Defender for Cloud apps

Murali, Akshyalakshmi (ITN) 5 Reputation points
2025-06-17T11:00:08.81+00:00

Hello Community ,

Recently we have been receiving alerts related to defender for cloud apps ,but not sure about the fields that have generated in the alert is sufficient for investigation, For further analysis we have reviewed Azure AAD for the apps For instance in this alert - "App metadata associated with known phishing campaign " we did not get the user list who are using the application we have checked in Azure ad for additional details about the users but not present in Defender .We have E5 License .What are the mandatory fields that needs to generated FOR DEFENDER FOR CLOUD APPS alert ? or do we need to always check in Azure ad for further information related to apps ?

Thanks in advance for your valuable suggestions and answers .

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud Apps
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Catherine Kyalo 2,195 Reputation points Microsoft Employee
    2025-07-07T10:21:53.1933333+00:00

    Hi Murali, Akshyalakshmi (ITN)

    This detection generates alerts for non-Microsoft OAuth apps with metadata, such as nameURL, or publisher, which had previously been observed in apps associated with a phishing campaign. These apps might be part of the same campaign and might be involved in exfiltration of sensitive information. https://learn.microsoft.com/en-us/defender-cloud-apps/app-governance-anomaly-detection-alerts#app-metadata-associated-with-known-phishing-campaign.

    This alert is not from data coming from your customer's tenant, but it is a trend that has been seen across many tenants. This alert provides a proactive notification to the customer, so they can review the application to identify any abnormal activity or determine if the app has high privileges.

    Since this data is collected among many tenants, there is not too much data to share here. The recommendation is to make sure that the application does not have high privilege permissions in the Entra portal

    If the application does have high permission, revaluate if the application really does need that high privilege permission. If determined that it is not needed, then remove the permissions from the application.

    Refer

    If you find the answer above helpful, please Accept the answer to help anyone in the community who might have a similar question to quickly find the solution.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.