> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blinkops.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Microsoft Defender for Cloud Apps

## Overview

This guide walks through how to create a Microsoft Defender for Cloud Apps connection and the permissions it requires to be used in Blink's Automated Case Management, across **Ingestion**, **Enrichment**, and **Response** workflows.

<Note>
  Defender for Cloud Apps exposes its **own dedicated API** with its own permission set, separate from both Microsoft Graph and Azure RBAC. When registering the app in Microsoft Entra ID, you add these permissions under **"Microsoft Cloud App Security"** (the API's legacy name), not under Microsoft Graph. See [Required Permissions](#required-permissions).
</Note>

***

## Creating a Connection

<Card title="Microsoft Defender for Cloud Apps Connection Guide" icon="arrow-up-right-from-square" href="https://docs.blinkops.com/docs/integrations/microsoft-defender-for-cloud-app">
  Follow this guide to create a Microsoft Defender for Cloud Apps connection
</Card>

***

## Required Permissions

Defender for Cloud Apps uses its own application permissions (issued as a `roles` claim in the token), assigned under the **Microsoft Cloud App Security** API. Grant the permissions matching the actions Blink performs:

| Permission | Purpose |
| - | - |
| `Investigation.Read` | Read investigation data (activities, files, entities) for enrichment |
| `Investigation.Manage` | Perform investigation actions where required by response content |
| `Discovery.Read` | Read Cloud Discovery data |
| `Settings.Read` | Read configuration needed to resolve the environment |

<Info>
  The exact permission set depends on which Defender for Cloud Apps APIs Blink's content calls. To confirm the permission a given API requires, check the **Permissions** section of that API in Microsoft's Defender for Cloud Apps API reference, and grant the least privilege necessary.
</Info>

<Warning>
  Some mailbox response actions attributed to Defender for Cloud Apps (for example, **Remove Mailbox Rule** and **Block Sending Email Address**) do not have an official Defender for Cloud Apps endpoint. Where these are supported, they rely on a Microsoft Graph message-rule API workaround rather than the Cloud Apps API. See the [Microsoft Graph](/docs/integrations/microsoft-graph) permissions for those scopes.
</Warning>

<AccordionGroup>
  <Accordion title="Which stage of Alert Processing need this connection?" icon="table">
    | Source | Requires this connection? | Notes |
    | - | - | - |
    | Ingestion | ✓ Yes | Pulls Cloud Apps alerts into Blink |
    | Enrichment | ✓ Yes | Adds Cloud Apps investigation context to cases |
    | Response | ✓ Yes | Scan an Endpoint (with Defender XDR); other mailbox actions may require a Graph workaround |
  </Accordion>
</AccordionGroup>

***


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.