1
00:00:00,000 --> 00:00:03,640
Welcome to another episode of Microsoft Knowledge Nuggets on M365.

2
00:00:03,640 --> 00:00:05,320
FM, I'm your host, Mirko Peters.

3
00:00:05,320 --> 00:00:07,720
Today's topic is one that almost everyone is heard of,

4
00:00:07,720 --> 00:00:09,840
but very few people actually understand.

5
00:00:09,840 --> 00:00:11,600
Microsoft Defender for Cloud Apps.

6
00:00:11,600 --> 00:00:14,440
It sounds like another security product you're supposed to buy,

7
00:00:14,440 --> 00:00:16,240
configure, and then forget about.

8
00:00:16,240 --> 00:00:19,360
But here's the thing, most businesses have no idea which Cloud Apps

9
00:00:19,360 --> 00:00:21,640
their employees are actually using, and I mean no idea.

10
00:00:21,640 --> 00:00:23,360
You probably know about the official ones.

11
00:00:23,360 --> 00:00:26,400
The Microsoft 365 subscription, maybe Salesforce or Dropbox

12
00:00:26,400 --> 00:00:27,760
if IT gave the green light.

13
00:00:27,800 --> 00:00:29,960
But what about the other ones, the free file sharing side,

14
00:00:29,960 --> 00:00:31,640
someone in Accounting Found last week,

15
00:00:31,640 --> 00:00:33,960
the AI writing tool, the marketing team started using

16
00:00:33,960 --> 00:00:36,120
without telling anyone, the project management app

17
00:00:36,120 --> 00:00:38,120
that just showed up on someone's browser one day,

18
00:00:38,120 --> 00:00:39,800
those are the apps you don't know about.

19
00:00:39,800 --> 00:00:41,800
And they're the ones that cause real problems.

20
00:00:41,800 --> 00:00:43,920
By the end of this episode, you'll understand

21
00:00:43,920 --> 00:00:46,320
what Defender for Cloud Apps actually is,

22
00:00:46,320 --> 00:00:49,360
why it matters for your business, and how it works.

23
00:00:49,360 --> 00:00:51,400
Without needing to touch a single setting.

24
00:00:51,400 --> 00:00:54,280
This is a plain English overview, no technical deep dives,

25
00:00:54,280 --> 00:00:55,920
no admin console walkthroughs,

26
00:00:55,960 --> 00:00:57,960
just the big picture explained clearly.

27
00:00:57,960 --> 00:01:00,000
So grab your coffee and let's dive in.

28
00:01:00,000 --> 00:01:03,280
The blind spot in your cloud, here's what actually happens every single day.

29
00:01:03,280 --> 00:01:05,720
Employees in your organization sign up for cloud services

30
00:01:05,720 --> 00:01:08,160
without telling anyone, they do it because it's faster.

31
00:01:08,160 --> 00:01:11,280
They need to send a large file, so they use a free file sharing app.

32
00:01:11,280 --> 00:01:13,000
They want to collaborate on a document,

33
00:01:13,000 --> 00:01:15,600
so they create an account on some online whiteboard tool.

34
00:01:15,600 --> 00:01:17,240
They hear about a new AI assistant,

35
00:01:17,240 --> 00:01:19,600
so they sign up and start feeding it company data.

36
00:01:19,600 --> 00:01:20,960
Let me give you a concrete example.

37
00:01:20,960 --> 00:01:24,720
Imagine someone in marketing needs to send a large presentation to a client.

38
00:01:24,760 --> 00:01:28,000
The file is too big for email, so they search for free file transfer

39
00:01:28,000 --> 00:01:29,360
and pick the first result.

40
00:01:29,360 --> 00:01:30,800
They upload the presentation,

41
00:01:30,800 --> 00:01:34,400
which contains next quarter's pricing strategy and share the link done.

42
00:01:34,400 --> 00:01:35,400
Problem solved, right?

43
00:01:35,400 --> 00:01:36,240
Not quite.

44
00:01:36,240 --> 00:01:39,320
That free file sharing app might not have any security controls,

45
00:01:39,320 --> 00:01:42,320
no encryption, no audit trail, no data retention policy.

46
00:01:42,320 --> 00:01:45,680
The company behind it might be based in a country with weak data protection laws.

47
00:01:45,680 --> 00:01:49,040
And once that file is uploaded, you have no idea who accesses it,

48
00:01:49,040 --> 00:01:51,880
where it gets downloaded, or whether it gets forwarded to someone else.

49
00:01:51,880 --> 00:01:54,640
This is what security experts call shadow IT.

50
00:01:54,680 --> 00:01:58,320
In plain English, shadow IT means using software or services at work

51
00:01:58,320 --> 00:02:00,400
without the IT department knowing about it.

52
00:02:00,400 --> 00:02:01,800
And it's more common than you think.

53
00:02:01,800 --> 00:02:02,880
So why should you care?

54
00:02:02,880 --> 00:02:04,000
Three big reasons.

55
00:02:04,000 --> 00:02:08,480
First, data leakage, your sensitive information ends up on service you don't control.

56
00:02:08,480 --> 00:02:10,280
Second, compliance violations.

57
00:02:10,280 --> 00:02:13,440
If you're subject to regulations like GDPR or HIPAA,

58
00:02:13,440 --> 00:02:17,040
using an app that doesn't meet those standards puts you in violation.

59
00:02:17,040 --> 00:02:18,680
Third, unknown risk.

60
00:02:18,680 --> 00:02:21,320
Every unapproved app is a potential entry point for an attacker

61
00:02:21,320 --> 00:02:23,760
because you can't protect what you can't see.

62
00:02:23,800 --> 00:02:25,960
The old way of solving this was impossible.

63
00:02:25,960 --> 00:02:27,680
You couldn't see what you couldn't control.

64
00:02:27,680 --> 00:02:29,720
You might block certain websites at the firewall,

65
00:02:29,720 --> 00:02:33,360
but employees working from home on their phones were just bypass those restrictions.

66
00:02:33,360 --> 00:02:35,640
You might ask people to only use approved apps,

67
00:02:35,640 --> 00:02:38,440
but that relied on everyone following the rules, which they didn't.

68
00:02:38,440 --> 00:02:41,640
And even if they did, new apps appeared every day that you never knew about.

69
00:02:41,640 --> 00:02:42,440
So what do you do?

70
00:02:42,440 --> 00:02:44,480
You need a tool that actually sees what's happening,

71
00:02:44,480 --> 00:02:46,680
a tool designed to shine a light on the shadows

72
00:02:46,680 --> 00:02:49,400
that's exactly what Defender for Cloud Apps is built to do.

73
00:02:49,400 --> 00:02:51,120
What is Defender for Cloud Apps?

74
00:02:51,120 --> 00:02:53,000
What exactly is Defender for Cloud Apps?

75
00:02:53,040 --> 00:02:54,320
Here's the simplest definition.

76
00:02:54,320 --> 00:02:58,640
It's a security guard that watches every connection between your users and the Cloud Apps they use.

77
00:02:58,640 --> 00:03:01,960
Checks who's using what flags anything suspicious.

78
00:03:01,960 --> 00:03:05,720
The technical name is Cloud Access Security Broker or CSB.

79
00:03:05,720 --> 00:03:07,120
But we're sticking with plain English.

80
00:03:07,120 --> 00:03:08,000
Think of it this way.

81
00:03:08,000 --> 00:03:10,160
Your business is a building with lots of doors.

82
00:03:10,160 --> 00:03:12,280
Each Cloud app is one of those doors.

83
00:03:12,280 --> 00:03:13,240
Some are safe.

84
00:03:13,240 --> 00:03:15,800
They lead to well-lit rooms with security cameras.

85
00:03:15,800 --> 00:03:17,400
Others lead to dark alleys.

86
00:03:17,400 --> 00:03:19,360
Defender for Cloud Apps stands at each door,

87
00:03:19,360 --> 00:03:21,400
checks who's coming in, what they're carrying,

88
00:03:21,440 --> 00:03:23,120
and whether they should be there at all.

89
00:03:23,120 --> 00:03:24,240
So what does it actually do?

90
00:03:24,240 --> 00:03:26,840
It finds every Cloud app being used in your company,

91
00:03:26,840 --> 00:03:28,400
whether you approved it or not,

92
00:03:28,400 --> 00:03:31,120
tells you how risky each app is based on security features,

93
00:03:31,120 --> 00:03:33,440
compliance certifications and legal policies,

94
00:03:33,440 --> 00:03:37,000
watches how people use those apps and flags on usual activity.

95
00:03:37,000 --> 00:03:39,000
And if something's dangerous, it can block it.

96
00:03:39,000 --> 00:03:41,080
Defender for Cloud Apps doesn't work alone.

97
00:03:41,080 --> 00:03:43,160
It's part of the Microsoft Defender suite,

98
00:03:43,160 --> 00:03:45,000
a collection of security tools,

99
00:03:45,000 --> 00:03:48,120
shares information with Defender for Endpoint for Device Protection,

100
00:03:48,160 --> 00:03:51,640
connects to Microsoft Enter ID for user identity management.

101
00:03:51,640 --> 00:03:54,120
Integrates with Microsoft Sentinel for enterprise security,

102
00:03:54,120 --> 00:03:56,280
but for now, just know it's one piece of a bigger system

103
00:03:56,280 --> 00:03:57,720
protecting your entire environment.

104
00:03:57,720 --> 00:04:00,800
That's the big picture, but how does it actually find those hidden apps?

105
00:04:00,800 --> 00:04:02,600
That's where Cloud Discovery comes in.

106
00:04:02,600 --> 00:04:04,880
Cloud Discovery, seeing the invisible.

107
00:04:04,880 --> 00:04:07,920
So how does Defender for Cloud Apps find those hidden apps?

108
00:04:07,920 --> 00:04:09,520
Through a feature called Cloud Discovery.

109
00:04:09,520 --> 00:04:11,040
It does exactly what it sounds like.

110
00:04:11,040 --> 00:04:14,240
Discovers every Cloud app in use across your organization,

111
00:04:14,240 --> 00:04:15,960
whether IT approved it or not.

112
00:04:16,000 --> 00:04:18,760
There are two ways this works and it depends on your license.

113
00:04:18,760 --> 00:04:21,320
The full version integrates directly with Microsoft Defender

114
00:04:21,320 --> 00:04:23,280
for Endpoint on your company devices.

115
00:04:23,280 --> 00:04:26,840
One setup, Cloud Discovery runs continuously and automatically.

116
00:04:26,840 --> 00:04:28,480
Reports everything it finds.

117
00:04:28,480 --> 00:04:31,720
Every app someone accesses, every login, every file upload,

118
00:04:31,720 --> 00:04:32,960
constant monitoring.

119
00:04:32,960 --> 00:04:35,520
The business premium version is different, less seamless.

120
00:04:35,520 --> 00:04:37,000
Instead of automatic integration,

121
00:04:37,000 --> 00:04:39,920
you upload log files from your firewall or network proxy,

122
00:04:39,920 --> 00:04:43,480
export traffic logs, upload them to Defender and it analyzes them.

123
00:04:43,520 --> 00:04:46,320
It gives you a snapshot of what apps were accessed during that period.

124
00:04:46,320 --> 00:04:48,080
Not a live feed, but it still works.

125
00:04:48,080 --> 00:04:50,600
For many small businesses, it's the only option.

126
00:04:50,600 --> 00:04:52,920
Once Cloud Discovery is running, you get a dashboard.

127
00:04:52,920 --> 00:04:55,080
Shows total apps used across your organization.

128
00:04:55,080 --> 00:04:57,600
How many users accessed them, which IP addresses?

129
00:04:57,600 --> 00:04:59,160
How much traffic they generated?

130
00:04:59,160 --> 00:05:02,120
You can filter by risk level, category, location or user.

131
00:05:02,120 --> 00:05:03,400
See exactly what's happening.

132
00:05:03,400 --> 00:05:04,640
Here's a real scenario.

133
00:05:04,640 --> 00:05:08,160
You discover 10 people in your company are using a file sharing app

134
00:05:08,160 --> 00:05:10,800
hosted in a country with weak data protection laws.

135
00:05:10,800 --> 00:05:12,520
You didn't approve it, nobody asked.

136
00:05:12,560 --> 00:05:15,600
But now you know, before Cloud Discovery, that app was invisible.

137
00:05:15,600 --> 00:05:16,680
Now you see it clearly.

138
00:05:16,680 --> 00:05:18,400
That visibility changes everything.

139
00:05:18,400 --> 00:05:20,200
You stop guessing and start knowing.

140
00:05:20,200 --> 00:05:23,640
And once you know, you can do something about it.

141
00:05:23,640 --> 00:05:26,120
The app catalog, risk scoring made simple.

142
00:05:26,120 --> 00:05:27,360
So you found all those apps.

143
00:05:27,360 --> 00:05:29,160
Now you need to know which ones are safe.

144
00:05:29,160 --> 00:05:30,720
That's where the app catalog steps in.

145
00:05:30,720 --> 00:05:34,120
Microsoft has already checked over 31,000 cloud apps

146
00:05:34,120 --> 00:05:35,880
against more than 90 risk factors.

147
00:05:35,880 --> 00:05:36,880
That's a lot of homework.

148
00:05:36,880 --> 00:05:39,200
Each app gets a risk score from 0 to 10.

149
00:05:39,200 --> 00:05:39,960
10 is the safest.

150
00:05:39,960 --> 00:05:41,600
0 means stay far away.

151
00:05:41,640 --> 00:05:42,880
What exactly are they checking?

152
00:05:42,880 --> 00:05:43,560
Three things.

153
00:05:43,560 --> 00:05:45,400
First, security features.

154
00:05:45,400 --> 00:05:47,000
Does the app support encryption?

155
00:05:47,000 --> 00:05:49,320
Does it offer multi factor authentication?

156
00:05:49,320 --> 00:05:50,600
Does it keep an audit trail?

157
00:05:50,600 --> 00:05:52,440
Second, compliance certifications.

158
00:05:52,440 --> 00:05:56,680
Is it certified for ISO 27001, SOC2 or GDPR?

159
00:05:56,680 --> 00:05:57,920
Third, legal policies.

160
00:05:57,920 --> 00:05:59,320
Who owns the data you store there?

161
00:05:59,320 --> 00:06:00,640
What happens if you stop paying?

162
00:06:00,640 --> 00:06:02,320
What privacy protections exist?

163
00:06:02,320 --> 00:06:04,920
Think of it like a restaurant health inspection school.

164
00:06:04,920 --> 00:06:07,360
You wouldn't eat at a place with a score of 2 out of 10.

165
00:06:07,360 --> 00:06:08,200
Same logic here.

166
00:06:08,200 --> 00:06:10,840
You want to know the kitchen is clean before your employees eat there.

167
00:06:10,880 --> 00:06:13,440
Once you know an app's score, you have three choices.

168
00:06:13,440 --> 00:06:14,600
You can sanction it.

169
00:06:14,600 --> 00:06:16,160
That means you approve it for use.

170
00:06:16,160 --> 00:06:18,560
You can un-sanction it and that blocks it completely.

171
00:06:18,560 --> 00:06:19,720
Or you can monitor it.

172
00:06:19,720 --> 00:06:20,880
Let people keep using it.

173
00:06:20,880 --> 00:06:23,360
But watch it closely and maybe show a warning that says

174
00:06:23,360 --> 00:06:25,840
this app hasn't been reviewed for security.

175
00:06:25,840 --> 00:06:27,560
The catalog updates continuously.

176
00:06:27,560 --> 00:06:29,200
New apps get added all the time.

177
00:06:29,200 --> 00:06:30,520
And as Microsoft learns more,

178
00:06:30,520 --> 00:06:32,760
maybe the app gets a new security certification

179
00:06:32,760 --> 00:06:34,800
or a data breach reveals a vulnerability.

180
00:06:34,800 --> 00:06:36,720
The risk score updates automatically.

181
00:06:36,720 --> 00:06:38,560
So you never work with stale information.

182
00:06:38,560 --> 00:06:40,280
Discovery gives you visibility.

183
00:06:40,320 --> 00:06:42,000
The catalog gives you context.

184
00:06:42,000 --> 00:06:44,600
Together they tell you what's out there and how risky it is.

185
00:06:44,600 --> 00:06:46,760
But knowing isn't the same as doing.

186
00:06:46,760 --> 00:06:48,160
The real power comes next.

187
00:06:48,160 --> 00:06:49,960
Automated protection.

188
00:06:49,960 --> 00:06:51,480
Policies and threat detection.

189
00:06:51,480 --> 00:06:52,880
So you've discovered the apps.

190
00:06:52,880 --> 00:06:54,080
You've checked their risk scores.

191
00:06:54,080 --> 00:06:54,800
Now what?

192
00:06:54,800 --> 00:06:57,400
Defender for Cloud Apps comes with built-in policies

193
00:06:57,400 --> 00:06:59,880
that watch for suspicious behavior automatically.

194
00:06:59,880 --> 00:07:01,240
You don't need to configure much.

195
00:07:01,240 --> 00:07:03,080
The system already knows what to look for.

196
00:07:03,080 --> 00:07:05,080
Let me give you some examples of what it detects.

197
00:07:05,080 --> 00:07:05,880
Impossible travel.

198
00:07:05,880 --> 00:07:07,200
This one is straightforward.

199
00:07:07,240 --> 00:07:10,320
Imagine a user logs in from New York at 9 a.m.

200
00:07:10,320 --> 00:07:13,400
Then 10 minutes later, the same user logs in from Tokyo.

201
00:07:13,400 --> 00:07:14,320
That's impossible.

202
00:07:14,320 --> 00:07:16,680
You can't get from New York to Tokyo in 10 minutes.

203
00:07:16,680 --> 00:07:17,680
So something is wrong.

204
00:07:17,680 --> 00:07:19,440
Either someone stole that user's password

205
00:07:19,440 --> 00:07:20,560
or they're using a VPN

206
00:07:20,560 --> 00:07:22,400
that makes it look like they're somewhere they're not.

207
00:07:22,400 --> 00:07:23,880
Either way, Defender flags it.

208
00:07:23,880 --> 00:07:25,320
Mass downloads or deletions.

209
00:07:25,320 --> 00:07:27,480
If someone suddenly downloads hundreds of files

210
00:07:27,480 --> 00:07:29,720
from SharePoint or OneDrive, that's unusual.

211
00:07:29,720 --> 00:07:31,960
If they delete a bunch of data all at once,

212
00:07:31,960 --> 00:07:32,800
that's also unusual.

213
00:07:32,800 --> 00:07:34,760
These could be signs of a disgruntled employee

214
00:07:34,800 --> 00:07:37,720
about to leave or an attacker trying to steal or destroy data

215
00:07:37,720 --> 00:07:38,960
before they get caught.

216
00:07:38,960 --> 00:07:40,640
Logins from risky IP addresses.

217
00:07:40,640 --> 00:07:42,760
Some IP addresses are known to be dangerous.

218
00:07:42,760 --> 00:07:44,800
They might belong to countries under sanctions.

219
00:07:44,800 --> 00:07:47,120
They might be associated with known hacking groups.

220
00:07:47,120 --> 00:07:49,280
When a login comes from one of these addresses,

221
00:07:49,280 --> 00:07:51,080
Defender raises an alert.

222
00:07:51,080 --> 00:07:52,920
Suspicious email forwarding rules.

223
00:07:52,920 --> 00:07:54,640
This is a common hacker tactic.

224
00:07:54,640 --> 00:07:56,920
They compromise an email account and set up a rule

225
00:07:56,920 --> 00:08:00,240
that forwards all incoming messages to an external address.

226
00:08:00,240 --> 00:08:03,120
That way they can read every email that person receives

227
00:08:03,160 --> 00:08:05,120
without logging into their account again.

228
00:08:05,120 --> 00:08:07,840
Defender can spot when a new forwarding rule is created

229
00:08:07,840 --> 00:08:09,160
and flag it immediately.

230
00:08:09,160 --> 00:08:10,920
How does it know what's normal and what's not?

231
00:08:10,920 --> 00:08:13,800
It uses something called user and entity behavior analytics,

232
00:08:13,800 --> 00:08:15,160
UEBA for short.

233
00:08:15,160 --> 00:08:17,680
The system learns what normal looks like for each person

234
00:08:17,680 --> 00:08:18,840
in your organization.

235
00:08:18,840 --> 00:08:21,040
It watches their patterns over time.

236
00:08:21,040 --> 00:08:23,400
Where they log in from, what time of day they work,

237
00:08:23,400 --> 00:08:25,240
how many files they typically access.

238
00:08:25,240 --> 00:08:28,560
Once it understands the baseline, it can spot deviations.

239
00:08:28,560 --> 00:08:29,960
And when it does, it takes action.

240
00:08:29,960 --> 00:08:32,640
The system can automatically respond in several ways.

241
00:08:32,680 --> 00:08:34,480
It can send an alert to the IT team.

242
00:08:34,480 --> 00:08:35,800
It can suspend the user's account.

243
00:08:35,800 --> 00:08:38,360
It can block the suspicious activity entirely.

244
00:08:38,360 --> 00:08:40,360
You decide how aggressive you want to be.

245
00:08:40,360 --> 00:08:43,160
You can also create custom policies for your specific needs.

246
00:08:43,160 --> 00:08:44,920
Maybe you want to be alerted any time someone

247
00:08:44,920 --> 00:08:47,600
from the finance team accesses files after midnight.

248
00:08:47,600 --> 00:08:50,200
Maybe you want to block all downloads from a particular app.

249
00:08:50,200 --> 00:08:51,760
You can build those rules yourself.

250
00:08:51,760 --> 00:08:53,240
Here's a real world scenario.

251
00:08:53,240 --> 00:08:55,760
A busy executive gets an email that looks legitimate.

252
00:08:55,760 --> 00:08:57,880
They click a link, their credentials get stolen.

253
00:08:57,880 --> 00:09:00,640
Within minutes, the attacker logs in from a different country.

254
00:09:00,640 --> 00:09:02,640
Defender spots the impossible travel

255
00:09:02,640 --> 00:09:05,200
checks the IP address against known threat databases

256
00:09:05,200 --> 00:09:07,120
and automatically disables the account.

257
00:09:07,120 --> 00:09:08,600
The IT team gets an alert.

258
00:09:08,600 --> 00:09:10,240
The executive gets a notification.

259
00:09:10,240 --> 00:09:12,760
The attacker stopped before any real damage happens.

260
00:09:12,760 --> 00:09:16,000
Policies cover threats, but what about protecting the data itself?

261
00:09:16,000 --> 00:09:17,840
Data protection and access control.

262
00:09:17,840 --> 00:09:19,680
So policies catch suspicious behavior,

263
00:09:19,680 --> 00:09:22,000
but Defender also protects the data itself.

264
00:09:22,000 --> 00:09:24,880
The files and documents your employees work with every day.

265
00:09:24,880 --> 00:09:27,160
Defender monitors file sharing to stop sensitive data

266
00:09:27,160 --> 00:09:28,640
from leaving your organization

267
00:09:28,640 --> 00:09:30,920
and it hooks into Microsoft Information Protection.

268
00:09:30,960 --> 00:09:33,760
The system behind those sensitivity labels you've seen.

269
00:09:33,760 --> 00:09:37,000
Confidential, internal only, highly confidential.

270
00:09:37,000 --> 00:09:38,440
Based on what a file contains,

271
00:09:38,440 --> 00:09:40,680
Defender can apply those labels automatically.

272
00:09:40,680 --> 00:09:41,480
Here's an example.

273
00:09:41,480 --> 00:09:43,720
Someone tries to share a confidential document

274
00:09:43,720 --> 00:09:44,920
to their personal email.

275
00:09:44,920 --> 00:09:48,040
They're working from home and want to finish something on their personal laptop.

276
00:09:48,040 --> 00:09:50,600
Defender spots the attempt and blocks the share entirely

277
00:09:50,600 --> 00:09:53,760
or applies a label that makes the file unreadable outside the company.

278
00:09:53,760 --> 00:09:55,720
Either way, that document stays protected.

279
00:09:55,720 --> 00:09:57,520
You also get conditional access app control,

280
00:09:57,520 --> 00:09:59,840
which gives you real time controls inside apps.

281
00:09:59,880 --> 00:10:03,120
You can block, cut, copy, paste, downloads, even printing.

282
00:10:03,120 --> 00:10:06,760
So if someone accesses a sensitive app from an unmanaged device,

283
00:10:06,760 --> 00:10:08,080
like their personal phone,

284
00:10:08,080 --> 00:10:09,680
you can restrict what they're allowed to do

285
00:10:09,680 --> 00:10:11,640
without cutting off access completely.

286
00:10:11,640 --> 00:10:14,440
And it works with both Microsoft apps and non-Microsoft apps.

287
00:10:14,440 --> 00:10:18,520
Google workspace, Salesforce, Box AWS, Defender Connects to all of them

288
00:10:18,520 --> 00:10:19,560
through API connectors.

289
00:10:19,560 --> 00:10:23,680
So whether your team is an outlook or Gmail, one drive or Google drive,

290
00:10:23,680 --> 00:10:25,480
you get the same protection.

291
00:10:25,480 --> 00:10:27,160
One more thing, OAuth app management.

292
00:10:27,200 --> 00:10:31,120
OAuth is the tech that lets third party apps request permission to your data.

293
00:10:31,120 --> 00:10:34,120
You know when you sign into a site with your Google or Microsoft account

294
00:10:34,120 --> 00:10:37,920
and it asks for permission to read your email or access your files, that's OAuth?

295
00:10:37,920 --> 00:10:40,640
Defender can detect when an app asks for too many permissions,

296
00:10:40,640 --> 00:10:44,440
maybe a simple note-taking app wants access to your entire one drive.

297
00:10:44,440 --> 00:10:45,440
That's suspicious.

298
00:10:45,440 --> 00:10:47,640
Defender flags it and lets you revoke those permissions.

299
00:10:47,640 --> 00:10:51,200
So you've got discovery, risk assessment, thread detection and data protection.

300
00:10:51,200 --> 00:10:52,600
But none of this works alone.

301
00:10:52,600 --> 00:10:55,280
Defender for cloud apps fits into a bigger picture.

302
00:10:55,320 --> 00:10:59,440
And understanding how it connects to everything else is where the real power lies.

303
00:10:59,440 --> 00:11:04,280
How it connects to everything else, you might wonder, can Defender for cloud apps work on its own?

304
00:11:04,280 --> 00:11:09,040
Yes, it can, but the real power comes from how it connects to the rest of the Microsoft security world.

305
00:11:09,040 --> 00:11:12,640
Defender for cloud apps is part of the Microsoft Defender XDR suite.

306
00:11:12,640 --> 00:11:17,400
XDR stands for Extended Detection and Response, basically a set of security tools that share information.

307
00:11:17,400 --> 00:11:21,440
Defender for endpoint protects devices, Defender for Office 365 protects email,

308
00:11:21,440 --> 00:11:23,920
Defender for Identity protects user accounts,

309
00:11:23,960 --> 00:11:26,320
and Defender for Cloud Apps protects cloud apps.

310
00:11:26,320 --> 00:11:30,760
Together they form a unified system where each tool feeds data to the others.

311
00:11:30,760 --> 00:11:33,680
Defender for cloud apps shares data with Microsoft Sentinel,

312
00:11:33,680 --> 00:11:37,720
Microsoft's enterprise level seam, security information and event management.

313
00:11:37,720 --> 00:11:40,600
Sentinel collects logs from across your entire organization,

314
00:11:40,600 --> 00:11:43,000
servers, firewalls, applications, everything.

315
00:11:43,000 --> 00:11:46,400
When Defender spots something suspicious, it sends that info to Sentinel.

316
00:11:46,400 --> 00:11:48,600
Sentinel then correlates it with other events.

317
00:11:48,600 --> 00:11:52,280
The same IP that accessed a risky cloud app also tried to log into a server,

318
00:11:52,280 --> 00:11:53,840
Sentinel connects those dots.

319
00:11:53,880 --> 00:11:56,760
Integration with Microsoft, EntraID is just as important.

320
00:11:56,760 --> 00:11:59,720
EntraID manages who your users are and what they can access.

321
00:11:59,720 --> 00:12:02,840
Defender uses that identity info to understand who's doing what.

322
00:12:02,840 --> 00:12:04,440
When it detects a compromised account,

323
00:12:04,440 --> 00:12:07,640
it can tell EntraID to block that user's access immediately,

324
00:12:07,640 --> 00:12:09,600
no waiting for a human to respond.

325
00:12:09,600 --> 00:12:12,960
It also connects to Defender for Endpoint, which runs on company devices.

326
00:12:12,960 --> 00:12:15,280
That's how cloud discovery works in the full version.

327
00:12:15,280 --> 00:12:19,080
Defender for Endpoints sees every website and app a user visits on their work computer

328
00:12:19,080 --> 00:12:22,720
and sends that data to Defender for cloud apps, which builds your discovery dashboard.

329
00:12:22,760 --> 00:12:26,240
Without this connection, you're stuck manually uploading firewall logs

330
00:12:26,240 --> 00:12:28,160
and there's integration with Power Automate,

331
00:12:28,160 --> 00:12:29,840
Microsoft's automation platform.

332
00:12:29,840 --> 00:12:33,200
You can create playbooks, automated response workflows.

333
00:12:33,200 --> 00:12:35,920
When Defender detects a threat, it triggers a Power Automate flow

334
00:12:35,920 --> 00:12:38,000
that sends a notification to a Teams channel,

335
00:12:38,000 --> 00:12:41,040
creates a helpdesk ticket and suspends the user's account

336
00:12:41,040 --> 00:12:42,960
all without anyone lifting a finger.

337
00:12:42,960 --> 00:12:46,760
So once a suspicious event can trigger actions across multiple tools,

338
00:12:46,760 --> 00:12:49,120
an impossible travel detection in Defender for cloud apps

339
00:12:49,120 --> 00:12:50,880
can block the user in EntraID,

340
00:12:50,920 --> 00:12:54,040
alert the security team and Teams and log the incident in Sentinel.

341
00:12:54,040 --> 00:12:56,120
Everything works together.

342
00:12:56,120 --> 00:12:57,760
Now, licenses matter.

343
00:12:57,760 --> 00:13:01,160
With Microsoft 365 Business Premium, you get a limited version.

344
00:13:01,160 --> 00:13:03,520
You can upload firewall logs for cloud discovery

345
00:13:03,520 --> 00:13:06,240
and use the app catalog to check risk scores,

346
00:13:06,240 --> 00:13:09,120
but you don't get automatic integration with Defender for Endpoint

347
00:13:09,120 --> 00:13:10,680
and some advanced features are missing.

348
00:13:10,680 --> 00:13:15,400
For the full version, you need Microsoft 365 e5 or an EMS e5 add-on.

349
00:13:15,400 --> 00:13:19,200
That's where continuous monitoring, real-time session controls and full automation come in.

350
00:13:19,200 --> 00:13:20,320
That's how everything connects.

351
00:13:20,360 --> 00:13:22,480
So what does it take to get started?

352
00:13:22,480 --> 00:13:24,360
Getting started in plain terms.

353
00:13:24,360 --> 00:13:27,960
You don't need to be a security expert to start using Defender for cloud apps.

354
00:13:27,960 --> 00:13:30,760
You can begin without configuring a single policy.

355
00:13:30,760 --> 00:13:32,560
The best approach is to start small.

356
00:13:32,560 --> 00:13:35,200
Learn what you're dealing with, then gradually add controls.

357
00:13:35,200 --> 00:13:38,480
Phase one is visibility, just turn on cloud discovery and see what's out there.

358
00:13:38,480 --> 00:13:42,280
If you have Business Premium, upload your firewall logs and get a snapshot.

359
00:13:42,280 --> 00:13:45,320
If you have e5, enable the Defender for Endpoint integration

360
00:13:45,320 --> 00:13:46,800
and watch the data flow in.

361
00:13:46,800 --> 00:13:48,920
Don't block anything yet, don't sanction anything yet.

362
00:13:48,960 --> 00:13:51,600
Just look, you'll probably be surprised by what you find.

363
00:13:51,600 --> 00:13:53,440
Phase two is policy definition.

364
00:13:53,440 --> 00:13:56,160
Now that you know which apps are in use, decide what to do.

365
00:13:56,160 --> 00:13:59,600
Use the app catalog to check risk scores, sanction the safe ones,

366
00:13:59,600 --> 00:14:02,160
un-sanction the dangerous ones, set the rest to monitored,

367
00:14:02,160 --> 00:14:05,320
then create a few alert policies for the most obvious threats.

368
00:14:05,320 --> 00:14:09,160
Impossible travel, logins from risky countries, mass downloads.

369
00:14:09,160 --> 00:14:10,280
Phase three is enforcement.

370
00:14:10,280 --> 00:14:12,200
This is where you start actively blocking things,

371
00:14:12,200 --> 00:14:16,680
implement session policies that restrict what users can do on unmanaged devices.

372
00:14:16,720 --> 00:14:19,800
Set up automated responses that suspend compromised accounts.

373
00:14:19,800 --> 00:14:23,400
Connect Defender to Power Automate so Alerts Trigger Real Actions.

374
00:14:23,400 --> 00:14:24,880
Phase four is optimization.

375
00:14:24,880 --> 00:14:27,160
Security isn't something you set once and forget.

376
00:14:27,160 --> 00:14:28,840
Review your alerts regularly.

377
00:14:28,840 --> 00:14:31,680
Tune your policies based on what you see.

378
00:14:31,680 --> 00:14:33,880
Get feedback from users who get blocked.

379
00:14:33,880 --> 00:14:36,560
Sometimes legitimate work gets caught by mistake.

380
00:14:36,560 --> 00:14:38,280
Adjust and improve over time.

381
00:14:38,280 --> 00:14:41,920
If you're not sure where to start, just look at the cloud discovery dashboard.

382
00:14:41,920 --> 00:14:44,160
Even a single snapshot from your firewall logs

383
00:14:44,160 --> 00:14:46,400
will show you apps you didn't know existed.

384
00:14:46,440 --> 00:14:47,640
That alone is worth the effort.

385
00:14:47,640 --> 00:14:49,560
The biggest risk isn't the apps you know about.

386
00:14:49,560 --> 00:14:50,640
It's the ones you don't.

387
00:14:50,640 --> 00:14:53,320
Defender for Cloud Apps turns those blind spots into something

388
00:14:53,320 --> 00:14:55,160
you can actually see and manage.

389
00:14:55,160 --> 00:14:57,200
So here's what Defender for Cloud Apps gives you.

390
00:14:57,200 --> 00:14:58,240
Four things.

391
00:14:58,240 --> 00:15:01,160
Visibility into every cloud app your employees use.

392
00:15:01,160 --> 00:15:03,720
Risk assessment to tell you which ones are safe.

393
00:15:03,720 --> 00:15:06,560
Threat detection that spots suspicious behavior automatically

394
00:15:06,560 --> 00:15:09,720
and data protection that keeps your sensitive files from leaking out.

395
00:15:09,720 --> 00:15:11,760
The real value isn't any single feature.

396
00:15:11,760 --> 00:15:14,640
It's that the tool turns blind spots into manageable risks.

397
00:15:14,680 --> 00:15:17,160
You go from not knowing what's happening to having a complete picture

398
00:15:17,160 --> 00:15:19,040
you can actually act on. Here's your challenge.

399
00:15:19,040 --> 00:15:22,240
If you have access to Microsoft 365, open the Defender portal

400
00:15:22,240 --> 00:15:24,040
and check your own cloud discovery report.

401
00:15:24,040 --> 00:15:26,440
Even if it's empty, you'll understand what's possible.

402
00:15:26,440 --> 00:15:28,160
And if you find something unexpected,

403
00:15:28,160 --> 00:15:30,080
you'll see exactly why this tool matters.

404
00:15:30,080 --> 00:15:33,640
In our next episode, we'll look at how to create your first security policy,

405
00:15:33,640 --> 00:15:36,200
the practical steps to start protecting your environment.

406
00:15:36,200 --> 00:15:38,480
Subscribe on your favorite podcast platform

407
00:15:38,480 --> 00:15:41,680
and share this with someone who's trying to make sense of cloud security.

