Overview
This guide walks through how to create a Microsoft Defender for Cloud Apps connection and the permissions it requires to be used in Blink’s Automated Case Management, across Ingestion, Enrichment, and Response workflows.Defender for Cloud Apps exposes its own dedicated API with its own permission set, separate from both Microsoft Graph and Azure RBAC. When registering the app in Microsoft Entra ID, you add these permissions under “Microsoft Cloud App Security” (the API’s legacy name), not under Microsoft Graph. See Required Permissions.
Creating a Connection
Microsoft Defender for Cloud Apps Connection Guide
Follow this guide to create a Microsoft Defender for Cloud Apps connection
Required Permissions
Defender for Cloud Apps uses its own application permissions (issued as aroles claim in the token), assigned under the Microsoft Cloud App Security API. Grant the permissions matching the actions Blink performs:
The exact permission set depends on which Defender for Cloud Apps APIs Blink’s content calls. To confirm the permission a given API requires, check the Permissions section of that API in Microsoft’s Defender for Cloud Apps API reference, and grant the least privilege necessary.
Which stage of Alert Processing need this connection?
Which stage of Alert Processing need this connection?