unified policy that will cover both SaaS apps and cloud workloads? Are you pointing only information protection policies or other policies too?- grantnelCopper ContributorWe'd be looking to use our existing EDM SITs to inspect files in locations such as AWS and quarantine if it finds matches. This is a capability that Trellix currently has and we'd love to be able to do the same with MDCA. We have this capability in MDCA for apps such as SharePoint/OneDrive, but the rest of the cloud apps lack the governance actions that those have, even GitHub which is owned by Microsoft.
- Simona_Balabanova
Microsoft
Hello! Often I hear feedback that the the risk scores of the applications in the cloud discovery page are not up to date. Hence, I am curious are planning on updating the risk scores that we currently provide for each app?- Maayan Bar-Niv
Microsoft
Great feedback, thank you, Simona! Defender for Cloud Apps has a rich catalog with many thousands of apps, and it is updated on an ongoing basis. Significant engineering efforts go into keeping the catalog up to date in terms of the apps that are covered and their risk scores. Are there specific apps that you feel are not up to date? We would love to hear more. There is also an in-product experience where you can request a score update. From discovered apps, click on “Request Score Update” in the top menu.- Itai_Cohen
Microsoft
For instructions how to request a score update see: https://learn.microsoft.com/en-us/defender-cloud-apps/risk-score#suggesting-a-change
- JHandlerCopper ContributorCan Microsoft Defender for Cloud Apps be an add-on for Microsoft Defender for Business within M365 Business Premium, and/or also Microsoft Defender for Business Standalone?
- Caroline_Lee
Microsoft
Hi Jonathan, thanks for so much for joining! Currently, Defender for Cloud Apps is not available as an add-on SKU for Microsoft Defender for Business (MDB) within M365 Business Premium or standalone. Happy to take this feedback to our MDB team, as its critical to have app protection for SMB.- JHandlerCopper ContributorCaroline, are there any electronic health record apps that are covered by Defender for Cloud Apps?
- Trevor_Rusher
Community Manager
Welcome to the Microsoft Defender for Cloud Apps SaaS Security AMA! This live hour gives you the opportunity to ask questions directly to the Microsoft team. Please post any questions in a separate, new comment thread on this event. Microsoft team- please introduce yourself on this thread to let the customers know who you are and what you do!- Yoann_David_Mallet
Microsoft
Hi all, David Mallet, Customer Experience Product Manager on Defender for Cloud Apps. Always happy to assist! - SharonNakibly
Microsoft
Hi everyone, my name is Sharon Nakibly. I am part of the Microsoft Defender for Cloud Apps product team, responsible for SOC experiences & threat protection domains. Excited to be here. - LeorHurwitz
Microsoft
Welcome, everyone. I am Leor Hurwitz, a product manager on the Defender for Cloud Apps team. Happy to help!
- pajenterprises1Copper ContributorWELCOME TO ALL ACROSS THE GLOBE
- Vusi_GCopper ContributorThank you, excited to contribute and learn.