Microsoft Defender for Cloud Apps – What Does It Mean for Microsoft 365 Business Premium Greenfield Customers?


When starting with a greenfield Microsoft 365 environment, Microsoft 365 Business Premium provides a surprisingly strong security foundation.

You get Microsoft Entra ID P1, Intune, Defender for Business, Defender for Office 365 Plan 1 and Microsoft Purview capabilities as part of the subscription. However, one area I’m frequently asked about by customers is Microsoft Defender for Cloud Apps (MDC), specifically, what does it actually add to Microsoft 365 Business Premium? More importantly, what can you do with MDC in a brand-new, cloud-only environment? Let's discuss..

Business Premium and Cloud App Discovery

Microsoft Entra ID P1 includes Cloud App Discovery at no additional cost. Cloud App Discovery provides visibility into cloud applications being used in an organisation. It analyses network and endpoint telemetry to identify the cloud applications being used within an organisation. The source of that data can vary depending on the environment and this is where things start get blurry.

In an existing enterprise environment, organisations may already have firewalls, proxy servers, Secure Web Gateways or other network security platforms generating traffic logs. These logs can be uploaded to Defender for Cloud Apps as snapshot reports, allowing existing network traffic to be analysed without requiring an MDE integration.

However, in a cloud-first or greenfield environment, there may be little or no traditional network infrastructure generating these logs. Does that mean Cloud App Discovery feature cannot be used for cloud only environments? Luckily there is a way a well supported way and the answer is integration with Defender for Endpoint.

Integrating Defender for Endpoint with Defender for Cloud Apps provides another source of telemetry from managed endpoints.

An integrated MDE deployment can provide a more continuous discovery capability from managed endpoints. This means Cloud App Discovery is not specifically a greenfield feature. It can add value to both established enterprise environments and newly deployed cloud-first environments — the main difference is how the discovery data is collected. 

The resulting architecture can look like this:


  1. Windows Endpoint - The user accesses a cloud application such as ChatGPT from a managed Windows device.
  2. Microsoft Defender for Endpoint - MDE provides the endpoint telemetry and, when the integration is enabled, makes relevant cloud application activity available to Defender for Cloud Apps.
  3. Cloud Application Telemetry - Information about the cloud application being accessed, such as the application/domain and associated user/device context, is captured.
  4. Defender for Cloud Apps - MDC processes and enriches the telemetry against its cloud application catalogue, applying application categorisation, risk information and governance capabilities.
  5. Cloud Discovery - The resulting information appears in the Cloud Discovery experience, allowing administrators to identify applications being used and decide whether they should be Sanctioned, Unsanctioned or otherwise governed.
Adding Defender for Cloud Apps

An important distinction is that Microsoft 365 Business Premium already provides Cloud App Discovery through Microsoft Entra ID P1, but it does not include the full Defender for Cloud Apps service or its native Microsoft Defender for Endpoint integration. Customer can still use Cloud App Discovery can analyse traffic data supplied through mechanisms such as manually uploaded or automatically collected logs without MDE integration. You will be presented with a screen similar to the one below.



However, in a cloud-first environment where there is no firewall, proxy or Secure Web Gateway providing those logs, the MDE integration becomes particularly useful.

The native integration requires a Defender for Cloud Apps licence. Once this is available, Defender for Endpoint can provide cloud application discovery signals directly to Defender for Cloud Apps, without requiring traffic to be routed through a traditional corporate network infrastructure.

In my greenfield Business Premium tenant, I therefore enabled a Defender for Cloud Apps trial. This exposed the additional MDC functionality and allowed me to enable the MDE integration for continuous endpoint-based Cloud Discovery.

Enabling the MDC feature

1. Navigate to the Microsoft Defender Security Portal.
2. In the navigation sidebar, go to Settings > Endpoints > Optional features.
3. Scroll down to locate the Microsoft Defender for Cloud Apps toggle and switch it to On.
4. Click Save preferences.


Enabling the MDE Integration

1. In the same Microsoft Defender Portal, go to Settings > Cloud Apps.
2. Under the Cloud Discovery header, click on Microsoft Defender for Endpoint.
3. Check the box for Enforce app access. Note - This tells MDC that when you block an app in the cloud dashboard, it should instruct MDE to block it on the computer.
4. Click Save settings


Verifying the Intune Onboarding Policy

MDC relies on the MDE agent being actively managed and running on the client machines. Therefore, devices need to be onboarded on MDE and easiest way is it to onboard using the EDR policy.


Also, we need to ensure that Network Protection is set to Enable (Block mode) in the AV policy as without the block mode, the MDE agent will only audit web traffic, not drop unsanctioned cloud connections.


Making sense of the Cloud Discovery Dashboard

Once these toggles are saved, Microsoft's back-end initiates a background compilation window (which can take up to 12 hours for a newly licensed pure-cloud tenant). After the initial compilation, the static "Create Report" page gets replaced by the interactive Cloud Discovery Dashboard driven by the live Defender-managed endpoints data stream. The dashboard provides visibility into areas such as:
  • Discovered applications
  • Application categories
  • Risk levels
  • Users
  • Devices
  • Source IPs
  • Application usage
  • Sanctioned applications
  • Unsanctioned applications


To see the practical value of this screen, let us look at an example using a discovered Generative AI.  Defender for Cloud Apps has a Generative AI category containing applications such as ChatGPT and many other AI services. Microsoft describes the category as containing more than a thousand generative-AI-related applications.

Navigate to Cloud Apps → Cloud Discovery → Discovered apps and filter for Category → Generative AI.



Let's assume that ChatGPT is not currently approved for use within the organisation. Select the three dots next to ChatGPT and choose Unsanctioned. 


There is an option to even mark the applications as Unsanctioned and apply a scoped enforcement profile to control which MDE device groups are affected, but that's for another time.



MDC will learn of the app as being Unsanctioned and tag it. Defender for Endpoint can then use its network protection capabilities to prevent access from onboarded devices. Note - It can take up to 2-3 hours for the app domains to propagate to endpoint devices after an application is tagged Unsanctioned.

Works on iOS as well through built-in web content and network protection. :-)


Informational alert is generated and can be administered on the Defender Portal. 



Notice the unsanctioned app policy created as an IoC? That is because Microsoft dynamically populates a list of URL/Domain Indicators inside the MDE backend.


Final Thoughts

For me, the interesting part of this exercise isn't simply discovering that ChatGPT is being used. It is the demonstration of how a greenfield Business Premium environment can evolve from having almost no historical Shadow IT visibility into a platform capable of discovering, assessing and governing cloud applications.

The combination of Cloud App Discovery, Defender for Cloud Apps and Defender for Endpoint provides a practical way to bring that activity into the security team's field of view.

For a cloud-first organisation, this is a much more interesting proposition than simply asking:

"Do we have Defender for Endpoint deployed?"

The better question is:

"What are our users actually doing in the cloud, and what controls do we want around it?"

References:




Until next time..

Comments

Popular posts from this blog

Fixing Tamper Protection Blob Error 65000 using Microsoft Intune

Defender Offboarding using Intune - The EDR way!

Enable and Configure Windows Defender Firewall rules using Intune