107 questions with Microsoft Defender for Cloud Apps-related tags

Sort by: Updated
2 answers One of the answers was accepted by the question author.

Teams account sign in error

Teams sign in error We can't sign in this account (yymyint@xxx.com) in Mobile version. It shows like this image error. Pls tell me how to solve that error. Kindly reply to me. Thanks.

Microsoft Teams
Microsoft Teams
A Microsoft customizable chat-based workspace.
9,226 questions
Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
10,806 questions
Microsoft Teams Development
Microsoft Teams Development
Microsoft Teams: A Microsoft customizable chat-based workspace.Development: The process of researching, productizing, and refining new or existing technologies.
2,912 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-07-06T06:17:38.0766667+00:00
IT Support 266 Reputation points
accepted 2023-07-17T04:15:11.66+00:00
IT Support 266 Reputation points
1 answer One of the answers was accepted by the question author.

Onboarding multiple devices by local script

Hello Microsoft, I have a question regarding onboarding devices on Microsoft 365 Defender. I was wondering if I could onboard multiple devices in a domain by a local script (more than 10 devices) !? Thank you for responding*

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,213 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,465 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,000 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-07-11T02:30:12.8066667+00:00
ehsanshirazi 80 Reputation points
accepted 2023-07-15T00:03:51.3233333+00:00
ehsanshirazi 80 Reputation points
2 answers

How do I export a list of Analytics from the Defender Products

As a MSSP for Microsoft Sentinel we have the Defender MDO Data connectors enabled and we're creating Incidents based on the Alerts that are created from each of the different MDO's Defender for Identity Defender for Office 365 Defender for Endpoint …

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,213 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,000 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-07-10T17:55:53.18+00:00
Kentucky Mike 51 Reputation points
commented 2023-07-11T17:45:01.57+00:00
Kentucky Mike 51 Reputation points
2 answers

How to prevent users to grant consent on third party apps which are using OAuth which is token based authentication and authorization?

How to prevent users to grant consent on third party apps which are using OAuth which is token based authentication and authorization? As we have seen many users are using their work account to grant on different apps to use those and seems those apps…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,213 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,814 questions
asked 2023-07-02T05:45:41.4266667+00:00
Vinod Survase 4,706 Reputation points
commented 2023-07-10T19:47:30.83+00:00
JamesTran-MSFT 36,476 Reputation points Microsoft Employee
0 answers

Prevent a user from trigerring the same cloud app policy multiple times

Hello, I have a policy that triggers when a user fails to connect 100 times in 60 minutes. The main use of this policy is to notify our security team when a user is likely to be under attack so that they can contact the user to establish a strong…

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
3,942 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-07-04T07:03:56.26+00:00
Jean Valjean 999 0 Reputation points
commented 2023-07-04T18:26:05.77+00:00
B santhiswaroop naik 385 Reputation points
2 answers

defender & intune-restrict access to a website based on device risk level

Hi all, is it possible to restrict access to a public website based on a risk level calculated by defender? Lets say that if a device has HIGH risk level, it will not be allowed to access particular web site.... PS: We use M365 E3 with M365 E5 Security…

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
350 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-06-13T22:01:41.91+00:00
michal 186 Reputation points
edited the question 2023-06-19T19:16:02.87+00:00
JamesTran-MSFT 36,476 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

MDE_365 _Integration with SIEM(ArcSight)

Hi All, In my environment ,we have integrated Microsoft 365 defender (mde) -EDR with ArcSight ,in our case we receive only Alerts and Incidents events only in our ArcSight logs .which is creating more noise and we are not able to create any rule in…

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
3,942 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,213 questions
Microsoft Configuration Manager Deployment
Microsoft Configuration Manager Deployment
Microsoft Configuration Manager: An integrated solution for for managing large groups of personal computers and servers.Deployment: The process of delivering, assembling, and maintaining a particular version of a software system at a site.
915 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-06-12T13:42:50.4533333+00:00
Akshyalakshmi Anandan Murali 20 Reputation points
accepted 2023-06-15T10:38:13.76+00:00
Akshyalakshmi Anandan Murali 20 Reputation points
2 answers One of the answers was accepted by the question author.

Azure License Allocation

Hi everyone, I am just getting started in azure which has lead me to a very junior license question. I have noticed we have a few licenses in our managed azure tenant which are not assigned. Licenses include: Microsoft Defender for Cloud Apps Microsoft…

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,814 questions
asked 2023-06-05T05:53:34.0033333+00:00
Callum C 20 Reputation points
accepted 2023-06-05T23:09:28.7333333+00:00
Callum C 20 Reputation points
1 answer One of the answers was accepted by the question author.

What all are the capabilities of Microsoft Cloud app security in terms of monitoring the M365 apps?

What all are the capabilities of Microsoft Cloud app security in terms of monitoring the M365 apps? Also need help on below query. As I have implemented it in our tenant and it shows below on each apps for end users but how we can silently disable that…

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
3,942 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,213 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,814 questions
asked 2023-05-10T08:02:58.4466667+00:00
Vinod Survase 4,706 Reputation points
commented 2023-06-02T22:26:40.73+00:00
Marilee Turscak-MSFT 34,626 Reputation points Microsoft Employee
0 answers

How can I get the badge of my challenge ?

Get challenge bage

Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-06-02T07:53:39.6266667+00:00
49204756 0 Reputation points
0 answers

We have files or folder restored by Danet which assigns us as the owner, but when the tenancy user shares or accesses a file, it generates a Cloud Apps Alert. It's a false alert and shouldn't assign us as the owner.

We have files or folder restored by Danet which assigns us as the owner, but when the tenancy user shares or accesses a file, it generates a Cloud Apps Alert. It's a false alert and shouldn't assign us as the owner.

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
3,942 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-05-29T10:19:41.65+00:00
edited the question 2023-05-30T20:57:45.9733333+00:00
JamesTran-MSFT 36,476 Reputation points Microsoft Employee
2 answers

O365 MS Defender URL indicator - URL is invalid

Hi, I'm trying to add URL Indicators in MS Defender but it doesn't seem to work. I've created a CSV file (based on the sample file provided by Microsoft). I did not fill in the columns for ExpirationTime, RecommendedActions, RbacGroups, Category,…

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,780 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-05-15T12:55:00.8833333+00:00
80463912 0 Reputation points
answered 2023-05-22T08:19:03.81+00:00
80463912 0 Reputation points
2 answers

Testing policy - Potential ransomware activity, nothing happens

I am testing Cloud Apps Security and I want to launch potential threat in action. So the policy "Potential ransomware activity" is enabled for all users, computer is onboarded to Defender for Endpoint, and when I create locally .zyx file and…

Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-05-19T16:45:30.2466667+00:00
Pavel yannara Mirochnitchenko 11,981 Reputation points MVP
answered 2023-05-20T10:19:22.0266667+00:00
Pavel yannara Mirochnitchenko 11,981 Reputation points MVP
2 answers

Troubleshoot SIEM tool integration issues

we have followed the docs to collect data from Microsoft Azure Event Hub, for Microsoft Defender integration on elastic stack. for some reason we're not receiving the data?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,213 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-05-02T21:05:42.3033333+00:00
12980401 0 Reputation points
commented 2023-05-18T20:12:36.2933333+00:00
12980401 0 Reputation points
1 answer One of the answers was accepted by the question author.

Is it recommended to block third party cookies for web browsers specially Chrome and Edge?

Is it recommended to block third party cookies for web browsers specially Chrome and Edge? As we have below security recommendation for the same. What all would be impacted and how to measure it?

Microsoft Edge
Microsoft Edge
A Microsoft cross-platform web browser that provides privacy, learning, and accessibility tools.
2,166 questions
Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
10,792 questions
Microsoft Intune Application management
Microsoft Intune Application management
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Application management: The process of creating, configuring, managing, and monitoring applications.
893 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,465 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-05-03T14:01:28.8833333+00:00
Vinod Survase 4,706 Reputation points
commented 2023-05-12T02:13:14.9133333+00:00
Lu Dai-MSFT 28,356 Reputation points
2 answers

edit severity forwarding/redirect rule from informational to High

Hiya, we have an information alert regarding forwarding/redirect rule. We are not firing emails off for informational else we would be swamped with emails. Is there a way to change this forwarding/redirect rule. to high rather than informational , or is…

Microsoft Exchange Online Management
Microsoft Exchange Online Management
Microsoft Exchange Online: A Microsoft email and calendaring hosted service.Management: The act or process of organizing, handling, directing or controlling something.
4,240 questions
Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,387 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,213 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-04-26T13:48:21.1933333+00:00
Ray Waldron 41 Reputation points
commented 2023-05-02T07:28:44.6233333+00:00
Aholic Liang-MSFT 13,821 Reputation points Microsoft Vendor
1 answer

Track change on DC with Defender for Identity?

We have 2016 Domain Controllers and Auditing is enabled. We are trying to configure/deny read permission, for members of a group, over the Domain Admins group in Active Directory. But something is removing that change after some time.    I can find…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,213 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-04-25T21:59:27.9533333+00:00
RT-7199 471 Reputation points
answered 2023-04-25T22:11:28.7833333+00:00
Andrew Blumhardt 9,581 Reputation points Microsoft Employee
1 answer

ALERT: Password reuse activity on multiple endpoints

We have started receiving multiple Defender alerts from yesterday - 20th April early morning. "A user on this device is reusing the currently logged in account password on a different credential. Use new and complex password for each credential to…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,213 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,749 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-04-21T11:00:31.3766667+00:00
Rakesh Sukumaran 0 Reputation points
answered 2023-04-24T02:23:13.0066667+00:00
Lu Dai-MSFT 28,356 Reputation points
1 answer

How to get defender for cloud plans activated for a long analytics workspace through powershell?

Hello everyone, I am trying to get the defender for cloud plans activated for a log analytics workspace through powershell, but there is no such command in powershell to get that. Can anyone help me with this would be highly appreciated. Thanks in…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,213 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-04-21T09:31:02.17+00:00
Lakshmi Bharath Kumar Dasa 0 Reputation points
answered 2023-04-22T12:31:46.8066667+00:00
David Broggy 5,686 Reputation points MVP
0 answers

ALERT: Password reuse activity - Behaviour

Hi Everyone. Recently we receive a bunch of the next Alerts!: Password reuse activity that is triggered every 3 minutes on Microsoft 365 Defender. The question here is, if anyone known the behavior or parameters that this alerts use to trigger the…

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
3,942 questions
Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
350 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-04-20T00:30:46.91+00:00
Sergy Lopez 161 Reputation points
commented 2023-04-20T15:54:30.8533333+00:00
Sergy Lopez 161 Reputation points