↳ GitHub sourceConnector

Microsoft Defender for Cloud Apps

Description

By connecting with [Microsoft Defender for Cloud Apps](https://aka.ms/asi-mcas-connector-description) you will gain visibility into your cloud apps, get sophisticated analytics to identify and combat cyberthreats, and control how your data travels. - Identify shadow IT cloud apps on your network. - Control and limit access based on conditions and session context. - Use built-in or custom policies for data sharing and data loss prevention. - Identify high-risk use and get alerts for unusual user activities with Microsoft behavioral analytics and anomaly detection capabilities, including ransomware activity, impossible travel, suspicious email forwarding rules, and mass download of files. - Mass download of files [Deploy now >](https://aka.ms/asi-mcas-connector-deploynow)
Declared status
2
Declared author / publisher
Microsoft

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

read and write permissions.
Workspace
Workspace

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

Connect Microsoft Defender for Cloud Apps to Microsoft Sentinel
In the Microsoft Defender for Cloud Apps portal, under Settings, select Security extensions and then SIEM and set Microsoft Sentinel as your SIEM agent. For more information, see [Microsoft Defender for Cloud Apps](https://aka.ms/azuresentinelmcas) . After you connect Microsoft Defender for Cloud Apps, the alerts and discovery logs are sent to this Microsoft Sentinel workspace.​
Alerts
Cloud Discovery Logs (Preview)

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
MicrosoftCloudAppSecurity
Additional source files 2Solutions/Microsoft Defender for Cloud Apps/Data Connectors/MicrosoftCloudAppSecurity.JSONsource ↗Solutions/Microsoft Defender for Cloud Apps/Data/Solution_Microsoft Defender for Cloud Apps.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.