For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex XDR 3.x

Ingest logs and data from Microsoft 365

Learn more about collecting logs and data from Microsoft 365.

The Microsoft 365 email collector fetches email metadata through Microsoft Graph API, using an authorized app. A compliance mailbox is not required.

Notice

Ingestion of logs and data requires a Cortex XDR Pro per GB license.

Danger

Scoping

You can narrow down the scope of ingested mailboxes by:

  • Microsoft 365 Group

  • Distribution List

  • Mail-enabled Security Group

  • Mail-enabled Users

Datasets

The Microsoft 365 collector provides a comprehensive data stream by ingesting information into the following datasets.

  • msft_o365_emails_raw: Metadata and logs for email traffic.

  • msft_o365_users_raw: Information regarding user accounts and identities.

  • msft_o365_groups_raw: Data related to Office 365 groups and distribution lists.

  • msft_o365_devices_raw: Details on devices registered within the M365 environment.

  • msft_o365_mailboxes_raw: Configuration and status logs for individual mailboxes.

  • msft_o365_rules_raw: Logs for mail flow, transport, and inbox rules.

  • msft_o365_contacts_raw: Organizational and user-defined contact information.

How to configure Microsoft 365 collection?
  1. Navigate to data source.

    On the Collection Integrations page, locate Microsoft 365, and select Add Instance to begin a new connection.

  2. Permissions verification

    In the wizard, review the required items on the Permissions page, and then click Next.

  3. Authorization

    Click OK to confirm you understand that API authorization consent is required.

  4. Microsoft Sign-in

    1. Select the Microsoft account for collection.

    2. Click Next.

    3. Enter your credentials for the Microsoft account and click Sign in.

    4. If you are asked to perform authentication using your organization's authentication tools, do so.

  5. Accept permissions

    Review the list of of permissions requested by the collector and click Accept.

  6. Define scope

    1. On the Scope page, select one of the following:

      • Entire organization: Emails will be collected from all mailboxes in your organization.

      • Specific groups: Enter the email addresses of group names, such as Microsoft 365 Groups, Mail-enabled Security Groups, Distribution Lists, or Mail-enabled Users.

    2. Click Next.

  7. Finalize

    1. On the Details page, enter a meaningful instance name, and click Next.

    2. On the Summary page, check your configurations, and then click Create.

Verification

Once the configuration is complete, a green check mark will appear below the Microsoft 365 configuration, and the console will display the amount of data received. You can now run queries against the datasets listed above.

Last updated

Was this helpful?