> For the complete documentation index, see [llms.txt](https://docs.threatdefence.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.threatdefence.com/getting-started/frequently-asked-questions/microsoft-365-monitoring.md).

# Microsoft 365 Monitoring

## What level of Microsoft 365 (MS365) license do I need to integrate into your platform?

Any MS365 licensing tier is supported - we do not require you to have Premium E5 or P1/P2 licenses from Microsoft. Our platform will automatically adjust and extract the available security events information based on your licensing tier.

## For how long do you keep our MS365 data?

We retain MS365 data for three months.

## What MS365 applications are supported?

We monitor user activity across all MS365 applications, including Entra ID, Exchange Online, SharePoint, OneDrive, and MS Teams.

## ​​How long does it take for my Microsoft logs to appear on your platform?

The logs will start loading onto the dashboards within 30-60 minutes after the integration has been added.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.threatdefence.com/getting-started/frequently-asked-questions/microsoft-365-monitoring.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
