Forum Discussion

NiklasM's avatar
NiklasM
Brass Contributor
Aug 03, 2020

Cannot find logs in Defender ATP for Discovered apps

We and our customers experience inaccurate data in the discovered apps in MCAS.

For example:
Discovered Apps show the up- and download of the app "Box" for multiple clients. If we search for connections in Defender ATP, we cannot find any indication for Box. The URL is not used in any Defender ATP logs. We can't hunt on IP address base, because there are no information which IP Addresses are behind the box service.

 

How can we bring the discovery and log data together for further investigation? If we can't hunt down the logs we can not stop data loss. We need a possibility to bring MCAS in correlation with Defender.

 

Niv Goldenbergyou have already answered the follwing post: https://techcommunity.microsoft.com/t5/microsoft-cloud-app-security/apps-seen-in-cloud-app-security-but-not-on-firewall/m-p/128084

Maybe you can assist here.

No RepliesBe the first to reply

Resources