Agent skill

Defender For Cloud Apps

by vinayaklatthe in vinayaklatthe/microsoft-security-skills

Guidance for Microsoft Defender for Cloud Apps (MDA) — the CASB for SaaS discovery, app governance, session controls, and threat detection.

MITAuto-check passedBackend & APIs

Install Defender For Cloud Apps

skills CLI
$ npx skills add vinayaklatthe/microsoft-security-skills --skill defender-for-cloud-apps -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinayaklatthe/microsoft-security-skills defender-for-cloud-apps --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/defender-for-cloud-apps .claude/skills/defender-for-cloud-apps && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
defender-for-cloud-apps
GitHub stars
175
Token cost
~1.9k tokens
SKILL.md length
806 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Guidance for Microsoft Defender for Cloud Apps (MDA) — the CASB for SaaS discovery, app governance, session controls, and threat detection.

  • Works in 7 steps: Enable Cloud Discovery via MDE —… → Triage the Cloud App Catalog — Sort by… → Connect sanctioned SaaS via app… → …
  • IaaS / PaaS posture (use defender-for-cloud-hardening)
  • SKILL.md covers When to use, Pick the MDA capability, Approach and Guardrails, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Defender For Cloud Apps is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Microsoft Defender for Cloud Apps (MDA) — the CASB for SaaS discovery, app governance, session controls, and threat detection. Covers Cloud Discovery via Defender for Endpoint integration, OAuth app governance, Conditional Access App Control (reverse-proxy session policies), and SaaS security posture (SSPM). WHEN: Defender for Cloud Apps, MDA, CASB, shadow IT discovery, cloud app governance, OAuth app risk, session control, Conditional Access App Control, SaaS security posture management, SSPM…

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Cloud networking and OAuth and OpenID Connect. It works with Microsoft Defender and Microsoft 365. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.

When your agent uses it

  • IaaS / PaaS posture (use defender-for-cloud-hardening)
  • Endpoint EDR (use defender-for-endpoint)
  • DLP (use purview-dlp-policy)

Example prompts

  • “/defender-for-cloud-apps”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Enable Cloud Discovery via MDE — Integration → Microsoft Defender for Endpoint → on.
  2. Triage the Cloud App Catalog — Sort by risk score + user count. Sanction approved
  3. Connect sanctioned SaaS via app connectors — Microsoft 365, Salesforce, ServiceNow,
  4. Turn on app governance for OAuth risk — Microsoft Graph permissions are the SaaS
  5. Conditional Access App Control - pilot session policies — Reverse-proxy session
  6. Anomaly detection + alert tuning — Default policies (impossible travel, mass
  7. Operationalise — Stream MDA alerts into XDR / Sentinel. Define playbooks for the

What it can do on your machine

Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Defender For Cloud Apps loads about 1.9k tokens when it runs. Until then it costs about 186 tokens; SKILL.md has 806 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~186
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 806 words, ~1,920 tokens.

Download SKILL.mdSave it as .claude/skills/defender-for-cloud-apps/SKILL.md (or your agent's skills folder).
name
defender-for-cloud-apps
description
Guidance for Microsoft Defender for Cloud Apps (MDA) — the CASB for SaaS discovery, app governance, session controls, and threat detection. Covers Cloud Discovery via Defender for Endpoint integration, OAuth app governance, Conditional Access App Control (reverse-proxy session policies), and SaaS security posture (SSPM). WHEN: Defender for Cloud Apps, MDA, CASB, shadow IT discovery, cloud app governance, OAuth app risk, session control, Conditional Access App Control, SaaS security posture management, SSPM, sanction or unsanction app, Cloud App Catalog, app connectors. DO NOT USE for IaaS / PaaS posture (use defender-for-cloud-hardening), endpoint EDR (use defender-for-endpoint), or DLP (use purview-dlp-policy).
license
MIT
metadata.author
Microsoft
metadata.version
0.1.0

Microsoft Defender for Cloud Apps

Microsoft Defender for Cloud Apps (MDA) is a Cloud Access Security Broker (CASB) and SaaS security solution providing visibility into cloud app usage, governance of OAuth-connected apps, real-time session controls via Conditional Access App Control, and threat detection across connected SaaS services.

When to use

Discovering shadow IT, governing OAuth apps connected to Microsoft 365, applying in-session controls, and managing SaaS posture (SSPM). Use this skill when the question is about applications (SaaS or third-party), not IaaS or endpoints.

Do not use this skill for IaaS / PaaS posture (defender-for-cloud-hardening), EDR (defender-for-endpoint), or DLP authoring (purview-dlp-policy).

Pick the MDA capability

GoalCapabilityNotes
Find unsanctioned cloud apps in useCloud Discovery via MDE integrationAgentless; uses MDE telemetry
Get activity / file visibility for sanctioned SaaSApp connector (API-based)M365, Salesforce, ServiceNow, Workday
Govern OAuth apps connected to Microsoft 365App governance add-onRisk score + automated policies
Block file download in browser sessionConditional Access App Control (session)Reverse proxy; integrates with CA
Detect anomalous user activity (impossible travel, mass download)Anomaly detection policiesUEBA-style
Posture for connected SaaS (config drift)SaaS Security Posture Management (SSPM)Per-app recommendations
Investigate / contain a compromised SaaS accountGovernance actionsSuspend, force re-auth, revoke OAuth

Rule of thumb: start with Cloud Discovery via MDE (free with E5) to find shadow IT and app governance for OAuth risk - those two cover 80% of the SaaS attack surface. Session control via CAAC is powerful but the reverse proxy adds operational surface area; pilot it narrowly.

Approach

  1. Enable Cloud Discovery via MDE — Integration → Microsoft Defender for Endpoint → on. No agents, no log uploads - discovery happens automatically from MDE telemetry on managed endpoints. Verify: Discovery dashboard populates within 24-48 hours; app catalogue scores visible.

  2. Triage the Cloud App Catalog — Sort by risk score + user count. Sanction approved apps; unsanction risky / unused apps (MDE then blocks them on managed endpoints). Verify: top 10 high-user-count high-risk apps reviewed weekly.

  3. Connect sanctioned SaaS via app connectors — Microsoft 365, Salesforce, ServiceNow, Workday, GitHub Enterprise via API connector. Provides activity log, file inventory, admin / user account governance.

  4. Turn on app governance for OAuth risk — Microsoft Graph permissions are the SaaS blast radius. App governance scores third-party OAuth apps by risk and permission privilege. Auto-policy: block apps requesting > X high-privilege permissions or unverified publisher. Verify: app governance shows risk distribution; high-risk apps either approved or blocked, not lingering.

  5. Conditional Access App Control - pilot session policies — Reverse-proxy session control for browser sessions to cloud apps. Use cases: block download on unmanaged devices, force document-labeling on upload, monitor copy/paste. Verify: a session from an unmanaged device shows the watermark / download block; from a compliant device, no friction.

  6. Anomaly detection + alert tuning — Default policies (impossible travel, mass download, multiple failed sign-ins, ransomware activity). Tune thresholds; stream to Defender XDR for unified incident view.

  7. Operationalise — Stream MDA alerts into XDR / Sentinel. Define playbooks for the top 5 alert types (impossible travel, mass download, OAuth consent granted, file externally shared, admin activity from unusual location).

Show full SKILL.md (300 more words)Show less

Guardrails

  • Cloud Discovery data can include user activity - set anonymisation per privacy requirements. EU works councils may require user anonymisation in the discovery view.
  • Pilot session policies; reverse-proxy session control can affect app behaviour. Some SaaS app features break under the reverse proxy. Test thoroughly per app.
  • Prioritise app governance for apps with broad Microsoft Graph permissions. Mail.Read
    • Files.Read.All for a third-party app = data-exfil risk on first compromise. Review before consent or auto-block.
  • Sanction state matters. Unsanctioning blocks via MDE - confirm impact before flipping high-user apps.
  • OAuth consent should be admin-only for most permissions. User-consent for high- privilege scopes is a phish-then-consent route.
  • MDA isn't DLP. Use Purview DLP for content-aware policies; MDA for context (session, app, device).

Common anti-patterns

  • "Discover apps but never sanction" - Visibility without action. Sort by risk, decide.
  • "Auto-block all newly discovered apps" - User outrage; legitimate apps blocked. Review then sanction / unsanction.
  • "OAuth governance later - it's just app permissions" - First compromised OAuth app with Mail.Read = mass exfil. Govern from day one.
  • "Session policies on every app" - Pilot one app; broaden carefully.
  • "Ignore the privacy / works-council angle" - Discovery rollout blocked by HR or legal mid-flight. Anonymisation question is the first one.
  • "MDA alerts not in XDR / Sentinel" - Analysts miss them. Stream by default.

Example prompts

  • Discover shadow IT via Defender for Endpoint integration and sanction or unsanction cloud apps.
  • Set up Conditional Access App Control session policies for unmanaged devices.
  • Assess OAuth app risk with app governance and block high-risk consents.
  • Connect Microsoft 365 and Salesforce via app connectors for full activity visibility.
  • Tune impossible-travel and mass-download anomaly policies.
  • Stream MDA alerts into Defender XDR for unified investigation.

Microsoft Learn

© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/defender-for-cloud-apps of vinayaklatthe/microsoft-security-skills.

Open the folder on GitHubat commit 15f16df

Compare with similar skills

Defender For Cloud Apps next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Defender For Cloud Apps compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Defender For Cloud Apps this skillvinayaklatthe/microsoft-security-skills175—~1.9kAutomated safety check: PassMIT
Entra Agent Idmicrosoft/GitHub-Copilot-for-Azure2552 repos~4kAutomated safety check: PassMIT
Detecting OAuth Token Theftmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.0
Implementing API Threat Protection With Apigeemukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.0
Implementing Zero Trust For SaaS Applicationsmukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.0
API GatewayCraftOS-dev/CraftBot3923 repos~7.1kAutomated safety check: PassMIT

Similar skills

  • Entra Agent Id

    microsoft/GitHub-Copilot-for-Azure

    Official

    Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmipath, OBO, cross-tenant)…

    255 GitHub starsUsed in 2 repos~4k tokens
    Backend & APIsAuto-check passed
  • Detecting OAuth Token Theft

    mukul975/Anthropic-Cybersecurity-Skills

    Detect and respond to OAuth token theft and replay in Microsoft Entra ID (Azure AD), covering access token theft, refresh token replay, Primary Refresh Token (PRT) abuse, pass-the-cookie attacks…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Implementing API Threat Protection With Apigee

    mukul975/Anthropic-Cybersecurity-Skills

    Implements API threat protection using Google Apigee reverse-proxy policies, including JSON/XML threat protection, OAuth 2.0 enforcement, SpikeArrest rate limiting, regex-based threat detection, and…

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Implementing Zero Trust For SaaS Applications

    mukul975/Anthropic-Cybersecurity-Skills

    Secures SaaS apps (Microsoft 365, Google Workspace, Salesforce, Slack) via CASB/SSPM deployment, conditional access policies, OAuth app governance, and session-level DLP controls enforcing identity…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • API Gateway

    CraftOS-dev/CraftBot

    Connect to 100+ APIs (Google Workspace, Microsoft 365, Notion, Slack, Airtable, HubSpot, etc.) with managed OAuth.

    392 GitHub starsUsed in 3 repos~7.1k tokens
    Backend & APIsAuto-check passed
  • Detecting Email Account Compromise

    mukul975/Anthropic-Cybersecurity-Skills

    Detect compromised O365 and Google Workspace email accounts by analyzing Unified Audit Logs and Azure AD sign-in logs for impossible travel, inbox rule creation/deletion (Set-InboxRule…

    34k GitHub stars~823 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from vinayaklatthe/microsoft-security-skills

All 50 skills in this repo
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Arc

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Confidential Computing

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).

    175 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Ddos Protection

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.

    175 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed

Categories

Questions about Defender For Cloud Apps

What does Defender For Cloud Apps do?

Guidance for Microsoft Defender for Cloud Apps (MDA) — the CASB for SaaS discovery, app governance, session controls, and threat detection. Defender For Cloud Apps is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Microsoft Defender for Cloud Apps (MDA) — the CASB for SaaS discovery, app governance, session controls, and threat detection.

When should I use Defender For Cloud Apps?

Defender For Cloud Apps fits situations like: iaaS / PaaS posture (use defender-for-cloud-hardening); endpoint EDR (use defender-for-endpoint); DLP (use purview-dlp-policy).

How do I install Defender For Cloud Apps in Claude Code?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill defender-for-cloud-apps -a claude-code`. Or copy the skill folder (skills/defender-for-cloud-apps in vinayaklatthe/microsoft-security-skills) into .claude/skills/defender-for-cloud-apps in your project. Claude Code loads it when a task matches its description.

How do I install Defender For Cloud Apps in Codex?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill defender-for-cloud-apps -a codex`. Or copy the skill folder (skills/defender-for-cloud-apps in vinayaklatthe/microsoft-security-skills) into .agents/skills/defender-for-cloud-apps in your project. Codex loads it when a task matches its description.

Can I use Defender For Cloud Apps in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill defender-for-cloud-apps -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/defender-for-cloud-apps, .gemini/skills/defender-for-cloud-apps, .github/skills/defender-for-cloud-apps and .opencode/skills/defender-for-cloud-apps in your project.

What does Defender For Cloud Apps need to run?

SKILL.md names no scripts, command-line tools or credentials: Defender For Cloud Apps is instructions for the agent only.

Does Defender For Cloud Apps access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Defender For Cloud Apps safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Defender For Cloud Apps use?

Defender For Cloud Apps is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Defender For Cloud Apps use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Defender For Cloud Apps?

Skills that share tags, products or a category with Defender For Cloud Apps: Entra Agent Id (microsoft/GitHub-Copilot-for-Azure, 255 stars), Detecting OAuth Token Theft (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing API Threat Protection With Apigee (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Implementing Zero Trust For SaaS Applications (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Defender For Cloud Apps?

vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.

Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.