Skip to content
Microsoft logo
Microsoft

Microsoft Defender for Cloud Apps [New Commerce Experience]

SecuritySaaSMonthly1-Year
SKU MST-NCE-DCA-C100

Microsoft Defender for Cloud Apps

Microsoft Defender for Cloud Apps is Microsoft's cloud access security broker. It discovers the SaaS applications actually in use, scores them against risk factors, governs OAuth application permissions, detects anomalous behaviour, and applies real-time access and session policies through Conditional Access App Control. Two things to check before buying it. A subset called Cloud App Discovery already comes at no extra cost with Microsoft Entra ID P1, Enterprise Mobility plus Security E3 and Microsoft 365 E3, and it covers the same catalogue of discovered applications. And file policies retire on 6 January 2027, with Microsoft directing customers to Microsoft Purview instead.

What it is

Microsoft Defender for Cloud Apps is a cloud access security broker. It answers which cloud applications your people are using, which of those you never approved, what permissions those applications hold over your data, and what to do about it.

Who it is for

Organisations that suspect their SaaS estate is wider than their contract list, and organisations that need to control what happens inside a session rather than only whether the sign-in was allowed.

Key capabilities

  • Cloud app discovery across a catalogue of tens of thousands of applications, from log upload or native Defender for Endpoint integration
  • Risk assessment of discovered applications against dozens of risk factors
  • App governance over OAuth permissions, including detecting overprivileged applications and revoking access
  • Anomaly detection and user and entity behaviour analytics
  • Access policies, which allow or block sign-in, and session policies, which allow the session while controlling what happens in it
  • Integration with Microsoft Entra ID, Microsoft Intune, Microsoft Defender for Endpoint and Microsoft Purview

Check this first: you may already have the discovery half

Cloud App Discovery is a subset of this product and comes at no additional cost with Microsoft Entra ID P1, Enterprise Mobility plus Security E3 and Microsoft 365 E3. It covers the same catalogue of discovered applications, the same risk assessment and the same usage analytics. What it does not include is anomaly detection on discovered applications, OAuth permission revocation, data loss prevention, policy enforcement and the session controls. If discovery alone is the requirement, check what your identity licence already gives you.

A dated change worth planning around

File policies retire on 6 January 2027. Microsoft's guidance is to migrate them to Microsoft Purview data loss prevention or auto-labelling policies. If a deployment plan is being written now, write it against Purview rather than against file policies.

What Office 365 Cloud App Security is

A smaller subset that supports only the Office 365 application connector. It has the features but not the reach.

Features
Cloud app discovery and Shadow IT visibility
Risk assessment of discovered applications
OAuth app governance and permission revocation
Anomaly detection and behaviour analytics
Access policies and real-time session policies
Conditional Access App Control
Integrates with Entra ID, Intune, Defender for Endpoint and Purview
Use cases
Finding the SaaS applications nobody put through procurement
Reviewing and revoking OAuth permissions granted to third-party apps
Allowing access from an unmanaged device while blocking downloads
Checking whether an existing identity licence already covers discovery
FAQ
Do I already have part of this?

Probably. Cloud App Discovery is a subset of Defender for Cloud Apps and comes at no additional cost with Microsoft Entra ID P1, Enterprise Mobility plus Security E3 and Microsoft 365 E3. It gives the same application catalogue, risk assessment and usage analytics.

What does the full product add over Cloud App Discovery?

Anomaly detection on discovered applications, OAuth permission review and revocation, data loss prevention across SaaS, policy setting and enforcement, session controls, the SIEM connector and Microsoft Purview integration.

Are file policies still the right thing to build on?

No. File policies retire on 6 January 2027, and Microsoft directs customers to migrate them to Microsoft Purview data loss prevention or auto-labelling policies. New work should target Purview.

What is the difference between an access policy and a session policy?

An access policy allows or blocks the sign-in outright. A session policy allows access and then controls what happens inside the session, for example blocking downloads of sensitive files or requiring step-up authentication for a specific activity.

How is it different from Office 365 Cloud App Security?

Office 365 Cloud App Security is a subset that supports only the Office 365 application connector. Defender for Cloud Apps covers cross-SaaS applications, and adds cloud platform security posture for Azure, AWS and Google Cloud.

Plan details
Vendor
Microsoft
Category
Security
Type
SaaS
Billing
Monthly
Commitment
1-Year
Available terms
1-Year, Monthly
Unit price
€2.90 /mo
SKU
MST-NCE-DCA-C100
How buying works
  1. 1You prepay through ITSailor (Malta). VAT handled, reverse-charge for valid EU VAT IDs.
  2. 2We provision through Pax8 wholesale into your Microsoft tenant, with no third-party MSP markup.
  3. 3You keep the tenant. Sovereign by default: every engagement closes with an Exit Kit.
Microsoft NCE termsNew Commerce Experience applies: within 7 days of activation you may cancel or reduce seats (pro-rated). After day 7 the subscription is committed for the term. We mirror this verbatim, with no surprises.
Your price
Term
Billing cycle
€3.10/mo
Pax8 suggested retail €3.15−1% off Pax8 suggested retail
Ask a question

Pax8 wholesale, margin in the price

More in Security
Add-on
Microsoft

Microsoft Defender Vulnerability Management Add-on (Education Student Pricing) [New Commerce Experience]

Microsoft Defender Vulnerability Management add-on is available to Defender for Endpoint Plan 2 customers to access continuous asset visibility, in-depth vulnerability assessments, and risk-based prioritization to help teams address critical vulnerabilities and misconfigurations.

€0.28/mo
SecurityEDU
SaaS
Microsoft

Microsoft Entra ID P1 (Education Student Pricing) [New Commerce Experience]

Microsoft Entra ID P1 provides single sign-on to thousands of cloud (SaaS) apps and access to web apps you run on-premises. Built for ease of use, Microsoft Entra ID P1 features multi-factor authentication (MFA); access control based on device health, user location, and identity; and holistic security reports, audits,

€0.28/mo
SecurityEDU
SaaS
Microsoft

Microsoft Entra ID P2 (Education Student Pricing) [New Commerce Experience]

Microsoft Entra ID P2 includes all the capabilities of P1 plus advanced identity protection features such as Identity Protection, which helps detect potential vulnerabilities affecting your organization’s identities, and Privileged Identity Management, which helps manage, control, and monitor access within your organiz

€0.42/mo
SecurityEDU
SaaS
Microsoft

Microsoft Defender Vulnerability Management (Education Student Pricing) [New Commerce Experience]

Microsoft Defender Vulnerability Management standalone is a comprehensive vulnerability management solution to access continuous asset visibility, in-depth vulnerability assessments, and risk-based prioritization to help teams address critical vulnerabilities and misconfigurations.

€0.42/mo
SecurityEDU