News

Microsoft Adds Auto-Remediation to SaaS Security Tool

Microsoft this week announced the addition of an auto-remediation capability to its Cloud App Security service, enabling administrators to compel user log-ins and invalidate user sessions in response to certain kinds of security threats.

The Cloud App Security service, which launched commercially last year, tracks the use of Software as a Service (SaaS) applications by end users in an organization. It ranks SaaS applications so that IT departments can better assess their risks.

The service is based on Adallom technology that Microsoft acquired when it bought that company about two years ago.

The Cloud App Security service will detect things like the sharing or downloading of sensitive files from atypical locations, which will send an alert to the management portal. With the auto-remediation feature addition, it's now possible for IT pros to specify certain actions to take when such threats are detected.

For instance, IT pros can set the service to revoke "all user sessions." Next, they can require end users to log back into their Office 365 or Azure Active Directory accounts.

The auto-remediation feature also permits IT pros to revoke the sessions associated with a compromised account by "invalidating all the user's refresh tokens." The security practice of simply disabling an account in such cases isn't sufficient to ward off attackers, Microsoft's announcement contended.

To use the Cloud App Security service, organizations need an Office 365 subscription plan that has support for the Azure Rights Management service, namely the E3, E4 and E5 plans, as well as corresponding Education and Government plans. For a list of Office 365 plans with Azure Rights Management support, see this Microsoft .PDF.

About the Author

Kurt Mackie is senior news producer for 1105 Media's Converge360 group.

Featured

  • Hands-On AI Skills Now Outshine Certs in Salary Stakes

    For AI-related roles, employers are prioritizing verifiable, hands-on abilities over framed certificates -- and they're paying a premium for it.

  • Roadblocks in Enterprise AI: Data and Skills Shortfalls Could Cost Millions

    Businesses risk losing up to $87 million a year if they fail to catch up with AI innovation, according to the Couchbase FY 2026 CIO AI Survey released this month.

  • Microsoft Cuts Windows 11 Recovery Time with New Update

    Microsoft has introduced two key enhancements to Windows 11 aimed at minimizing downtime and streamlining error resolution.

  • Microsoft Offers Support Extensions for Exchange 2016 and 2019

    Microsoft has introduced a paid Extended Security Update (ESU) program for on-premises Exchange Server 2016 and 2019, offering a crucial safety cushion as both versions near their Oct. 14, 2025 end-of-support date.