107 questions with Microsoft Defender for Cloud Apps-related tags

Sort by: Updated
1 answer One of the answers was accepted by the question author.

How can we procure the Microsoft Defender Experts for XDR service?

Hi All, I want to explore the Microsoft Defender Experts for XDR Services for Microsoft. How can I procure this service from Microsoft? Please guide.

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,779 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,212 questions
Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
349 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-11-01T18:09:52.1633333+00:00
Garima Das 1,041 Reputation points
accepted 2023-11-16T11:49:28.7266667+00:00
Garima Das 1,041 Reputation points
1 answer

What are the tools required to work using MXDR?

Hi everyone, I am researching on Microsoft Defender for XDR service. I wanted to understand what other Microsoft tools can be used for Security that are either available or can be integrated with the Security Portal. Thanks.

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,212 questions
Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
349 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,000 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-11-01T07:31:48.9233333+00:00
Garima Das 1,041 Reputation points
commented 2023-11-14T20:16:31.52+00:00
JamesTran-MSFT 36,476 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

BYOD Microsoft Entra ID Registered: differenciate personal device to allow download or block

Hello team, I have a user who registered 2 devices as Microsoft Entra ID registered which are recognized as personal devices. In theory, one device should be used for work and access corporate data, in this registered device the user can download data…

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
349 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
Microsoft Entra
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,807 questions
asked 2023-10-26T13:28:17.6733333+00:00
Sergio Londono 321 Reputation points
commented 2023-10-30T19:01:18.76+00:00
Sergio Londono 321 Reputation points
1 answer One of the answers was accepted by the question author.

What these listed action do when we do perform them via M365 Defender under "Explorer" on Phish/Spam emails?

What these listed action do when we do perform them via M365 Defender under "Explorer" on Phish/Spam emails? Is there any official document which states all about these options and their actions? See below screenshot.

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
3,940 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,212 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,807 questions
asked 2023-09-25T14:18:57.74+00:00
Vinod Survase 4,706 Reputation points
commented 2023-10-01T07:05:32.6733333+00:00
Vinod Survase 4,706 Reputation points
1 answer

How to get alerts/notifications from M365 Defender for Endpoints, Identity and others when there is new updates and vulnerabilities if any are available on any the third-party apps like Chrome, Firefox and others?

How to get alerts/notifications from M365 Defender for Endpoints, Identity and others when there is new updates and vulnerabilities if any are available on any the third-party apps like Chrome, Firefox and others?

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,807 questions
asked 2023-09-23T10:48:32.62+00:00
Vinod Survase 4,706 Reputation points
answered 2023-09-30T07:27:47.27+00:00
Rhys Bristow 160 Reputation points
0 answers

OpenSSL vulnerabilities showing in Defender Dashboard

We have serval devices indicating a OpenSSL vulnerability. It is multiple applications through out our devices. There are two dlls that are flagged libcrypto-3-x64.dll and libssl-3-x64.dll. Is defender throwing false positives? If they are not false…

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
10,788 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,212 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-09-22T20:24:03.2033333+00:00
Jeff Thorne 40 Reputation points
commented 2023-09-27T05:28:47.2966667+00:00
Givary-MSFT 28,571 Reputation points Microsoft Employee
2 answers

How to block/remove adware and pop-up ads on devices via Intune or M365 Defender in browser and any other SaaS/Web Apps which users are browsing/using?

How to block/remove adware and pop-up ads on devices via Intune or M365 Defender in browser and any other SaaS/Web Apps which users are browsing/using?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,212 questions
Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
349 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,463 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,807 questions
asked 2023-09-19T14:52:45.67+00:00
Vinod Survase 4,706 Reputation points
commented 2023-09-21T05:31:11.38+00:00
ZhoumingDuan-MSFT 8,920 Reputation points Microsoft Vendor
2 answers

Repeatedly having "Multiple failed user log on attempts to an app" incidents and alerts

I have cloud-only environment without local Active Directory and after Defender for Cloud Apps was implemented, only one policy generates these "Multiple failed user log on attempts to an app" alerts and incidents all the time. Is this a known…

Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-06-13T07:21:47.31+00:00
Pavel yannara Mirochnitchenko 11,961 Reputation points MVP
answered 2023-09-18T14:17:08.73+00:00
Ramon Diaz 0 Reputation points
1 answer One of the answers was accepted by the question author.

How to monitor/get the email alerts of Service accounts being used/someone tried to login to that account in M365 via Cloud app security policy alerts or any other way as I saw blogs but it was not clear to me?

How to monitor/get the email alerts of Service accounts being used/someone tried to login to that account in M365 via Cloud app security policy alerts or any other way as I saw blogs but it was not clear to me?

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
3,940 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,212 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,807 questions
asked 2023-09-08T14:54:27.21+00:00
Vinod Survase 4,706 Reputation points
accepted 2023-09-16T06:53:43.75+00:00
Vinod Survase 4,706 Reputation points
1 answer

Onboarding devices to Microsoft Defender for endpoint

Hi team, Could you please send me steps on how to manage security settings through Defender for endpoint. Also, we don't want to enroll devices to intune, we just want to manage them through Defender. Thank you for your help.

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,212 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,267 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-09-13T21:57:36.5333333+00:00
J-3804 1,516 Reputation points
answered 2023-09-14T01:59:55.48+00:00
Crystal-MSFT 44,321 Reputation points Microsoft Vendor
1 answer

400 Bad request

Error running command synapse.createNotebook: HTTP Error Response: 400 Bad Request. This is likely caused by the extension that contributes synapse.createNotebook.

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
3,940 questions
Microsoft Teams
Microsoft Teams
A Microsoft customizable chat-based workspace.
9,225 questions
Microsoft Configuration Manager Deployment
Microsoft Configuration Manager Deployment
Microsoft Configuration Manager: An integrated solution for for managing large groups of personal computers and servers.Deployment: The process of delivering, assembling, and maintaining a particular version of a software system at a site.
915 questions
Microsoft Configuration Manager
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-08-23T03:33:48.78+00:00
BI - Data Engineer 0 Reputation points
answered 2023-08-23T08:32:38.9033333+00:00
Iftikhar Ali 170 Reputation points
2 answers

What is included in MS Defender for business ?

What is included in MS Defender for Business ? I read the doc but not able to get it. I get that it contains Defender for Endpoint but boes it contain Defender for Office 365? Defender for Office 365 ? Identity ? or parts of it ?

Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-08-14T14:43:05.2866667+00:00
Rishineken Pongen 161 Reputation points
commented 2023-08-14T19:36:02.01+00:00
Rishineken Pongen 161 Reputation points
1 answer One of the answers was accepted by the question author.

Onboarding devices on Microsoft 365 Defender remotely

Hello, I have a question regarding onboarding devices on Microsoft 365 Defender. I was wondering if I could onboard computers in my domain remotely by a local script using PowerShell or PsTools without logging in User's computer? Thank you for…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,212 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,000 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,807 questions
asked 2023-08-10T05:46:34.02+00:00
ehsanshirazi 80 Reputation points
accepted 2023-08-11T04:43:41.9666667+00:00
ehsanshirazi 80 Reputation points
0 answers

How Defender EASM found open port 500 on my IP address, and using Nmap scanner I didn't find that the port is open?

I'm using defender currently on a 30 day trial, I'm wondering how Defender EASM managed to find open port 500. I've used Nmap scanner with different switches and tried to scan port 500 directly but I got no result that the port is open. Now I don't know…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,212 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-07-15T08:11:25.85+00:00
FP 0 Reputation points
commented 2023-08-01T09:52:33.88+00:00
Givary-MSFT 28,571 Reputation points Microsoft Employee
1 answer

How to block Save As option in Microsoft 365

I can restrict document downloads in Microsoft 365 applications with Microsoft Defender for Cloud Apps. However, when I open a document with a client, the Save As option is enabled. How can I prevent this action?

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
3,940 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-07-28T16:05:52.4566667+00:00
Samuel Peña 1 Reputation point
answered 2023-08-01T01:52:11.0333333+00:00
Byron Dittberner 0 Reputation points
1 answer One of the answers was accepted by the question author.

Mac OS accessing restricted application

Hey team, We have setup a policy to allow devices to access some applications and sites but we noticed that MAC OS users are now able to access restricted and unrestricted applications and sites. Can you please provide us with steps to prevent Mac users…

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,463 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,807 questions
asked 2023-07-27T23:03:02.6666667+00:00
J-3804 1,516 Reputation points
accepted 2023-07-28T14:27:39.03+00:00
J-3804 1,516 Reputation points
1 answer

Cannot turn feature on. This feature requires an Office 365 E5 license or the Threat Intelligence add-on for Office 365.

I already have M365 E5 license. Do we require 1 threat intelligence license for everyone in the company or how does it work?

Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-06-12T13:15:09.8466667+00:00
Rishineken Pongen 161 Reputation points
answered 2023-07-27T10:20:19.8433333+00:00
Rob H 0 Reputation points
1 answer One of the answers was accepted by the question author.

Can the defender for identity sensor be installed on normal vms being used for DBs and Apps? because we fully cloud based and have no on prem domain controllers

Improvement Action: Start your Defender for Identity deployment, installing Sensors on Domain Controllers and other eligible servers. We need to establish if we can utilize this service on normal VMs and if there is any benefit of it?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,212 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-07-24T08:06:28.89+00:00
Rizwan Assad 321 Reputation points
accepted 2023-07-26T12:06:23.26+00:00
Rizwan Assad 321 Reputation points
1 answer

Prevent access to personal accounts from Office 365

Hello, I have been given the task of researching and implementing restrictions within our organization, specifically regarding user access to personal accounts and services from within the Office 365 app suite. For example, by default, there appears to…

Microsoft Exchange Online
Office
Office
A suite of Microsoft productivity software that supports common business tasks, including word processing, email, presentations, and data management and analysis.
1,350 questions
Microsoft Purview
Microsoft Purview
A Microsoft data governance service that helps manage and govern on-premises, multicloud, and software-as-a-service data. Previously known as Azure Purview.
960 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-07-17T14:39:53.0733333+00:00
Matt Pollock 246 Reputation points
answered 2023-07-25T19:53:35.38+00:00
Matt Pollock 246 Reputation points
1 answer One of the answers was accepted by the question author.

I want to know the policy of Microsoft Defender for Cloud App

I want to know if the policy of Microsoft Defender for Cloud App 'Ransomware activity,' includes the condition of detecting the file named 'HELP_DECRYPT.URL' as a normal file but still triggers an alert.

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,000 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-07-23T18:11:03.58+00:00
Koonnamchok Klongkaew 140 Reputation points
accepted 2023-07-25T09:39:58.4566667+00:00
Koonnamchok Klongkaew 140 Reputation points