What's changed: Created MS-102 Chapter 4 (domain: Defender XDR, part 2). Defender for Endpoint (onboarding script/Intune/GPO, endpoint settings ASR/EDR block mode/tamper protection, Defender Vulnerability Management surfacing/remediating) and Defender for Cloud Apps (Microsoft 365 app connector, activity/file policies for alerts, Cloud App Discovery for shadow IT and risk scores, activity log investigation).
4.2Defender for Cloud Apps
Understand Microsoft Defender for Cloud Apps: connecting via the Microsoft 365 app connector, policies (activity/file policies that trigger alerts), Cloud App Discovery for shadow IT, and interpreting/responding to the activity log.
Microsoft Defender for Cloud Apps provides visibility and control over SaaS/cloud apps (a CASB)—combining "connect","detection policies","shadow IT discovery",and "log investigation"
4.2.1App connectors and policies
An app connector uses APIs to connect apps like Microsoft 365 to Defender for Cloud Apps, enabling deep visibility and control over activities and files. With policies—activity policies (suspicious sign-ins, mass downloads) and file policies (sensitive file sharing)—you trigger alerts on matches and run automated actions (e.g., remove sharing).
4.2.2Cloud App Discovery and logs
Cloud App Discovery analyzes firewall/proxy traffic logs to find unsanctioned cloud apps (shadow IT) actually used in the org, assigning each a risk score; risky discovered apps can be sanctioned (blocked). Interpret the daily activity log to investigate and respond to suspicious actions. Unlike app connectors (deep control of connected apps), Discovery’s role is "finding still-unmanaged apps".
Cues: "connect M365 via API for deep visibility/control" = app connector. "detection rule that alerts on match" = activity/file policy. "discover unsanctioned cloud apps (shadow IT) from log analysis with risk scores" = Cloud App Discovery. "investigate suspicious actions" = activity log. Cloud Apps = SaaS visibility; Endpoint = devices.
Watch the mix-ups: (1) App connector (deep control of connected apps) vs Cloud App Discovery (finding unmanaged apps). (2) Policies (detection rules) vs the activity log (raw logs). (3) Defender for Cloud Apps (SaaS/CASB) vs Defender for Endpoint (device EDR). (4) Shadow-IT discovery is Discovery.
4.2.3Section summary
- App connectors connect apps like M365 via API for deep visibility and control
- Activity/file policies trigger alerts on matches and automate response
- Cloud App Discovery finds shadow IT via log analysis and risk-scores apps
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. You want to analyze firewall/proxy logs to discover unsanctioned cloud apps (shadow IT) employees use. Best?
Q2. You want to connect Microsoft 365 via API to Defender for Cloud Apps for deep visibility/control over activities and files. Best?
Q3. You want automatic alerts when sensitive files are shared externally or mass downloads occur. Best?
Q4. You want to review chronological user actions in connected apps to spot suspicious activity. Best?
Q5. A CASB that visualizes/controls SaaS app usage and a device EDR are different products. Which handles the SaaS/cloud-app side?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

