Microsoft 365 Integration
This guide walks you through enabling Microsoft 365 API access in ThreatDefence SIEM.
Requirements:
Access to Microsoft 365 services (Microsoft 365 Compliance Center, Azure Active Directory)
Any O365 licensing tier is supported.
Step 1: Enable Auditing in Microsoft 365
To enable auditing, follow standard procedures to turn auditing on or off.
Step 2: Register an Application in Entra ID
Download ThreatDefence's EntraID Integration Certificate: Download Certificate
Sign in to the Entra ID portal.
Navigate to Microsoft Entra ID.
Select App registrations and click New registration.
Fill in the required information and click Register.
Make note of the Application (client) ID and Directory (tenant) ID for later use.
Navigate to Certificates & secrets.
Click Upload Certificate.
Upload the certificate downloaded in step 1 and press Add.
Step 3: Grant API Permissions
After creating the application ID and secret, grant permissions to access the Office 365 Management APIs.
Navigate to API permissions and select Office 365 Management APIs.
Select Application permissions and enable the following:
ActivityFeed.Read
ActivityFeed.ReadDlp
Click Grant admin consent and confirm.
Step 4: Configure ThreatDefence SIEM
Log in to the ThreatDefence SIEM Portal.
Go to Deployments > Integrations.
Click Add and select Microsoft 365.
Step 5: Add Microsoft Graph Integration
For advanced security auditing, Defender event ingestion, and user isolation features, complete the Microsoft Graph API Integration.
Last updated