Proof Of Concept : The Power Of Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
Today, many companies are moving their data and operations to the cloud. This shift means that companies need consistent strategies for securing cloud applications and data, backed up by effective security tools. One of the best tools for this purpose is the Cloud Access Security Broker (CASB) – Microsoft Defender for Cloud Apps – a part of the Microsoft 365 XDR suite. Before diving deeper into this tool, let’s first understand what a CASB is and why it’s vital for cloud security.
What is a Cloud Access Security Broker (CASB)?
A cloud access security broker serves as a checkpoint between company users and cloud service providers. CASBs handle various security tasks, such as checking user identities, encrypting data, spotting malware, and more. Think of a CASB as a security guard for cloud services. Its job is to keep an eye on cloud app use, catch possible threats, and make sure companies handle data correctly.
Cloud security access Broker [1]
Key Benefits of CASBs
CASBs provide several security advantages for businesses, helping them reduce risks, set rules for apps and devices, and follow important regulations, here is the five foundational pillars of a CASB [2]:
-
-
Shadow IT Assessment and Management : CASBs reveal all cloud apps in use, whether the company knows about them or not.
-
Detailed Cloud Control : With CASBs, companies can closely manage cloud use, deciding who uses which apps and how.
-
Prevent Data Loss (DLP) : CASBs can set rules that stop unauthorized data sharing.
-
Risk visibility : CASBs allow enterprises to assess the risk of unsanctioned applications and make access decisions accordingly.
-
Threat prevention: They can identify risky apps or unusual user behavior and automatically remediate threats, limiting an organization’s risk.
-
How Does a CASB Work?
CASBs use a three-step approach to offer visibility across apps and protect company data [2]:
-
- Discovery : The CASB identifies all cloud applications in use as well as affiliated employees.
- Classification : The CASB assesses each application, identifies its data, and calculates a risk factor.
- Remediation : The CASB creates a tailored policy for the enterprise based on its security needs. From there the CASB identifies and remediates any incoming threats or violations.
Given their abilities, CASBs are essential tools for companies wanting to keep their cloud data and apps safe. One of the leading tools in this space is Microsoft Defender for Cloud Apps.
Microsoft Defender for Cloud Apps Overview
In hybrid work environments, Software as a Service (SaaS) applications have become a standard, and protecting SaaS apps and the important data they store is a big challenge for organizations. The increasing dependency on apps, coupled with remote access to company resources, has opened new vectors for cyber threats. To combat these attacks effectively, security teams need an approach that protects their data within cloud apps beyond the traditional scope of cloud access security brokers (CASBs).
Diagram of the Defender for Cloud App pillars [3]
Microsoft Defender for Cloud Apps delivers full protection for SaaS applications, helping you monitor and protect your cloud app data across the following feature areas:
-
- CASB Features : This includes functionalities like Shadow IT discovery, insight into cloud app utilization, defenses against cloud-native threats, and tools for information protection and compliance assessments.
- SaaS Security Posture Management (SSPM) : This allows security teams to fine-tune and enhance an organization’s cloud security posture
- Advanced Threat Protection : Integrated into Microsoft’s Extended Detection and Response (XDR) suite, this provides extensive visibility and effective countermeasures against sophisticated cyber-attacks across their entire lifecycle.
- App-to-App Protection : Designed for OAuth-enabled applications, this feature ensures security for apps that have permissions to access essential data and resources.
Microsoft Defender for Cloud Apps POC
Objective of the POC
To assess the efficacy of Microsoft Defender for Cloud Apps in the context of small to medium-sized businesses (SMEs), we at Windfiel decided to conduct this proof of concept (POC) and share the results subsequently. This POC will center around three key areas :
-
- Visibility : Microsoft Defender for Cloud Apps will be used to gain visibility into cloud app usage, including who is accessing apps, where they are accessing them from, and what data is being stored and shared.
- Threat detection and prevention : Microsoft Defender for Cloud Apps will be used to detect and prevent threats, such as data exfiltration, malware, and phishing attacks.
- Compliance reporting : Microsoft Defender for Cloud Apps will be used to generate reports on cloud app usage and data protection, which can help SMEs comply with regulations.
POC Setup
Environment : The tests are performed in a dedicated test environment on the Microsoft Defender online platform (https://security.microsoft.com).
Configuration and Settings:
-
- Licensing: We’re using the E5 license of Microsoft 365. This license allows us to use all of Microsoft Defender’s tools, making it ideal for our application and for small and medium businesses.
- SaaS Application Integration: Integrating different online apps with Microsoft Defender for Cloud Apps is a key part of our setup. Without this connection, we won’t get alerts from those apps. To set this up:
- Navigate to: Settings > Cloud Apps > Connected app > app connector.
- Select connect an app.
Cloud app Connect
-
- Integration with Microsoft Defender for Endpoint: Another essential step of our setup is the linking with Microsoft Defender for Endpoint. If a discovered cloud app is identified as risky then classified as unsanctioned, this tool can block it right away directly in the user workstation. To enable this:
- Go to: Settings > Cloud Apps > Cloud discovery.
- Choose Microsoft Defender for Endpoint.
- Tick the box for Enforce app access to block apps labeled as non-approved
- Integration with Microsoft Defender for Endpoint: Another essential step of our setup is the linking with Microsoft Defender for Endpoint. If a discovered cloud app is identified as risky then classified as unsanctioned, this tool can block it right away directly in the user workstation. To enable this:
Integration with Microsoft Defender for Endpoint
Test Scenarios
In the context of enhancing security for SMEs and capitalizing on the capabilities of Microsoft Defender for Cloud Apps, we’ve strategically identified specific risk scenarios for evaluation. These scenarios serve as the blueprint for our tests. Our objective is to evaluate Microsoft Defender for Cloud Apps efficacy in mitigating these potential risks. The scope of our tests has been deliberately narrowed to focus on the most critical and relevant policies for SMEs environment.
N.B. : Our primary focus has been on tests related to Microsoft 365 integrations. However, we have also conducted tests with other SaaS tools once integrated, and the outcomes were equally conclusive.
In this section, we will primarily concentrate our tests on the following three aspects of Microsoft Defender for Cloud Apps: Shadow IT, Threat Protection, and Information Protection. Below, you will find a visual representation of the product’s interface.
microsoft defender for cloud apps policy management interface
Shadow IT
Test 1: New high-volume app.
-
- Description: Alert in case of discovery of new applications with a daily total traffic greater than XX Mo.
- Risk: Undetected applications could be malicious, insecure, or non-compliant with company policies. This might expose the company to security threats like data breaches, intrusions, or malware attacks. Uncontrolled network resource usage could also degrade network performance.
Test 2: New risky app.
-
- Description: Alert when new applications are discovered with a risk score below 6.
- Risk: Use of risky applications without detection can expose the company to data breaches, regulatory non-compliances, loss of company reputation, or potential facilitation of malicious activities like spam or DDoS attacks.
Threat Detection
Test 1: Multiple failed login attempts.
-
- Description: Alert when a single user attempts to log on to a single app and fails more than 3 times within 5 minutes.
- Risk: If not detected, the company is vulnerable to potential brute force attacks or unauthorized access attempts, which could lead to data breaches, theft of sensitive information, operational disruptions, and significant reputational or financial consequences.
Test 2: Mass download by a single user.
-
- Description: Alert when a single user performs more than 5 downloads within 1 minute.
- Risk: Unusual file downloads could indicate malicious activity, unauthorized access to sensitive data, or a compromised user account, potentially leading to data breaches, loss of intellectual property, regulatory non-compliances, or loss of trust among clients and partners.
Information Protection
Test 1: Externally shared source code.
-
- Description: Alert when a file containing source code is shared outside your organization.
- Risk: Sharing source code externally can lead to the disclosure of intellectual property, expose sensitive algorithms, or specific configurations. Unauthorized third parties could exploit any vulnerabilities in the code, resulting in potential financial losses, damaged reputation, or legal repercussions.
Test 2: Activity from infrequent country.
-
- Description: This policy profiles your environment and triggers alerts when activity is detected from a location that was not recently or never visited by the user or by any user in the organization. Detecting anomalous locations necessitates an initial learning period of 7 days, during which it does not alert on any new locations.
- Risk: Unexpected geolocation-based activities can be indicative of unauthorized access, potential security breaches, or other malicious intents. Such breaches can lead to data theft, unauthorized transactions, operational disruptions, and reputational damage. Furthermore, it might expose the company to regulatory penalties if sensitive data is accessed or manipulated from regions that are not in compliance with data protection regulations or company policies.
Execution & Results
Shadow IT
Test 1: High Volume App Alert
Goal : Trigger an alert if new applications are discovered with daily traffic exceeding XX MB.
Procedure :
-
- Navigate to: Menu > Cloud apps > Policies > Policy management > Create app discovery policy.
- Select the “New High Volume App” template.
- Provide a name for your rule and set the desired severity level.
- Adjust the filter based on the template, for this test, set the daily traffic threshold for e.g. at 500 MB.
- Choose your alert delivery method, e.g., via email, and decide on the daily alert frequency.
- For enhanced oversight, you can also integrate governance actions into your policy configuration. This ensures not just alerting but also taking preventive measures against potential threats.
- Navigate to: Governance Actions within the policy configuration > Check the option “Tag app as unsanctioned”. This action classify apps that violate the policy as not approved or potentially harmful.
- Furthermore, to block these unsanctioned apps, you should enable the linking with Microsoft Defender for Endpoint. Refer to the POC setup mentioned earlier for more details on this configuration.
create cloud apps discovery policy
cloud apps discovery governance
Deployment Example : Once the policy triggers, you’ll receive alerts both through email and on the portal: https://security.microsoft.com/incidents
New high volume discovered app alert
Test 2: New risky app
Goal : Send an alert when new apps are discovered with a risk score below 6.
Procedure :
-
- Navigate to: Menu > Cloud apps > Policies > Policy management > Create app discovery policy.
- Choose the “New Risky App” template.
- Specify a name for your rule and set the severity level.
- Adjust the filter, for this test, to trigger an alert for apps with a risk score below 6.
- Decide on your alert delivery method and the daily alert frequency. For this example, we set it to 5.
Deployment Example : If an app, e.g., “Dailymotion” with a Risk Score of 5 is detected, it triggers this rule.
New risky discovered app alert
Threat Detection
Test 1: Multiple failed login attempts
Goal : Detect numerous unsuccessful login attempts during a single session, indicating potential intrusion attempts.
Procedure :
-
- Navigate to: Menu > Cloud apps > Policies > Policy management > Threat detection.
- From the list, select “Multiple Failed Login Attempts”.
- Adjust the name, severity level, and scope as needed.
Deployment Example : After connecting Office 365 in Connected app > app connector > connect an app, create a custom policy named “multiple failed user log on attempts to an app” based on the same template. Set it to alert after 3 failed attempts within 5 minutes.
multiple failed login attemps alert
Test 2: Mass download by a single user
Goal : Alert for unusual file download patterns by a user.
Procedure :
-
- This policy is deployed by default, to add custom rules or to learn more go to: Menu > Cloud apps > Policies > Policy management > Threat detection > Mass download by a single user.
- Or you can create your custom policy using the same template. To do so, navigate to : Menu > Cloud apps > Policies > Policy management > Threat detection > create activity policy, then choose mass download policy template.
- Create a rule to alert when a single user performs more than 5 downloads within a minute.
Deployment Example : For a real-world test, attempt to download a file from SharePoint 6 times.
mass download by a single user alert
Information Protection
Test 1: Externally shared source code
Goal : Alert when source code is shared externally.
Procedure :
-
- This policy is deployed by default, to add custom rules or to learn more go to: Menu > Cloud apps > Policies > Policy management > Information protection > Externally shared source code.
- Or you can create your custom policy using the same template. To do so, navigate to: Menu > Cloud apps > Policies > Policy management > Information protection > create file policy, and then choose Externally shared source code Template.
Deployment Example : Create a Python “Hello World” script and send it to a personal email using OneDrive, which is integrated with Defender for Cloud Apps, will immediately trigger the configured policy alert.
externally shared source code alert
Test 2: Activity from infrequent country
Goal : Identify and alert on user activity originating from countries or regions that are not commonly associated with the company’s regular operations. This aims to detect potential unauthorized or suspicious access, especially if it’s from locations where the company does not have any known business presence or employees.
Procedure :
-
- This policy is deployed by default but you can also create your own custom one from this template using the same steps.
- To add custom rules or to learn more go to: Menu > Cloud apps > Policies > Policy management > Information protection > Activity from infrequent country.
Deployment example : Alert received after logging in to office 365 multiple times from a non-usual location. For this test, we used a VPN.
activity from infrequent country alert
Key Observations
Detection Abilities:
-
- Our tests showed that Microsoft Defender for Cloud Apps is great for small to medium-sized businesses. It can identify and alert about security issues quickly.
- The Shadow IT and Threat Detection functionalities efficiently detect unauthorized apps and abnormal user behaviors.
- The Information Protection features empower SMEs to oversee file-sharing practices, especially when sensitive or confidential files are being shared inappropriately.
However, for more refined control, businesses can delve deeper into CASB policies. Once the foundational Data Loss Prevention (DLP) is configured via compliance.microsoft.com (Purview), CASB offers an additional layer of protection. It provides a nuanced monitoring approach, adaptive policies, and integrated cloud app surveillance. Essentially, while DLP sets the basic rules, CASB enhances the security by analyzing real-time data activities and context, ensuring comprehensive data protection for SMEs.
Integration Capabilities:
-
- Linking with tools like Defender for Endpoint augments security, especially beneficial for small businesses.
- Integration with UEBA (User & Entity Behavior Analytics) provides visibility into user behaviors, enabling early detection of potential risks.
- The XDR functionality streamlines threat detection across various sectors without the need for numerous tools.
User-Friendly for SMEs:
-
- Microsoft Defender for Cloud Apps is intuitive and user-friendly, even for those without an extensive IT background. It stands out as a leading choice for SMEs striving for enhanced online security.
Recommandations
-
- Integrative Approach: When we speak of an integrative approach, we mean that Microsoft Defender for Cloud Apps should work in conjunction with other tools for a comprehensive security stance, for example :
- Azure Active Directory (Azure AD): When Microsoft Defender for Cloud Apps detects unusual access patterns, such as a user who typically accesses resources from one location suddenly trying to connect from a different country, it can raise an alert. With the integration to Azure AD, appropriate security measures, such as triggering multi-factor authentication or immediate access denial, can be enforced to ensure security.
- Microsoft Purview: Purview, utilizing its data classification capabilities, can block unauthorized transfers of sensitive data to cloud apps based on tags such as “public”, “internal”, or “confidential”. When integrated with Defender for Cloud Apps, alerts about such unauthorized transfers are generated for any data transfer attempt, ensuring that IT and security teams are promptly informed and can take swift action if needed.
- Defender for Endpoint: If Defender for Cloud Apps classifies a particular cloud app as unsanctioned or risky, Defender for Endpoint can enforce policies to block access to that app from company devices.
- Integrative Approach: When we speak of an integrative approach, we mean that Microsoft Defender for Cloud Apps should work in conjunction with other tools for a comprehensive security stance, for example :
-
- Discovery and Integration of New Apps: With the discovery feature, as more apps are detected and validated, companies should be proactive in integrating these apps into the ‘connected apps’ section and setting up conditional access. This ensures that as new cloud apps are brought into the operational fold, they are automatically covered by the existing policies, ensuring a consistent security posture.
-
- SME-Specific Policy Configurations: SMEs might have different operational nuances compared to larger enterprises. For instance, an SME might have a higher reliance on specific SaaS tools for CRM(Customer Relationship Management) or project management. As such, they could configure a policy that closely monitors data interactions with these tools, ensuring no confidential client data is inappropriately shared or exported.
-
-
- Adaptive Policy Configurations: Threats evolve, and so do businesses. It’s essential to periodically review and update the policies in Microsoft Defender for Cloud Apps. This ensures that the tool’s features continue to serve the company’s dynamic requirements.
-
- Awareness & Training: Ensure employees undergo regular training sessions. Familiarizing them with company policies on app usage and data sharing minimizes risks and reduces the frequency of false alerts.
Conclusion
In our Proof of Concept (POC) tailored for small to medium-sized enterprises (SMEs), Microsoft Defender for Cloud Apps clearly displayed its capability in promptly identifying, alerting, and addressing potential security threats. The scenarios we spotlighted—Shadow IT, Threat Detection, and Information Protection—underscored the essential role this tool plays for SMEs looking to protect their digital assets and maintain strict security standards.
However, it’s crucial to note that while the scenarios we selected were successful, not all the tests we carried out gave the same positive results. Some policies did not trigger as anticipated. One reason for this could be the inherent learning algorithm associated with certain policies, especially those related to User and Entity Behavior Analytics (UEBA). For instance, UEBA policies may require up to 7 days of learning to build a comprehensive profile of typical user behavior, meaning that any anomalies detected shortly after implementation might not be flagged. These subtleties weren’t detailed in this review, as our aim was to focus on the most pertinent tests for SMEs.
In terms of XDR (Extended Detection and Response), Microsoft Defender for Cloud Apps plays a key role. Combining regular checks, updates, and making sure users know the best practices will help make this tool a core part of SMEs’ cybersecurity
References
[1] Cloud Access Security Broker: Pillars, Architecture, Uses (spiceworks.com)
[2] What Is a Cloud Access Security Broker (CASB)? | Microsoft
[3] Overview – Microsoft Defender for Cloud Apps | Microsoft Learn
