What is Microsoft Defender for Cloud Apps? Cloud Discovery and E3/E5

セキュリティカテゴリを表すパンダのイラスト Security

What is Microsoft Defender for Cloud Apps? Understanding the differences between Cloud Discovery and E3/E5

About This Article
This article was created using an automated generation workflow utilizing generative AI. Based on official Microsoft information as of September 17, 2026, it organizes the roles of Microsoft Defender for Cloud Apps and Cloud Discovery, as well as their positioning in E3/E5, from a practical perspective.

Verification Status: 📘 Confirmed with official Microsoft documentation; actual device not tested

Microsoft Defender for Cloud Apps is a SaaS security product designed to visualize SaaS used within an organization and to investigate and control risky apps, OAuth apps, and suspicious cloud activities. You can manage CASB, SaaS Security Posture Management, threat protection, and cross-app protection from the Microsoft Defender portal.

How do E3 and E5 differ?

Microsoft 365 E5 includes Defender for Cloud Apps. While Microsoft 365 E3 includes related foundational features such as Microsoft Entra ID P1, full functionality for Defender for Cloud Apps is not automatically included with E3 alone. When using it from an E3 baseline, verify the appropriate licenses for the required features, such as standalone or target Security/Purview SKUs.

According to official Microsoft service descriptions for 2026, Defender for Cloud Apps is included in multiple plans, including standalone, Microsoft 365 E5, EMS E5, the Microsoft Defender Suite, and the Microsoft Purview Suite.

What is Cloud Discovery?

Cloud Discovery serves as an entry point to visualize which cloud apps are being used across your organization's network. Beyond simply listing app names, it allows you to check usage volume, users, traffic, and risk assessments, enabling you to investigate unauthorized SaaS and generative AI service usage.

First Step: Check Cloud Discovery in Read-Only Mode

If licenses and data integration are already configured, open Cloud Apps > Cloud Discovery in the Microsoft Defender portal.

Key items to review here:

  • Top Discovered apps

  • Risk score

  • Number of users

  • Traffic volume

  • Sanctioned / Unsanctioned status

Initially, observe which services are actually being used without changing apps to Unsanctioned.

Try Changing One Parameter

Narrow down categories using dashboard filters. For example, limit the investigative scope to Generative AI or Cloud storage and compare the displayed results. Because this does not involve changing policies, it is ideal for initial assessments.

A Practical and Interesting Use Case: Inventorying Generative AI

If you only monitor "AI contracted by the company," you will overlook external AI services accessed via browsers. If your configuration allows data retrieval from Cloud Discovery, you can check usage trends within the generative AI category and use them to examine the gap between usage policies and reality.

However, rather than instantly blocking discovered apps, proceed to enforcement only after confirming business purposes, data types, alternative solutions, and user impact.

Relationship with Conditional Access App Control

Defender for Cloud Apps integrates with Microsoft Entra Conditional Access to control sessions for target SaaS. However, this feature requires not only Defender for Cloud Apps but also related licenses such as Microsoft Entra ID P1.

Avoid applying strict controls—such as download blocks—to all production users during initial testing; instead, verify the impact using test users and limited apps.

Practical Use Cases

  • Inventory usage status of unauthorized SaaS

  • Check actual usage trends of generative AI services

  • Investigate risks associated with OAuth applications

  • Verify security posture of SaaS configurations

  • Correlate cloud app alerts with other attack signals using Defender XDR

Key Considerations for Administrators

  • Licenses of protected users

  • Cloud Discovery data sources

  • Log collection scope and privacy

  • Dependencies with Microsoft Entra Conditional Access

  • Impact when modifying Sanctioned / Unsanctioned status

  • Integration status with Defender XDR

Cloud Discovery results include organizational behavioral data such as users and traffic volumes. Restrict viewing permissions to the minimum necessary and clearly define the monitoring objective.

Official Microsoft Information and Primary Sources

  • Microsoft Defender for Cloud Apps documentation: https://learn.microsoft.com/en-us/defender-cloud-apps/

  • Get started with Defender for Cloud Apps: https://learn.microsoft.com/en-us/defender-cloud-apps/get-started

  • Cloud Discovery dashboard: https://learn.microsoft.com/en-us/defender-cloud-apps/discovered-apps

  • Microsoft Defender service description: https://learn.microsoft.com/en-us/office365/servicedescriptions/microsoft-365-service-descriptions/microsoft-365-tenantlevel-services-licensing-guidance/microsoft-defender-service-description

Defender for Cloud Apps is not a product designed to "ban the cloud," but rather a solution to first make actual SaaS usage visible. Simply reviewing Cloud Discovery in read-only mode can reveal gaps between expectations and reality.

Document information

Article title
What is Microsoft Defender for Cloud Apps? Cloud Discovery and E3/E5
Published
Updated
Source
https://papanda925.com/?p=16300&lang=en

License: Text and original figures for which this site holds the relevant rights are available under CC BY 4.0 , unless otherwise noted. This article may include content created or edited with generative AI. If code has a separate license notice or a linked GitHub repository license, that license takes precedence for the code. Quotations, third-party materials, images, and trademarks are excluded from this license. Usage policy

Copied title and URL