workers compensation claims

How to Enable Office 365 Cloud App Security for Comprehensive Protection

By 3 min read 1,256 views
Featured image for How to Enable Office 365 Cloud App Security for Comprehensive Protection

Why Enable Office 365 Cloud App Security?

Office 365 Cloud App Security (CAS) adds real‑time monitoring, risk‑based conditional access, and automated remediation to Microsoft 365 environments. By turning on CAS you gain visibility into shadow IT, detect anomalous user behavior, and enforce data loss prevention across SharePoint, OneDrive, Teams, and other SaaS services. The platform also integrates with Azure AD Conditional Access, allowing you to block or challenge risky sign‑ins before data is exposed.

More from this site

Keep reading the latest coverage

Browse latest →

Prerequisites Before Activation

Ensure you have a Microsoft 365 E5 license or a standalone Cloud App Security subscription. An Azure AD Global Administrator account is required to grant the necessary permissions. Verify that your tenant's security defaults are either disabled or configured to work with custom Conditional Access policies, as CAS will create its own policy set.

Step‑by‑Step Activation

1. Access the Cloud App Security Portal

Sign in to the Microsoft 365 admin center, navigate to Security → Cloud App Security, or go directly to https://portal.cloudappsecurity.com. Use your Global Administrator credentials.

2. Turn On the Service

In the CAS dashboard, click Settings → Enable Cloud App Security. Confirm the prompt; the service will provision within a few minutes.

3. Connect Office 365 Data Sources

Under Data Sources, select Microsoft 365. Follow the wizard to grant read‑only permissions for activity logs, file events, and audit data. Choose the specific workloads (Exchange, SharePoint, OneDrive, Teams) you want to monitor.

4. Configure Conditional Access Integration

In Azure AD, create a new Conditional Access policy named "CAS‑Risk‑Based Access." Set Cloud apps to Microsoft Cloud App Security, assign the required users or groups, and enable the Session control "Use app enforced restrictions." This links CAS risk scores to Azure AD sign‑in decisions.

5. Define Policies and Alerts

Back in CAS, go to Policies → Control policies. Create policies for:

  • Impossible travel (logins from distant locations within a short timeframe)
  • Bulk file download or share
  • Unusual PowerShell activity

Set each policy to trigger an alert, block the session, or require multi‑factor authentication.

Key Configuration Options

Below is a quick reference of the most impactful settings and typical values.

SettingRecommended ValueWhy It Matters
Log retention90 days (default) or longer if compliance requiresEnsures sufficient historical data for investigations
Risk score thresholdMedium (3) for most orgsBalances alert noise with security coverage
Session controlBlock download for high‑risk sessionsPrevents data exfiltration in real time

Monitoring and Ongoing Management

After activation, regularly review the Dashboard for top alerts and risk trends. Use the built‑in investigation tools to drill into suspicious activities, export logs for SIEM integration, and refine policies based on false‑positive rates. Schedule quarterly policy audits to align with evolving business processes and regulatory requirements.

Troubleshooting Common Issues

If alerts are not appearing, verify that the data source connections are healthy and that Azure AD Conditional Access policies are not overriding CAS controls. For latency in log ingestion, check the tenant's service health and consider enabling "High‑frequency data collection" in the CAS settings, noting the increased storage impact.

Editor's pick

Keep exploring our latest stories

Fresh reads, picked daily.

Browse latest
Share: