A
Assistant System Engineer
"MCAS Evaluation"
This Microsoft CASB solution is excellent for detecting threats and discovering shadow IT, providing rich information for investigating alerts and identifying OAuth applications used within the organization. There is little to dislike about Defender for Cloud Apps. It assists in shadow IT discovery, allowing security administrators to monitor which OAuth apps users are utilizing.
S
Senior Operations Executive - Data Engineering
"Ensuring Cloud Data Safety with Microsoft Defender"
1. Integrates with the Microsoft security stack for a unified security experience. 2. Provides real-time threat detection and prevention using advanced intelligence and machine learning. 3. Allows customization of security policies to meet specific organizational needs. 4. Cloud-based architecture ensures real-time updates and improvements. 5. Strong performance in quickly and accurately detecting threats. Some limitations include limited coverage for only a few cloud apps, complexity in managing features, and potential false positives. These may not affect all users, so it's crucial to thoroughly evaluate before adoption. The solution offers advanced threat protection, improved security visibility, real-time threat response, integration with Microsoft 365, and compliance support.
"Comprehensive Cloud-Native Security"
Offers comprehensive visibility, threat detection, and data protection, addressing various cloud security concerns. Integration is strong, especially within the Microsoft ecosystem, but configuration can be complex at times. While Microsoft integration is beneficial, it may complicate integration with non-Microsoft products. It aids in cloud application security, provides better visibility and control, supports compliance and governance, and enables centralized management.
"Deep Insights Before Problems Arise"
A key strength is its seamless integration with Windows, running efficiently in the background without affecting performance. It offers real-time protection, cloud-based defense, and automatic updates against the latest threats. It's also user-friendly, pre-installed on Windows 10, with a simple interface ideal for non-technical users. However, it has limited support for third-party cloud apps and requires Azure AD for integration. Setting it up demands technical expertise and can be challenging for novices, with significant configuration including policies, DLP rules, and integrations. It helps manage shadow IT by identifying unapproved cloud applications, giving IT visibility and control. It also provides DLP to prevent unauthorized data sharing and advanced threat detection with real-time monitoring and automated remediation. Overall, benefits include improved visibility, enhanced security and compliance, and reduced risk of data loss and attacks.
"A Powerful Native CASB"
Microsoft Defender for Cloud Apps (MDA) is a native CASB that protects M365 apps like Teams and SharePoint, and can also cover third-party applications. It handles scenarios like mass file downloads or sharing files with competitor domains by enforcing policies. Combined with Defender for Endpoint, it uncovers apps used on devices, providing control and reducing shadow IT. I particularly like that setting up a Microsoft 365 connector takes under five minutes. It has converged with the Microsoft 365 Defender Portal, allowing access alongside Defender for Endpoint, Identity, and alerts/incidents. Policy application is easy due to many templates. My advice is to start with a few policies and users in a PoC and scale up. Advanced features like automatic sensitivity labeling, conditional access app control, and app governance are great once you gain experience. Previously, the separate Cloud App Security portal felt disconnected, but the convergence now enables seamless movement across stack products. I'm excited for future enhancements like continuous access evaluation. As a trainer, MDA helps police misuse of M365 apps and sensitive information, uncovers shadow IT, and alerts on incidents. Automation speeds up decisions and reduces manual overhead.
S
Senior Information Security Specialist
"Excellent Cloud App Security Solution"
Getting started is straightforward if you have Defender for Endpoint in place, as it serves as a source for initial cloud discovery and shadow IT detection. It's a vital component of the Defender suite. Seamless integration with AAD, DFE, and Purview amplifies its power. However, AAD group synchronization is not immediate and can take painfully long, which affects applying policies to targeted users and may hinder real-time automation involving dynamic group additions. Features like blocking unwanted apps via policies help stop access to malicious applications, and connected apps enable governance actions with Power Automate for more granular control.
"Cloud App Security Review"
Defender for Cloud Apps offers rich logs as one of its standout features, integration with Defender for Endpoint and Azure AD Identity Protection, and correlates all logs into intuitive visual representations. A limitation is the lack of automation; for instance, I can't directly quarantine or remove malware detected in SharePoint/OneDrive through policies, requiring manual file deletion via alerts. It's one of the best CASB solutions available, especially when users log in from untrusted locations or devices. It alerts on suspicious activities like mass downloads, uploads, deletions from Tor network, or logins from unusual countries, providing a holistic view of user behavior in cloud apps.
I
Information Security Analyst
"Top-Tier CASB Solution"
I appreciate how MDCA safeguards sensitive information across integrated cloud applications from unauthorized exfiltration. The dashboard customization options are impressive, allowing us to display detailed metrics through templates. However, integrating and maintaining various SaaS apps within MDCA poses challenges and requires specialized skills that are hard to find. MDCA has significantly improved our cloud app security posture by enabling us to enforce security policies and maintain protection across all our SaaS applications. Additionally, we used MDCA for security monitoring, as it sends timely alerts for anomalies or data exfiltration attempts.
"Comprehensive Cloud App Protection"
Microsoft 365 threat detection integrates well with broad cloud app security policies, compliance, and ease of management and deployment. When evaluating Microsoft Defender for Cloud Apps, it's essential to consider your organization's specific needs, the state of your cloud apps, and your existing security posture. This tool covers all essential cloud security aspects to ensure data and environment safety. However, the feature set and available integrations can be somewhat confusing for end users; improving this would make the tool more user-friendly and effective. It has enhanced our cloud service security by providing visibility, control, and threat protection. Overall, it has strengthened our cybersecurity stance and aided in better decision-making.
M
Mid-Market (51-1000 emp.)
"Dependable and effective cloud security solution"
This security product is dependable, efficient, and reliable, with the top feature being instant threat alerts and smooth connections to other platforms like ServiceNow. The initial learning curve for Microsoft Defender can be somewhat steep, especially regarding its architecture and linking it with other systems such as XDR, and it could be more intuitive. It assists in safeguarding both on-premises employee machines and approved client cloud setups for data management development initiatives.