Getting Office 365 Security Events and Incidents in Sentinel

%3CLINGO-SUB%20id%3D%22lingo-sub-1585643%22%20slang%3D%22en-US%22%3EGetting%20Office%20365%20Security%20Events%20and%20Incidents%20in%20Sentinel%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1585643%22%20slang%3D%22en-US%22%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20I%E2%80%99ve%20created%20a%20custom%20detection%20in%20Office%20365%E2%80%99s%20security%20portal%20that%20generated%20an%20incident%2C%20but%20that%20incident%20is%20not%20showing%20up%20in%20Azure%20Sentinel.%26nbsp%3B%20I%E2%80%99ve%20done%20queries%20in%20Sentinel%20via%20the%20following%20log%20types%20to%20no%20avail%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOfficeActivity%20(plenty%20of%20Office%20365%20activity%20shows%20up%20here%2C%20but%20not%20security%20incidents%20like%20the%20one%20in%20question)%3C%2FP%3E%3CP%3ESecurityAlert%20(Defender%20ATP%20Alerts%20DO%20show%20up%2C%20but%20not%20Office%20365%20alerts%20or%20incidents)%3C%2FP%3E%3CP%3ESecurityDetection%3C%2FP%3E%3CP%3ESecurityEvent%20(no%20data%20of%20this%20type%20at%20all)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20Where%20do%20I%20need%20to%20look%20or%20how%20do%20I%20start%20feeding%20O365%20security%20events%20into%20Sentinel%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%20%26nbsp%3B%20If%20it's%20not%20yet%20possible%2C%20my%20secondary%20question%20is%20how%20can%20I%20get%20email%20notifications%20based%20on%20custom%20detections%20at%20the%20Office%20365%20Security%20level%3F%26nbsp%3B%20I%20get%20wonderful%20notifications%20from%20Defender%20ATP%2C%20but%20I%20followed%20Microsoft's%20breadcrumbs%20to%20creating%20detections%20in%20O365%20but%20can't%20construct%20a%20notification%20policy%20based%20on%20them.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%20Thanks%20in%20advance%20for%20any%20assistance!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBe%20safe...%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1587374%22%20slang%3D%22en-US%22%3ERe%3A%20Getting%20Office%20365%20Security%20Events%20and%20Incidents%20in%20Sentinel%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1587374%22%20slang%3D%22en-US%22%3EGetting%20Office%20365%20alerts%20in%20Sentinel%20is%20not%20possible%20yet.%3CBR%20%2F%3E%3CBR%20%2F%3EYou%20can%20configure%20notifications%20by%20updating%20the%20alert%20policies%20at%20protection.office.com%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1587506%22%20slang%3D%22en-US%22%3ERe%3A%20Getting%20Office%20365%20Security%20Events%20and%20Incidents%20in%20Sentinel%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1587506%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F186539%22%20target%3D%22_blank%22%3E%40Thijs%20Lecomte%3C%2FA%3E%26nbsp%3BHow%20do%20I%20configure%20a%20policy%20to%20enable%20alerts%20for%20custom%20detections%3F%26nbsp%3B%20The%20category%20and%20%22Activity%20is%22%20selectors%20in%20the%20alert%20policy%20wizard%20do%20not%20seem%20to%20provide%20a%20means%20to%20setup%20alerts%20for%20Office%20365%20custom%20detections.%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20I'm%20about%20ready%20to%20just%20move%20my%20custom%20detections%20back%20to%20the%20ATP%20level%20(if%20anybody%20knows%20of%20an%20automated%20way%20to%20do%20that%20let%20me%20know!).%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1590658%22%20slang%3D%22en-US%22%3ERe%3A%20Getting%20Office%20365%20Security%20Events%20and%20Incidents%20in%20Sentinel%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1590658%22%20slang%3D%22en-US%22%3ECould%20you%20specify%20custom%20detections%3F%3CBR%20%2F%3ENot%20sure%20if%20I%20follow%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1610898%22%20slang%3D%22en-US%22%3ERe%3A%20Getting%20Office%20365%20Security%20Events%20and%20Incidents%20in%20Sentinel%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1610898%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F186539%22%20target%3D%22_blank%22%3E%40Thijs%20Lecomte%3C%2FA%3E%26nbsp%3BSay%20you%20do%20this%3A%3CBR%20%2F%3Ego%20to%20security.microsoft.com%2Fadvanced-hunting%3C%2FP%3E%3CP%3EYou%20create%20a%20query%20and%20then%20%22Create%20detection%20rule%22%3C%2FP%3E%3CP%3ENow%20you've%20got%20a%20Custom%20Detection%3B%20how%20do%20you%20set%20a%20notification%20policy%20for%20it%3F%26nbsp%3B%20Within%20the%20detection%20you%20can%20configure%20actions%2C%20but%20email%20notifications%2Falerts%20isn't%20one%20of%20them.%26nbsp%3B%20I%20ended%20up%20giving%20up%20and%20based%20on%20feedback%20I've%20seen%20from%20a%20couple%20of%20sources%20moved%20my%20custom%20detection%20rules%20from%20Office%20365%20back%20to%20ATP.%26nbsp%3B%20What%20I%20really%20wanted%20was%20to%20feed%20it%20all%20to%20Azure%20Sentinel%2C%20but%20the%20best%20combination%20of%20flexibility%20and%20alerting%20seems%20to%20be%20at%20the%20ATP%20level.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1613219%22%20slang%3D%22en-US%22%3ERe%3A%20Getting%20Office%20365%20Security%20Events%20and%20Incidents%20in%20Sentinel%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1613219%22%20slang%3D%22en-US%22%3EI%20see%3CBR%20%2F%3EThen%20I%20would%20advise%20you%20to%20connect%20MDATP%20to%20Sentinel%20(%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fconnect-microsoft-defender-advanced-threat-protection%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fconnect-microsoft-defender-advanced-threat-protection%3C%2FA%3E)%3CBR%20%2F%3E%3CBR%20%2F%3EAnd%20enable%20the%20analytics%20rule%20-%20Create%20incidents%20based%20on%20Microsoft%20Defender%20Advanced%20Threat%20Protection%20alerts%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1657745%22%20slang%3D%22en-US%22%3ERe%3A%20Getting%20Office%20365%20Security%20Events%20and%20Incidents%20in%20Sentinel%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1657745%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F186539%22%20target%3D%22_blank%22%3E%40Thijs%20Lecomte%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%20I'll%20investigate...%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

              I’ve created a custom detection in Office 365’s security portal that generated an incident, but that incident is not showing up in Azure Sentinel.  I’ve done queries in Sentinel via the following log types to no avail:

 

OfficeActivity (plenty of Office 365 activity shows up here, but not security incidents like the one in question)

SecurityAlert (Defender ATP Alerts DO show up, but not Office 365 alerts or incidents)

SecurityDetection

SecurityEvent (no data of this type at all)

 

              Where do I need to look or how do I start feeding O365 security events into Sentinel?

    If it's not yet possible, my secondary question is how can I get email notifications based on custom detections at the Office 365 Security level?  I get wonderful notifications from Defender ATP, but I followed Microsoft's breadcrumbs to creating detections in O365 but can't construct a notification policy based on them.

 

  Thanks in advance for any assistance!

 

Be safe...

6 Replies
Getting Office 365 alerts in Sentinel is not possible yet.

You can configure notifications by updating the alert policies at protection.office.com

@Thijs Lecomte How do I configure a policy to enable alerts for custom detections?  The category and "Activity is" selectors in the alert policy wizard do not seem to provide a means to setup alerts for Office 365 custom detections.      I'm about ready to just move my custom detections back to the ATP level (if anybody knows of an automated way to do that let me know!). 

Could you specify custom detections?
Not sure if I follow

@Thijs Lecomte Say you do this:
go to security.microsoft.com/advanced-hunting

You create a query and then "Create detection rule"

Now you've got a Custom Detection; how do you set a notification policy for it?  Within the detection you can configure actions, but email notifications/alerts isn't one of them.  I ended up giving up and based on feedback I've seen from a couple of sources moved my custom detection rules from Office 365 back to ATP.  What I really wanted was to feed it all to Azure Sentinel, but the best combination of flexibility and alerting seems to be at the ATP level. 

I see
Then I would advise you to connect MDATP to Sentinel (https://docs.microsoft.com/en-us/azure/sentinel/connect-microsoft-defender-advanced-threat-protectio...)

And enable the analytics rule - Create incidents based on Microsoft Defender Advanced Threat Protection alerts

@Thijs Lecomte 

Thank you I'll investigate...