Contact us

We are here to answer any questions you might have. Please fill out the form below, and we will get back to you shortly.

microsoft defender for cloud apps

Proof Of Concept : The Power Of Microsoft Defender for Cloud Apps

by | 2023

Microsoft Defender for Cloud Apps

 

Today, many companies are moving their data and operations to the cloud. This shift means that companies need consistent strategies for securing cloud applications and data, backed up by effective security tools. One of the best tools for this purpose is the Cloud Access Security Broker (CASB) – Microsoft Defender for Cloud Apps – a part of the Microsoft 365 XDR suite. Before diving deeper into this tool, let’s first understand what a CASB is and why it’s vital for cloud security.

What is a Cloud Access Security Broker (CASB)?

A cloud access security broker serves as a checkpoint between company users and cloud service providers. CASBs handle various security tasks, such as checking user identities, encrypting data, spotting malware, and more. Think of a CASB as a security guard for cloud services. Its job is to keep an eye on cloud app use, catch possible threats, and make sure companies handle data correctly.

cloud access security broker phone
Cloud security access Broker [1]

Key Benefits of CASBs

CASBs provide several security advantages for businesses, helping them reduce risks, set rules for apps and devices, and follow important regulations, here is the five foundational pillars of a CASB [2]:

    • Shadow IT Assessment and Management : CASBs reveal all cloud apps in use, whether the company knows about them or not.

    • Detailed Cloud Control : With CASBs, companies can closely manage cloud use, deciding who uses which apps and how.

    • Prevent Data Loss (DLP) : CASBs can set rules that stop unauthorized data sharing.

    • Risk visibility : CASBs allow enterprises to assess the risk of unsanctioned applications and make access decisions accordingly. 

    • Threat prevention: They can identify risky apps or unusual user behavior and automatically remediate threats, limiting an organization’s risk.

How Does a CASB Work?

CASBs use a three-step approach to offer visibility across apps and protect company data [2]:

    • Discovery : The CASB identifies all cloud applications in use as well as affiliated employees.
    • Classification : The CASB assesses each application, identifies its data, and calculates a risk factor.
    • Remediation : The CASB creates a tailored policy for the enterprise based on its security needs. From there the CASB identifies and remediates any incoming threats or violations.

Given their abilities, CASBs are essential tools for companies wanting to keep their cloud data and apps safe. One of the leading tools in this space is Microsoft Defender for Cloud Apps.

Microsoft Defender for Cloud Apps Overview

In hybrid work environments, Software as a Service (SaaS) applications have become a standard, and protecting SaaS apps and the important data they store is a big challenge for organizations. The increasing dependency on apps, coupled with remote access to company resources, has opened new vectors for cyber threats. To combat these attacks effectively, security teams need an approach that protects their data within cloud apps beyond the traditional scope of cloud access security brokers (CASBs).

diagram of the defender for cloud app pillars phone
Diagram of the Defender for Cloud App pillars [3]

Microsoft Defender for Cloud Apps delivers full protection for SaaS applications, helping you monitor and protect your cloud app data across the following feature areas:

    • CASB Features : This includes functionalities like Shadow IT discovery, insight into cloud app utilization, defenses against cloud-native threats, and tools for information protection and compliance assessments.
    • SaaS Security Posture Management (SSPM) : This allows security teams to fine-tune and enhance an organization’s cloud security posture
    • Advanced Threat Protection : Integrated into Microsoft’s Extended Detection and Response (XDR) suite, this provides extensive visibility and effective countermeasures against sophisticated cyber-attacks across their entire lifecycle.
    • App-to-App Protection : Designed for OAuth-enabled applications, this feature ensures security for apps that have permissions to access essential data and resources.

Microsoft Defender for Cloud Apps POC

Objective of the POC

To assess the efficacy of Microsoft Defender for Cloud Apps in the context of small to medium-sized businesses (SMEs), we at Windfiel decided to conduct this proof of concept (POC) and share the results subsequently. This POC will center around three key areas :

    • Visibility : Microsoft Defender for Cloud Apps will be used to gain visibility into cloud app usage, including who is accessing apps, where they are accessing them from, and what data is being stored and shared.
    • Threat detection and prevention : Microsoft Defender for Cloud Apps will be used to detect and prevent threats, such as data exfiltration, malware, and phishing attacks.
    • Compliance reporting : Microsoft Defender for Cloud Apps will be used to generate reports on cloud app usage and data protection, which can help SMEs comply with regulations.

POC Setup

Environment :  The tests are performed in a dedicated test environment on the Microsoft Defender online platform (https://security.microsoft.com).

Configuration and Settings:

    • Licensing: We’re using the E5 license of Microsoft 365. This license allows us to use all of Microsoft Defender’s tools, making it ideal for our application and for small and medium businesses.
    • SaaS Application Integration: Integrating different online apps with Microsoft Defender for Cloud Apps is a key part of our setup. Without this connection, we won’t get alerts from those apps. To set this up:
      1. Navigate to: Settings > Cloud Apps > Connected app > app connector.
      2. Select connect an app.
cloud app connect phone
Cloud app Connect
    • Integration with Microsoft Defender for Endpoint: Another essential step of our setup is the linking with Microsoft Defender for Endpoint. If a discovered cloud app is identified as risky then classified as unsanctioned, this tool can block it right away directly in the user workstation. To enable this:
      1. Go to: Settings > Cloud Apps > Cloud discovery.
      2. Choose Microsoft Defender for Endpoint.
      3. Tick the box for Enforce app access to block apps labeled as non-approved
integration with microsoft defender for endpoint phone
Integration with Microsoft Defender for Endpoint

    Test Scenarios

    In the context of enhancing security for SMEs and capitalizing on the capabilities of Microsoft Defender for Cloud Apps, we’ve strategically identified specific risk scenarios for evaluation. These scenarios serve as the blueprint for our tests. Our objective is to evaluate Microsoft Defender for Cloud Apps efficacy in mitigating these potential risks. The scope of our tests has been deliberately narrowed to focus on the most critical and relevant policies for SMEs environment. 

    N.B. : Our primary focus has been on tests related to Microsoft 365 integrations. However, we have also conducted tests with other SaaS tools once integrated, and the outcomes were equally conclusive.

    In this section, we will primarily concentrate our tests on the following three aspects of Microsoft Defender for Cloud Apps: Shadow IT, Threat Protection, and Information Protection. Below, you will find a visual representation of the product’s interface.

    microsoft defender for cloud apps policy management interface phone
    microsoft defender for cloud apps policy management interface

      Shadow IT

      Test 1: New high-volume app.

        • Description: Alert in case of discovery of new applications with a daily total traffic greater than XX Mo.
        • Risk: Undetected applications could be malicious, insecure, or non-compliant with company policies. This might expose the company to security threats like data breaches, intrusions, or malware attacks. Uncontrolled network resource usage could also degrade network performance.

      Test 2: New risky app.

        • Description: Alert when new applications are discovered with a risk score below 6.
        • Risk: Use of risky applications without detection can expose the company to data breaches, regulatory non-compliances, loss of company reputation, or potential facilitation of malicious activities like spam or DDoS attacks.

      Threat Detection

      Test 1: Multiple failed login attempts.

        • Description: Alert when a single user attempts to log on to a single app and fails more than 3 times within 5 minutes.
        • Risk: If not detected, the company is vulnerable to potential brute force attacks or unauthorized access attempts, which could lead to data breaches, theft of sensitive information, operational disruptions, and significant reputational or financial consequences.

      Test 2: Mass download by a single user.

        • Description: Alert when a single user performs more than 5 downloads within 1 minute.
        • Risk: Unusual file downloads could indicate malicious activity, unauthorized access to sensitive data, or a compromised user account, potentially leading to data breaches, loss of intellectual property, regulatory non-compliances, or loss of trust among clients and partners.

      Information Protection

      Test 1: Externally shared source code.

        • Description: Alert when a file containing source code is shared outside your organization.
        • Risk: Sharing source code externally can lead to the disclosure of intellectual property, expose sensitive algorithms, or specific configurations. Unauthorized third parties could exploit any vulnerabilities in the code, resulting in potential financial losses, damaged reputation, or legal repercussions.

      Test 2: Activity from infrequent country.

        • Description: This policy profiles your environment and triggers alerts when activity is detected from a location that was not recently or never visited by the user or by any user in the organization. Detecting anomalous locations necessitates an initial learning period of 7 days, during which it does not alert on any new locations.
        • Risk: Unexpected geolocation-based activities can be indicative of unauthorized access, potential security breaches, or other malicious intents. Such breaches can lead to data theft, unauthorized transactions, operational disruptions, and reputational damage. Furthermore, it might expose the company to regulatory penalties if sensitive data is accessed or manipulated from regions that are not in compliance with data protection regulations or company policies.

      Execution & Results

      Shadow IT

      Test 1: High Volume App Alert

      Goal : Trigger an alert if new applications are discovered with daily traffic exceeding XX MB.

      Procedure :

        • Navigate to: Menu > Cloud apps > Policies > Policy management > Create app discovery policy.
        • Select the “New High Volume App” template.
        • Provide a name for your rule and set the desired severity level.
        • Adjust the filter based on the template, for this test, set the daily traffic threshold for e.g. at 500 MB.
        • Choose your alert delivery method, e.g., via email, and decide on the daily alert frequency.
      1. For enhanced oversight, you can also integrate governance actions into your policy configuration. This ensures not just alerting but also taking preventive measures against potential threats.
      1. Navigate to: Governance Actions within the policy configuration > Check the option “Tag app as unsanctioned”. This action classify apps that violate the policy as not approved or potentially harmful.
      1. Furthermore, to block these unsanctioned apps, you should enable the linking with Microsoft Defender for Endpoint. Refer to the POC setup mentioned earlier for more details on this configuration.

      create cloud apps discovery policy
      create cloud apps discovery policy
      create cloud apps discovery policy
      create cloud apps discovery policy
      cloud apps discovery governance

      Deployment Example : Once the policy triggers, you’ll receive alerts both through email and on the portal: https://security.microsoft.com/incidents

      new high volume app poc
      New high volume discovered app alert

      Test 2: New risky app

      Goal : Send an alert when new apps are discovered with a risk score below 6.

      Procedure :

        • Navigate to: Menu > Cloud apps > Policies > Policy management > Create app discovery policy.
        • Choose the “New Risky App” template.
        • Specify a name for your rule and set the severity level.
        • Adjust the filter, for this test, to trigger an alert for apps with a risk score below 6.
        • Decide on your alert delivery method and the daily alert frequency. For this example, we set it to 5.

      Deployment Example : If an app, e.g., “Dailymotion” with a Risk Score of 5 is detected, it triggers this rule.

      new risky app
      New risky discovered app alert

       

      Threat Detection

      Test 1: Multiple failed login attempts

      Goal : Detect numerous unsuccessful login attempts during a single session, indicating potential intrusion attempts.

      Procedure :

        • Navigate to: Menu > Cloud apps > Policies > Policy management > Threat detection.
        • From the list, select “Multiple Failed Login Attempts”.
        • Adjust the name, severity level, and scope as needed.

      Deployment Example : After connecting Office 365 in Connected app > app connector > connect an app, create a custom policy named “multiple failed user log on attempts to an app” based on the same template. Set it to alert after 3 failed attempts within 5 minutes.

      multiple failed logon
      multiple failed login attemps alert

      Test 2: Mass download by a single user

      Goal : Alert for unusual file download patterns by a user.

      Procedure :

        • This policy is deployed by default, to add custom rules or to learn more go to: Menu > Cloud apps > Policies > Policy management > Threat detection > Mass download by a single user.
        • Or you can create your custom policy using the same template. To do so, navigate to : Menu > Cloud apps > Policies > Policy management > Threat detection > create activity policy, then choose mass download policy template.
        • Create a rule to alert when a single user performs more than 5 downloads within a minute.

      Deployment Example : For a real-world test, attempt to download a file from SharePoint 6 times.​​

      mass download by a single user
      mass download by a single user alert

      Information Protection

      Test 1: Externally shared source code

      Goal : Alert when source code is shared externally.

      Procedure :

        • This policy is deployed by default, to add custom rules or to learn more go to: Menu > Cloud apps > Policies > Policy management > Information protection > Externally shared source code.
        • Or you can create your custom policy using the same template. To do so, navigate to: Menu > Cloud apps > Policies > Policy management > Information protection > create file policy, and then choose Externally shared source code Template.

      Deployment Example : Create a Python “Hello World” script and send it to a personal email using OneDrive, which is integrated with Defender for Cloud Apps, will immediately trigger the configured policy alert.

      source code share
      externally shared source code alert

      Test 2: Activity from infrequent country

      Goal : Identify and alert on user activity originating from countries or regions that are not commonly associated with the company’s regular operations. This aims to detect potential unauthorized or suspicious access, especially if it’s from locations where the company does not have any known business presence or employees.

      Procedure : 

        • This policy is deployed by default but you can also create your own custom one from this template using the same steps.
        • To add custom rules or to learn more go to: Menu > Cloud apps > Policies > Policy management > Information protection > Activity from infrequent country.

      Deployment example : Alert received after logging in to office 365 multiple times from a non-usual location. For this test, we used a VPN.

      activity from infrequent country
      activity from infrequent country alert

      Key Observations

      Detection Abilities:

        • Our tests showed that Microsoft Defender for Cloud Apps is great for small to medium-sized businesses. It can identify and alert about security issues quickly.
        • The Shadow IT and Threat Detection functionalities efficiently detect unauthorized apps and abnormal user behaviors.
        • The Information Protection features empower SMEs to oversee file-sharing practices, especially when sensitive or confidential files are being shared inappropriately.

      However, for more refined control, businesses can delve deeper into CASB policies. Once the foundational Data Loss Prevention (DLP) is configured via compliance.microsoft.com (Purview), CASB offers an additional layer of protection. It provides a nuanced monitoring approach, adaptive policies, and integrated cloud app surveillance. Essentially, while DLP sets the basic rules, CASB enhances the security by analyzing real-time data activities and context, ensuring comprehensive data protection for SMEs.

      Integration Capabilities:

        • Linking with tools like Defender for Endpoint augments security, especially beneficial for small businesses.
        • Integration with UEBA (User & Entity Behavior Analytics) provides visibility into user behaviors, enabling early detection of potential risks.
        • The XDR functionality streamlines threat detection across various sectors without the need for numerous tools.

      User-Friendly for SMEs:

        • Microsoft Defender for Cloud Apps is intuitive and user-friendly, even for those without an extensive IT background. It stands out as a leading choice for SMEs striving for enhanced online security.

      Recommandations

       

        • Integrative Approach: When we speak of an integrative approach, we mean that Microsoft Defender for Cloud Apps should work in conjunction with other tools for a comprehensive security stance, for example :
          • Azure Active Directory (Azure AD): When Microsoft Defender for Cloud Apps detects unusual access patterns, such as a user who typically accesses resources from one location suddenly trying to connect from a different country, it can raise an alert. With the integration to Azure AD, appropriate security measures, such as triggering multi-factor authentication or immediate access denial, can be enforced to ensure security.
          • Microsoft Purview: Purview, utilizing its data classification capabilities, can block unauthorized transfers of sensitive data to cloud apps based on tags such as “public”, “internal”, or “confidential”. When integrated with Defender for Cloud Apps, alerts about such unauthorized transfers are generated for any data transfer attempt, ensuring that IT and security teams are promptly informed and can take swift action if needed.
          • Defender for Endpoint: If Defender for Cloud Apps classifies a particular cloud app as unsanctioned or risky, Defender for Endpoint can enforce policies to block access to that app from company devices.
        • Discovery and Integration of New Apps: With the discovery feature, as more apps are detected and validated, companies should be proactive in integrating these apps into the ‘connected apps’ section and setting up conditional access. This ensures that as new cloud apps are brought into the operational fold, they are automatically covered by the existing policies, ensuring a consistent security posture.
        • SME-Specific Policy Configurations: SMEs might have different operational nuances compared to larger enterprises. For instance, an SME might have a higher reliance on specific SaaS tools for CRM(Customer Relationship Management) or project management. As such, they could configure a policy that closely monitors data interactions with these tools, ensuring no confidential client data is inappropriately shared or exported.
          • Adaptive Policy Configurations: Threats evolve, and so do businesses. It’s essential to periodically review and update the policies in Microsoft Defender for Cloud Apps. This ensures that the tool’s features continue to serve the company’s dynamic requirements.
          • Awareness & Training: Ensure employees undergo regular training sessions. Familiarizing them with company policies on app usage and data sharing minimizes risks and reduces the frequency of false alerts.

         

        Conclusion

         

        In our Proof of Concept (POC) tailored for small to medium-sized enterprises (SMEs), Microsoft Defender for Cloud Apps clearly displayed its capability in promptly identifying, alerting, and addressing potential security threats. The scenarios we spotlighted—Shadow IT, Threat Detection, and Information Protection—underscored the essential role this tool plays for SMEs looking to protect their digital assets and maintain strict security standards.

        However, it’s crucial to note that while the scenarios we selected were successful, not all the tests we carried out gave the same positive results. Some policies did not trigger as anticipated. One reason for this could be the inherent learning algorithm associated with certain policies, especially those related to User and Entity Behavior Analytics (UEBA). For instance, UEBA policies may require up to 7 days of learning to build a comprehensive profile of typical user behavior, meaning that any anomalies detected shortly after implementation might not be flagged. These subtleties weren’t detailed in this review, as our aim was to focus on the most pertinent tests for SMEs.

        In terms of XDR (Extended Detection and Response), Microsoft Defender for Cloud Apps plays a key role. Combining regular checks, updates, and making sure users know the best practices will help make this tool a core part of SMEs’ cybersecurity

        References

         

        [1] Cloud Access Security Broker: Pillars, Architecture, Uses (spiceworks.com)

        [2] What Is a Cloud Access Security Broker (CASB)? | Microsoft

        [3] Overview – Microsoft Defender for Cloud Apps | Microsoft Learn