Microsoft Defender for Cloud Apps (MDCA) can integrate with Defender for Endpoint (MDE). With the integration, it is possible to get an out-of-the-box cloud app discovery view of the used apps and Shadow IT. When blocking apps via Defender for Cloud Apps, indicators will be synced directly to the Defender for Endpoint indicators list.

While the integration works well, one longstanding challenge has been the large number of alerts generated in the Microsoft Defender portal. It generates many alerts in the Defender portal, and there is no native way to stop the alert generation.

How does the integration work?

Cloud Discovery in Microsoft Defender for Cloud Apps relies on cloud traffic logs to identify cloud application usage across the organization. When using Microsoft Defender for Endpoint, traffic logs are integrated with Defender for Cloud Apps, which collects and forwards all cloud app network activity. This monitoring functionality is part of the sensor itself, so there is no need to connect to additional network services.

Configuration in MDE

For the configuration, the first point is the enablement of the integration with Defender for Cloud Apps via the advanced features of Defender. Go to Microsoft Defender -> Settings -> Endpoints -> Advanced features and enable the integration: Microsoft Defender for Cloud Apps.

When enabling the integration, traffic will be forwarded to Defender for Cloud Apps to get a unified view of the shadow IT and cloud app network usage.

How to confirm the integration is enabled?

After the integration enablement, data from the Endpoint will show up in the dashboard of Defender for Cloud Apps – Cloud discovery. (It can take some time before the first data is visible. The source should be: Defender managed endpoints.

Configuration in Defender for Cloud Apps

Defender for Cloud Apps also includes the Enforce app access capability, which allows administrators to block applications that are tagged as unsanctioned. When this setting is enabled, apps will be blocked when tagged as unsanctioned.

Blocked app in Defender for Cloud Apps -> Synced to the indicators list of MDE with the value block.


Blocking apps

When blocking apps, indicators will be synced to Defender for Endpoint (indicators). Sanction is allowing the app; unsanction is blocking the app.

When blocking the app (ChatGPT), the indicators included in the “Domain” section will be synced to Defender for Endpoint.


Alert generation

One of the most common challenges when blocking applications such as ChatGPT is the large number of alerts that can be generated in the Microsoft Defender portal.

Alert Severity Configuration

When the Generate alerts for blocked access setting is enabled, Microsoft Defender creates an alert each time access to a blocked application is attempted. The severity of these alerts is determined by the severity you select.

  • Informational: All generated alerts appear in the Defender portal with an Informational severity level. This option is useful when you want visibility into blocked access attempts without creating high-priority security events.
  • High: Alerts are created with a High severity level, making them more prominent within the Defender portal and ensuring they receive greater attention from security teams.

Selecting the appropriate severity level is important to avoid alert fatigue while still maintaining visibility into user attempts to access blocked applications.

Previously, there was no way to disable the alert generation, and automation via Logic Apps or Microsoft Graph was required to automatically resolve the alerts (or recently the alert tuning rules). Since the setting Generate alerts for blocked app access was not available in the portal.

After many years of feedback, Microsoft finally released a feature to disable the unsanctioned alerts of blocked apps manually.

Old way; without the option to disable alerts.

How to disable alerts

Disable the checkbox “Generate alert for blocked app access” to disable the alert generation. This will just disable the alert generation; apps are still blocked and logged in the Advanced Hunting schema of Defender.

Although the change is relatively small, it addresses a longstanding operational challenge for many security teams. Organizations that block popular applications such as ChatGPT, WhatsApp, or other unsanctioned cloud services can now significantly reduce alert noise while maintaining enforcement and visibility through Defender’s logging and hunting capabilities. This enhancement helps improve signal-to-noise ratios in the Microsoft Defender portal and reduces unnecessary analyst workload.