Implement access management for apps

 MODULE 1

Plan and design the integration of enterprise apps for SSO


Discover apps by using Microsoft Defender for Cloud Apps and Active Directory Federation Services app report

Cloud Access Security Broker (CASB) is a security solution that sits between users and cloud apps to enforce company security policies when cloud services are accessed.

Microsoft Defender for Cloud Apps (MDCA) is Microsoft’s CASB solution. It helps protect cloud data, apps, and services by applying security policies and providing visibility, monitoring, and reports on cloud activity.

Microsoft Defender for Cloud Apps

Microsoft Defender for Cloud Apps (MDCA) is Microsoft’s Cloud Access Security Broker (CASB). It helps organizations see and control how cloud apps are used, protect sensitive data, and detect threats. MDCA gives visibility into cloud activity (including Shadow IT), applies security policies, and protects Microsoft and third-party cloud apps using logs, APIs, and proxy controls—all from one central place.

Architecture

Microsoft Defender for Cloud Apps integrates visibility with your cloud by:

  • Using Cloud Discovery to map and identify your cloud environment and the cloud apps your organization is using.

  • Sanctioning and de-authorizing apps in your cloud.

  • Using easy-to-deploy app connectors that take advantage of provider APIs, for visibility and governance of apps that you connect to.

  • Using Conditional Access App Control protection to get real-time visibility and control over access and activities within your cloud apps.

  • Helping you have continuous control by setting and continually fine-tuning policies.

Cloud Discovery

Cloud Discovery helps you find and analyze all cloud apps your organization is using by reviewing network traffic logs from firewalls or proxies. It helps identify Shadow IT (unsanctioned apps).

How Cloud Discovery Works

  • Upload firewall/proxy logs for a one-time snapshot.

  • Use log collectors for continuous monitoring.

  • Automatically detects and evaluates cloud apps in use.


Cloud Discovery Dashboard – What to Review

  • High-level usage overview: Overall cloud app usage.

  • Top app categories: Most-used types of apps (storage, social, etc.).

  • Sanctioned vs unsanctioned apps: Approved vs risky apps.

  • Discovered apps tab: Full list of detected apps.

  • Top users & IPs: Who uses cloud apps the most.

  • App headquarters map: Where apps are hosted geographically.

  • App risk score: Security risk level of each app.

  • Discovery alerts: Apps or activities that need investigation.


Filtering Discovered Apps

You can filter apps by:

  • App tag: Sanctioned, unsanctioned, or custom tags.

  • Apps/domains: Search specific apps or domains.

  • Categories: Storage, social, collaboration, etc.

  • Risk score: Focus on high-risk apps.

  • Compliance: HIPAA, ISO 27001, SOC 2, PCI-DSS, etc.

  • Security features: MFA, encryption, data protection.

  • Usage: Number of users, uploads, or activity level.

  • Legal factors: Data retention, privacy policies, DMCA.


Why Cloud Discovery Is Important

  • Gives visibility into all cloud app usage.

  • Helps control Shadow IT.

  • Improves security, compliance, and governance.

  • Enables informed decisions on which apps to allow or block.

Sanctioning and Unsanctioning Apps

Microsoft Defender for Cloud Apps lets you approve (sanction) or block (unsanction) cloud apps used in your organization. It uses a large cloud app catalog with risk scores based on security, compliance, and best practices. You can customize these scores to match your organization’s needs, helping you control which apps are safe to use and reduce security risks.

Active Directory Federation Services

AD FS is an on-premises identity service that lets users sign in once and access multiple applications (Single Sign-On), including on-prem apps, SaaS apps, and Microsoft 365. Many organizations use AD FS to authenticate users to cloud apps, but moving these apps to Microsoft Entra ID improves security, reduces costs, and simplifies management. Microsoft Entra provides one set of access policies for both cloud and on-prem apps. The AD FS application activity report helps organizations identify which AD FS apps can be migrated by showing recent app usage, compatibility, and migration guidance.

Types of apps to migrate

To simplify identity and access management, organizations should migrate app authentication to Microsoft Entra ID. There are two main types of apps to migrate: SaaS apps (third-party apps used by the organization) and line-of-business (LoB) apps (custom apps built internally). 

SaaS apps usually use modern authentication methods like SAML or OpenID Connect, making them easier to migrate using built-in connectors or app registration in Entra ID.

 LoB or legacy apps that use older authentication methods can still be migrated by using Application Proxy or Microsoft Entra Domain Services.

Discover AD FS applications that can be migrated

Microsoft Entra ID provides an AD FS application activity report in the Azure portal to help you find which AD FS apps can be migrated. The report shows AD FS applications that were used in the last 30 days and checks their compatibility with Microsoft Entra ID. Each app is marked as Ready to migrate (can move as-is), Needs review (some settings need checking), or Additional steps required (not supported in its current setup). This report helps you plan and prioritize your AD FS to Microsoft Entra ID migration easily.




Comments

Popular posts from this blog

Implement an identity management solution

IAM Concepts Covered

Implement an Authentication and Access Management solution