Managing cloud apps with policies
Now that you’ve mastered how to discover and govern shadow IT, we’ll dive into managing cloud apps. MDA offers us two ways to do this, as depicted in the following figure:
Figure 16.19 – Difference between MDA app control methods
Connected apps is the first method. This feature is for a list of supported cloud apps and integrates them with MDA directly using APIs. This is the highest level of integration with MDA as its CASB capabilities can directly communicate with and control the cloud app to the furthest extent the provider’s APIs allow. This list, and the extent of your control, are managed by Microsoft. For example, you could connect Dropbox to govern files saved in it. An advantage of this method is that you achieve deep integration with the cloud app.
Conditional Access App Control is the second method. This is a reverse proxy capability that’s integrated with your identity...