LogoLogo
⌘Ctrlk
BlogSupport
  • Home
AI Assistant

I'm here to help you with the docs.

⌘Ctrli
AI Based on your context
LogoLogo
    • Navigate the Cortex Cloud Runtime Security docs
    • What is Cortex Cloud?
    • What is Cortex Cloud Runtime Security?
    • Agentic AI in Cortex Cloud
    • Supported web browsers
    • Use the interface
    • In-product support ticket creation
    • Understand your user persona
    • Understand license plans
    • Fair Usage policy for Cortex Cloud
    • Learn how to onboard and configure Cortex Cloud Runtime Security
    • Plan and prepare
    • Deployment steps and checklist
    • Post-deployment steps
    • Endpoint protection
    • Install and manage endpoints
    • Endpoint DLP
    • Extended Threat Intelligence
    • Detection rules
    • Analytics
    • Identity Threat Detection and Response (ITDR)
    • Overview
    • Personas workflow
    • Secure your API landscape
    • Asset management
    • Asset inventory overview
    • All assets
    • All cloud assets
    • Asset classes
    • Asset groups
    • Manage Risk Scores
    • Asset configurations
    • Overview of cases
    • Case concepts
    • Analyze and resolve cases
    • Investigation and response
    • Customize cases and issues
    • Agentic Assistant chat
    • Monitor dashboards and reports
    • Learn about the Discovery Engine
    • What is Cortex Cloud AI Security?
    • Supported services in Cortex Cloud AI Security
    • Cortex Cloud AI Security concepts
    • Cortex Cloud AI Security use cases
    • How to perform advanced AI Security investigations using XQL
    • About Cortex Cloud Application Security
    • Code-to Cloud
    • Learn about Cloud ASM
    • Enable Cloud ASM
    • Attack surface management detections
    • Attack surface assets
    • Review your unmanaged cloud services
    • Review unmanaged cloud issues
    • About network exposure detection
    • What is Cloud Network Analyzer?
    • Internet exposure detection
    • Outbound exposure detection
    • East-west exposure detection
    • Investigate an internet exposure
    • Configure trusted IPs
    • About Cortex Cloud Data Classification
    • How to create and validate a custom data pattern
    • How to disable and enable data patterns in Data Classification
    • How to create and validate a custom data profile
    • How to disable and enable data profiles in Cortex Cloud Data Classification
    • How to report a false positive in Cortex Cloud Data Classification
    • Topic classification
    • What is Cortex Data Security?
    • What is Cortex Cloud Identity Security?
    • Review and improve your Identity Security posture
    • How does Effective Permission Calculation work?
    • Cortex Cloud Identity Security functionality
    • Configure Cortex Cloud Identity Security
    • Unified Human Identities
    • Achieve the principle of least privilege access
    • Explore permissions using the simple and advanced access tables
    • Create a custom detection rule in Cortex Cloud Identity Security
    • Perform advanced Identity Security investigations using XQL
    • Ingest logs and data from Okta
    • Enable inactive human identity logs on Azure in Cortex Cloud Identity Security
    • Manage RBAC and SBAC in Cortex Cloud Identity Security
    • SaaS Security
    • Vulnerability management in Cortex Cloud
    • Cortex Vulnerability Risk Score
    • Vulnerability policies
    • Investigate and remediate vulnerabilities
    • Vulnerability Intelligence
    • Emerging Vulnerabilities
    • Recast CVSS scores and CVSS severities
    • Registry scanning
    • Configure registry scanning for cloud accounts
    • Configure registry scanning for third party integrations
    • Manage registry scanning with APIs
    • About Rules and Policies
    • Cloud security rules and policies
    • Cloud workload policies and rules
    • Base image rules
    • Monitor and track compliance adherence
    • Broker VM
    • Dataset management
    • Manage Event Forwarding
    • Manage compute units
    • What are Cortex Cloud data sources and connectors?
    • What is the data source and connector catalog?
    • Vendor-specific data sources and connectors
      • AbuseIPDB
      • AIOps
      • Amazon
      • Anomali
      • Anthropic
      • API Security
      • Atlassian
      • BeyondTrust
      • Box
      • Check Point
      • Cisco
      • Corelight
      • Cribl
      • CyberArk
      • Databricks
      • Docker
      • Dropbox
      • Elastic
      • Forcepoint
      • Fortinet
      • Freshworks
      • Generic
      • GitHub
      • GitLab
      • Google
      • Harbor
      • HTTP log collector
      • IBM
      • iZOOlogic
      • JFrog
      • Koi
      • Kubernetes
      • Mail Utilities
      • Microsoft
        • Azure Event Hub
        • Microsoft Azure
        • Microsoft Entra ID
        • Microsoft365 (legacy)
        • Microsoft 365 (new)
        • Microsoft Office 365
        • Microsoft Office 365 (email)
        • Microsoft 365 (Posture)
        • Microsoft Teams
        • Microsoft Active Directory
        • Microsoft Graph
        • Microsoft Identity
        • Microsoft Security Automation and Collection
        • M365 Automation and Collection
      • Monday
      • MongoDB
      • Okta
      • OneLogin
      • Oracle
      • PagerDuty
      • Ping Identity
      • Salesforce
      • ServiceNow
      • Slack
      • SMB
      • Snowflake
      • Sonatype Nexus registry
      • Workday
      • Zendesk
      • Zscaler
    • Connectors
    • Standard data sources
    • Cloud service provider (CSP) onboarding
    • Generic on-premise data collectors
    • Palo Alto Networks integrations
    • Cloud Posture and Runtime Security data sources
    • Administration and troubleshooting
    • What is the Cortex Marketplace
    • Content Pack Support Types
    • Cortex Cloud content
    • Manage content packs
    • Marketplace FAQs
    • Content changes when upgrading Cortex Cloud versions
    • Learn about Serverless function posture security
    • Onboard cloud providers for serverless functions
    • Serverless function posture rules
    • Serverless function posture policies
    • Serverless function usage
    • Overview
    • Set up serverless function protection
    • Serverless runtime issues
    • About Cortex CLI
    • Connect Cortex CLI
    • Cortex CLI usage
    • Cortex CLI common command line reference guide
    • Cortex CLI for Code Security
    • Cortex CLI for Cloud Workload Protection
    • Cortex CLI for API Security
    • Get started with XQL
    • Build XQL queries
    • Cortex XQL syntax, parameters, and examples
    • What is Graph Search?
    • Get started with Graph Search queries
    • How to build Graph Search queries?
    • Understand Graph Search query results
    • Create Graph Search query
    • Graph Search examples
    • Manage the Graph Search Query Library
    • Edit and run queries in Query Center
    • Supported assets and findings
    • FAQ on Graph Search
    • Create detection rules based on graph search
    • Learn how to a migrate a new Broker VM image
    • Standalone Broker VM
    • Broker VM high availability cluster node
For the complete documentation index, see llms.txt. This page is also available as Markdown.
  1. Guides
  2. Cortex Cloud
  3. Cortex CLOUD Runtime Security
  4. Cortex Cloud Data Sources and Connectors
  5. Vendor-specific data sources and connectors

Microsoft

Configure the Microsoft data sources and connectors for Cortex Cloud.

Here are the articles in this section:

  • Azure Event Hub

  • Microsoft Azure

  • Microsoft Entra ID

  • Microsoft365 (legacy)

  • Microsoft 365 (new)

  • Microsoft Office 365

  • Microsoft Office 365 (email)

  • Microsoft 365 (Posture)

  • Microsoft Teams

  • Microsoft Active Directory

  • Microsoft Graph

  • Microsoft Identity

  • Microsoft Security Automation and Collection

  • M365 Automation and Collection

PreviousMail Utilities
NextAzure Event Hub

Last updated 8 days ago

Was this helpful?

LogoLogo

‍

  • Trust Center

‍

  • Privacy

‍

  • Terms of Use

‍

  • Legal

© 2026 Palo Alto Networks, Inc. All rights reserved.

Was this helpful?