Event details

If you're interested in learning more about Defender for Cloud Apps and have any questions around our SaaS capabilities or on SaaS Security in general, join our Ask Me Anything event to get your questions answered by our product experts!

An AMA is a live text-based online event similar to an "Ask Me Anything," on Reddit. This AMA gives you the opportunity to connect with members of the Defender for Cloud Apps product group who will be on hand to answer your questions and listen to feedback.

Feel free to post your questions about Defender for Cloud Apps anytime in the comments beforehand!

Trevor_Rusher
Updated Feb 21, 2023

72 Comments

  • JHandler's avatar
    JHandler
    Copper Contributor
    Will we receive a link to download this AMA afterwards?
    • Trevor_Rusher's avatar
      Trevor_Rusher
      Icon for Community Manager rankCommunity Manager
      Hi Jonathan! This event page will live on Tech Community under the same link in perpetuity, so feel free to bookmark it for reference!
  • SMAC1157's avatar
    SMAC1157
    Copper Contributor
    Is the Defender for Mac sensor able to send the network cloud discovery data into MDCA as well? Right now seeing just Win10 with no other reports. Is it likely a Defender for Mac configuration issue?
    • Itai_Cohen's avatar
      Itai_Cohen
      Icon for Microsoft rankMicrosoft
      Defender for Cloud Apps send cloud discovery data from Microsoft Defender for Endpoint to Microsoft Defender for Cloud Apps via Windows devices (Windows 10 and above). Note although we currently don't Discover MacOS traffic coming from Defender for Endpoint, we are able to block/warn on MacOS devices. We've heard a lot of feedback around the need for discovery on MacOS devices via Microsoft Defender for Endpoint. It is high on our list and and is something we are actively looking into. Stay tuned for updates on this! 
  • Hello! I am a Business Architect, covering - data, technology and also applications. Where do I start, as a lead architect, on designing the blueprint for SaaS security based on Azure?
  • Could you please elaborate on the value of app governance add-on as I know that an overview of the delegated permissions to applications can be downloaded from Azure AD, too, but without any cost?

    • WendyLiu's avatar
      WendyLiu
      Former Employee

      The app governance add on provides much more info beyond just delegated permissions. Our value aligns to three pillars:

      • Deep visibility & insights into app configuration & high-risk behaviors. Such as priority account access, sensitivity label access, what permissions are in use/not, how much data is being accessed and tailored KQL queries, and more
      • Policy-driven governance for Azure-connected apps to meet security & compliance mandates for data access. Such as generate an alert for overprivileged apps, or set up a custom policy to automatically shut down apps that have accessed sensitivity labeled data for a particular workload over a particular threshold data volume
      • Comprehensive ML-based detection & remediation of unusual app activity. We offer in built detections based on previously seen attack patterns. You can see a list of our active detections here https://learn.microsoft.com/en-us/defender-cloud-apps/app-governance-anomaly-detection-alerts
      • WendyLiu's avatar
        WendyLiu
        Former Employee
        In case you'd like to learn more about the capabilities I mentioned above you can also take a look at our documentation! The trial user guide is a good place to start https://aka.ms/AppGTrialGuide
  • grantnel's avatar
    grantnel
    Copper Contributor
    Hey there! Is there any plan to add additional governance actions in cloud apps such as AWS, GCP, GitHub, etc.? We're currently using Trellix's CASB and it has the ability to quarantine sensitive files based on an exact data match. We'd love to migrate this to Microsoft but there isn't the ability to do so natively.
    • Dan Michelson's avatar
      Dan Michelson
      Icon for Microsoft rankMicrosoft
      Thanks Grant. It will be great to get more details about the entire need. We are prioritizing more capabilities to all the supported SaaS apps connectors. If there is a specific need, please share it with me directly. For cloud workloads like AWS we have different efforts that are covering them. The question from our side to you will be about the way you use them. Are you looking for a unified policy that will cover both SaaS apps and cloud workloads? Are you pointing only information protection policies or other policies too?
      • grantnel's avatar
        grantnel
        Copper Contributor
        We'd be looking to use our existing EDM SITs to inspect files in locations such as AWS and quarantine if it finds matches. This is a capability that Trellix currently has and we'd love to be able to do the same with MDCA. We have this capability in MDCA for apps such as SharePoint/OneDrive, but the rest of the cloud apps lack the governance actions that those have, even GitHub which is owned by Microsoft.
  • Hello! Often I hear feedback that the the risk scores of the applications in the cloud discovery page are not up to date. Hence, I am curious are planning on updating the risk scores that we currently provide for each app?
    • Maayan Bar-Niv's avatar
      Maayan Bar-Niv
      Icon for Microsoft rankMicrosoft
      Great feedback, thank you, Simona! Defender for Cloud Apps has a rich catalog with many thousands of apps, and it is updated on an ongoing basis. Significant engineering efforts go into keeping the catalog up to date in terms of the apps that are covered and their risk scores. Are there specific apps that you feel are not up to date? We would love to hear more. There is also an in-product experience where you can request a score update. From discovered apps, click on “Request Score Update” in the top menu.
  • JHandler's avatar
    JHandler
    Copper Contributor
    Can Microsoft Defender for Cloud Apps be an add-on for Microsoft Defender for Business within M365 Business Premium, and/or also Microsoft Defender for Business Standalone?
    • Caroline_Lee's avatar
      Caroline_Lee
      Icon for Microsoft rankMicrosoft
      Hi Jonathan, thanks for so much for joining! Currently, Defender for Cloud Apps is not available as an add-on SKU for Microsoft Defender for Business (MDB) within M365 Business Premium or standalone. Happy to take this feedback to our MDB team, as its critical to have app protection for SMB.
      • JHandler's avatar
        JHandler
        Copper Contributor
        Caroline, are there any electronic health record apps that are covered by Defender for Cloud Apps?
  • Trevor_Rusher's avatar
    Trevor_Rusher
    Icon for Community Manager rankCommunity Manager
    Welcome to the Microsoft Defender for Cloud Apps SaaS Security AMA! This live hour gives you the opportunity to ask questions directly to the Microsoft team. Please post any questions in a separate, new comment thread on this event. Microsoft team- please introduce yourself on this thread to let the customers know who you are and what you do!
    • Yoann_David_Mallet's avatar
      Yoann_David_Mallet
      Icon for Microsoft rankMicrosoft
      Hi all, David Mallet, Customer Experience Product Manager on Defender for Cloud Apps. Always happy to assist!
    • SharonNakibly's avatar
      SharonNakibly
      Icon for Microsoft rankMicrosoft
      Hi everyone, my name is Sharon Nakibly. I am part of the Microsoft Defender for Cloud Apps product team, responsible for SOC experiences & threat protection domains. Excited to be here.
    • LeorHurwitz's avatar
      LeorHurwitz
      Icon for Microsoft rankMicrosoft
      Welcome, everyone. I am Leor Hurwitz, a product manager on the Defender for Cloud Apps team. Happy to help!
    • Vusi_G's avatar
      Vusi_G
      Copper Contributor
      Thank you, excited to contribute and learn.