Microsoft Cloud App Security is a Cloud Access Security Broker (CASB) that operates on multiple clouds. It provides rich visibility, control over data travel, and sophisticated analytical insight to identify and combat threats across all your cloud services.
Deploy a Microsoft-provided Java program into the environment that will pull logs from Microsoft CASB using a "Generic SIEM Integration". See Microsoft documentation here.
The Java program will push the logs to the CYDERES API via the CYCLOPS forwarder running in the environment. See CYCLOPS installation instructions found here.
CYDRERES will provide a port number.
Create firewall rules to allow HTTPS traffic to and from the Microsoft CASB to the server hosting the Java program.
Create a Microsoft CASB API token and provide to CYDERES. See Microsoft documentation here.
CYDERES will deploy a cloud-based collector and provide the connection information.
Configure Microsoft CASB to push logs to the CYDERES collector.