Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
This article shows you how to view and prioritize SaaS security recommendations in Microsoft Defender XDR by using the SaaS Security Initiative. Before you start, make sure you meet the prerequisites.
Overview of the SaaS Security Initiative
The SaaS Security Initiative is the main hub for SaaS security posture management (SSPM). It gives you a central place to manage software as a service (SaaS) security best practices.
The initiative groups best-practice tips into 12 metrics. You can use these metrics to rank and act on security tasks. Focus on the metrics with the most impact to improve your SaaS security posture.
How to use the SaaS Security Initiative
Watch the following video for an overview of how to use the SaaS Security Initiative.
Prerequisites
Before you view these recommendations, make sure you meet these requirements:
- Your organization must have Microsoft Defender for Cloud Apps licenses.
- The app you want to check must be connected to Defender for Cloud Apps. To learn how to connect apps and which connectors provide security tips, see Connect apps to get visibility and control with Microsoft Defender for Cloud Apps.
View SaaS Security Initiative recommendations
To view SaaS Security Initiative recommendations, perform the following steps:
- In the Defender portal, go to Exposure Management and select Initiatives.
- Select the SaaS Security initiative, and then select Open Initiative Page.
The page that appears lists the 12 metrics that categorize hundreds of best-practice recommendations.
Start with the metrics that have the highest Impact on Initiative Score level. This score combines the Weight of each item with the share of Non-Compliant items.
To track progress, set a target score for your security posture. Use this target as a benchmark to measure gains over time.
For example, to review tips for privileged access in SaaS apps, select Missing Best Practices to Secure Privileged Access in SaaS Apps. Then select any Non-Compliant item to see the fix steps.
Related resources for SaaS Security Initiative
Use these resources to understand and build on the initiative results:
- Each metric lists its linked app connectors. Enable more connectors to get broader coverage. To see tips for a specific app, go to the Security recommendations tab and filter by that app.
- To learn more about Microsoft Security Exposure Management initiatives, see Review security initiatives.