You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: CloudAppSecurityDocs/applications-inventory.md
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,17 +7,17 @@ description: The new Applications page located under Assets in Microsoft Defende
7
7
---
8
8
# Applications inventory (Preview)
9
9
10
-
Protecting your SaaS ecosystem requires taking inventory of all SaaS and OAuth connected apps that are in your environment. With the increasing number of applications, having a comprehensive inventory is crucial to ensure security and compliance. The Defender for Cloud apps Applications page provides a centralized view of all SaaS and connected OAuth apps in your organization, enabling efficient monitoring and management.
10
+
Protecting your SaaS ecosystem requires taking inventory of all SaaS and connected OAuth apps that are in your environment. With the increasing number of applications, having a comprehensive inventory is crucial to ensure security and compliance. The Applications page provides a centralized view of all SaaS and connected OAuth apps in your organization, enabling efficient monitoring and management.
11
11
At a glance you can see information such as app name, risk score, privilege level, publisher information, and other details for easy identification of SaaS and OAuth apps most at risk.
12
12
13
-
The Application page includes the following tabs:
13
+
The Applications page includes the following tabs:
14
14
15
15
* SaaS apps: A consolidated view of all SaaS applications in your network. This tab highlights key details, including app name, status (unprotected/protected app) and whether the app is marked as sanctioned or unsanctioned.
16
-
* OAuth apps: Displays a list of OAuth apps such as Microsoft Entra ID, Google workspace and Salesforce.
16
+
* OAuth apps: A comprehensive view of OAuth apps registered on Microsoft Entra ID, Google workspace and Salesforce. This tab highlights OAuth apps metadata, publisher info and app origin, permissions used, data accessed and other insights.
17
17
18
18
## Navigate to the Applications page
19
19
20
-
In the Defender portal at <https://security.microsoft.com>, go to **Assets**\>**Applications**. Or, to go directly to the **Applications** page, by clicking on the banner links on the existing Cloud discovery and App governance pages.
20
+
In the Defender portal at <https://security.microsoft.com>, go to **Assets** > **Applications**. Or, go directly to the **Applications** page, by clicking on the banner links on the existing Cloud discovery and App governance pages.
21
21
22
22
:::image type="content" source="media/banner-on-cloud-discovery-pages.png" alt-text="Screenshot of the Cloud Discovery page with a banner about the new unified application inventory experience" lightbox="media/banner-on-cloud-discovery-pages.png":::
Copy file name to clipboardExpand all lines: CloudAppSecurityDocs/network-requirements.md
+15-12Lines changed: 15 additions & 12 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,13 +1,15 @@
1
1
---
2
2
title: Network requirements
3
3
description: This article describes the IP addresses and ports you need to open to work with Defender for Cloud Apps.
4
-
ms.date: 02/29/2024
4
+
ms.date: 04/04/2024
5
5
ms.topic: reference
6
6
---
7
7
8
8
# Network requirements
9
9
10
-
10
+
>[!IMPORTANT]
11
+
>
12
+
> **Take Immediate Action by April, 21 2025**, to ensure optimal service quality and prevent the interruption of some services: Please update your firewall rules to allow outbound traffic on port 443 for the following IP addresses: 13.107.228.0/24, 13.107.229.0/24, 13.107.219.0/24, 13.107.227.0/24, 150.171.97.0/24. Alternatively, if you currently allow outbound traffic based on Azure service tags, please add the new Azure service tag, ‘AzureFrontDoor.MicrosoftSecurity’ to your allowlist. This tag will be adjusted to reflect the above range by April 21, 2025.
11
13
12
14
This article provides a list of ports and IP addresses you need to allow and allowlist to work with Microsoft Defender for Cloud Apps.
13
15
@@ -16,6 +18,7 @@ In order to stay up to date on IP ranges, it's recommended to refer to the follo
16
18
| Service tag name | Defender for Cloud Apps services included |
17
19
|:---|:---|
18
20
| MicrosoftCloudAppSecurity | Portal access, Access and session controls, SIEM agent connection, App connector, Mail server, Log collector. |
The following tables list the current static IP ranges covered by the MicrosoftCloudAppSecurity service tag. For latest list, refer to the [Azure service tags](/azure/virtual-network/service-tags-overview) documentation.
21
24
@@ -56,11 +59,11 @@ To use Defender for Cloud Apps in the Microsoft Defender Portal:
Copy file name to clipboardExpand all lines: CloudAppSecurityDocs/protect-aws.md
+1-2Lines changed: 1 addition & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -161,8 +161,7 @@ You can connect AWS **Security auditing** to Defender for Cloud Apps connections
161
161
**For an existing connector**
162
162
163
163
1. In the list of connectors, on the row in which the AWS connector appears, select **Edit settings**.
164
-
165
-

164
+
166
165
167
166
1. On the **Instance name** and **Connect Amazon Web Services** pages, select **Next**. On the **Security auditing page**, paste the **Access key** and **Secret key** from the .csv file into the relevant fields, and select **Next**.
Copy file name to clipboardExpand all lines: CloudAppSecurityDocs/protect-gcp.md
+3-4Lines changed: 3 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,7 +1,7 @@
1
1
---
2
2
title: Protect your Google Cloud Platform environment | Microsoft Defender for Cloud Apps
3
3
description: Learn how about connecting your Google Cloud Platform app to Defender for Cloud Apps using the API connector.
4
-
ms.date: 12/05/2023
4
+
ms.date: 03/04/2025
5
5
ms.topic: how-to
6
6
---
7
7
# How Defender for Cloud Apps helps protect your Google Cloud Platform (GCP) environment
@@ -47,7 +47,8 @@ For more information about remediating threats from apps, see [Governing connect
47
47
48
48
## Protect GCP in real time
49
49
50
-
Review our best practices for [securing and collaborating with external users](best-practices.md#secure-collaboration-with-external-users-by-enforcing-real-time-session-controls) and [blocking and protecting the download of sensitive data to unmanaged or risky devices](best-practices.md#block-and-protect-download-of-sensitive-data-to-unmanaged-or-risky-devices).
50
+
Review our best practices for [securing and collaborating with external users](best-practices.md#secure-collaboration-with-external-users-by-enforcing-real-time-session-controls) and [
51
+
blocking and protecting the download of sensitive data to unmanaged or risky devices](best-practices.md#block-and-protect-download-of-sensitive-data-to-unmanaged-or-risky-devices).
51
52
52
53
## Connect Google Cloud Platform to Microsoft Defender for Cloud Apps
53
54
@@ -167,8 +168,6 @@ This procedure describes how to add the GCP connection details to connect Google
167
168
168
169
1. In the list of connectors, on the row in which the GCP connector appears, select **Edit settings**.
169
170
170
-

171
-
172
171
1. In the **Enter details** page, do the following, and then select **Submit**.
173
172
1. In the **Organization ID** box, enter the organization you made a note of earlier.
174
173
1. In the **Private key file** box, browse to the JSON file you downloaded earlier.
Copy file name to clipboardExpand all lines: CloudAppSecurityDocs/protect-zoom.md
+7-2Lines changed: 7 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,7 +1,7 @@
1
1
---
2
2
title: Connect Zoom | Microsoft Defender for Cloud Apps
3
3
description: This article provides information about how to connect your Zoom environment to Defender for Cloud Apps using the API connector for visibility and control over use.
4
-
ms.date: 06/18/2023
4
+
ms.date: 03/04/2025
5
5
ms.topic: how-to
6
6
---
7
7
@@ -20,7 +20,7 @@ To see security posture recommendations for Zoom in Microsoft Secure Score, crea
20
20
For example, recommendations for Zoom include:
21
21
22
22
-*Enable multi-factor authentication (MFA)*
23
-
-*Enable session timeout for web users*
23
+
- Enable session timeout for web users
24
24
-*Enforce end to end encryption in all Zoom meetings*
25
25
26
26
If a connector already exists and you don't see Zoom recommendations yet, refresh the connection by disconnecting the API connector, and then reconnecting it with the `“account:read:admin`, `chat_channel:read:admin` and `user:read:admin”` permissions.
@@ -39,6 +39,11 @@ Before connecting Zoom to Defender for Cloud Apps, make sure that you have the f
39
39
40
40
The admin account is used only for initial consent while connecting Zoom to Defender for Cloud Apps. Defender for Cloud Apps uses an OAuth app for daily transactions.
41
41
42
+
>[!NOTE]
43
+
> The authentication mechanism utilized in the Zoom connector doesn't support two separate connectors utilizing the same user credentials.<br>
44
+
>
45
+
> When a new instance with an existing authentication token is used, this revokes the old connector token and will cause a "Bad credentials" error.
Copy file name to clipboardExpand all lines: CloudAppSecurityDocs/release-notes.md
+10Lines changed: 10 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,6 +7,10 @@ ms.topic: overview
7
7
8
8
# What's new in Microsoft Defender for Cloud Apps
9
9
10
+
>[!IMPORTANT]
11
+
>
12
+
> **Take Immediate Action by April, 21 2025**, to ensure optimal service quality and prevent the interruption of some services. This change will only affect your organization if you are using a firewall allowlist that restricts outbound traffic based on IP addresses or Azure service tags. Please update your firewall rules to allow outbound traffic on port 443 for the following IP addresses:13.107.228.0/24, 13.107.229.0/24, 13.107.219.0/24, 13.107.227.0/24, 150.171.97.0/24. Alternatively use as an additional Azure service tag, ‘AzureFrontDoor.MicrosoftSecurity’, that will be adjusted to reflect the above range by April 21, 2025. This update should be completed and the IP addresses or new Azure service tag added to your firewall's allowlist by April 21, 2025. Learn more: [Network requirements](https://aka.ms/MDANetworkDocs).
13
+
>
10
14
*Applies to: Microsoft Defender for Cloud Apps*
11
15
12
16
This article is updated frequently to let you know what's new in the latest release of Microsoft Defender for Cloud Apps.
@@ -22,6 +26,12 @@ For news about earlier releases, see [Archive of past updates for Microsoft Defe
22
26
23
27
## April 2025
24
28
29
+
### OAuthAppInfo table added to Defender XDR advanced hunting (Preview)
30
+
31
+
The [OAuthAppInfo](/defender-xdr/advanced-hunting-oauthappinfo-table) table is now available in Defender XDR advanced hunting, enabling security teams to explore and analyze OAuth app-related metadata with enhanced visibility.
32
+
33
+
This table provides details on Microsoft 365-connected OAuth applications that are registered with Microsoft Entra ID and accessible through the Defender for Cloud Apps app governance capability.
34
+
25
35
### New Applications page in Defender XDR (Preview)
26
36
27
37
The new Applications page consolidates all SaaS and connected OAuth applications into a single, unified inventory. This centralized view streamlines application discovery, monitoring, and management, providing greater visibility and control across your environment.
0 commit comments