118 questions with Microsoft Defender for Cloud Apps-related tags

Sort by: Updated
0 answers

Hunting: why some quiries is not working like user name, InitiatingProcessCommandLine , user Id and a lot of them thee is redline under it while it is correctly connected with intune and avaliable

example and most of my quries is like this

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,640 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
172 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
118 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
26 questions
asked 2024-06-25T23:26:27.2666667+00:00
Abdelgalil, Mohamed 0 Reputation points
commented 2024-06-27T14:09:33.48+00:00
Akshay-MSFT 17,486 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

Defender for endpoint: Controlled Folder Access: Where Can I find the list of well known apps allowed to access the protected folders?

Hello team, https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/controlled-folders?view=o365-worldwide#windows-system-folders-are-protected-by-default Controlled folder access protects your data by checking apps against a list of…

Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
118 questions
asked 2024-03-22T13:20:46.1366667+00:00
Sergio Londono 406 Reputation points
accepted 2024-06-26T12:58:30.36+00:00
Sergio Londono 406 Reputation points
0 answers

Cloudapps Unsanctioning apps

Unsanction of Cloudapps is only blocking on Edge browser but can access on chrome and firefox.How can i effect unsanctioning across all browsers? All my devices are managed by intune

Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
118 questions
asked 2024-06-11T09:22:07.14+00:00
Landrover 20 Reputation points
commented 2024-06-21T19:55:22.3966667+00:00
Pauline Mbabu 90 Reputation points Microsoft Employee
0 answers

Does Defender for Cloud Apps access policy apply to desktop and mobile apps in addition to the browser?

I created an access policy on Defender for Cloud Apps to block access from risky IP addresses. However, I am unsure if the policy applies to desktop and mobile apps or just the browser. Although testing shows that the browser session is blocked, Outlook…

Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
118 questions
asked 2024-05-31T09:03:10.8766667+00:00
Hamed, Ali 0 Reputation points
commented 2024-06-21T19:23:44.86+00:00
Pauline Mbabu 90 Reputation points Microsoft Employee
0 answers

Due to the scoring of MDCA being discontinued, if we need to retain the TOP 10 users using UEBA, what methods can we use?

Due to the scoring of MDCA being discontinued, if we need to retain the TOP 10 users using UEBA, what methods can we use? 'Investigation priority score' feature and 'Investigation priority score increase policy' will be phased out in the coming weeks,…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,037 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
118 questions
asked 2024-06-20T09:25:17.94+00:00
Koonnamchok Klongkaew 140 Reputation points
commented 2024-06-20T23:39:14.9633333+00:00
Marilee Turscak-MSFT 35,901 Reputation points Microsoft Employee
1 answer

your system administrator has blocked this program. for more info contact your system administrator

I am using a domain account and, as per company policy, I cannot create a local account. Additionally, I am unable to access the User Account Control (UAC) window to add or remove programs on this system. Could you please provide assistance with this…

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,812 questions
Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
8,738 questions
Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
370 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
118 questions
asked 2024-06-12T05:42:38.8066667+00:00
Mr Sonbir 40 Reputation points
commented 2024-06-20T07:27:39.76+00:00
Karlie Weng 15,916 Reputation points Microsoft Vendor
7 answers

Defender 365 admin console - Disabled Connected to a custom indicator & Connected to a unsanctionned blocked app rules

I want to know how I can disable these two following alerts : Disabled Connected to a custom indicator Connected to an unsanctioned blocked app I didn't find these alerts on the Alerts Policy of XDR/EPP or Cloud apps. Since all the changed that…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
118 questions
asked 2024-03-21T14:28:41.46+00:00
Étienne Fiset 50 Reputation points
answered 2024-06-19T19:36:11.75+00:00
Étienne Fiset 50 Reputation points
8 answers

OpenSSL vulnerabilities showing in Defender Dashboard

We have multiple devices showing up with OpenSSL vulnerabilities. It is detecting two dll files that it is flagging. Which they are libssl-3-x64.dll and libcrypto-3-x64.dll. It is flagging this for multiple different applications through out multiple…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
172 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
118 questions
asked 2023-09-22T20:14:57.2433333+00:00
Jeff Thorne 40 Reputation points
edited an answer 2024-06-11T07:59:39.7466667+00:00
Ronald Bok 0 Reputation points
1 answer

Defender for cloud apps

The requirement is when the user uploads any files/documents from personal owned Android/IOS managed through intune to (OneDrive for business). Files should be scanned for malicious content, including Links and any file type, document, file, etc.. Is…

Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
118 questions
asked 2024-05-28T06:37:34.6066667+00:00
answered 2024-06-10T13:36:12.19+00:00
Catherine Kyalo 655 Reputation points Microsoft Employee
0 answers

Defender for Cloud Apps Generative AI Category

We're running Defender for Cloud Apps in our organization and we've detected over 100 applications in use, however, no Generative AI app usage has been detected on any of our endpoints despite it definitely being used. I've even used ChatGPT and Google…

Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
118 questions
asked 2024-06-06T17:17:15.8966667+00:00
Richard Long 321 Reputation points
0 answers

How to get the impacted asset (user or client) when fetching alerts (v2) from Defender using API?

Hello, I followed this documentation to list alerts from Defender https://learn.microsoft.com/en-us/graph/api/security-list-alerts_v2?view=graph-rest-beta&tabs=http While I am getting the output, it is very different from when I fetch the alerts…

Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
11,189 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
172 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
118 questions
asked 2024-05-30T13:30:38.1333333+00:00
Rawad BASSIL 0 Reputation points
edited the question 2024-06-06T06:12:59.9466667+00:00
Rakesh Gurram 5,070 Reputation points Microsoft Vendor
1 answer

MSDefender Android Application Issue: Infinite Loading and "Accept" Button Failed

Hello, When trying to log in, the application loads infinitely and does not progress. Furthermore, when we re-register an account for login, it takes us to a screen to accept the terms, but the "Accept" button does not perform any function. It…

Microsoft Intune Android
Microsoft Intune Android
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Android: An open-source mobile platform based on the Linux kernel, developed by Google, and maintained by the Open Handset Alliance.
257 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
118 questions
asked 2024-05-28T12:22:10.85+00:00
Mateus Alves 0 Reputation points
answered 2024-05-29T05:15:57.16+00:00
ZhoumingDuan-MSFT 10,420 Reputation points Microsoft Vendor
0 answers

Windows Defender Advanced Threat Protection - DataCollection PS1

Dear Community, I have a question regarding Windows Defender Advanced Threat Protection*DataCollection*\folderName*.ps1. My EDR raised multiple alerts from a PowerShell script that came from the above directory but was launched by a default browser like…

PowerShell
PowerShell
A family of Microsoft task automation and configuration management frameworks consisting of a command-line shell and associated scripting language.
2,255 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
118 questions
asked 2024-05-28T07:36:47.4166667+00:00
TristanBOZZETTI-0587 10 Reputation points
0 answers

Practice Test AZ - 204 got stuck on "Compiling your assessment" page and after a while I refreshed it and now it result is nowhere to be found

I had given a practice test for AZ- 204, but at the end when I submitted the practice exam it got stuck on the "Compiling your assessment" page and after over 30mins of it still being stuck on the same screen, I refreshed the page and now I am…

Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
118 questions
asked 2024-05-26T09:22:01.94+00:00
Atharv Dhamal 0 Reputation points
1 answer One of the answers was accepted by the question author.

No License Found - Microsoft Defender

Hi there, I am seeing the following message when opening Microsoft Defender on a Mac (deployed via Intune). We do have Defender license assigned to user via Business Premium. We already have set section 1 set to Windows 10 and 11 in Microsoft Defender…

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,781 questions
Microsoft Intune MacOs
Microsoft Intune MacOs
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.MacOs: A family of Apple operating systems for the Apple Mac line of computers.
76 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
172 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
118 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,275 questions
asked 2024-05-17T15:46:34.9233333+00:00
Anam Ahmed 61 Reputation points
commented 2024-05-22T01:11:00.07+00:00
Xenia-MSFT 545 Reputation points Microsoft Vendor
1 answer

Visual Studio blocked by MS Defender

Microsoft defender blocked visual studio 2022 ( C#) and I can't enter windows forms, console, etc. Please help.

Visual Studio
Visual Studio
A family of Microsoft suites of integrated development tools for building applications for Windows, the web and mobile devices.
4,813 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
172 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
118 questions
asked 2024-05-18T09:09:30.3366667+00:00
Pepe 0 Reputation points
answered 2024-05-20T07:33:09.3466667+00:00
Anna Xiu-MSFT 27,551 Reputation points Microsoft Vendor
2 answers

Block Download is not working when configured on Conditional Access

Hello everyone, I tried to create conditional access policy with this scenario : Block user to access office 365 except from browser, and block download any file while accessing office 365 apps on the web I've configured CA policies like the pict…

Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
118 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,275 questions
asked 2024-05-16T10:26:26.2066667+00:00
Muhammad Farid Rahmatulloh 0 Reputation points
commented 2024-05-17T03:32:06.4933333+00:00
Muhammad Farid Rahmatulloh 0 Reputation points
1 answer

MS Defender: Attack Simulation Training - Unable to see all the Tenant Payloads

Hi All I have created five tenant payload in the Microsoft Defender Attack Simulation Training module. However, when I go to test, only 11 items are displayed and some of my templates are missing, yet they exist as I can see and edit them. Is there a way…

Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
118 questions
asked 2024-05-02T09:37:43.8733333+00:00
Tony Anstis 0 Reputation points
commented 2024-05-02T14:14:06.6433333+00:00
Tony Anstis 0 Reputation points
0 answers

What is Device type: OfficePowerPointWRS in Microsoft Defender?

Hello, I'd like to know what is OfficePowerPointWRS device type. I found this on the user's activity logs in Defender for Cloud Apps. It appears to be related to OneDrive for Business and uses Microsoft 365 Common and Office Online server IP add. See…

Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
118 questions
asked 2024-04-22T16:40:40.19+00:00
ghshspgt2p 1 Reputation point
edited the question 2024-04-23T16:24:21.23+00:00
ghshspgt2p 1 Reputation point
1 answer One of the answers was accepted by the question author.

The Address you provided is invalid, please provide a valid address and try again!!!

Hi, While I was trying to schedule the SC-200 Exam, I got the error message that the billing address isn't valid. How can I fix this issue. Thanks! Best Regards, Jasmina Jakob

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,037 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
172 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
118 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
26 questions
asked 2024-04-12T19:23:56.8333333+00:00
Anonymous
accepted 2024-04-13T12:24:56.7366667+00:00
Anonymous