Skip to main content

Overview

This guide walks through how to create a Microsoft Defender for Cloud Apps connection and the permissions it requires to be used in Blink’s Automated Case Management, across Ingestion, Enrichment, and Response workflows.
Defender for Cloud Apps exposes its own dedicated API with its own permission set, separate from both Microsoft Graph and Azure RBAC. When registering the app in Microsoft Entra ID, you add these permissions under “Microsoft Cloud App Security” (the API’s legacy name), not under Microsoft Graph. See Required Permissions.

Creating a Connection

Microsoft Defender for Cloud Apps Connection Guide

Follow this guide to create a Microsoft Defender for Cloud Apps connection

Required Permissions

Defender for Cloud Apps uses its own application permissions (issued as a roles claim in the token), assigned under the Microsoft Cloud App Security API. Grant the permissions matching the actions Blink performs:
The exact permission set depends on which Defender for Cloud Apps APIs Blink’s content calls. To confirm the permission a given API requires, check the Permissions section of that API in Microsoft’s Defender for Cloud Apps API reference, and grant the least privilege necessary.
Some mailbox response actions attributed to Defender for Cloud Apps (for example, Remove Mailbox Rule and Block Sending Email Address) do not have an official Defender for Cloud Apps endpoint. Where these are supported, they rely on a Microsoft Graph message-rule API workaround rather than the Cloud Apps API. See the Microsoft Graph permissions for those scopes.