Quick Links

Integrating with Microsoft Defender for Cloud Apps

Overview

Microsoft Defender for Cloud Apps (formerly Cloud App Security) is a multimode cloud access security broker (CASB) that provides visibility, control over data travel, and sophisticated analytics to identify and combat cyber threats across all Microsoft cloud services. Blumira integrates with Microsoft Defender for Cloud Apps to stream Microsoft cloud security event logs and alerts to the Blumira service for threat detection and actionable response. 

Note: If you are looking to integrate with other Microsoft products or want to understand how Microsoft Defender for Cloud Apps differs from the other Microsoft integrations, see Getting started with Blumira's Microsoft 365 and Azure log monitoring.

Before you begin

If you have not previously configured Microsoft Defender for Cloud Apps in your Microsoft 365 tenant, please see Microsoft’s Get Started Guide for initial setup instructions.

To gather your Cloud Apps token and URL, do the following:

  1. Log in to https://security.microsoft.com.
  2. Navigate to System > Settings.
  3. Click Cloud Apps.
  4. Click API Tokens.
  5. Click + to add a new token.
  6. Enter a name, such as “Blumira Cloud Connector.”
  7. Copy the token and the URL for use in the Blumira Cloud Connector.

Note: The API token generated for Defender for Cloud Apps is linked to the user that generated it. If the user is removed from the Microsoft 365 tenant or has roles removed, the token will be invalidated.

Configuring the MS Cloud Apps Cloud Connector

To configure the Blumira Cloud Connector and begin logging, do the following:

  1. In Blumira, navigate to Ingestion > Cloud Connectors.
  2. Click + Add Cloud Connector.
  3. In the Available Cloud Connectors window, select the connector you want to add.
  4. In Cloud Connector Name, type a name that will help you identify the integration.
  5. In the remaining fields, enter the credentials you gathered in the previous steps.
  6. Click Connect.