Views:

View information about the Cloud app activity risk factor, which is determined by user and endpoint access to suspicious cloud locations.

Operations Dashboard assesses user accounts and endpoints for any cloud activity to potentially risky cloud apps. If the assessment of cloud app access indicates a risk, the cloud app access information displays in the Top 5 High Risk Cloud Apps with the Most Visits and the High Risk Cloud App Visits widgets. The Cloud App Activity risk factor contributes to the Exposure Index.
When viewing risk events, click the number in the case column to view current cases involving the specified risk event. Click the options icon (options=ddb0b67f-0654-4aa5-8bc7-48ec554c5448.png) to open a new case for the risk event or add the case to an existing risk event.
Note
Note
For customers that have updated to the Foundation Services release, information on the Cloud App Activity risk factor is only available for users with the Applications asset visibility scope.
The following table describes the risk indicators associated with the Cloud app activity risk factor.
Indicator
Description
Data Sources
Target
Cloud app reputation
Calculated by Trend Micro threat experts based on historical app data, known security features, and community knowledge
  • Endpoint Sensor
  • Trend Micro Apex One as a Service
  • Trend Micro Deep Security
  • Trend Micro Web Security
  • Trend Micro Mobile Security
  • Microsoft Entra ID
  • Okta
  • Splunk - Network Firewall / Web Gateway Logs
  • Cloud app