Instiq
Chapter 4 · Defender for Endpoint and Cloud Apps·v1.0.0·Updated 6/30/2026·~13 min

What's changed: Created MS-102 Chapter 4 (domain: Defender XDR, part 2). Defender for Endpoint (onboarding script/Intune/GPO, endpoint settings ASR/EDR block mode/tamper protection, Defender Vulnerability Management surfacing/remediating) and Defender for Cloud Apps (Microsoft 365 app connector, activity/file policies for alerts, Cloud App Discovery for shadow IT and risk scores, activity log investigation).

4.2Defender for Cloud Apps

Key points

Understand Microsoft Defender for Cloud Apps: connecting via the Microsoft 365 app connector, policies (activity/file policies that trigger alerts), Cloud App Discovery for shadow IT, and interpreting/responding to the activity log.

Microsoft Defender for Cloud Apps provides visibility and control over SaaS/cloud apps (a CASB)—combining "connect","detection policies","shadow IT discovery",and "log investigation"

4.2.1App connectors and policies

An app connector uses APIs to connect apps like Microsoft 365 to Defender for Cloud Apps, enabling deep visibility and control over activities and files. With policiesactivity policies (suspicious sign-ins, mass downloads) and file policies (sensitive file sharing)—you trigger alerts on matches and run automated actions (e.g., remove sharing).

4.2.2Cloud App Discovery and logs

Cloud App Discovery analyzes firewall/proxy traffic logs to find unsanctioned cloud apps (shadow IT) actually used in the org, assigning each a risk score; risky discovered apps can be sanctioned (blocked). Interpret the daily activity log to investigate and respond to suspicious actions. Unlike app connectors (deep control of connected apps), Discovery’s role is "finding still-unmanaged apps".

Exam point

Cues: "connect M365 via API for deep visibility/control" = app connector. "detection rule that alerts on match" = activity/file policy. "discover unsanctioned cloud apps (shadow IT) from log analysis with risk scores" = Cloud App Discovery. "investigate suspicious actions" = activity log. Cloud Apps = SaaS visibility; Endpoint = devices.

Warning

Watch the mix-ups: (1) App connector (deep control of connected apps) vs Cloud App Discovery (finding unmanaged apps). (2) Policies (detection rules) vs the activity log (raw logs). (3) Defender for Cloud Apps (SaaS/CASB) vs Defender for Endpoint (device EDR). (4) Shadow-IT discovery is Discovery.

Diagram: SaaS/cloud-app visibility and control (CASB). An app connector connects apps like Microsoft 365 via API for deep visibility/control; activity/file policies trigger alerts on matches; Cloud App Discovery finds unsanctioned apps (shadow IT) via log analysis with risk scores; the activity log investigates suspicious actions; distinct from Endpoint (devices).
See SaaS

4.2.3Section summary

  • App connectors connect apps like M365 via API for deep visibility and control
  • Activity/file policies trigger alerts on matches and automate response
  • Cloud App Discovery finds shadow IT via log analysis and risk-scores apps

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. You want to analyze firewall/proxy logs to discover unsanctioned cloud apps (shadow IT) employees use. Best?

Q2. You want to connect Microsoft 365 via API to Defender for Cloud Apps for deep visibility/control over activities and files. Best?

Q3. You want automatic alerts when sensitive files are shared externally or mass downloads occur. Best?

Q4. You want to review chronological user actions in connected apps to spot suspicious activity. Best?

Q5. A CASB that visualizes/controls SaaS app usage and a device EDR are different products. Which handles the SaaS/cloud-app side?

Check your understandingPractice questions for Chapter 4: Defender for Endpoint and Cloud Apps

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.