詳細検索

How to use Microsoft Defender for Cloud Apps to enhance cloud security

Avatar
by 堤
5 min read

How to use Microsoft Defender for Cloud Apps to enhance cloud security
Translated from 日本語 • View original
堤

Hello! This is Tsutsumi, sales representative of Colorkrew Security. In this article, we'll show you how to use Microsoft Defender for Cloud Apps.

**What is Microsoft Defender for Cloud Apps in the first place? **

It is a Cloud Access Security Broker (CASB) that is provided as part of the security capabilities of your Microsoft 365 environment.

By visualizing and preventing so-called shadow IT, it will be a service that strengthens the security of the cloud environment.

Shadow IT Risks

**What is Shadow IT in the First Place? **

It refers to cloud apps and software that employees use personally without the permission of the company's IT or intelligence department. Typical examples include:

・Cloud storage (Google Drive, Dropbox, OneDrive, etc.)
・SaaS (Slack, ChatGPT, Trello, etc.)
・Free software and free apps
As the name suggests, Microsoft Defender for Cloud Apps covers cloud-related services, so the above only covers cloud storage and SaaS.

Specific Risks

There are several, but I will pick up the most representative ones.

  1. Information Leakage Risk
    By using unauthorized cloud services and personal devices, there is a risk of leaking sensitive corporate information to the outside world.
    → Example: Important company files are stored in a personal cloud and their accounts are hacked.
  2. Growing Security Vulnerabilities
    Software and devices that businesses cannot control are likely not to have the latest security measures in place, increasing the risk of malware infections and unauthorized access.
    → Example: An employee accesses business data over free Wi-Fi and the data is intercepted.
  3. Increased Difficulty in Incident Response
    The proliferation of shadow IT increases the number of systems that corporate IT departments cannot manage, making it difficult to respond to incidents when they occur.
    → Example: An informal chat tool used for work has been attacked and the scope of impact cannot be determined.

As mentioned above, I think it is clear that leaving shadow IT unattended carries a huge risk for companies.

Introduction to Utilization

Here are two ways to take advantage of Microsoft Defender for Cloud Apps to combat this shadow IT.

- Control of available cloud apps
- Detect the use of shadow IT by setting policies
- Integrate with Entra ID Conditional Access

(1) Control Available Cloud Services

◼︎ What kind of scene will it be active in?
When you have decided on a cloud app that you want to clearly control, such as "I definitely don't want to let you use this"

◼︎ How to set it up
⚠️ The following integrations with Microsoft Defender for Endpoint are required:

From the menu on the left side of the Defender portal, click
Cloud App Catalog
Enter the name of the app you want to control in the → app field.
Disapproved in the → action field

If you visit a site that you have disapproved, you will be blocked.

(2) Detecting Shadow IT Usage by Policy Settings

◼︎ What kind of scene will it be active in?
I don't want to go that far because it would be difficult to strictly control shadow IT, but if you are using an app that is not famous, I would like to detect it for the time being.

◼︎ How to set it up
From the menu on the left side of the Defender portal, click
Policies
→ Policy Management
→ Shadow IT
Create a → policy
→ app detection policies

Set the risk score between 0 and X for apps that match all of the following: (Set from 0 to 6 in the image)

The risk score is a 10-point scale of risk set by Microsoft for more than 30,000 cloud apps.
0 is the highest risk, and 10 is the lowest risk.

There are not many apps with a risk score of 10, except for Microsoft and AWS services, and even famous SaaS products in Japan may have a score of 6, so if you set this setting, you need to carefully consider where to set the score.

(3) Integrating with Entra ID Conditional Access

◼︎ What kind of scene will it be active in?

I'm setting up conditional access in Entra ID, but I'd like to set up a little more granularity around the cloud.

◼︎ Specific Examples

Conditional access is a feature that allows you to decide whether to allow or not to allow access by setting conditions such as device, user, and location to access. (Example: Access from within the company is OK, external access is not allowed, etc.)

However, there are cases where you want to set up a little more detail around the cloud, as shown below.

・Devices that are not registered with Entra or Intune want to be read-only instead of uniformly disabling access to apps.
・(In relation to the above), I want to prohibit downloading only certain file formats (such as .docx and .pptx), even if it is not read-only.
・I want to block the use of a specific browser.

The above controls can be achieved by aligning Conditional Access with Microsoft Defender for Cloud Apps.

Conclusion

In this article, we showed you how to use Microsoft Defender for Cloud Apps.

Although it is included in the Microsoft 365 E5 license, many people may feel that they are not using it well or that it seems difficult to set up.

In fact, many companies see the following challenges.

・I don't know what settings to put
・I set it up, but I don't know what to do when an alert comes out
Even if an alert occurs, there are no resources in the company to respond
.
Microsoft Defender for Cloud Apps is a very powerful tool, but proper configuration and operation are essential. That's why our "Colorkrew Security" provides strong support for your company's security operations.

・Advice on recommended settings
・24/365 alert monitoring
・Analysis and formulation of countermeasures after alerts occur

In addition, it supports not only Defender for Cloud Apps but also other Microsoft Defender series.
In addition, it also works with the following security products to achieve integrated security monitoring and operation.

・WAF (AWS WAF, Azure WAF, etc.)
・EDR (Cybereason, CrowdStrike, etc.)
・SaaS (Slack, Dropbox, etc.)
・Firewall (Fortigate, Meraki, etc.)
・PC operation log (SKYSEA Client) View, LANSCOPE Endpoint Manager, etc.)

Enterprises that want to take full advantage of Microsoft Defender for Cloud Apps and enhance the security of their cloud environments should consider implementing "Colorkrew Security".

Related Articles