> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-365.md).

# Microsoft 365

Secure sensitive data, monitor configurations, and track identity risks across your Microsoft 365 environment, including OneDrive, SharePoint, Teams, and Entra ID.

This connector includes the following capabilities and sub-capabilities (if applicable):

* **Data Security:** Scan and protect data across the selected services. This capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud Runtime Security, or Cortex Data Security license.
* **Identity Posture:** Maintain visibility and control over Microsoft Entra ID identities, including users, groups, roles, and granular permissions. This capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud Runtime Security, or Cortex Data Security license.

To configure this connector, follow these steps:

### Prerequisite

#### 1. Global Administrator access to the Azure portal

Sign in to the [Microsoft Azure portal](https://portal.azure.com/) as a Global Administrator. Use the [Create a Microsoft Entra ID page](/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-365/create-a-microsoft-entra-id.md) to obtain the following values:

* **Tenant ID:** Directory ID for your Microsoft 365 tenant.
* **Client ID:** Application ID generated during app registration.
* **Client Secret:** Client secret generated for the registered application.

#### 2. Configure the Office 365 Log Collector

Configure the Office 365 log collector before configuring Microsoft 365. The Office 365 log collector collects Microsoft 365 Management Activity logs required for SharePoint Online and OneDrive scanning. **Note:** This prerequisite is not required while configuring Microsoft Teams.

1. In Cortex Cloud, go to **Settings** > **Data Sources & Integrations**.
2. Search for **Office 365**, hover over it, and click **Add**.
3. Enter the Azure directory configuration values for **Tenant Domain**, **Application Client ID**, and **Client Secret**.
4. Under **Office 365 Management Activity API**, select **SharePoint Online** only.

   **Note:** Selecting additional services may result in duplicate logs and increased Microsoft API usage. All critical event tracking strings are embedded within the SharePoint syslog profile.
5. Click **Test** to validate the connection.
6. Click **Enable** to enable the log collector.
7. Verify that the connection status changes to **Connected** and that incoming events are displayed in the **Data Sources & Integrations** dashboard.

### How to configure the **Microsoft 365** connector

#### Task 1. Select services

1. In Cortex Cloud, navigate to **Settings** → **Data Sources & Integrations**.
2. Click **+ Add new**.
3. On the **Add Data Source** page, search for **Microsoft 365 (New)**, hover over it, and click **Add**.
4. In the wizard, select the Microsoft 365 services that you want to configure, such as:
   * **OneDrive for Business**
   * **SharePoint Online**
   * **Microsoft Teams**

{% hint style="info" %}
**Note**

Select one or more services based on your requirements. You can onboard all three services or select only the services you need.
{% endhint %}

5\. Click **Next**.

#### Capabilities tab

1. Enter a unique name for the new connector instance.
2. Review the available capabilities and select **Data Security** to enable scanning and inventory collection across the selected repositories.
3. (Optional) Enable **Automation and Remediation** if you plan to use automated labelling with Microsoft Purview Information Protection (MIP).

{% hint style="info" %}
**Note**

**Identity Posture** is automatically enabled when **Data Security** is selected and cannot be disabled during setup. Identity Posture is required for user and group validation and cross-tenant exposure analysis.
{% endhint %}

4. Click **Next**.

#### Connection tab

1. On the **Connection** page, enter the **Tenant ID** and click **Apply**.
2. After the Tenant ID is validated, enter the **Client ID** and **Client Secret** in their respective fields.
3. Click **Test** to validate the connection settings.
4. If the connection is successful, the wizard displays a green **Verified** status indicator.

{% hint style="info" %}
**Note**

If validation fails because of incorrect field values, close the wizard and restart the workflow. The current wizard session cannot be reused after a validation failure.
{% endhint %}

5\. Click **Next** to proceed.

#### Summary tab

1. On the **Summary** page, verify that each selected capability displays a **Connected** status.
2. If validation succeeds, the wizard displays a **Verification Success** message.
3. Click **Create Instance** to create the Microsoft 365 connector.

#### Task 2. (Optional) Post verification

After onboarding is complete, verify asset discovery and data security findings.

#### 1. Verify discovered assets

1. Go to **Inventory** > **All Assets**.
2. Filter the asset list by setting **Provider** to **Microsoft 365**.
3. Verify that Cortex discovers the following supported asset types:
   * **Microsoft OneDrive:** Individual user cloud storage environments provisioned within the Microsoft 365 organization.
   * **Microsoft Document Library:** Document containers, document sets, and file repositories hosted in OneDrive and SharePoint.
   * **Microsoft SharePoint Site:** Root and sub-level team sites, communication sites, and site collections that contain collaborative files and permissions.
   * **Microsoft Teams Workspace:** Mapped to Active Directory (AAD) Groups containing Public, Private, or Shared Channels.
   * **Microsoft Personal Workspace:** Captures 1-on-1 Direct Messages (DMs) and multi-user Group Chats.

#### 2. Verify policy findings

1. Select a OneDrive or other supported asset to open the details panel.
2. Review the **Overview** tab for asset health and other details.
3. Go to **Findings** to review detected security findings, including:
   * **Sensitive Content Detections:** Sensitive data matches, such as financial data, health records, credentials, API tokens, credit card numbers, and personally identifiable information (PII), detected in files stored in OneDrive and SharePoint or in Microsoft Teams chat messages and conversations.
   * **Insecure Sharing and External Exposure:** Files and folders exposed through anonymous access links, such as **Anyone with the link**, organization-wide shared links, or external guest user access in OneDrive and SharePoint. This also includes sensitive information shared in Microsoft Teams chats or conversations with external users or guest users.
   * **Misconfigured Permissions and Excessive Exposure:** Overly permissive access controls, broken permission inheritance, or unrestricted access to sensitive OneDrive folders, SharePoint sites, and document libraries.

{% hint style="info" %}
**Note**

* Any user addition to or removal from a Microsoft Teams group chat may take up to **6 hours** to be reflected.
* ACLs for messages sent before a user is added to or removed from a Microsoft Teams group chat are not updated to reflect the membership change.
* After onboarding a connector, Cortex Cloud may take **24 hours to 7 days** to fully process the data and generate findings. If you attempt to re-onboard the same connector using the same credentials during this transition period, previously generated findings and other data may temporarily reappear.
  {% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-365.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
