How to find out if your endpoint traffic is steering through MCAS

Copper Contributor

Hi Fellowmates,

I just want to understand is there a way to find out how to check if your endpoint traffic is steering though MCAS other than seeing the URL showing mcas?
Like in Netskope if you type in search bar notskope.com you can get to know whether the traffic is steering through the casb/proxy or no, also it gives the datacenter the traffic is steering through.
Any provision in MS for this, please let me know

3 Replies
As of today, Defender for CLoud Apps offers a Reverse Proxy, not a forward proxy. This means that anything that does not have the .mcas.ms suffix is simply not proxied.
HOWEVER, through our integration with Defender for Endpoint, we are also able to block some web apps altogether, should you wish to do so.
We also have other offerings, such as Endpoint DLP, that would allow you to decide what kind of data goes out of your endpoints.
Hope this helps!
I understand, so other than the suffix there is not other way to know if the traffic is steering through MCAS or no?

@Ruben1996 as long as you did not setup a specific Conditional Access policy for the app, the traffic will not be proxied through Defender for Cloud apps. But in general: Yes - if the URL does not end with mcas.ms the traffic is not proxied.