Microsoft Defender for Cloud Apps in 2026: What It Finds, What It Can't Stop
.jpeg)
Microsoft Defender for Cloud Apps is the CASB a lot of companies already own without having decided to buy it. It shows up inside Microsoft 365 E5 and the Defender bundles, it lights up a Cloud Discovery dashboard the moment Defender for Endpoint is onboarded, and suddenly there is a list of thousands of apps your people use. The question is what you can actually do with that list, especially now that half of it is AI. If you are comparing CASBs more broadly, our guide to CASB vendors in 2026 covers the whole field. This post goes deep on the Microsoft one.
The short answer
Microsoft Defender for Cloud Apps, formerly Microsoft Cloud App Security, is Microsoft's cloud access security broker. It discovers SaaS and AI apps from endpoint and network logs, scores them against a catalog of more than 31,000 apps, connects to sanctioned apps over APIs, applies session controls to browser sign-ins through Conditional Access App Control, and governs OAuth apps. It is a discovery and posture engine, not an inline AI control. Microsoft's own documentation says its session policies do not apply to generative AI apps like ChatGPT, and marking an app unsanctioned becomes a domain-level block pushed through Defender for Endpoint in up to three hours. dope.security governs AI at the device, in real time, at the tenant and prompt level.
That is a testable claim. Tag a generative AI app as unsanctioned, start a timer, and then try to use the corporate workspace and a personal account of the same tool from one laptop.
What is Microsoft Defender for Cloud Apps?
Microsoft renamed Microsoft Cloud App Security to Microsoft Defender for Cloud Apps at Ignite in November 2021, and the product now lives inside the Microsoft Defender portal. Since June 16, 2024, Microsoft has redirected all users to the Defender XDR portal with no option to stay on the standalone experience.
Microsoft describes the product in four parts.
- SaaS discovery and CASB. Cloud Discovery finds apps in use, rates each one against more than 90 risk factors, and supports information protection for connected apps.
- SaaS security posture management. Posture recommendations for connected SaaS apps.
- Threat protection. Detections and alerts that feed Microsoft Defender XDR.
- App governance. Visibility and control over OAuth apps and app-to-app access, with recent additions such as unused-app insights and Salesforce connected apps in preview.
On licensing, Microsoft's product page no longer leads with a standalone price. It points buyers to the Microsoft Defender Suite at $12.00 per user per month, which requires Microsoft 365 E3, and Microsoft's documentation lists Defender for Cloud Apps plus Defender for Endpoint, or Microsoft 365 E5, as the license requirement for endpoint-based blocking.
How Defender for Cloud Apps works
The mechanics matter, because each capability runs through a different path.
- Discovery from logs. Cloud Discovery ingests traffic data from Defender for Endpoint, third-party firewalls, or proxy appliances through a log collector that runs as a container. Apps outside the catalog are not discovered by default.
- API connectors. For sanctioned apps such as Microsoft 365, Defender for Cloud Apps connects over APIs to scan content and activity at rest.
- Session control. Conditional Access App Control routes browser sessions for apps integrated with your identity provider through a reverse proxy on mcas.ms domains, or, in preview, enforces policy inside Microsoft Edge for Business.
- Blocking. Tagging an app as unsanctioned syncs its domains to Defender for Endpoint as custom indicators, which network protection then blocks on the device.
Notice what that means. Discovery is retrospective, API control only covers apps you have connected, session control only covers browser sign-ins through your identity provider, and blocking is a domain list delivered to the endpoint. For a structured approach to the discovery half, see our shadow IT discovery playbook.
What Defender for Cloud Apps does well
Credit where it is due. For Microsoft-centric organizations, this is a capable tool.
- A big catalog. More than 31,000 cataloged apps scored on more than 90 risk factors is a genuinely useful starting point for a risk review. Microsoft has added dedicated categories for generative AI, MCP servers, and AI model providers.
- Zero-install discovery for MDE shops. If Defender for Endpoint is already on every device, discovery data flows without extra agents.
- OAuth governance. App governance for OAuth apps addresses a real attack path, and Microsoft keeps extending it.
- One portal with XDR. Alerts land alongside endpoint, identity, and email detections in the Defender portal.
Where Defender for Cloud Apps falls short for AI in 2026
The gaps are specific, and Microsoft documents them itself.
Session policies do not cover consumer-style AI apps
Microsoft's coexistence guidance for Global Secure Access and Defender for Cloud Apps states that session policies do not apply to generative AI apps like ChatGPT because they are not sanctioned enterprise apps, and it recommends Global Secure Access with Purview DLP for inline AI data protection instead. In other words, the CASB that discovers your AI apps is not the tool Microsoft points to for controlling what goes into them. We break down the gap between those two jobs in CASB vs DLP.
Unsanctioned means a domain block, eventually
Microsoft's governance documentation says an unsanctioned tag can take up to three hours to reach devices: roughly an hour to sync and up to two hours to push. It requires Defender for Endpoint onboarding with real-time protection, cloud-delivered protection, and network protection in block mode. Microsoft also warns that vendors add and change URLs across web, desktop, and mobile, which results in inconsistent unsanctioned behavior. And because the block is a list of domains, the decision is allow or block the domain. Separating a corporate AI workspace from a personal account on the same domain is a tenant-level question that Microsoft handles with Entra tenant restrictions, a different product.
Session control has hard edges
Microsoft's known issues page for Conditional Access App Control lists limits that matter for a real rollout.
- Browser only. Session controls apply to interactive browser sign-ins, and desktop clients such as the Teams desktop app are not covered, so Microsoft's guidance is to block native clients if you want to stop bypass.
- File size limits. Session policies cover files up to 50 MB, and content inspection runs only on files under 30 MB.
- IPv4 only. IPv6 requests skip IP-based rules.
- Edge-first. In-browser protection is in preview and limited to Edge for Business work profiles on Windows and macOS, with other browsers falling back to the reverse proxy.
File policies are being retired
Microsoft's release notes state that Defender for Cloud Apps file policies retire on January 6, 2027, with file-based data protection moving to Microsoft Purview DLP and auto-labeling. If your data-at-rest controls live in file policies today, a migration is already on the calendar.
The hard AI test is the same for every tool: allow the corporate ChatGPT workspace, block personal ChatGPT on the same domain, and read the prompt before it leaves. We walk through it in how to block personal ChatGPT while keeping the corporate account.
Defender for Cloud Apps vs dope.security: the head-to-head
Both products help you find and govern SaaS and AI usage. They act at different moments. Here is the comparison, line by line.
- When control happens. Defender for Cloud Apps discovers usage from logs and pushes unsanctioned domains to Defender for Endpoint in up to three hours. dope.security enforces policy on the device in real time, pushed from dope.console to individual users and groups.
- Tenant-level AI control. Defender for Cloud Apps blocks at the domain level and leaves tenant restrictions to Entra. dope.security Cloud Application Control restricts ChatGPT, Claude, Google, and Microsoft 365 to corporate tenants and blocks personal logins on the same domain.
- Prompt and upload DLP. Microsoft says its session policies do not apply to apps like ChatGPT and points to Purview through Global Secure Access. Dopamine DLP intercepts file uploads and AI prompts on the device and classifies them with large language models through zero-retention OpenAI APIs, covering ChatGPT, Claude, Perplexity, Abacus, and Copilot.
- Coverage beyond the browser. Conditional Access App Control covers browser sessions. dope.security inspects web traffic on the endpoint with an on-device SSL inspection proxy, so enforcement follows the device rather than one browser.
- Data at rest. Defender for Cloud Apps file policies retire in January 2027. CASB Neural scans OneDrive and Google Drive for publicly or externally shared files containing PII, PCI, PHI, or IP, with one-click remediation.
- OAuth app risk. Both address it. dope.security AI-Powered SSPM analyzes OAuth-connected apps in Microsoft 365 and Google tenants and gives prioritized recommended actions for each.
- Visibility. dope.security AI Usage Analytics shows top AI applications, top AI users, and apps per user across all endpoints.
For more on the pieces, read what CASB Neural is, how AI-Powered SSPM works, and how to detect shadow AI in desktop apps, IDEs, and CLIs.
Do you need Defender for Cloud Apps, or something that acts in real time?
If you own Microsoft 365 E5 already, keep Defender for Cloud Apps for what it does best: discovery, catalog risk scoring, OAuth governance, and XDR alerting. It is a strong inventory tool, and you have paid for it.
The gap is enforcement at the moment of use. When the risk is an employee pasting source code into a personal AI account, a domain block that arrives in three hours and a session policy that does not apply are not the control you need. That moment happens on the device, which is where dope.security runs.
A practical division of labor looks like this.
- Keep Defender for Cloud Apps for inventory. Use Cloud Discovery and the catalog risk scores to decide which AI and SaaS apps are sanctioned, tolerated, or out of bounds, and keep app governance on OAuth grants.
- Enforce at the endpoint in real time. Use dope.security Cloud Application Control to allow corporate tenants and block personal logins for ChatGPT, Claude, Google, and Microsoft 365 the moment a policy changes.
- Inspect the prompt, not just the domain. Put Dopamine DLP in Monitor mode first to see what sensitive data is flowing into AI tools, then move the riskiest categories to Block.
That sequence gives security teams the Microsoft inventory they already trust and an enforcement point that acts at the speed people actually work. Deployment is fast: a Fortune 100 company scaled from 900 to more than 18,000 devices in weeks, deployed silently through Intune.
The bottom line on Microsoft Defender for Cloud Apps
Put simply: Defender for Cloud Apps is very good at telling you which AI apps your people use and how risky they look, and by Microsoft's own documentation it is not the inline control for what they type into them. If you want tenant-level AI control and prompt-level DLP enforced on the laptop in real time, that is what dope.security was built to do. Explore Dopamine DLP and the Fly-Direct Secure Web Gateway, or book a 20-minute demo and we will run the personal ChatGPT test live.
Frequently Asked Questions
Is Microsoft Defender for Cloud Apps a CASB?
Yes. Microsoft Defender for Cloud Apps is Microsoft's cloud access security broker, formerly called Microsoft Cloud App Security. Microsoft describes it as combining SaaS discovery, information protection, SaaS security posture management, threat protection, and OAuth app governance, managed in the Microsoft Defender portal.
Is Defender for Cloud Apps included in Microsoft 365 E5?
Microsoft lists Microsoft 365 E5 as one of the licenses that includes Defender for Cloud Apps capabilities, including endpoint-based blocking with Defender for Endpoint. Microsoft's product page also points buyers to the Microsoft Defender Suite at $12.00 per user per month, which requires Microsoft 365 E3. Check your agreement for exactly which features you hold.
Can Defender for Cloud Apps block ChatGPT?
Defender for Cloud Apps can mark ChatGPT as unsanctioned, which pushes its domains to Defender for Endpoint to block on devices, and Microsoft says that can take up to three hours. That is a domain-level block. dope.security Cloud Application Control can allow a corporate ChatGPT workspace while blocking personal ChatGPT logins on the same domain.
Does Defender for Cloud Apps inspect AI prompts?
Microsoft's own guidance states that Defender for Cloud Apps session policies do not apply to generative AI apps like ChatGPT because they are not sanctioned enterprise apps, and it recommends Global Secure Access with Purview DLP for inline AI data protection. Dopamine DLP intercepts AI prompts and file uploads on the device and classifies them with zero-retention APIs.
What is happening to Defender for Cloud Apps file policies?
Microsoft's release notes state that Defender for Cloud Apps file policies retire on January 6, 2027, and that file-based data protection moves to Microsoft Purview DLP and auto-labeling. Organizations using file policies for data at rest should plan that migration now.
Can I use dope.security with Defender for Cloud Apps?
Yes. Many teams keep Defender for Cloud Apps for discovery, catalog risk scoring, and OAuth governance inside the Defender portal, and use dope.security on the device for real-time web security, AI tenant control, and prompt-level DLP. dope.security deploys through standard device management such as Intune.



