What's changed: Created MS-102 Chapter 4 (domain: Defender XDR, part 2). Defender for Endpoint (onboarding script/Intune/GPO, endpoint settings ASR/EDR block mode/tamper protection, Defender Vulnerability Management surfacing/remediating) and Defender for Cloud Apps (Microsoft 365 app connector, activity/file policies for alerts, Cloud App Discovery for shadow IT and risk scores, activity log investigation).
4.2Defender for Cloud Apps
Understand Microsoft Defender for Cloud Apps: connecting via the Microsoft 365 app connector, policies (activity/file policies that trigger alerts), Cloud App Discovery for shadow IT, and interpreting/responding to the activity log.
Microsoft Defender for Cloud Apps provides visibility and control over SaaS/cloud apps (a CASB)—combining "connect","detection policies","shadow IT discovery",and "log investigation"
4.2.1App connectors and policies
An app connector uses APIs to connect apps like Microsoft 365 to Defender for Cloud Apps, enabling deep visibility and control over activities and files. With policies—activity policies (suspicious sign-ins, mass downloads) and file policies (sensitive file sharing)—you trigger alerts on matches and run automated actions (e.g., remove sharing).
4.2.2Cloud App Discovery and logs
Cloud App Discovery analyzes firewall/proxy traffic logs to find unsanctioned cloud apps (shadow IT) actually used in the org, assigning each a risk score; risky discovered apps can be sanctioned (blocked). Interpret the daily activity log to investigate and respond to suspicious actions. Unlike app connectors (deep control of connected apps), Discovery’s role is "finding still-unmanaged apps".
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

