Discover, Protect, and Control SaaS Apps with Microsoft Defender for Cloud Apps
Microsoft Cloud App Security is now Microsoft Defender for Cloud Apps. In 2026, it remains a key Microsoft security tool for discovering shadow IT, assessing SaaS risk, controlling user sessions, protecting cloud data, and connecting cloud app activity into Microsoft Defender XDR.
What changed since Microsoft Cloud App Security?
Microsoft Cloud App Security was renamed Microsoft Defender for Cloud Apps and is now managed primarily through the Microsoft Defender portal at security.microsoft.com. The surrounding ecosystem has also changed: Microsoft Defender ATP is now Microsoft Defender for Endpoint, Azure AD is now Microsoft Entra ID, and Azure Information Protection capabilities are now part of Microsoft Purview Information Protection and sensitivity labels. The core use case is still the same: help organizations understand which cloud apps are in use, reduce risky SaaS exposure, detect suspicious behavior, and enforce Zero Trust controls for cloud access.
Cloud discovery: find sanctioned apps, shadow IT, and risky SaaS usage
Defender for Cloud Apps cloud discovery helps identify cloud services used across your organization, including apps that were not approved by IT. Discovery data can come from firewall and proxy logs, log collectors, and Microsoft Defender for Endpoint integration. The service compares discovered apps against Microsoft’s cloud app catalog, which includes risk attributes such as compliance certifications, security controls, data handling practices, and business risk indicators. Security teams can mark apps as sanctioned or unsanctioned, review usage by users and devices, and use the findings to reduce shadow IT.
Block or control unsanctioned apps with Defender for Endpoint
When Defender for Cloud Apps is integrated with Microsoft Defender for Endpoint, organizations can move beyond reporting and take action. Unsanctioned app indicators can be used with endpoint network protection to help block access from managed devices. This is especially useful for reducing risk from unapproved file-sharing, personal storage, generative AI, messaging, or collaboration apps that may expose corporate data. Blocking should be introduced carefully: review usage, identify business owners, communicate alternatives, and test policies before broad enforcement.
Connect approved SaaS apps for deeper visibility and control
Cloud discovery shows what is being used, while app connectors provide deeper API-based visibility into sanctioned services. Defender for Cloud Apps supports connectors for Microsoft and selected third-party SaaS platforms so security teams can investigate activities, files, sharing links, users, configuration risks, and policy violations. Connected apps can be monitored with activity policies, file policies, anomaly detection policies, and OAuth app policies. This gives administrators a way to detect risky behavior such as impossible travel, mass downloads, suspicious sharing, unusual admin activity, or excessive permissions granted to third-party apps.
Protect cloud data with Microsoft Purview labels and DLP
For data protection, Defender for Cloud Apps works best when combined with Microsoft Purview Information Protection. Sensitivity labels and content inspection help identify confidential information in cloud apps, while Microsoft Purview DLP policies can reduce accidental or intentional data leakage. Practical policy examples include detecting externally shared confidential files, identifying files with sensitive information types, alerting on public sharing, removing risky permissions, or applying governance actions where supported. This modernizes the older Azure Information Protection model into the current Microsoft Purview labeling and compliance approach.
Use Microsoft Entra Conditional Access App Control for real-time session protection
Microsoft Entra Conditional Access can route selected SaaS sessions through Defender for Cloud Apps Conditional Access App Control. This enables real-time session policies for supported apps, especially when users access data from unmanaged devices, risky locations, or non-compliant endpoints. Common controls include monitoring sessions, blocking downloads, protecting downloads with sensitivity labels, blocking uploads of sensitive files, preventing copy or paste in selected scenarios, or limiting access based on device and user risk. These controls support a Zero Trust model: verify explicitly, use least privilege, and assume breach.
Investigate incidents in Microsoft Defender XDR
Defender for Cloud Apps is part of the broader Microsoft Defender XDR experience. Alerts and incidents can be correlated with signals from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, and Microsoft Entra ID. This helps analysts investigate cloud app activity alongside endpoint, identity, and email events instead of treating SaaS alerts as isolated findings. Security teams can also use advanced hunting where available to query activity patterns and support threat investigations.
Licensing considerations in 2026
Microsoft Defender for Cloud Apps is available as a standalone subscription and is also commonly included in suites such as Microsoft 365 E5, Microsoft 365 E5 Security, and Enterprise Mobility + Security E5. Some capabilities depend on related licenses, such as Microsoft Defender for Endpoint for endpoint-based app discovery and blocking, Microsoft Entra ID for Conditional Access, and Microsoft Purview for sensitivity labels and DLP. For organizations purchasing through CSP, Microsoft New Commerce Experience subscription terms, billing frequency, and commitment options should be reviewed before rollout. Licensing can vary by tenant, plan, and feature, so validation before deployment is recommended.
Recommended rollout approach
Start with discovery and visibility before enforcing controls. First, enable cloud discovery and review the highest-usage and highest-risk apps. Next, define sanctioned and unsanctioned app categories, connect critical SaaS platforms, and create alerting policies for high-risk activity. Then add Microsoft Purview labels and DLP for sensitive data, and use Microsoft Entra Conditional Access App Control for real-time controls on risky sessions. Finally, connect alerts into Microsoft Defender XDR operations and review policies regularly as business apps, user behavior, and Microsoft security features evolve.
Key takeaways
- Microsoft Cloud App Security is now Microsoft Defender for Cloud Apps and is managed through the Microsoft Defender portal.
- Cloud discovery helps identify shadow IT, assess SaaS risk, and classify apps as sanctioned or unsanctioned.
- Integration with Microsoft Defender for Endpoint can help block unsanctioned apps on managed devices.
- Microsoft Entra Conditional Access App Control provides real-time session controls for supported SaaS apps.
- Microsoft Purview sensitivity labels and DLP strengthen data protection across connected cloud apps.
- Defender for Cloud Apps contributes alerts and investigation context to Microsoft Defender XDR.
Need help modernizing SaaS security and shadow IT controls? IT Partner can assess your Microsoft 365 security stack, validate Defender for Cloud Apps licensing under NCE, configure discovery and app governance policies, and integrate controls with Microsoft Entra ID, Microsoft Purview, and Microsoft Defender XDR.
Questions this article didn’t answer?
Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.