Implement access management for apps
- Get link
- X
- Other Apps
MODULE 1
Plan and design the integration of enterprise apps for SSO
Discover apps by using Microsoft Defender for Cloud Apps and Active Directory Federation Services app report
Microsoft Defender for Cloud Apps (MDCA) is Microsoft’s CASB solution. It helps protect cloud data, apps, and services by applying security policies and providing visibility, monitoring, and reports on cloud activity.
Microsoft Defender for Cloud Apps
Architecture
Microsoft Defender for Cloud Apps integrates visibility with your cloud by:
Using Cloud Discovery to map and identify your cloud environment and the cloud apps your organization is using.
Sanctioning and de-authorizing apps in your cloud.
Using easy-to-deploy app connectors that take advantage of provider APIs, for visibility and governance of apps that you connect to.
Using Conditional Access App Control protection to get real-time visibility and control over access and activities within your cloud apps.
Helping you have continuous control by setting and continually fine-tuning policies.
Cloud Discovery
How Cloud Discovery Works
-
Upload firewall/proxy logs for a one-time snapshot.
-
Use log collectors for continuous monitoring.
-
Automatically detects and evaluates cloud apps in use.
Cloud Discovery Dashboard – What to Review
-
High-level usage overview: Overall cloud app usage.
-
Top app categories: Most-used types of apps (storage, social, etc.).
-
Sanctioned vs unsanctioned apps: Approved vs risky apps.
-
Discovered apps tab: Full list of detected apps.
-
Top users & IPs: Who uses cloud apps the most.
-
App headquarters map: Where apps are hosted geographically.
-
App risk score: Security risk level of each app.
-
Discovery alerts: Apps or activities that need investigation.
Filtering Discovered Apps
You can filter apps by:
-
App tag: Sanctioned, unsanctioned, or custom tags.
-
Apps/domains: Search specific apps or domains.
-
Categories: Storage, social, collaboration, etc.
-
Risk score: Focus on high-risk apps.
-
Compliance: HIPAA, ISO 27001, SOC 2, PCI-DSS, etc.
-
Security features: MFA, encryption, data protection.
-
Usage: Number of users, uploads, or activity level.
-
Legal factors: Data retention, privacy policies, DMCA.
Why Cloud Discovery Is Important
-
Gives visibility into all cloud app usage.
-
Helps control Shadow IT.
-
Improves security, compliance, and governance.
-
Enables informed decisions on which apps to allow or block.
Sanctioning and Unsanctioning Apps
Microsoft Defender for Cloud Apps lets you approve (sanction) or block (unsanction) cloud apps used in your organization. It uses a large cloud app catalog with risk scores based on security, compliance, and best practices. You can customize these scores to match your organization’s needs, helping you control which apps are safe to use and reduce security risks.
Active Directory Federation Services
AD FS is an on-premises identity service that lets users sign in once and access multiple applications (Single Sign-On), including on-prem apps, SaaS apps, and Microsoft 365. Many organizations use AD FS to authenticate users to cloud apps, but moving these apps to Microsoft Entra ID improves security, reduces costs, and simplifies management. Microsoft Entra provides one set of access policies for both cloud and on-prem apps. The AD FS application activity report helps organizations identify which AD FS apps can be migrated by showing recent app usage, compatibility, and migration guidance.
Types of apps to migrate
To simplify identity and access management, organizations should migrate app authentication to Microsoft Entra ID. There are two main types of apps to migrate: SaaS apps (third-party apps used by the organization) and line-of-business (LoB) apps (custom apps built internally).
SaaS apps usually use modern authentication methods like SAML or OpenID Connect, making them easier to migrate using built-in connectors or app registration in Entra ID.
LoB or legacy apps that use older authentication methods can still be migrated by using Application Proxy or Microsoft Entra Domain Services.
Discover AD FS applications that can be migrated
Microsoft Entra ID provides an AD FS application activity report in the Azure portal to help you find which AD FS apps can be migrated. The report shows AD FS applications that were used in the last 30 days and checks their compatibility with Microsoft Entra ID. Each app is marked as Ready to migrate (can move as-is), Needs review (some settings need checking), or Additional steps required (not supported in its current setup). This report helps you plan and prioritize your AD FS to Microsoft Entra ID migration easily.
- Get link
- X
- Other Apps
Comments
Post a Comment