Alerts related to data source "Office 365 Audit".
A Microsoft Teams application was installed
A Microsoft Teams bot was added to a team
A user uploaded malware to SharePoint or OneDrive
Azure Privilege Escalation Using an Application
DLP sensitive data exposed to external users
Exchange anti-phish policy disabled or removed
Exchange audit log disabled
Exchange compliance search created
Exchange DKIM signing configuration disabled
Exchange email-hiding inbox rule
Exchange email-hiding transport rule
Exchange inbox forwarding rule configured
Exchange mailbox audit bypass
Exchange mailbox delegation permissions added
Exchange mailbox folder permission modification
Exchange malware filter policy removed
Exchange Safe Attachment policy disabled or removed
Exchange Safe Link policy disabled or removed
Exchange transport forwarding rule configured
Exchange user mailbox forwarding
External SaaS file-sharing activity
External user added a link to a Microsoft Teams chat
External user call via Microsoft Teams
External user created a Microsoft Teams conversation with suspicious operations
External user started a Microsoft Teams conversation
Massive file downloads from SaaS service
Massive files deletion in Microsoft SharePoint or OneDrive
Massive upload to SaaS service
Microsoft 365 DLP policy disabled or removed
Microsoft Teams application setup policy was modified
Microsoft Teams external communication policy was modified
Microsoft Teams messages were exported from conversation
Multiple mail items were accessed in a short period of time
New Teams application published to the organization catalog
Penetration testing tool activity attempt
Possible Insider Threat Activity
Possible multistage attack in Microsoft Teams
Possible phishing attack via Microsoft Teams
Potential extraction of NAA Account Credentials in Microsoft Configuration Manager
Potential Phishing has been detected
Rare DLP rule match by user
SAAS - Email was reported by the user or administrator as a phishing attempt
SaaS suspicious external domain user activity
Sensitive Exchange mail sent to external users
SharePoint Site Collection admin group addition
Single IP accessed mail items of multiple users
Suspicious SaaS API call from a Tor exit node
Suspicious theme and sentiment in email
User accessed multiple O365 AIP sensitive files
User accessed SaaS resource via anonymous link
User exported multiple messages in Microsoft Teams via Graph API
User mail items accessed from multiple IPs in the same subnet
User moved Exchange sent messages to deleted items
Was this helpful?