Cloud adoption—accelerated by the coronavirus pandemic—has made most organizations dependent on cloud services for business-critical applications, creating a hybrid IT delivery environment with significant management, security, and compliance challenges. These problems persist because cloud services are often poorly integrated into established IT security processes, while employees and business units frequently procure or use personal and unsanctioned cloud services without risk assessments. Expanding privacy and data regulations such as GDPR and CCPA intensify pressure, and the accessibility of cloud platforms increases exposure to data theft, corruption, and malware placement.
Cloud Access Security Brokers (CASBs) help by improving visibility and controlling user access to cloud services, but the text argues modern cloud risk requires more than a standalone CASB. Current expectations include deep integration with endpoint and network controls (anti-malware, DLP, secure web gateways) and capabilities for Cloud Security Posture Management (CSPM) to detect and remediate misconfigurations—especially as IaaS use grows for modernized applications. The market trend described is a shift from standalone CASBs toward comprehensive cloud security solutions combining CASB, CSPM, data and user protection, SWG, and zero trust network controls, with future expansion to hybrid delivery, edge computing, and 5G.
The report focuses on Microsoft Cloud App Security (MCAS), derived from Adallom (acquired in 2015) and integrated into Microsoft Enterprise Mobility + Security. MCAS provides shadow IT discovery, app risk scoring, policy-based controls, reverse-proxy conditional access, API connectors to major SaaS and cloud platforms, data classification and labeling, behavioral analytics, ransomware templates, SIEM integrations, and compliance reporting. Strengths include broad integration, threat intelligence, conditional access across apps, and simplified licensing. Challenges include limited protection for structured SaaS data (no encryption/tokenization), reliance on additional Microsoft tools for full value, weaker fit in non-Microsoft environments, and a need to broaden posture management across more IaaS resources.
See All Locations
See All Locations