Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDRMedium

A large multinational corporation is implementing Microsoft Defender for Cloud Apps to gain visibility and control over its cloud application usage. The security team needs to identify all unsanctioned cloud applications currently being used by employees across the organization's network, including those accessed from unmanaged devices. This discovery process must be comprehensive and provide risk assessment for each discovered app. Which method for cloud app discovery should the administrator prioritize to achieve this goal?

  1. AAutomatic log upload (Log collector)
  2. BManual log upload
  3. CMicrosoft Defender for Endpoint integration
  4. DApp connectors
Show answer & explanation

Correct answer: C. Microsoft Defender for Endpoint integration

Integrating Microsoft Defender for Endpoint with Defender for Cloud Apps provides the most comprehensive and real-time discovery of cloud apps across all devices, including unmanaged ones, by leveraging Defender for Endpoint's network protection capabilities. This allows for shadow IT discovery and risk assessment.

Why the other options are wrong

  • A. Automatic log upload via log collectors processes firewall/proxy logs from managed devices but may miss traffic from unmanaged devices or specific endpoints.
  • B. Manual log upload is suitable for one-time or infrequent analysis but is not comprehensive or real-time for continuous discovery across a large organization.
  • D. App connectors provide deep visibility and control for *sanctioned* apps but are not designed for discovering *unsanctioned* shadow IT across the network.

Defender for Cloud Apps - Defender for Endpoint Integration

A powerful integration that enables Microsoft Defender for Cloud Apps to leverage network traffic information from Microsoft Defender for Endpoint-onboarded devices for comprehensive Shadow IT discovery, including applications accessed from unmanaged devices.

  • Provides comprehensive cloud app discovery (Shadow IT).
  • Leverages network data from Defender for Endpoint.
  • Discovers apps on both managed and unmanaged devices.
  • Enables risk assessment for discovered apps.

Memory trick: Defender for Endpoint is like the ultimate spy on every device, telling Cloud Apps everything it sees.

More Implement and manage Microsoft Defender XDR questions