Microsoft Cloud App Security Implementation — Threat Protection & Cloud App Control
This service implements Microsoft Cloud App Security for Microsoft Cloud services protection, helping organizations define cloud security requirements, configure Cloud App Security, integrate it with cloud services and Windows 10 operating systems through Microsoft Defender, and set up policies, reporting, and notifications for suspicious or dangerous activity.
What this engagement is
Microsoft Cloud App Security is a cloud-based service for protecting work with cloud services. It can help monitor employees' personal devices, obtain information about device security, vulnerabilities, attempts to hack devices, possible credential compromise, and suspicious activity. It includes data visualization, threat analysis, flexible management policies, and automation of security monitoring processes. These capabilities help minimize the security specialist's workload while maintaining a high level of control and protection, and MS CAS transparently integrates into employees' daily work. This engagement focuses on using MS CAS in the Microsoft Cloud services protection scenario: data protection and privacy, including the use of Conditional Access App Control; prevention of information theft; forced data encryption and control of the device network location; detection of suspicious and viral activity and possible attacks; and bringing cloud infrastructure to match industry-standard requirements, including analysis of used applications and potential risks, user risk assessment, and data access restriction. IT Partner will take personalized requirements into consideration while implementing Microsoft Cloud App Security. Service details: SKU ITPWW370IMPOT; price $4900; duration 3 weeks; manager Roman Sotnik. The plan may vary depending on your needs.
Success criteria
What you receive
How the work unfolds
Kickoff meeting
Collecting information about current infrastructure, users, applications, and devices
Cloud App Security implementation planning
Configuring the Cloud App Security portal
Configuring integration with cloud services
Deploying Microsoft Defender ATP using Group Policy or Microsoft Intune
Configuring the integration of Cloud Discovery and Windows 10 operating systems by integrating Microsoft Defender with Cloud App Security
Configuring policies and reports according to Cloud App Security data
Configuring notifications of potentially dangerous and dangerous actions
Verifying and fixing issues
Prerequisites
Who does what
IT Partner
- Gain an understanding of Client's cloud security objectives and requirements toward cloud usage and verify this against real usage of cloud applications and services
- Provide a prioritized and actionable road map for the customer containing proposed actions based on user impact and implementation cost
- Develop a plan and scenario of MS CAS
- Configure the Cloud App Security portal
- Configure integration with cloud services
- Deploy Microsoft Defender ATP using Group Policy or Microsoft Intune
- Configure the integration of Cloud Discovery and Windows 10 operating systems by integrating Microsoft Defender with Cloud App Security
- Configure Access Policies and Suspicious Activity Detection Policies
- Configure data management policies
- Configure application detection
- Configure reporting of Cloud App Security data
- Configure notifications of potentially dangerous and dangerous actions
Your team
- Coordinate Client resources and staff schedules
- Provide a dedicated point of contact responsible for working with IT Partner
- Provide all the necessary information for the statement of work preparation
- Coordinate any outside vendor resources and schedules
- Configure all network equipment, such as load balancers, routers, firewalls, and switches
- Review and approve engagement deliverables in a timely manner
What's not included
Limitations & technical notes
Frequently asked questions
What does the Cloud App Security Information and Threat Protection service implement?
This service implements Microsoft Cloud App Security for Microsoft Cloud services protection, because the engagement is focused on defining cloud security requirements, configuring the Cloud App Security portal, integrating it with cloud services and Windows 10 through Microsoft Defender, and setting up policies, reports, and notifications. The goal is to help detect suspicious or dangerous activity, assess cloud application risk, restrict data access, and give administrators operational and analytical visibility from the Cloud App Security dashboard.
What is included in IT Partner’s Microsoft Cloud App Security implementation?
The service includes requirements discovery, an implementation plan and scenario, a prioritized road map, Cloud App Security portal configuration, integration with cloud services, Microsoft Defender ATP deployment by Group Policy or Microsoft Intune, and Cloud Discovery integration with Windows 10. It also includes configuration of access policies, suspicious activity detection policies, data management policies, application detection, Cloud App Security reporting, and notifications for potentially dangerous and dangerous actions.
What is not included in this Cloud App Security service?
Employee training for administrators or security professionals is not included, because the engagement is an implementation service rather than a training program. Regular monitoring of reports, ongoing response to incidents, 24/7 support, continuous monitoring, ongoing maintenance, purchase of required product licenses, and more extensive documentation are also outside the standard scope; additional documentation may be available for an additional fee. 24/7 support, continuous monitoring, and ongoing maintenance are available as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.
How long does the Cloud App Security implementation take?
The stated duration for this service is 3 weeks. The plan may vary depending on customer needs, because the final scope is based on requirements, the current Microsoft 365 environment, available licenses, user devices, applications, and the policies to be configured.
How much does the Cloud App Security Information and Threat Protection service cost?
The listed service price is $4,900 for SKU ITPWW370IMPOT. Required Microsoft product licenses are not included in that price, because license purchase is explicitly outside the standard service scope.
What Microsoft licenses or prerequisites are required before starting?
The service requires a Microsoft 365 tenant and Microsoft Cloud App Security service, either in a customer production Office 365 tenant with Cloud App Security through an E5 license or in a trial Office 365 tenant with a Cloud App Security trial for up to 30 days. The listed prerequisites also include Windows 10 Corporate E5 and Microsoft 365 E5, including Windows 10 Corporate E5.
Can IT Partner use a trial tenant or trial Cloud App Security license for the engagement?
Yes, the service prerequisites allow either a production Office 365 tenant with Cloud App Security through E5 or a trial Office 365 tenant and Cloud App Security trial for up to 30 days. If required licenses are not purchased, a demo license may be used for appropriate products, but the client remains responsible for purchasing working licenses afterward independently or with IT Partner’s help.
What happens during the Cloud App Security engagement?
The engagement begins with a kickoff meeting, then IT Partner collects information about the current infrastructure, users, applications, and devices. The team then plans the Cloud App Security implementation, configures the portal and cloud service integrations, deploys Microsoft Defender ATP using Group Policy or Intune, integrates Cloud Discovery with Windows 10, configures policies, reports, and notifications, and then verifies and fixes issues.
What deliverables will the customer receive at the end of the service?
The customer receives a prioritized and actionable road map, a plan and scenario for Microsoft Cloud App Security, a configured Cloud App Security portal, configured cloud service integrations, deployed Microsoft Defender ATP, configured Cloud Discovery and Windows 10 integration, and configured policies, reports, application detection, and notifications. The engagement also includes a project closeout report showing final project status, acceptance criteria matching, outstanding issues, and final budget.
What are the success criteria for this Cloud App Security implementation?
The service is considered successful when client requirements for Microsoft Cloud App Security operations are defined, a statement of work matching implementable customer requirements is developed and provided, and Cloud App Security services are configured according to that statement of work. A further success criterion is that administrators can view operational and analytical information from the Cloud App Security dashboard.
Who is responsible for what during the project?
IT Partner is responsible for understanding cloud security objectives, verifying requirements against actual cloud application usage, creating the road map and Microsoft Cloud App Security plan, and configuring the portal, integrations, policies, reporting, notifications, Microsoft Defender ATP deployment, and Cloud Discovery integration. The client is responsible for coordinating staff and vendor schedules, assigning a dedicated point of contact, providing information for the statement of work, configuring network equipment such as firewalls, routers, switches, and load balancers, and reviewing deliverables on time.
Will this service configure my firewalls, routers, switches, or load balancers?
No, configuration of network equipment such as load balancers, routers, firewalls, and switches is the client’s responsibility. IT Partner’s scope is focused on Microsoft Cloud App Security configuration, cloud service integration, Microsoft Defender ATP deployment, Cloud Discovery integration, policies, reports, and notifications.
Does this service deploy Microsoft Defender ATP?
Yes, the service includes deploying Microsoft Defender ATP using Group Policy or Microsoft Intune. It also includes integrating Microsoft Defender with Cloud App Security so that Cloud Discovery and Windows 10 operating systems can be connected to the Cloud App Security scenario.
Does the service support Cloud Discovery and shadow IT application detection?
Yes, the engagement includes Cloud Discovery integration and configured application detection. This is relevant for analyzing used cloud applications, identifying potential risks, and supporting user risk assessment and data access restriction within the Microsoft Cloud App Security protection scenario.
Can this service configure Conditional Access App Control and data protection policies?
Yes, the service overview includes data protection and privacy scenarios, including the use of Conditional Access App Control. The engagement also includes configuring access policies, suspicious activity detection policies, and data management policies, based on the agreed statement of work and the customer’s current environment.
Will this implementation automatically respond to security incidents after the project?
No, ongoing monitoring of reports, regular review of actions, reaction to incidents, 24/7 support, continuous monitoring, and ongoing maintenance are not included in the standard service. The service configures reporting and notifications for potentially dangerous and dangerous actions, but day-to-day operational monitoring, incident response, 24/7 support, continuous monitoring, and ongoing maintenance remain outside the stated scope unless purchased as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.
Will the Cloud App Security implementation cause downtime or interrupt users?
The service description does not state a specific downtime window or downtime guarantee. Because the work mainly involves portal configuration, cloud service integration, Defender deployment, and policy configuration, the practical user impact depends on the policies selected, such as access restrictions or data controls; planned business impact should be confirmed with IT Partner during the statement of work.
Can Microsoft Cloud App Security monitor employees’ personal devices?
Microsoft Cloud App Security can help monitor employees’ personal devices and provide information about device security, vulnerabilities, hacking attempts, possible credential compromise, and suspicious activity. In this service, those capabilities are implemented according to the customer’s cloud security objectives, requirements, licensing, and the agreed Cloud App Security scenario.
What happens after IT Partner completes the implementation?
After completion, the customer should have a configured Cloud App Security portal, configured integrations, policies, reports, and notifications, and administrators should be able to view operational and analytical information from the dashboard. IT Partner also provides a project closeout report, but ongoing report monitoring, incident response, user or administrator training, license purchasing, 24/7 support, continuous monitoring, and ongoing maintenance are not included in the standard engagement. 24/7 support, continuous monitoring, and ongoing maintenance are available as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.