Microsoft 365

Introduction

This article shows you how to integrate Microsoft 365 (M365) in the Field Effect MDR Portal for the first time. 


If you want to enable Active Response for a cloud service that has already been added in the MDR Portal, see Configuring Active Response.


Optionally, you can request that this integration be limited to a specific subset of your M365 users by Group. This is useful if you have licensing limitations that can't cover the full user count. Please reach out at support@fieldeffect.com to make these specifications.


This article covers the following:  


Requirements

To enroll M365 for cloud monitoring, you will need the following:


Licensing

It's important for clients to review their Microsoft 365 licensing to ensure they meet the necessary requirements, are leveraging the appropriate features, and remain compliant with Microsoft’s Terms and Services.


Some features of this integration require the Enterprise ID Plan 1 or 2 (Entra P1 or P2) licenses:


LicenseGraph APIActive Response (Standard Only)Conditional Access Policy (CA)Account MFA Reporting (Accounts Page)Default Log Retention
No Entra P1 or P2YesYes NoNo30 days, raw logs
90 days, security events
Entra P1 or P2YesYesYesYes30 days, raw logs
90 days, security events


See the chart below to determine if your license includes Entra P1 or P2. To view the full Microsoft licensing matrix, visit Microsoft Feature Matrix.  

 

LicenseFeatureEntra ID Plan 1 or 2 
Office 365E1No
E3No
E5 No
M365 BusinessBasic No
StandardNo
PremiumYes
M365 FrontlineF1Yes
F3Yes
F5 SecurityYes
F5 ComplianceNo
F5 Sec+CompYes
M365 EnterpriseE3Yes
E5 SecurityYes
E5 ComplianceNo
E5Yes
M365 EducationA1 (Legacy)No
A1 for DevicesNo
A3Yes
A5 SecurityYes
A5 ComplianceNo
A5Yes


Setting up M365 Monitoring


Partners: This procedure is performed on a per-client basis. Ensure that the Organization Selector is set to the appropriate client before continuing.


From the Integrations page's (Administration section) Cloud Monitoring tab, click Add in the Microsoft 365 (with Azure AD) card.



The Microsoft 365 window will open. The first page asks if you would like to enable Active Response for the account. 


If your organization has an Active Response policy in place, selecting Standard will apply it to this cloud service. Visit Active Response for Cloud Service to learn more.



You’ll be taken to a Microsoft page listing the accounts you’re currently logged into. Select your Microsoft 365 admin account.


Graphical user interface, application

Description automatically generated


After logging in, you will be asked to grant Field Effect MDR permission to access the metrics listed in the image below. If you approve of this, click Accept.



The example above shows the permissions required for the Standard integration. If you are selecting the Limited integration, you will see fewer permissions listed. 

 

You'll be taken back to the integrations page, and the integration card will show that the integration is connected and promoted to the top, alongside any other connected integrations. 


Due to the time it takes for configuration changes to propagate through Microsoft’s servers, it may take up to 4 hours for audit logging to start collecting logs.




Troubleshooting

"Need admin approval"

If you try enabling integrating this service with an account that does not have admin privileges, you’ll receive the following "Need admin approval" error:



Have an admin in your organization follow the steps above to resolve this. Alternatively, if you have an admin account, click Have an admin account? Sign in with that account and continue the process.




Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article