Your organization is planning to deploy Microsoft Defender for Cloud Apps to discover shadow IT. You need to ensure that logs from your network proxy servers are ingested. Which method should you use to connect the logs?
For Microsoft Defender for Cloud Apps to perform Shadow IT discovery, it requires network traffic logs from an organization's firewalls and proxies. A log collector is a lightweight agent deployed on-premises, typically on a dedicated server, that securely ingests these logs, parses them, and then forwards them to Defender for Cloud Apps. This process enables the service to analyze user activity, identify sanctioned and unsanctioned cloud applications, and assess their risk.
Why this answer
Microsoft Defender for Cloud Apps uses log collectors to ingest traffic logs from network proxy servers for shadow IT discovery. The log collector is a dedicated component that parses and uploads proxy logs (e.g., from Squid, Blue Coat, or Zscaler) to Defender for Cloud Apps for analysis. This method is specifically designed for log-based discovery of unsanctioned cloud app usage.
Exam trap
A common mistake on the SC-900 exam is confusing the App connector API (which connects to sanctioned cloud apps via their APIs for activity monitoring) with the Log collector (which ingests proxy logs for shadow IT discovery). Remember: Log collector is for log-based discovery of unsanctioned apps; App connector is for API-based monitoring of already-sanctioned apps.
How to eliminate wrong answers
Option B is wrong because Conditional Access App Control is a session-level policy enforcement feature that controls access to cloud apps in real time, not a method for ingesting proxy logs. Option C is wrong because the Microsoft Sentinel data connector is used to bring Defender for Cloud Apps alerts into Sentinel for SIEM correlation, not to ingest raw proxy logs for shadow IT discovery. Option D is wrong because the App connector API connects directly to cloud app APIs (e.g., Office 365, Salesforce) to pull activity logs, not to ingest network proxy traffic logs.