What is Microsoft Cloud App Security?
Microsoft Cloud App Security (MCAS) is a Cloud Access Security Broker (CASB) that gives visibility into cloud app usage, detects risky behavior, and enforces security policies across SaaS, PaaS, and IaaS environments. It integrates with Azure AD, Office 365, and third‑party services, providing real‑time alerts and automated actions.
- What is Microsoft Cloud App Security?
- Why Use a PDF Installation Guide?
- Prerequisites Before Installing MCAS
- Step‑by‑Step Installation Process
- 1. Sign In to Microsoft 365 Admin Center
- 2. Access the Security & Compliance Center
- 3. Navigate to Cloud App Security Settings
- 4. Register the MCAS App
- 5. Assign Permissions
- 6. Generate Client Secret
- 7. Configure MCAS in the Cloud App Security Portal
- 8. Enable Data Loss Prevention (DLP)
- 9. Test the Integration
- 10. Export the Installation Steps to PDF
- Common Troubleshooting Tips
- Maintenance and Updates
- FAQs
More from this site
Keep reading the latest coverage
Why Use a PDF Installation Guide?
Many IT professionals prefer a PDF guide because it can be printed, annotated, and shared offline. A well‑structured PDF also allows step‑by‑step screenshots and detailed notes that are easier to follow than web pages. This article explains how to create and use such a guide for MCAS installation.
Prerequisites Before Installing MCAS
Before you start, ensure the following:
- Active Microsoft 365 or Azure subscription with admin rights.
- Azure Active Directory (AAD) tenant configured.
- Proper licensing: MCAS requires an Enterprise Mobility + Security E5 or Microsoft 365 E5 license.
- Network connectivity to Microsoft's cloud endpoints.
- Browser: Microsoft Edge or Google Chrome (latest version).
Step‑by‑Step Installation Process
1. Sign In to Microsoft 365 Admin Center
Navigate to https://admin.microsoft.com and log in with global admin credentials.
2. Access the Security & Compliance Center
In the left pane, click Show all → Security & Compliance to open the portal.
3. Navigate to Cloud App Security Settings
In the Security & Compliance Center, select Threat Management → Policy → Cloud App Security.
4. Register the MCAS App
Click Register new application. Follow the wizard to provide an application name, description, and redirect URI. The wizard will generate an Application (client) ID and Tenant ID.
5. Assign Permissions
Under API permissions, add the required Microsoft Graph permissions: Application.Read.All, Policy.ReadWrite.ConditionalAccess, and Directory.ReadWrite.All. Grant admin consent.
6. Generate Client Secret
In the Certificates & secrets tab, create a new client secret. Note the secret value; you will need it in the PDF guide.
7. Configure MCAS in the Cloud App Security Portal
Open https://portal.cloudappsecurity.microsoft.com and sign in. Navigate to Settings → Integration → Azure AD. Input the Application ID, Tenant ID, and Client Secret.
8. Enable Data Loss Prevention (DLP)
In the Cloud App Security portal, go to Policy → DLP. Create a new DLP policy tailored to your organization's data classification.
9. Test the Integration
Run a test by generating a synthetic alert or reviewing the Activity dashboard. Verify that user activities are logged and alerts trigger as expected.
10. Export the Installation Steps to PDF
Open the browser's print dialog, choose "Save as PDF," and adjust settings to include all screenshots and notes. Save the file with a descriptive name like MCAS_Installation_Guide.pdf.
Common Troubleshooting Tips
- Permission Errors: Ensure admin consent is granted for all API permissions.
- Connection Timeouts: Verify that firewall rules allow outbound traffic to *.microsoft.com.
- License Issues: Check that the user account has the correct MCAS license assigned.
Maintenance and Updates
Microsoft regularly releases updates to MCAS. Keep the PDF guide current by reviewing the release notes on the Microsoft Docs site and updating screenshots accordingly. Schedule a quarterly review of the guide to capture new features.
FAQs
Q: Can I install MCAS without a Microsoft 365 license? A: No, MCAS requires an Enterprise Mobility + Security E5 or Microsoft 365 E5 license.
Q: Is a separate Azure AD tenant needed? A: MCAS can operate within the same tenant as Azure AD; a separate tenant is not required.