Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Egnyte is a cloud platform for file sharing and data governance. Cloud tools like Egnyte help teams work together, but they can also expose critical assets to threats. You need to monitor Egnyte so that bad actors or careless insiders can't leak sensitive data.
Connecting Egnyte to Defender for Cloud Apps gives you improved insights into your users' activities and provides threat detection for anomalous behavior.
Main threats
Using Egnyte without Defender for Cloud Apps exposes your organization to the following threats:
Compromised accounts and insider threats
Insufficient security awareness
Unmanaged bring your own device (BYOD)
How Defender for Cloud Apps helps to protect your environment
Defender for Cloud Apps helps protect your Egnyte environment in the following ways:
Detect cloud threats, compromised accounts, and malicious insiders
Use the audit trail of activities for forensic investigations
Control Egnyte with policies
The following table lists the policy types you can use to monitor and control Egnyte activities:
| Type | Name |
|---|---|
| Built-in anomaly detection policy | Activity from anonymous IP addresses Activity from infrequent countries/regions Activity from suspicious IP addresses Impossible travel Activity performed by terminated user (requires Microsoft Entra ID as IdP) Multiple failed login attempts |
| Activity policy | Build a customized policy by the Egnyte activities |
For more information about creating policies, see Create a policy.
Automate governance controls
You can also automate Egnyte governance actions to respond to detected threats:
| Type | Action |
|---|---|
| User governance | Notify user on alert (via Microsoft Entra ID) Require user to sign in again (via Microsoft Entra ID) Suspend user (via Microsoft Entra ID) |
For more information about remediating threats from apps, see Governing connected apps.
Protect Egnyte in real time
Review our best practices for securing and collaborating with external users and blocking and protecting the download of sensitive data to unmanaged or risky devices.
Connect Egnyte to Microsoft Defender for Cloud Apps
Use the App Connector APIs to connect Microsoft Defender for Cloud Apps to your existing Egnyte environment. The resulting connection gives you visibility into and control over your organization's use of Egnyte.
Prerequisites
Make sure you meet the following requirements before you connect Egnyte to Defender for Cloud Apps:
The authorizing user must be one of the following:
- Power user with can run reports role
- Administrator
Audit reporting must be available in Egnyte's plan
To connect Egnyte to Microsoft Defender for Cloud Apps:
In the Microsoft Defender Portal, select Settings. Then choose Cloud Apps. Under Connected apps, select App Connectors.
In the App connectors page, select +Connect an app, and then select Egnyte.
In the window that appears, give the connector a descriptive name, and then select Next.
In the Enter details page, in Application URL, insert your Egnyte URL by using the following format:
https://<domain_name>.egnyte.comSelect Next.
Select Connect Egnyte.
In the redirected page, select Allow.
In the Microsoft Defender Portal, select Settings. Then choose Cloud Apps. Under Connected apps, select App Connectors. Make sure the status of the connected App Connector is Connected.
Note
Microsoft recommends using a short lived access token. Egnyte doesn't currently support short lived tokens. We recommend refreshing your access token every 6 months as a security best practice. To refresh the access token, revoke the old token. For more information, see Revoking an oAuth token. Once the old token is revoked, reconnect the Egnyte connector.
Microsoft Defender for Cloud Apps intentionally provides a lower rate limit than Egnyte's maximum to avoid exceeding the API constraints. For more information, see the relevant Egnyte documentation Rate limiting and Audit Reporting API v2.