Microsoft Defender for Cloud Apps: Configuring the XOps Integration

Prev Next

Overview

Using the Microsoft API, you can integrate alert data from Microsoft Defender for Cloud Apps to generate stories for apps. These stories help you get a more complete picture of potential threats in your network.

The Cato engine creates a story by correlating data from Defender Alerts related to the same Defender Incident. Cloud App Alert stories include all relevant evidence for the Alerts detected by Defender. The Stories Workbench shows the stories together with the other story types, and you can sort and filter the stories to focus on the Cloud App Alert stories.

To integrate Defender for Cloud App alert data with Cato XOps, you need to first set up API connectors for Microsoft 365 and then for Defender for Cloud Apps. After creating the connectors, the Cloud Apps Alert engine retrieves and analyzes the alert data from Defender for Cloud Apps.

For more information on reviewing XOps stories, including data from Microsoft Defender, see Drilling-Down and Analyzing XOps Security Stories.

Understanding Microsoft Cloud App Alert Stories

The Microsoft Cloud Apps Alert producer generates stories based on the integration. This section explains the information available in the Overview tab of the story drill-down page.

These are the story Overview widgets:

Name

Description

Summary widget

The bar at the top of the page shows a summary of basic information about the story, including the:

  • Criticality of the threat

  • Summary of the story details

  • Severity of the threat as determined by an analyst

  • Verdict for the threat as determined by an analyst

Timeline

A timeline of events or actions taken in the story.

Details

Basic information for the story.

  • Click the Incident URL link to view the Incident in Microsoft Defender.

Entities

The apps, alerts, and users involved in the incident.

Evidences

Aggregates details for all the Processes, Files, Registry values, and Network parameters identified in the evidence for the various story Alerts.

Some of the columns in the Evidences table are shared by all the types of Evidences, and some are specific per type.

These are the columns that appear for all types of Evidences:

  • Verdict - Verdict generated by Defender for the piece of evidence (Malicious, Suspicious, or No threats found)

  • Remediation Status - Shows whether the threat was remediated

  • Created - Date and time when the event was recorded

These are the specific columns for each type of Evidence:

  • Processes:

    • Process Name - Name of the executable file for the process

    • Process ID - Windows-assigned ID number for the process

    • Process Command Line - Arguments that were passed to the process in Windows. This can reveal important context about the execution of a suspicious process

    • File Path - Location on the endpoint device of the executable file for the process

  • Files:

    • File Path - Location of the file on the endpoint device

    • File Name - Name of the file including extension

    • File Size - Size of the file in bytes, kilobytes, or megabytes

  • Registry:

    • Registry key Name

    • Registry Value Type - Format of the data stored in the registry value

    • Registry Value - The value of the registry entry

  • Network:

    • Shows network data for the flow that generated the alert, such as the Destination IP, Destination Port, DNS and HTTP data, and the URL accessed

Configuring the Defender for Cloud Apps Connector

To configure Defender for Cloud Apps connector to fetch alert data, first you need to configure the Microsoft 365 connector as the parent app to give read permissions for the Defender connector. The parent app only has permissions to manage the Microsoft connectors. After configuring the Microsoft 365 connector, you can configure a Defender for Cloud Apps connector to retrieve the alert data.

If you want to import alert data from different sub-organizations within your organization, create a separate Microsoft 365 connector for each relevant Azure tenant, and then configure a Defender connector for each tenant.

To configure the Defender for Cloud Apps connector, you need to:

  1. Create the Microsoft 365 parent connector.

  2. Create the Defender for Endpoint connector.

Prerequisites

  • One of these Microsoft Licenses:

    • Microsoft Defender for Endpoint Plan 2

    • Microsoft 365 E5 (or higher) or Microsoft 365 E5 Security

    • Microsoft 365 A5 (Education) or Microsoft 365 G5 (Government)

    • Windows 11 Enterprise E5

  • The Microsoft 365 connector requires an admin with the global admin role to give permissions to Cato's Defender connector

Step 1: Creating the Microsoft 365 Parent Connector

First, configure the MS Tenant integration as the parent connector. This connector can be used for all Microsoft integrations. If you have already created the parent connector, go to step 2.

To configure the Microsoft 365 parent endpoint connector:

  1. From the navigation menu, select Security > Connectors, and select the Connectors Settings tab.

  2. Click New. The New Connector panel opens.

  3. From the SaaS Application drop-down menu, select the Microsoft 365 app.

    MIP_New_Connector_MS365.png

  4. Enter a unique Connector Name.

  5. Click Authorize and Save.

    A new browser tab opens to the Microsoft 365 app.

  6. In the new browser tab, authenticate to the Microsoft 365 app:

    1. Select the Microsoft account for the Microsoft 365 app.

    2. Enter the password for the app and approve it.

    3. Accept the permissions to let Cato access the Microsoft 365 app.

      MIP_Labels_Parent_Connector_Permissions.png

    4. The screen shows that you have successfully applied the permissions for the app.

      Success_Connector_Permissions.png

      You can close the browser tab and return to the Cato Management Application.

  7. The Microsoft 365 SaaS application is added to the Connectors Settings page.

Step 2: Creating the Defender for Cloud Apps Connector

After you have set up the parent connector, add Defender for Cloud Apps connector.

To create the Defender for Cloud Apps connector:

  1. From the navigation menu, click Resources > Integrations.

  2. Click the Configured Integrations tab.

  3. Click New.

    The New Integration panel opens.

  4. Select Microsoft Defender for Cloud Apps.

  5. In the Auth drop-down, select the Microsoft Primary Tenant that was created in Step 1.

  6. Add a Name for the connector.

  7. Click Save.

    The CMA connects to the vendor

  8. Click Authorize.

    image-20250826-133358.png

    A Microsoft permissions screen will appear.

  9. Review the requested permissions and click Accept.

  10. The app is visible on the Integrated Apps table with a Connected status.

Viewing the Stories Workbench Page

Once you have created the connector, stories will be visible in the Stories Workbench.

To view the Stories Workbench page:

  • From the navigation menu, click Home > Stories Workbench.

For information about the columns in the Stories Workbench, see Understanding the Stories Columns

For more information on reviewing XOps stories, including data from Microsoft Defender, see Drilling-Down and Analyzing XOps Security Stories