Great product for E5 customers
Use Cases and Deployment Scope
We utilize Microsoft Defender for Cloud apps for several functions including web filtering, SaaS app management and control, and Data Loss Prevention. The cloud inventory works well and provides a simple interface with all of the discovered SaaS apps accessed by the organization. By utilizing the sanctioned and unsanctioned tags, we are able to control the SaaS apps by blocking outright or allowing with controls and monitoring. For DLP, we utilize the alerting to report on suspicious or unusual file transfers.
Pros
- SaaS application discovery
- Detection alerts
- Integration with other Microsoft Defender products to enhance the capabilities.
Cons
- Integrate better with Purview for DLP rules
- Onboard more supported applications with fine grained controls.
- Provide more reporting aside from shadow it report
Likelihood to Recommend
Microsoft Defender for Cloud Apps is part of the E5 license suite. For organizations that have the E5 license in place, I would recommend using Defender for Cloud Apps as it provides a good level of functionality and the cost is already covered in the E5 license.
If an organization does not have the E5 license, I would suggest looking at alternative solutions like Zscaler or Netskope.
Overall, Defender for Cloud Apps is a decent product but does not provide as many features as their competitors. The real advantage to using it is when an environment has the E5 license and is utilizing all of the other Microsoft security products that are part of the license. They integrate extremely well and provide a high level of security.

