---
name: Cloud App Risk Catalogue Review
description: Review Microsoft Defender for Cloud Apps catalogue risk scores and sanctioned or unsanctioned tagging for the apps in use.
---

# Cloud App Risk Catalogue Review

> **TL;DR:** Inspect the Microsoft Defender for Cloud Apps catalogue to confirm each in-use app has an acceptable risk score and the correct sanctioned or unsanctioned tag, without changing anything.

## Reviewing the Microsoft Defender for Cloud Apps catalogue

Microsoft Defender for Cloud Apps maintains a Cloud App Catalog of over 31,000 discoverable apps, each scored against more than 90 risk factors covering general, security, compliance, and legal categories. As part of Microsoft Defender XDR, it surfaces Shadow IT discovered from your traffic and lets administrators tag apps as sanctioned or unsanctioned. This skill reviews those catalogue scores and tags so they align with your organisation's security requirements and the Essential Eight.

## When should you run this skill?

- "Are the cloud apps our staff use rated as low risk in Defender for Cloud Apps?"
- "Which discovered apps are still untagged or marked unsanctioned?"
- "Show me apps with a risk score of 6 or lower that are in active use."
- "Do our sanctioned apps meet SOC 2 and ISO 27001 compliance?"
- "Has anything risky appeared in Shadow IT since our last review?"
- "Which apps lack data-at-rest encryption or multifactor authentication?"
- "Confirm our business-ready apps are tagged sanctioned and the rest are flagged."

## How this skill works, step by step

1. Sign into Microsoft Defender XDR and open **Cloud apps** then **Cloud app catalog**.
2. Cross-reference the catalogue against the **Discovered apps** list so the review covers apps genuinely in use.
3. For each app, read the total risk score, a weighted average of the general, security, compliance, and legal subscores.
4. Inspect how the score is derived: each property is scored 0 to 10 (true or false values map to 10 or 0; continuous values such as domain age fall along a range), then weighted within its category.
5. Apply advanced filters for **Compliance risk factor** (for example SOC 2, ISO 27001), **Security risk factor** (encryption at rest, multifactor authentication, audit trails), and **Risk score** thresholds.
6. Check the **App tags** filter for **Sanctioned**, **Unsanctioned**, and any custom tags to identify untagged or mis-tagged apps.
7. Drill into individual apps and hover the information markers to understand the weighting behind each risk factor.
8. Note any score overrides or custom score-metric weightings already in place, recording the business justification.
9. Record findings, including apps that warrant a score-update request to the Defender for Cloud Apps analysis team.

## Output format

The review produces a table of in-use apps with their catalogue risk score, key compliance and security factors, and current app tag.

| App | Risk score | SOC 2 | Data-at-rest encryption | App tag |
| --- | --- | --- | --- | --- |
| Microsoft 365 | 10 | Yes | Supported | Sanctioned |
| Example File Share | 4 | No | Not supported | Unsanctioned |

A short summary follows the table:

- Total in-use apps reviewed and how many sit below your acceptable risk threshold.
- Count of apps tagged sanctioned, unsanctioned, and untagged.
- Apps failing key compliance or security factors that need remediation or a score-update request.

## Licensing and permissions

### Licences and add-ons

| Capability used | Minimum licence |
| --- | --- |
| Cloud App Catalog and risk scoring | Microsoft Defender for Cloud Apps (standalone or via Microsoft 365 E5 / E5 Security) |
| Cloud Discovery of in-use apps | Microsoft Defender for Cloud Apps |

### Least-privilege roles

- Global Reader (read-only visibility across the Microsoft Defender portal)
- Security Reader (read-only access to Cloud Apps and Cloud Discovery data)

### Microsoft Graph permissions (read-only)

- This skill is administered through the Microsoft Defender portal (Microsoft Defender XDR), not Microsoft Graph. Reviewing catalogue risk scores and app tags is performed in **Cloud apps** then **Cloud app catalog** and the **Discovered apps** pages, so no Microsoft Graph scopes apply.

## Scope and safety

This skill is read-only by default. It inspects catalogue risk scores, risk factors, and existing sanctioned or unsanctioned tags to report on alignment with your security requirements.

This skill does NOT:

- Change, override, or recalculate any app risk score or score-metric weighting.
- Apply, remove, or modify sanctioned or unsanctioned app tags.
- Generate or import block scripts, or block any app via Defender for Endpoint.
- Submit score-update or new-app requests to the Microsoft analysis team.

## Sources and compliance

- [Find your cloud app and calculate risk scores](https://learn.microsoft.com/en-us/defender-cloud-apps/risk-score)
- [Govern discovered apps](https://learn.microsoft.com/en-us/defender-cloud-apps/governance-discovery)
- Supports Essential Eight mitigation of risky and unsanctioned applications, complementing application control by surfacing apps for review before tagging or blocking.
- Aligns with ISM guidance on managing the use of cloud services and unapproved applications.
- [ASD Essential Eight Maturity Model](https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/essential-eight/essential-eight-maturity-model)
- Output in Australian English.
