M ManySignal

Integration Category

SaaS Application Integrations

Microsoft 365, Google Workspace, Salesforce, Slack, Box — ManySignal monitors your SaaS applications for compromised accounts, insider data theft, OAuth abuse, and business email compromise.

SaaS integration FAQs

What SaaS security risks does ManySignal detect?

Key SaaS threats: compromised user accounts (phishing, credential stuffing), insider data exfiltration (mass download, external sharing), OAuth app abuse (illicit consent grant), business email compromise (mailbox forwarding rules), and SaaS misconfiguration (public sharing, excessive permissions).

Does ManySignal cover both Microsoft 365 and Google Workspace?

Yes. ManySignal has native connectors for both — M365 via the Unified Audit Log and Graph API, Google Workspace via the Admin SDK Audit API. Detections are equivalent across both platforms.

What is the most important Microsoft 365 event to monitor?

Email forwarding rule creation to external domains is the highest-priority single event. Other critical events: new OAuth app consent, admin role assignment, mailbox access by non-owner, and bulk email access via Graph API.

Can ManySignal detect Salesforce data exfiltration?

Yes. ManySignal ingests Salesforce EventLogFile data including Report export events. Alerts fire when a user exports more than a configured record count, when export activity occurs from a new IP, or when export patterns deviate from the user's baseline.

Does ManySignal monitor Box and Dropbox for data exfiltration?

Yes. Box and Dropbox audit logs capture file access, download, and sharing events. ManySignal detects mass download events, sharing with external parties, and access from unexpected locations.

How does ManySignal handle OAuth app risk in SaaS environments?

ManySignal monitors OAuth consent events in Microsoft 365 and Google Workspace. New apps requesting high-privilege scopes (Mail.Read, Files.ReadWrite) trigger alerts. A periodic audit of all consented OAuth apps is surfaced in the ManySignal risk dashboard.

Can ManySignal detect when a SaaS account is compromised?

Yes. ManySignal correlates authentication anomalies (new country, new device, MFA bypass) with subsequent suspicious activity (bulk download, sharing changes, admin actions) to detect and automatically respond to compromised SaaS accounts.

Does ManySignal support Google Workspace Business and Enterprise editions?

Google Workspace Audit API access is included in Business Starter and above. Admin SDK access for all event types requires Business Standard or above. ManySignal works with all editions that provide API access.

How does ManySignal handle the Notion workspace as a data exfiltration risk?

Notion audit events (page creation, sharing changes, member additions) are ingested. ManySignal alerts when internal pages are shared externally, when guest user counts increase significantly, or when bulk page export occurs.

What SaaS monitoring does ManySignal provide for departing employees?

ManySignal detects mass download events, external sharing changes, and abnormal activity patterns that match departing employee data theft behaviour — automatically correlating HR system deprovisioning events with SaaS activity spikes in the preceding days.

Monitor your SaaS applications for insider threats

Connect Microsoft 365 or Google Workspace in minutes and detect your first SaaS threat.