Our primary reason for implementing this product is to deal with spam email.
Business System Analyst at a tech company with 201-500 employees
Good logging, offers a single pane of glass for administration, and has effective anti-spam capabilities
Pros and Cons
- "Better logging allows us to find problems and take appropriate steps to lock them out."
- "In the future, I would like to see more plug-and-play capabilities that use AI to tell you what needs to be done. It would be helpful if it scanned our devices and made security suggestions, on a configuration basis."
What is our primary use case?
How has it helped my organization?
In general, this product helps to best secure our network.
It has features that help to improve our security posture that include better logging and better detection of threats. Since implementing it, we have been finding more malicious emails and files. Better logging allows us to find problems and take appropriate steps to lock them out.
We really like the fact that we have a single web-based pane of glass for administration. We can use our Azure Active Directory accounts to access it, and we don't need a local application.
What is most valuable?
The most valuable feature is the anti-spam capabilities.
What needs improvement?
Since implementing this solution, we have had more support calls regarding false positives. This means that we have had to do a little more work finding these issues, although it is getting better. It is just a matter of fine-tuning the system at this point.
The false positives we have experienced so far are rare and have come from customer-specific programs. I can't say that it would be easy for Microsoft to solve them. Fortunately, we have not had any false positives for known software.
In the future, I would like to see more plug-and-play capabilities that use AI to tell you what needs to be done. It would be helpful if it scanned our devices and made security suggestions, on a configuration basis. For example, it could make more suggestions that include specific points, or offer to have something configured in the standard way.
Buyer's Guide
Microsoft Defender for Cloud Apps
May 2025

Learn what your peers think about Microsoft Defender for Cloud Apps. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
857,028 professionals have used our research since 2012.
For how long have I used the solution?
We have been using Microsoft Cloud App Security for approximately three months.
What do I think about the stability of the solution?
Stability-wise, so far, I'm satisfied and it works well. We haven't had any issues that I attribute to Microsoft. There were a couple of days where we had problems logging on but I think that it was related to an issue with SolarWinds. My understanding is that some sites were shut down and a lot of companies had the same problem.
What do I think about the scalability of the solution?
At this point, we have not had the need to scale up or scale down. We have approximately 250 devices that we are protecting.
How are customer service and support?
We have not needed to contact technical support.
Which solution did I use previously and why did I switch?
We were using F-Secure before implementing Microsoft Cloud App Security, and we are still using it. In fact, it is just another layer of protection. If in the future we see that the Microsoft product is good enough, then we might stop using F-Secure. However, that is not the plan at the moment.
The main reason that we chose this product is for its good compatibility with Office 365 and Azure Active Directory.
How was the initial setup?
The initial setup was pretty straightforward. There were some Azure Active Directory options that we needed to tweak before we got everything running properly.
Our deployment took approximately one month to complete. Part of this time was spent adjusting for false positives.
We followed a step-by-step process for deployment where we started with the computers in our location, then moving to other devices. After our location was complete, we moved to other offices.
What about the implementation team?
We set it up with the help of an external consultant. The company sold us the product, set it up, and we use it. We have an ongoing support contract with them. Our experience with them was good and the consultant's knowledge of Microsoft products was very good. They are a Microsoft partner.
We are still learning the product and over time, we are getting more versed in it. There are two of us, myself and my colleague, responsible for the maintenance. We are both system administrators.
What's my experience with pricing, setup cost, and licensing?
The pricing is a little bit high but right now, we are okay with it because of the compatibility with Office 365, Teams, and Azure AD. These features make it worth the cost.
Which other solutions did I evaluate?
We did not evaluate other options before choosing this one.
What other advice do I have?
My advice for anybody who is implementing this product is to get assistance with deployment from somebody who can help you. Don't do it by yourself, if you're not a reseller for it. As a company, get somebody who has experience with the product.
In summary, we have just begun using this product but so far, it works well and we are satisfied with it.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Enterprise System Engineer at a government with 501-1,000 employees
We have become more aware of what services our users are using and how often they are using them
Pros and Cons
- "We have become more aware of what services our users are using, how often they are using them, and what data is being sent out of the organization and to which services. So, it is really a lot about visibility and helping us make decisions based on that. It drives some of our policy decisions for adding extra security controls."
- "They should continue integration with all other Microsoft security-related products. The integration with all the other products is still ongoing."
What is our primary use case?
The use case is for getting visibility over cloud applications that our users are consuming, how they consume it, and using the protection which comes with Cloud App Security with that visibility. It provides monitoring and visibility into cloud apps that our users are using and has ;a layer of security wrapped around that. It identifies malicious activity, if it's occurring, and provides overall protection of our company data from things like data exfiltration and all the other integrations that it has with other Microsoft security products.
It is protecting approximately 800 users. We have four other sources feeding into it from other products that we use. We have several thousand applications for which we get reports and visibility.
It is one of our core tools for monitoring and managing our security posture. In the future, I don't see that changing much. At this stage, I think we are at a good level of how we are using it.
How has it helped my organization?
It has helped identify areas where we should improve, make changes to improve, the reason why we should make a change, and the impact of making the change. So, it helps drive us to make changes and see the benefits of those changes.
We have become more aware of what services our users are using, how often they are using them, and what data is being sent out of the organization and to which services. So, it is really a lot about visibility and helping us make decisions based on that. It drives some of our policy decisions for adding extra security controls.
It has all been very seamless to our users. It indirectly positively impacts them because we are keeping them more secure. No one has been saying, "Because we are using this product, it is slowing me down or causing me problems." As standard users, they wouldn't really need to know that this solution exists. They just rely on us to keep them safe.
What is most valuable?
- Helps us have a view into our overall security posture and how we can improve it.
- The ability to perform investigations is very useful.
- Identifying the number of applications, particularly connected via OAuth.
- Has great, general overall visibility of who is using what and how.
- We are using it as an indicator for any indicators of compromise that might be coming up.
Identity security posture points out a preset number of security posture improvements, or areas of focus, and whether they are being met. It also points out what changes need to be made in order to meet them. Therefore, we can have better security posture.
There is a feature called security configuration. This is across the whole Microsoft set of products regarding what changes can be done. Specifically within a product, we use it to improve the security posture by making changes.
What needs improvement?
They should continue integration with all other Microsoft security-related products. The integration with all the other products is still ongoing. However, the solution has already begun scaling to meet the needs of getting visibility through from other products as well.
For how long have I used the solution?
About three years.
What do I think about the stability of the solution?
The stability has been fantastic. I have no complaints at all. It has been 100%.
What do I think about the scalability of the solution?
The scalability is really good. It has improved while I have been using it. It definitely appears to be able to scale easily and well.
How are customer service and technical support?
The technical support is very good. They are responsive, knowledgeable, and skilled. We have great communication with them.
Which solution did I use previously and why did I switch?
This is the only CASB product that I have ever used.
How was the initial setup?
Anecdotally, I believe the initial setup is quite straightforward.
What about the implementation team?
According to the person who originally set up the solution in our organization, but has since left, it was originally straightforward to set up.
My colleague and I share the day-to-day maintenance for one person. It needs only a few hours a day to get a lot out of it.
What was our ROI?
We have seen ROI. Its main capabilities are:
- The protection that it gives.
- Visibility
- The protection for cloud products.
- It helps with the improvement of our overall security posture.
What other advice do I have?
Make full use of all the options available and focus a lot on policies. There are a lot of policies and alerts available which might not be used to their fullest extent.
We are pretty happy with how it all works and fits together.
I would rate this solution as a solid nine (out of 10). The product is constantly improving. It has a low amount of false positives, i.e., true alerts identified as requiring attention.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
Microsoft Defender for Cloud Apps
May 2025

Learn what your peers think about Microsoft Defender for Cloud Apps. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
857,028 professionals have used our research since 2012.
Cloud Security Architect at a tech services company with 501-1,000 employees
Easy to use, scales well, and is good for our clients who are transitioning to the cloud
Pros and Cons
- "It is very easy to use, which is what we look for in these types of solutions."
- "This service would be better if it had a separate license, only for this service, that could be used to track usage."
What is our primary use case?
We are a consulting firm and we configure this service for our clients.
Our clients use it for Shadow IT systems and processes. It is used specifically for cloud services, such as services that reside in Microsoft Azure.
What is most valuable?
It is very easy to use, which is what we look for in these types of solutions.
What needs improvement?
This service would be better if it had a separate license, only for this service, that could be used to track usage.
For how long have I used the solution?
We have been using Microsoft Cloud App Security for the past month.
What do I think about the stability of the solution?
This is a stable product.
What do I think about the scalability of the solution?
This solution is scalable. You simply buy licenses and access the platform.
Currently, we have five people in the company who are using it. With new clients using our service and other clients moving to the cloud, I want to have a security broker in place so I expect to increase our usage.
How are customer service and technical support?
I have not contacted technical support yet.
How was the initial setup?
As a cloud-based service, there is no installation.
What's my experience with pricing, setup cost, and licensing?
Our clients normally use the Microsoft E1 licensing, which is renewed yearly. It gives them access to many Microsoft services, and one of them is Microsoft Cloud App Security.
Which other solutions did I evaluate?
We are currently evaluating other products such as Netskope, to see what it can offer us. We primarily want to see if it is easier for our clients to use. It seems that the integration with the cloud service is much more difficult.
Licensing for this product is not as expensive as Netskope.
What other advice do I have?
This is a pretty good service and I definitely recommend it if you are using Microsoft Azure or Microsoft services.
I would rate this solution an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Sr. Technical Engineer/ Sr. Executive at PSR
Enables us to protect our organisation's data and has good support
Pros and Cons
- "All of the features are valuable because all of the features are related."
- "I would like for it to be available on Mac and for it to support all of the features of Microsoft financing products. It is really for Windows."
What is our primary use case?
We use it to protect our organization's data. It has the ability to create and can copy-paste for the end-user. You can take a screenshot from your mobile devices and download some confidential things. After creating the policy you can be assured that a user's data is being protected
We give devices access within a particular device that the user is accessing. We are also certain that there is no chance of scamming or that an email account can be hacked.
We also create a password policy. Whenever the end-user wants to download anything or wants to access anything there has to be some security. It secures the customer's data in their organization.
What is most valuable?
All of the features are valuable because all of the features are related.
What needs improvement?
I would like for it to be available on Mac and for it to support all of the features of Microsoft financing products. It is really for Windows.
For how long have I used the solution?
I have been using Microsoft Cloud App Security for the last three years.
What do I think about the stability of the solution?
The stability is good.
What do I think about the scalability of the solution?
It is very easy to expand it and it is also very easy to manage because it has a centralized dashboard. You can see all of our teams and activate the software. Any person can export a report. It's very easy to access for me.
Our clients are enterprise-size.
How are customer service and technical support?
Support is very good. If we have any problems, Microsoft will drop us an email and suggest that the server cannot be accessed due to some maintenance.
How was the initial setup?
The initial setup is straightforward. You only need to set up the policies. The devices need to be compliant and particular applications have to be protected.
It generally requires two staff members to deploy but it depends on the management. It depends if the IT staff or the customers understand the process. The only difficult part is pairing it to a mobile device. To my understanding, it's the only part that the IT staff has to handle.
Setting up the policy is easy and then it's easy to replicate the policy. It takes maximum two hours.
What's my experience with pricing, setup cost, and licensing?
Customers are looking to protect their data and to protect their organization's files. For this, we offer them a package but the price is very high. This particular product, the Indian product, is running very well in the US and UK.
What other advice do I have?
It is certainly a good product. It is important to get a cloud-based product so that if you want to manage it remotely, you can work on a PC that is ready for that mission then.
I would rate it an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Director Global Strategic Alliances at Larsen & Toubro Infotech Ltd.
A stable solution that integrates seamlessly across different clouds
Pros and Cons
- "The most valuable feature is the seamless integration across different clouds."
- "The interface needs to be more user-friendly."
What is our primary use case?
We are a solution provider and this is one of the products that we implement for our customers.
Our customers have applications that are running across different clouds or on different platforms. Microsoft Cloud App Security brings them together onto the same platform from a security standpoint. The application can run seamlessly across different clouds, which helps.
What is most valuable?
The most valuable feature is the seamless integration across different clouds.
What needs improvement?
If this solution were more robust then it would be much more useful.
The interface needs to be more user-friendly.
Cloud App Security should be more lightweight.
For how long have I used the solution?
We have been working with Microsoft Cloud App Security for almost eight years.
What do I think about the stability of the solution?
I have not seen any trouble in terms of stability. We have not experienced bugs to this point in time.
What do I think about the scalability of the solution?
We have had no problem with scalability.
How are customer service and technical support?
I have not personally been in contact with technical support. The feedback that I have heard from the teams is more or less good.
Which solution did I use previously and why did I switch?
I have experience with Netskope and I think that it has higher marks. It is more lightweight.
How was the initial setup?
The initial setup is straightforward and absolutely fine.
What's my experience with pricing, setup cost, and licensing?
This product is not expensive.
What other advice do I have?
This is a product that I recommend.
Overall, it is a good product but the robustness should be improved.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Hybrid active directory that is easy to manage, but integration with Apple products is needed
Pros and Cons
- "The most valuable feature is the ease of management. It's important."
- "Generally, the pricing can always be improved along with the management system."
What is our primary use case?
We have an educational institution and we are using this solution to personally teach our students these applications.
What is most valuable?
The most valuable feature is the ease of management. It's important. The management is cloud-based and we can work inside or outside on public networks.
What needs improvement?
Generally, the pricing can always be improved along with the management system.
We are using new Apple products increasingly in our company, such as iPads and Mac computers. The integration with Apple products would be good. They have started with some implementation using Microsoft Softbox from Apple products in there.
For how long have I used the solution?
I have been using this solution for two years.
We are using the Microsoft 365 Version. It is a hybrid Azure Active Directory.
They have an in-tune modified in this platform that we are using.
What do I think about the scalability of the solution?
We have plans to increase our usage.
We have 1000 students at the moment, but not all of them are using this solution right now. In total, we have between 300 and 500 users.
What's my experience with pricing, setup cost, and licensing?
We have an educational licensing agreement. It's a customer agreement for multiple years.
What other advice do I have?
We have experience with Microsoft products, Windows Server Data Centers, Microsoft Office 365, and they have a new branch called M365 products, Cloud systems, and Branch Management systems.
We are working on implementing the MDM system and we are looking for alternatives.
We are using an Apple-based system as well as Microsoft.
Generally, there is always room for improvement. It can always be better.
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cloud Services Director at a tech services company with 11-50 employees
Useful IT shadow prevention, scalable, and good support
Pros and Cons
- "The most valuable feature of Microsoft Defender for Cloud Apps is to stop shadow IT."
- "Microsoft Defender for Cloud Apps' initial setup was quite technical but we were prepared. The time of the implementation depends on the job and how many users are being set up."
What is our primary use case?
We are using Microsoft Defender for Cloud Apps for different purposes and one of them is for ensuring there is no shadow IT.
What is most valuable?
The most valuable feature of Microsoft Defender for Cloud Apps is to stop shadow IT.
For how long have I used the solution?
I have been using Microsoft Defender for Cloud Apps for approximately three years
What do I think about the stability of the solution?
Microsoft Defender for Cloud Apps is a stable solution.
What do I think about the scalability of the solution?
The scalability of Microsoft Defender for Cloud Apps is good.
We plan to increase the usage of the solution.
How are customer service and support?
I found the support to be satisfying.
How was the initial setup?
Microsoft Defender for Cloud Apps' initial setup was quite technical but we were prepared. The time of the implementation depends on the job and how many users are being set up.
What about the implementation team?
We did the implementation of the solution. We used two engineers and one project manager for the deployment and maintenance.
What's my experience with pricing, setup cost, and licensing?
We are an MST and we do not pay for the solution. However, the price of the solution could be better.
What other advice do I have?
I would recommend this solution to others.
I rate Microsoft Defender for Cloud Apps a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Microsoft Defender for Cloud Apps Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2025
Product Categories
Cloud Access Security Brokers (CASB) Advanced Threat Protection (ATP) Microsoft Security SuitePopular Comparisons
Microsoft Intune
Microsoft Defender for Endpoint
Microsoft Defender for Office 365
Microsoft Sentinel
Microsoft Entra ID
Microsoft Defender for Cloud
Cisco Umbrella
Microsoft Defender XDR
Prisma Access by Palo Alto Networks
Microsoft Purview Data Governance
Zscaler Zero Trust Exchange Platform
Azure Firewall
Azure Front Door
Buyer's Guide
Download our free Microsoft Defender for Cloud Apps Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which is the better security solution - Cisco Umbrella or Microsoft Cloud App Security?
- Evaluating CASBs. Looking for community feedback on some vendors.
- What are your best practices for Identity and Access Management (IAM) in the Cloud?
- CloudLock vs. Skyhigh
- Why do organizations need CASB?
- When evaluating Cloud Security, what aspect do you think is the most important to look for?
- What is Unified Cloud Security? Can you define the scope and use cases of the term?
- Adallom vs. Cloudlock
- What is the difference between SASE and CASB?
- What are your recommended best practices and tools to prevent cloud jacking in your organization?
An honest review with utmost sincerity