Microsoft Defender for Cloud Apps a viable CASB solution
Use Cases and Deployment Scope
In my organization we use Microsoft Defender for Cloud Apps as a CASB and also to investigate security events. As a CASB we use it primarily to detect Shadow IT, over permissive applications, risky application and blocked content from being downloaded onto non-managed corporate devices. The integration to Microsoft Entra ID is seamless which allows Conditional Access to redirect session to Microsoft Defender for Cloud Apps for it to take actions (Block or Monitor).
Pros
- The integration to Microsoft Entra ID is seamless, which allows Conditional Access to redirect the session to Microsoft Defender for Cloud App for it to take actions (Block or Monitor).
- Tracker users' activity is very good when troubleshooting or running an investigate.
- Detecting risky users through tight integration with Microsoft Entra ID is a very good feature.
- Detecting mass downloads and blocking the download of files from non-manage company devices is a very good feature as well.
Cons
- Sometimes the activity data takes a while to be presented in the portal. Updating this data fasting would add immensely to the performance of this tool.
- Ingesting logs from some firewalls do not work particularly well.
- I don't like that when you implement blocking or monitoring of websites the message is not very customizable.
Return on Investment
- Microsoft Defender for Cloud Apps has had a positive impact on your overall business objectives in the area of security. With the investment in Microsoft E5 licenses it comes as a part of the package. No additional investment for a separate tool and reduces risk which is one of our key business objectives.
Usability
Alternatives Considered
Netskope CASB
Other Software Used
Netskope CASB, CrowdStrike Falcon



