Edit

Submit an App Catalog update request

To keep the Microsoft Defender for Cloud Apps (MDA) catalog accurate, use the submission method that fits your role and the type of update you need. App owners can submit updates through a self-attestation questionnaire, while other users can request risk score changes or suggest catalog corrections. This article explains each submission path and what to expect during processing.

Submit updates as an app owner or verified vendor

If you're a verified app vendor or developer, complete the Self-Attestation Questionnaire to:

  • Add a new app to the catalog.

  • Update risk attributes.

While we review your request:

  • If the app isn’t in the catalog, you can add it as a custom app in Cloud Discovery to monitor its usage in your environment.
  • If the app is listed but its risk score doesn’t reflect your organization’s security posture, you can manually override the app’s risk score.

Request updates as a nonowner

Even if you're not the app owner, you can help improve the app catalog's accuracy:

Validation and processing timeline

We thoroughly validate all catalog update requests to ensure accuracy and relevance. All app catalog requests must meet these criteria:

  • The submitted domain must map to a known application.
  • The app must qualify as a SaaS product.
  • The request must include complete and verifiable information.

After we validate and accept your request, the standard turnaround time for a catalog update is approximately seven weeks.

Submit other catalog update requests

For general inquiries, metadata corrections, or requests other than self-attestation submissions or risk score updates, open a support ticket.

Note

We review support tickets individually. They aren’t a fast track for catalog updates, but they help us find edge cases or routing issues.

For more information, see the following articles: