What is Microsoft Defender for Cloud Apps? Understanding the differences between Cloud Discovery and E3/E5
About This Article
This article was created using an automated generation workflow utilizing generative AI. Based on official Microsoft information as of September 17, 2026, it organizes the roles of Microsoft Defender for Cloud Apps and Cloud Discovery, as well as their positioning in E3/E5, from a practical perspective.Verification Status: 📘 Confirmed with official Microsoft documentation; actual device not tested
Microsoft Defender for Cloud Apps is a SaaS security product designed to visualize SaaS used within an organization and to investigate and control risky apps, OAuth apps, and suspicious cloud activities. You can manage CASB, SaaS Security Posture Management, threat protection, and cross-app protection from the Microsoft Defender portal.
How do E3 and E5 differ?
Microsoft 365 E5 includes Defender for Cloud Apps. While Microsoft 365 E3 includes related foundational features such as Microsoft Entra ID P1, full functionality for Defender for Cloud Apps is not automatically included with E3 alone. When using it from an E3 baseline, verify the appropriate licenses for the required features, such as standalone or target Security/Purview SKUs.
According to official Microsoft service descriptions for 2026, Defender for Cloud Apps is included in multiple plans, including standalone, Microsoft 365 E5, EMS E5, the Microsoft Defender Suite, and the Microsoft Purview Suite.
What is Cloud Discovery?
Cloud Discovery serves as an entry point to visualize which cloud apps are being used across your organization's network. Beyond simply listing app names, it allows you to check usage volume, users, traffic, and risk assessments, enabling you to investigate unauthorized SaaS and generative AI service usage.
First Step: Check Cloud Discovery in Read-Only Mode
If licenses and data integration are already configured, open Cloud Apps > Cloud Discovery in the Microsoft Defender portal.
Key items to review here:
Top Discovered apps
Risk score
Number of users
Traffic volume
Sanctioned / Unsanctioned status
Initially, observe which services are actually being used without changing apps to Unsanctioned.
Try Changing One Parameter
Narrow down categories using dashboard filters. For example, limit the investigative scope to Generative AI or Cloud storage and compare the displayed results. Because this does not involve changing policies, it is ideal for initial assessments.
A Practical and Interesting Use Case: Inventorying Generative AI
If you only monitor "AI contracted by the company," you will overlook external AI services accessed via browsers. If your configuration allows data retrieval from Cloud Discovery, you can check usage trends within the generative AI category and use them to examine the gap between usage policies and reality.
However, rather than instantly blocking discovered apps, proceed to enforcement only after confirming business purposes, data types, alternative solutions, and user impact.
Relationship with Conditional Access App Control
Defender for Cloud Apps integrates with Microsoft Entra Conditional Access to control sessions for target SaaS. However, this feature requires not only Defender for Cloud Apps but also related licenses such as Microsoft Entra ID P1.
Avoid applying strict controls—such as download blocks—to all production users during initial testing; instead, verify the impact using test users and limited apps.
Practical Use Cases
Inventory usage status of unauthorized SaaS
Check actual usage trends of generative AI services
Investigate risks associated with OAuth applications
Verify security posture of SaaS configurations
Correlate cloud app alerts with other attack signals using Defender XDR
Key Considerations for Administrators
Licenses of protected users
Cloud Discovery data sources
Log collection scope and privacy
Dependencies with Microsoft Entra Conditional Access
Impact when modifying Sanctioned / Unsanctioned status
Integration status with Defender XDR
Cloud Discovery results include organizational behavioral data such as users and traffic volumes. Restrict viewing permissions to the minimum necessary and clearly define the monitoring objective.
Official Microsoft Information and Primary Sources
Microsoft Defender for Cloud Apps documentation: https://learn.microsoft.com/en-us/defender-cloud-apps/
Get started with Defender for Cloud Apps: https://learn.microsoft.com/en-us/defender-cloud-apps/get-started
Cloud Discovery dashboard: https://learn.microsoft.com/en-us/defender-cloud-apps/discovered-apps
Microsoft Defender service description: https://learn.microsoft.com/en-us/office365/servicedescriptions/microsoft-365-service-descriptions/microsoft-365-tenantlevel-services-licensing-guidance/microsoft-defender-service-description
Defender for Cloud Apps is not a product designed to "ban the cloud," but rather a solution to first make actual SaaS usage visible. Simply reviewing Cloud Discovery in read-only mode can reveal gaps between expectations and reality.

