Microsoft Defender for Cloud Apps is Microsoft's cloud access security broker (CASB). It connects to cloud services such as Microsoft 365 and other software-as-a-service (SaaS) apps through APIs (app connectors), discovers shadow IT from network logs, and applies policies to user activity. For the security operations center (SOC), its most important outputs are anomaly detection alerts and visibility into OAuth apps, both of which feed Defender XDR incidents. Anomaly detection policies are built in and turned on by default. They learn each user's normal behavior over an initial learning period, then alert on deviations. Impossible travel fires when the same user signs in from two locations so far apart that nobody could travel between them in the time elapsed, which suggests a stolen credential used from another country. It has known sources of false positives, such as VPNs and corporate proxies, so the policy's sensitivity can be tuned and known IP ranges can be tagged as corporate or VPN under the IP address range settings. Other anomaly alerts include activity from infrequent country, activity from anonymous IP addresses, activity from suspicious IP addresses, mass download, mass deletion, ransomware activity (many file uploads with unusual extensions), unusual file sharing, and suspicious inbox manipulation rules such as forwarding mail to an outside address or moving messages to hidden folders.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.