Forum Discussion
Office365 S&C Alerts available in Sentinel?
- Jan 09, 2020
If i'm not mistaken Office Security & Compliance Center Alerts Connector is currently in private preview.
Alternatively, you could ingest these alerts via Graph Security API https://techcommunity.microsoft.com/t5/azure-sentinel/ingesting-office-365-alerts-with-graph-security-api/ba-p/984888
- PJR_CDFJul 14, 2020Iron Contributor
has this changed?
The default "A potentially malicious URL click was detected" alert policy in my demo tenant has these alerts as high severity and as it's a default policy the severity cannot be altered so it appears to be high by default now.
The following defaults are all still informational though:
- Email messages containing malware removed after delivery
- mail messages containing phish URLs removed after delivery
- Email reported by user as malware or phish
Would be nice if the severity of these could be altered.
Paul
- nrupaksNov 16, 2020Copper Contributor
PJR_CDF , Ofer_Shezaf - Is it this one? - "Office 365 Advanced Threat Protection (Preview)"
- Ofer_ShezafNov 16, 2020
Microsoft
nrupaks : yes