Microsoft 365

Source Connector

Overview

Office365

This source connector fetches Audit events from the Office 365 Management APIs.

Streams

Streams are pulled from the Office 365 Management Activity API

Data SourceStream NameNotes
Audit.AzureActiveDirectoryaudit_azure_active_directory
Audit.Exchangeaudit_exchange
Audit.SharePointaudit_share_point
Audit.Generalaudit_generalincludes all other workloads not included in the previous content types
DLP.Alldlp_allDLP events only for all workloads

Prerequisites

  1. In Microsoft Purview, turn auditing on
  2. Register an Active Directory Application
    1. Supported account types: Accounts in this organization directory only
    2. Certificates & secrets: Create a new client secret. You will need this to configure the tarsal source connector
    3. API Permissions:
      1. Office 365 Management APIs
        1. ActivityFeed.Read
        2. Activity.Feed.ReadDlp
        3. ServiceHealth.Read

Configuration

FieldRequiredDescription
Client IDyesAzure AD Application (Client) ID
Client SecretyesAzure AD Application (Client) Secret
Tenant IDyesDirectory (Tenant) ID

Connector Limitations

  1. This connector is restricted by rate limits.