Skip to main content
Microsoft Defender for Cloud Apps integrates with Inviolet in the two directions described in the network enforcement overview: observe (read the vendor’s egress logs into Inviolet) and enforce (block direct LLM access).

Observe (CASB) — available today

Inviolet’s casb-mcas connector pulls Microsoft Defender for Cloud Apps egress events and ingests the ones bound for LLM providers, so bypass volume and attribution show up in the Shadow IT analytics view. Set it up: Inviolet → Settings → Data Sources → Admin Connectors → New → Microsoft Defender for Cloud Apps, then paste your credentials. Credentials: MDCA — an Entra app (client-credentials) with CloudApp.Read.All admin-consented + your MDCA tenant host.

Enforce (SWG) — on request

Network enforcement packs for Microsoft Defender for Cloud Apps (block direct LLM API + consumer UIs, forcing traffic through Inviolet) are delivered per engagement. Unlike Cloudflare — which matches at the DNS layer natively — Microsoft Defender for Cloud Apps enforcement is scoped to your tenant’s capabilities. Contact us to scope a deployment.
Cloudflare is the reference vendor, validated end to end (enforcement + observability). See the Cloudflare guide for the full pattern; the same shape applies here once your enforcement pack is built.