4.4. Microsoft Defender for Cloud Apps
💡 First Principle: You can't govern the SaaS you can't see, and you can't see it from the identity plane alone — users reach apps that never touched your tenant. Defender for Cloud Apps adds the traffic and API vantage: discover what's actually used, sanction or ban it, connect the sanctioned apps for deep control, and police live sessions in between.
Think of it as the x-ray layer over everything Phase 4 built: enterprise apps you know about get session policing and API-level governance; the long tail you didn't know about gets discovered from network logs and endpoint signal. For the exam, MDCA questions cluster around four verbs — discover, sanction, connect, police — one per subsection pattern below.
⚠️ Common Misconception: MDCA session controls stand alone. The reverse-proxy session policies work only when Conditional Access routes the session into MDCA (the Use Conditional Access App Control session control, 2.2.2) — author policies in MDCA, but the traffic arrives via CA. No CA integration, no session policing.