Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
01Microsoft Defender XDR6 modules · 53 units · Defender XDR, Defender for Office 365, Entra ID Protection, Defender for Identity, and Defender for Cloud Apps0/53 units complete
Learning path 01 · Microsoft Defender XDR

6 modules · 53 units · Defender XDR, Defender for Office 365, Entra ID Protection, Defender for Identity, and Defender for Cloud Apps

0%

Study focus

Incident operations

Correlate, investigate, hunt, and remediate threats across Defender XDR.

Domain protection

Protect email, identities, Active Directory, cloud apps, and sensitive data.

6 modules · 53 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

06

Module 6

Secure your cloud apps and services with Microsoft Defender for Cloud Apps

Focus: CASB architecture, Cloud Discovery, Conditional Access App Control, information protection, and anomaly detection.
0/9
01 / 09Introduction

Defender for Cloud Apps balances cloud productivity with visibility, control over data movement, and threat analytics. The module covers Shadow IT discovery, real-time access/session controls, sensitive-information protection, and anomaly detection.

Official lessonCloud Apps objectives
02 / 09Understand the Defender for Cloud Apps framework

Defender for Cloud Apps is a cloud access security broker (CASB)—an enforcement point between users and cloud providers. Its four framework pillars are:

  1. Discover and control Shadow IT across SaaS, IaaS, and PaaS.
  2. Protect sensitive information with classification and DLP.
  3. Protect against threats and anomalies with UEBA, machine learning, and rules.
  4. Assess cloud-app compliance against organizational and regulatory requirements.
Exam takeaway: remember the four pillars and the CASB intermediary role.
Official lessonCASB and four-part framework
03 / 09Explore cloud apps with Cloud Discovery

Cloud Discovery analyzes traffic logs against a catalog of more than 16,000 apps and scores them using over 80 risk factors. The dashboard summarizes usage, alerts, risk, top users, source IPs, categories, and app headquarters.

  1. Review high-level usage and top users/IPs.
  2. Analyze categories and sanctioned usage.
  3. Inspect discovered apps and risk scores from 1–10.
  4. Mark risky apps Unsanctioned.
  5. Use Defender for Endpoint integration to block unsanctioned apps automatically.
Exam takeaway: Cloud Discovery provides retrospective visibility; sanctioning controls known app risk.
Official lessonShadow IT dashboard and app risk
04 / 09Conditional Access App Control

Conditional Access App Control uses a reverse-proxy session to enforce controls in real time. Entra Conditional Access decides who, what, and where; eligible sessions are routed through Defender for Cloud Apps for access and session policies.

  • Block download, copy, cut, or print on unmanaged devices.
  • Protect files on download with classification and encryption.
  • Block upload of unlabeled files.
  • Monitor risky sessions and user actions.
  • Block access or application-specific activities, such as Teams messages containing sensitive data.
Exam takeaway: Conditional Access determines session routing; Cloud Apps applies real-time session controls.
Official lessonAccess and session policies
05 / 09Walk through discovery and access control

The walkthrough demonstrates Cloud Discovery and Conditional Access App Control in Defender XDR: discover app use, evaluate risk, route sessions through the proxy, and enforce controls on sensitive activity.

Official lesson + embedded videoCloud app protection walkthrough
06 / 09Classify and protect sensitive information
1 · DiscoverConnect apps and scan data.
2 · ClassifyUse sensitive information types and labels.
3 · ProtectApply file policies and governance actions.
4 · MonitorInvestigate alerts and report.

File policies can alert, change sharing, quarantine, remove permissions, or move content to trash. Built-in DLP and Data Classification Services inspect content; Microsoft recommends DCS for unified Microsoft 365 labeling.

Common labels: Personal, Public, General, Confidential, and Highly confidential. Policies should use narrow filters to reduce false positives.

Official lessonDiscovery, classification, protection, and monitoring
07 / 09Detect threats

Anomaly policies use UEBA and machine learning to compare activity with organizational and user baselines. The service learns the environment for the first seven days. Detection is nondeterministic and must be tuned to manage false positives.

  • Risk factors include IP reputation, failures, admin activity, dormant accounts, location, impossible travel, device/user agent, and activity rate.
  • Detections include impossible travel, infrequent country, malware, ransomware, suspicious IPs, inbox forwarding, mass downloads, and unusual administration.
  • Discovery anomaly policies compare sudden usage, upload, download, transaction, or user increases with the app baseline.
  • Suppression and sensitivity settings help control alert fatigue.
Exam takeaway: anomaly detection depends on deviation from learned behavior—not a fixed signature alone.
Official lessonUEBA, anomaly policies, and tuning
08 / 09Module assessment
At-a-glance app usage → Cloud Discovery Dashboard
Framework element → Discover and control Shadow IT
Conditional Access App Control feature → Protect on download
Send file for administrator review → Put in admin quarantine
Distant locations in a short time → Impossible travel
Official assessmentFive questions
09 / 09Summary

You should be able to explain the CASB framework, discover and score Shadow IT, apply Conditional Access App Control, classify/protect sensitive information, and detect cloud anomalies.

Official summaryCloud Apps module recap
End of learning pathMicrosoft Defender XDR