Microsoft 365 Integration
Unified visibility across Exchange, SharePoint, Teams, and Entra ID.
What this integration does
Microsoft 365 meets agentic SOC
Microsoft 365 is the productivity backbone of most enterprise environments — and a primary target for email compromise, OAuth abuse, and insider data theft. ManySignal ingests M365 audit logs, Entra ID sign-ins, and Defender for Office 365 alerts via the Microsoft Graph API, correlating SaaS activity with endpoint and identity signals.
Unified Audit Log ingestion via Microsoft Graph Activity API
Entra ID sign-in and risk events correlation
Exchange Online mailbox rule creation detection
Data collected
- Unified Audit Log events (Exchange, SharePoint, Teams, Entra)
- Entra ID sign-in logs and risk detections
- Defender for Office 365 alerts
- OAuth application consent and delegation events
- Teams channel creation and membership changes
Actions supported
- Disable M365 user account via Graph API
- Revoke all Entra ID refresh tokens for a user
- Block sign-in for a user in Entra ID
- Remove external sharing permissions from SharePoint
- Delete malicious inbox rule
Getting started
Set up in minutes
- 1
Register an Entra ID app registration
- 2
Grant admin consent
- 3
Configure in ManySignal
- 4
Enable the M365 detection pack
Microsoft 365 Integration: frequently asked questions
Does the integration require a Defender for Office 365 licence?
No. Base Unified Audit Log ingestion works with any M365 plan that has auditing enabled. Defender for Office 365 alert ingestion requires the Defender for Office 365 Plan 1 or Plan 2 licence.
How is Teams data handled?
ManySignal ingests Teams audit metadata (channel events, membership changes, sharing events) but does not ingest message content. Only activity telemetry is processed.
Related integrations
Amazon Web Services Integration
Integration
Aws Cloudtrail Integration
Integration
Aws Guardduty Integration
Integration
Aws Security Hub Integration
Integration
Aws Config Integration
Integration
Aws Vpc Flow Logs Integration
Integration
Microsoft Azure Integration
Integration
Azure Activity Logs Integration
Integration
Microsoft Entra Id Integration
Integration
Microsoft Defender Integration
Integration
Microsoft Defender For Cloud Integration
Integration
Microsoft Defender For Identity Integration
Integration
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.