Overview
Using the Microsoft API, you can integrate alert data from Microsoft Defender for Cloud Apps to generate stories for apps. These stories help you get a more complete picture of potential threats in your network.
The Cato engine creates a story by correlating data from Defender Alerts related to the same Defender Incident. Cloud App Alert stories include all relevant evidence for the Alerts detected by Defender. The Stories Workbench shows the stories together with the other story types, and you can sort and filter the stories to focus on the Cloud App Alert stories.
To integrate Defender for Cloud App alert data with Cato XOps, you need to first set up API connectors for Microsoft 365 and then for Defender for Cloud Apps. After creating the connectors, the Cloud Apps Alert engine retrieves and analyzes the alert data from Defender for Cloud Apps.
For more information on reviewing XOps stories, including data from Microsoft Defender, see Drilling-Down and Analyzing XOps Security Stories.
Understanding Microsoft Cloud App Alert Stories
The Microsoft Cloud Apps Alert producer generates stories based on the integration. This section explains the information available in the Overview tab of the story drill-down page.

These are the story Overview widgets:
Name | Description |
|---|---|
Summary widget | The bar at the top of the page shows a summary of basic information about the story, including the:
|
Timeline | A timeline of events or actions taken in the story. |
Details | Basic information for the story.
|
Entities | The apps, alerts, and users involved in the incident. |
Evidences | Aggregates details for all the Processes, Files, Registry values, and Network parameters identified in the evidence for the various story Alerts. Some of the columns in the Evidences table are shared by all the types of Evidences, and some are specific per type. These are the columns that appear for all types of Evidences:
These are the specific columns for each type of Evidence:
|
Configuring the Defender for Cloud Apps Connector
To configure Defender for Cloud Apps connector to fetch alert data, first you need to configure the Microsoft 365 connector as the parent app to give read permissions for the Defender connector. The parent app only has permissions to manage the Microsoft connectors. After configuring the Microsoft 365 connector, you can configure a Defender for Cloud Apps connector to retrieve the alert data.
If you want to import alert data from different sub-organizations within your organization, create a separate Microsoft 365 connector for each relevant Azure tenant, and then configure a Defender connector for each tenant.
To configure the Defender for Cloud Apps connector, you need to:
Create the Microsoft 365 parent connector.
Create the Defender for Endpoint connector.
Prerequisites
One of these Microsoft Licenses:
Microsoft Defender for Endpoint Plan 2
Microsoft 365 E5 (or higher) or Microsoft 365 E5 Security
Microsoft 365 A5 (Education) or Microsoft 365 G5 (Government)
Windows 11 Enterprise E5
The Microsoft 365 connector requires an admin with the global admin role to give permissions to Cato's Defender connector
Step 1: Creating the Microsoft 365 Parent Connector
First, configure the MS Tenant integration as the parent connector. This connector can be used for all Microsoft integrations. If you have already created the parent connector, go to step 2.
To configure the Microsoft 365 parent endpoint connector:
From the navigation menu, select Security > Connectors, and select the Connectors Settings tab.
Click New. The New Connector panel opens.
From the SaaS Application drop-down menu, select the Microsoft 365 app.

Enter a unique Connector Name.
Click Authorize and Save.
A new browser tab opens to the Microsoft 365 app.
In the new browser tab, authenticate to the Microsoft 365 app:
Select the Microsoft account for the Microsoft 365 app.
Enter the password for the app and approve it.
Accept the permissions to let Cato access the Microsoft 365 app.

The screen shows that you have successfully applied the permissions for the app.

You can close the browser tab and return to the Cato Management Application.
The Microsoft 365 SaaS application is added to the Connectors Settings page.
Step 2: Creating the Defender for Cloud Apps Connector
After you have set up the parent connector, add Defender for Cloud Apps connector.
To create the Defender for Cloud Apps connector:
From the navigation menu, click Resources > Integrations.
Click the Configured Integrations tab.
Click New.
The New Integration panel opens.
Select Microsoft Defender for Cloud Apps.
.png?sv=2026-02-06&spr=https&st=2026-09-09T19%3A56%3A25Z&se=2026-09-09T20%3A10%3A25Z&sr=c&sp=r&sig=7mOcT%2BvkXr62rEyDP7%2BPqbyIhdt2Pr5gGRZ%2F90SIigg%3D)
In the Auth drop-down, select the Microsoft Primary Tenant that was created in Step 1.
Add a Name for the connector.
Click Save.
The CMA connects to the vendor
Click Authorize.

A Microsoft permissions screen will appear.
Review the requested permissions and click Accept.
The app is visible on the Integrated Apps table with a Connected status.
Viewing the Stories Workbench Page
Once you have created the connector, stories will be visible in the Stories Workbench.
To view the Stories Workbench page:
From the navigation menu, click Home > Stories Workbench.
For information about the columns in the Stories Workbench, see Understanding the Stories Columns
For more information on reviewing XOps stories, including data from Microsoft Defender, see Drilling-Down and Analyzing XOps Security Stories