Forum Discussion

mclaes's avatar
mclaes
Brass Contributor
Jan 09, 2020
Solved

Office365 S&C Alerts available in Sentinel?

Hey all,

 

we're trying to use our Sentinel to centralize alerts from all different E5 security solutions (wdatp, mcas, o365atp ..) 

Are O365 Alerts available in sentinel? Or are only the base O365 events available via the "officeactivity" ?
For example: "Potentially unsafe URL click was detected

Thanks, Maarten.

15 Replies

    • Julian's avatar
      Julian
      Brass Contributor
      Is the connector still in private preview?
      • rafaelruales's avatar
        rafaelruales
        Copper Contributor

         

         

        Update 03/22, this event "Potentially unsafe URL click was detected" can be found under connectors:

        • Microsoft 365 Defender
        • Microsoft Defender for Office 365

        SecurityAlert table in sentinel

    • mclaes's avatar
      mclaes
      Brass Contributor

      ehloworldio 

       

      hey all, thanks for the quick replies! We do have all connectors live for the security solutions and have the MCAS/WDATP/ASC/IdentityProtection Analytics rules enabled.

      The question was indeed about O365 alerts (not the events/logs) feeding in to Sentinel. I'll give the Graph API way a shot for now! We want to be on top of 'clicked-on-phishing-link' alerts as they present a significant risk to our org so having these alerts in Sentinel would be really helpful

      Cheers, Maarten.

      • CurlX2305's avatar
        CurlX2305
        Copper Contributor

        mclaes 

        Having the same issue, were you able to integrate the alerts into Sentinel?

    • PJR_CDF's avatar
      PJR_CDF
      Iron Contributor

      chrisbuesold 

       

      has this changed?

       

      The default "A potentially malicious URL click was detected" alert policy in my demo tenant has these alerts as high severity and as it's a default policy the severity cannot be altered so it appears to be high by default now.

       

      The following defaults are all still informational though:

       

      • Email messages containing malware removed after delivery
      • mail messages containing phish URLs removed after delivery
      • Email reported by user as malware or phish

      Would be nice if the severity of these could be altered.

       

      Paul

  • thomasdefise's avatar
    thomasdefise
    Brass Contributor

    Hello Maarten,

    I would suggest to follow the following steps:

     

    1. Connect data from Azure Active Directory
      https://docs.microsoft.com/en-us/azure/sentinel/connect-azure-active-directory
    2. Connect data from Office 365 Logs
      https://docs.microsoft.com/en-us/azure/sentinel/connect-office-365
    3. Connect data from Azure Activity log
      https://docs.microsoft.com/en-us/azure/sentinel/connect-azure-activity
    4. Connect data from Azure AD Identity Protection (If deployed too)
      https://docs.microsoft.com/en-us/azure/sentinel/connect-azure-ad-identity-protection
    5. Connect alerts from Microsoft Defender Advanced Threat Protection
      https://docs.microsoft.com/en-us/azure/sentinel/connect-microsoft-defender-advanced-threat-protection
    6. Connect data from Azure Security Center
      https://docs.microsoft.com/en-us/azure/sentinel/connect-azure-security-center

    Once that is done, Azure Sentinel will be able to get all the data that you listed above.
    Then, I would suggest you to go the the "Analytics" blade (Azure Sentinel > Configuration > Analytics) and make sure that the Fusion rule is enabled as you have both Office 365 and MCAS and Fusion is a very advanced engine that correlate incidents from both Office 365 and MCAS to find incidents that are high fidelity, and high severity.

    (https://docs.microsoft.com/en-us/azure/sentinel/fusion) 

    Then I would suggest to go to the Rule Templates and select and create the "Microsoft Security" rules, you should find what you are looking for.

    (below on the right you can click on "Create"

    Kind Regards,
    Thomas

Resources