Microsoft 365 Security Lab: Cloud Discovery

Hands-On Microsoft 365 Security & Compliance Tasks

๐Ÿ“– Overview

This lab provides hands-on experience with Microsoft Defender for Cloud Apps (MDCA) to discover Shadow IT and assess cloud app risk. Walkthroughs simulate real-world Microsoft 365 security engineering tasks and focus on uploading network logs, creating snapshot reports, reviewing apps, and applying governance policies.

๐Ÿ“š What This Covers

๐Ÿ“ค Uploading Network Traffic Logs

Ingest firewall or proxy logs into Microsoft Defender for Cloud Apps for discovery analysis.

๐Ÿ“‘ Cloud Discovery Snapshot Reports

Create snapshot reports to analyze cloud usage patterns and uncover shadow IT.

๐Ÿ”Ž Reviewing Cloud Apps & Risk Scores

Evaluate discovered applications, review risk scores, and assess compliance posture.

โœ… App Sanctioning & Governance Policies

Sanction or unsanction apps and apply governance policies to enforce safe cloud usage.

๐Ÿ“ Lab Walkthroughs

Cloud Discovery Snapshot

Upload W3C firewall logs, create a snapshot report, analyze discovered apps, and review risk scores.

View Walkthrough

Shadow IT Analysis

Identify unsanctioned apps, prioritize risk based on scores, and evaluate governance actions.

View Walkthrough

App Governance Policies

Plan actions to sanction/unsanction apps, configure monitoring, and integrate with compliance workflows.

View Walkthrough

๐Ÿ›  Tools Used

Microsoft Defender for Cloud Apps
Microsoft 365 Lab Tenant
Sample Firewall Log (Generic W3C)

๐Ÿ”— Related Labs

Okta IAM Lab โ€“ Cloud IAM, SSO, MFA policies, and lifecycle automation
Microsoft Entra ID โ€“ Cloud IAM, Conditional Access, MFA, and PowerShell automation
Active Directory (On-Prem) โ€“ OU design, delegation, PowerShell automation, and AD management

๐Ÿ’ก Next Steps