DET-MS-MCAS-MANUAL-001 Defender for Cloud Apps Application Connector config Severity: Informational
Defender for Cloud Apps — manual log upload from firewall (E3-friendly)
For Microsoft minimal stacks, periodic manual log upload to Defender for Cloud Apps Shadow IT Discovery to catalog AI services seen on the network.
Rule
# Defender for Cloud Apps — Manual log upload (Snapshot Report)
#
# Steps:
# 1. Export firewall / proxy logs for a representative period (typically 7 days)
# 2. Defender for Cloud Apps > Cloud Discovery > Create snapshot report
# 3. Choose log type (Cisco ASA / Palo Alto / Fortinet / Generic CEF / etc.)
# 4. Upload log file
# 5. Discovered apps appear after parsing (typically 15–30 min for 1 GB log file)
# 6. Filter by Category = 'Generative AI'
# 7. Triage apps: Sanction approved / Tag 'Block' for unsanctioned / Tag 'Monitor' for review
#
# Cadence: monthly snapshot reports for orgs that cannot afford continuous discovery
# Limitations:
# - Point-in-time only
# - Manual workflow does not generate continuous alerts
# - Sanction status does not enforce without Conditional Access App Control # Defender for Cloud Apps — Manual log upload (Snapshot Report) # # Steps: # 1. Export firewall / proxy logs for a representative period (typically 7 days) # 2. Defender for Cloud Apps > Cloud Discovery > Create snapshot report # 3. Choose log type (Cisco ASA / Palo Alto / Fortinet / Generic CEF / etc.) # 4. Upload log file # 5. Discovered apps appear after parsing (typically 15–30 min for 1 GB log file) # 6. Filter by Category = 'Generative AI' # 7. Triage apps: Sanction approved / Tag 'Block' for unsanctioned / Tag 'Monitor' for review # # Cadence: monthly snapshot reports for orgs that cannot afford continuous discovery # Limitations: # - Point-in-time only # - Manual workflow does not generate continuous alerts # - Sanction status does not enforce without Conditional Access App Control
How it works
Discovery-only workflow for organizations without continuous-discovery licensing. Cheap to operate at 1-hour-per-month cadence; produces the foundational catalog of AI services in use.
Required data sources
- Firewall or proxy logs from your existing perimeter device
Prerequisites
- Defender for Cloud Apps Discovery licensed (included in some M365 E3 add-on scenarios)
Expected volume
Per snapshot: 20–80 AI apps surfaced for an org of 10k seats.
False-positive guidance
Microsoft's app catalog occasionally mis-categorizes apps; validate before sanctioning/blocking.
Tuning steps
- Set a monthly reminder for snapshot upload.
- Track sanctioning decisions in the Governance Toolkit Inventory.
Framework mappings
- NIST AI RMF: GOVERN-4.1, MANAGE-4.1
- ISO/IEC 42001: 8.2
- NIST CSF: DE.CM-7, ID.AM-2