Microsoft is promoting Cloud App Discovery as the answer to shadow AI, the unapproved AI tools staff bring to work themselves, and presenting it as a reason to move to Microsoft 365 E3. The discovery tool is genuinely useful, but the licensing line is misleading for small businesses. Microsoft's own documentation confirms Cloud App Discovery is included at no extra cost with Microsoft Entra ID P1, and that Entra ID P1 is included in Microsoft 365 Business Premium. So a business already on Business Premium has the same discovery capability and the same catalogue of more than 31,000 cloud apps without upgrading. This guide covers what Cloud App Discovery shows you, the feature gap against full Defender for Cloud Apps (no anomaly detection on discovered apps, no data loss prevention, no OAuth app revocation, no policy enforcement), and the practical catch that discovery runs on firewall or proxy log uploads while the native Defender for Endpoint feed requires a paid Defender for Cloud Apps licence. Written for Australian businesses with 5 to 50 staff.
Shadow AI at work: you probably already own the tool that finds it
Your team is using AI tools you never approved. Microsoft has a way to show you which ones, and is presenting it as a reason to upgrade to E3. If you are on Business Premium, you already have it.
The short version
Staff are bringing their own AI tools to work. Microsoft's research puts it at more than 70 percent of the knowledge workers who use AI at work, and that data is from 2024. It has not gone down since.
Cloud App Discovery is not an E3 feature. It comes with Microsoft Entra ID P1, and Entra ID P1 is in Business Premium. Check your licence list before you accept a quote for an upgrade.
Discovery shows you, it does not stop anything. Blocking, data loss prevention and OAuth app control sit in the paid Defender for Cloud Apps product. Know which problem you are solving.
Why this is happening in your business too
Microsoft's Work Trend Index found that 80 percent of the knowledge workers it surveyed said they lack the time or energy to do their work. That is 31,000 people across 31 countries, asked in early 2025.
The year before, the same research found that more than 70 percent of the people using AI at work were bringing their own AI tools with them. Not tools the business chose. Tools they found, signed up for and started pasting work into.
Put those two together and you have the whole story. Nobody is being reckless. They are behind, a free tool does in four minutes what used to take forty, and the approval process either does not exist or takes three weeks. Of course they use it.
The part that should worry you is not the tool. It is what goes into it.
A marketing coordinator uploads the brand guidelines and an unreleased campaign. A bookkeeper drops a debtors report into a free analysis tool to get a chart out of it. Someone in operations pastes a client contract in and asks for a plain English summary. None of that feels like a security incident while it is happening. It feels like getting the job done.
Meanwhile more than half the C-suite and IT people in a separate 2023 survey said they were worried about exactly this and had no visibility into it. Worried, and blind. That combination is what the tooling is meant to fix.
The E3 line, and what it leaves out
The Microsoft material doing the rounds at the moment says Cloud App Discovery is included in Microsoft 365 E3, and frames E3 as the way to get a handle on shadow IT. That statement is true. It is also incomplete in a way that matters if you run a business with 5 to 50 staff.
Cloud App Discovery is not really an E3 feature. It is an Entra ID P1 feature.
Microsoft's documentation puts it plainly: Cloud App Discovery comes at no additional cost as part of Microsoft Entra ID P1, Enterprise Mobility + Security E3, and Microsoft 365 E3. E3 is one of three ways in, not the only one.
And on a separate page, the Entra licensing documentation says Entra ID P1 is included in Microsoft 365 Business Premium.
Follow those two sentences and you land somewhere useful. If your business is on Business Premium, which most Perth businesses in this size range are, you already have Cloud App Discovery. Same tool. Same catalogue of more than 31,000 cloud apps. Same risk scoring. You do not need to move to E3 to get it, and for an SMB that move is rarely the right one for other reasons anyway.
We are not accusing anyone of lying. Enterprise marketing material is written for enterprises, and in an enterprise E3 genuinely is the shape of the answer. But that flyer gets forwarded to small business owners, and it reads as a reason to upgrade. Before it becomes a quote, open your licence list.
If you want the fuller picture of what Business Premium already includes, we have written that up separately in our Business Premium deep dive and the Microsoft Entra ID guide.
What Cloud App Discovery will not do
Here is the other half of the honesty, and it cuts the other way. Cloud App Discovery is the free-with-your-licence subset of a paid product called Microsoft Defender for Cloud Apps. The discovery part is identical. Almost everything you would do after discovering something is not included.
You get the seeing. You do not get the doing.
What is in both: the catalogue of more than 31,000 apps, the risk assessment of each one, usage analytics by app, user and IP address, ongoing reporting, custom policy creation, and log anonymisation so you can run this without turning it into staff surveillance.
What only comes with the paid product: anomaly detection on the apps you discover, data loss prevention across SaaS, the ability to see and revoke OAuth app permissions, policy enforcement, integration with Microsoft Purview, behavioural analytics, alert remediation and a SIEM connector.
So discovery answers the question "what is being used". It does not answer "and now stop it".
For a lot of small businesses that is genuinely fine, because the honest first step is not blocking anything. It is finding out. Nine times out of ten the fix is a conversation and two approved tools, not a technical control.
If you decide you do want the control layer, the sensible path for a Business Premium tenant is the Microsoft Defender Suite for Business Premium add-on, which includes full Defender for Cloud Apps along with Entra ID P2, Defender for Identity and the Plan 2 versions of Defender for Endpoint and Defender for Office 365. That add-on replaced the old Microsoft 365 E5 Security add-on in September 2025. It is a real cost per user, so weigh it against what discovery actually turns up rather than buying it first. Purview is the other piece of that puzzle, and we cover it in the Microsoft Purview deep dive.
Getting the data in is the hard part
Nobody mentions this bit in the marketing, and it is the bit that decides whether your afternoon goes well.
Cloud App Discovery does not magically know what your staff are using. It reads your network traffic logs. You feed it firewall or proxy logs, either by uploading them yourself or by setting up a log collector to send them automatically, and it matches what it finds against the app catalogue.
There is a much tidier way to do this, where Defender for Endpoint reports app usage straight from the devices and no network gear is involved at all. That one requires a Defender for Cloud Apps licence. It is listed as a Defender for Cloud Apps capability, not a Cloud App Discovery one.
Which leaves a practical question worth answering before you start: can your firewall export its logs, and does your team's traffic actually go through it?
For a business with an office and a decent firewall, usually yes, and this is an hour of work. For a business where half the team works from home on their own internet and the other half is on site with a router the landlord installed, the log-based approach will show you a fraction of the picture. Pretending otherwise wastes everyone's time.
And no approach here covers personal devices on mobile data. Someone with a client list open on their own phone is outside all of this. That is not a reason to skip discovery. It is a reason not to treat the report as the finish line.
What to do now
Four moves, in this order. The first one is free and takes ten minutes.
Check what you are already paying for
Open your licence list before you open a quote. If it says Business Premium or E3, Cloud App Discovery is sitting there unused. Most businesses we look at have never opened it.
Find out if your firewall can export logs
This is the step that decides whether the next hour is easy or annoying. Most business firewalls can do it. Older gear and a fully remote team are where it gets awkward.
Look before you block
Run discovery for a few weeks and read it properly. Blocking on day one just pushes people onto their phones, where you cannot see anything at all.
Write the rule people can actually follow
Two approved AI tools and a plain sentence about what never goes into them beats a ten page policy nobody finishes reading.
On that last point, we wrote what never goes into a chatbot for exactly this. Send it to your team and you have done more for your risk position than most discovery reports will.
The takeaway
Shadow AI is real, it is in your business, and the people doing it are your good staff trying to keep up. Treat it as a discipline problem and you will lose both the visibility and the goodwill.
The tool Microsoft is pointing at is worth using. Just check whether you are already paying for it before anyone quotes you an upgrade to get it, because on Business Premium you almost certainly are.
And know what you are buying if you go further. Discovery shows you the problem. Control costs extra, and it is worth deciding that after you have seen the report rather than before.
If you would rather someone just ran this and told you what turned up, that is what our AI usage analysis is. No upgrade required to find out.
Where this comes from
This article corrects a licensing impression that a piece of Microsoft marketing leaves behind, so every claim about what is included where comes from Microsoft's own documentation. Check it yourself.
Compare discovery capabilities for Defender for Cloud Apps and Cloud App Discovery
Microsoft Learn
Confirms Cloud App Discovery is included at no extra cost with Microsoft Entra ID P1, EMS E3 and Microsoft 365 E3, and sets out the feature-by-feature gap against full Defender for Cloud Apps.
Microsoft Entra licensing
Microsoft Learn
States that Microsoft Entra ID P1 is included in Microsoft 365 Business Premium. This is the step that makes discovery available to small businesses without an E3 upgrade.
Add Microsoft Defender Suite for Business Premium to your subscription
Microsoft Learn
The add-on that brings full Defender for Cloud Apps to a Business Premium tenant, along with Entra ID P2, Defender for Identity, and the Plan 2 versions of Defender for Endpoint and Office 365.
Work Trend Index Annual Report 2025: The Year the Frontier Firm Is Born
Microsoft and LinkedIn
The source of the 80 percent figure, from survey data covering 31,000 knowledge workers across 31 countries between February and March 2025.
The 2023 figure on executive concern about unsanctioned generative AI comes from a survey of more than 400 C-suite and IT professionals conducted with CensusWide and reported via PR Newswire, cited in Microsoft's own material. Microsoft licensing changes regularly, so confirm what is in your tenant against your current subscription rather than against this page.
Common questions
Do we need Microsoft 365 E3 to find shadow AI?
No, and this is the part worth knowing before you take a quote. Cloud App Discovery is included with Microsoft Entra ID P1, and Entra ID P1 is included in Microsoft 365 Business Premium. So a business on Business Premium already has the same discovery tool and the same catalogue of more than 31,000 cloud apps that an E3 tenant has. Microsoft's own documentation says both things plainly. Moving to E3 to get discovery would be paying twice for something you have.
What is the difference between Cloud App Discovery and Defender for Cloud Apps?
Discovery tells you what is being used. Defender for Cloud Apps lets you do something about it. The discovery half is the same in both, including the app catalogue and the risk scoring. The paid product adds anomaly detection on discovered apps, data loss prevention, the ability to review and revoke OAuth app permissions, policy enforcement, Purview integration and a SIEM connector. If you want to see, discovery is enough. If you want to control, it is not.
How do we get the logs in? We do not run a proxy.
This is the practical catch. Cloud App Discovery works from firewall or proxy traffic logs, uploaded manually or automatically through a log collector. The neat option, where Defender for Endpoint feeds discovery straight from the devices with no network gear involved, needs a Defender for Cloud Apps licence. Most small businesses have a firewall that can export the logs. If yours cannot, or your team is fully remote and rarely behind it, the endpoint route is the honest answer and it costs money.
Will this see what staff do on their own phones?
Not unless the traffic crosses a network you control or a device you manage. Someone pasting a client list into a chatbot on their personal phone over mobile data is invisible to this and to every other tool of its kind. That is worth saying out loud, because it is the reason discovery is a starting point rather than an answer. What you do with what you find matters more than the finding.
Should we just block AI tools instead?
We would not, and we say that as the people who would get paid to set up the blocking. Staff reach for these tools because the work is not fitting in the day. Block everything and the work still does not fit, so it moves to a phone you cannot see. Give people two tools you have checked, say clearly what must never go in, and you keep both the productivity and the visibility.