Microsoft 365: 配置SaaS态势

Prev Next

Overview

SaaS Posture integrations provide visibility into the configuration and security posture of your connected SaaS applications. Cato continuously reviews the application settings and compares them to the recommended posture defined by Cato’s research team. This helps identify misconfigurations that can increase risk, such as authentication settings, third-party integrations, and data-sharing controls.

Posture data appears in the Applications dashboard, where you can view posture scores and the highest-severity findings across connected applications. You can review each posture check from the Posture page, including the issue details, status, and remediation action required to pass the check.

For more information, see Reviewing the Security Posture of Your SaaS Applications.

To configure the SaaS Posture integration, you need to:

  1. Configure the required settings in the SaaS application

  2. Create the API connector in the CMA

A CASB license is required for SaaS Posture integrations.

配置Microsoft 365集成

要配置集成,请创建API应用程序。

条件

  • 您必须拥有以下之一许可证:

    • Microsoft 365 E3

    • Microsoft 365 E3许可证,附带E5合规性附加组件

    • Microsoft 365 E3许可证,附带E5 eDiscovery和审计附加组件

    • Office 365 E5许可证

步骤 1: 创建MS租户集成

首先,配置MS租户集成作为父连接器。 该连接器可用于所有Microsoft集成。 如果您已创建父连接器,请进入步骤2。

创建MS租户集成:

  1. 从导航菜单中选择 资源 > 集成 并点击 集成应用程序 标签。

  2. 点击 新建。 新建连接器 面板打开。

  3. 在 新连接器 面板中,选择 MS租户(配置一个新的MS租户) 应用程序。

  4. 输入 连接器名称。

  5. 点击 授权并保存。

    一个新的浏览器标签打开到Microsoft 365应用程序。

  6. 在新的浏览器标签中,对Microsoft 365应用程序进行认证:

    1. 选择用于Microsoft 365应用程序的Microsoft账户。

      否则,可能会发生Microsoft认证错误。

    2. 输入应用程序的密码并批准它。

    3. 接受 权限以允许Cato访问Microsoft 365应用程序。

    4. 屏幕显示您已成功应用应用程序的权限。

      您可以关闭浏览器标签返回到Cato管理应用程序。

  7. Microsoft 365 SaaS应用程序已添加到 集成应用程序 标签。

步骤 2: 在CMA中创建API连接器

在您设置了所需应用程序的集成后,请在CMA中添加详情。

在CMA中创建API连接器:

  1. 从导航菜单中,点击资源 > 集成。

  2. 点击 集成应用程序 标签。

  3. 新建集成 面板打开。

    新集成面板开启。

  4. 选择您要添加的 SaaS应用程序。

  5. 选择 SaaS态势。

  6. 选择在步骤1中创建的 Microsoft主要租户。

  7. (可选)添加描述。

  8. 单击 保存。

    CMA连接到供应商

  9. 点击 授权 。

  10. 将出现Microsoft权限屏幕。

  11. 查看请求的权限并点击 接受。期间Always-On和防篡改被禁用多久。

应用程序在集成应用程序表中可见,并显示为已连接状态。