> For the complete documentation index, see [llms.txt](https://cybrhawksoc.gitbook.io/cybrhawk-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cybrhawksoc.gitbook.io/cybrhawk-docs/getting-started/frequently-asked-questions/microsoft-365-monitoring.md).

# Microsoft 365 Monitoring

## What level of Microsoft 365 (MS365) license do I need to integrate into your platform?

Any MS365 licensing tier is supported - we do not require you to have Premium E5 or P1/P2 licenses from Microsoft. Our platform will automatically adjust and extract the available security events information based on your licensing tier.

## For how long do you keep our MS365 data?

We retain MS365 data for three months.

## What MS365 applications are supported?

We monitor user activity across all MS365 applications, including Entra ID, Exchange Online, SharePoint, OneDrive, and MS Teams.

## ​​How long does it take for my Microsoft logs to appear on your platform?

The logs will start loading onto the dashboards within 30-60 minutes after the integration has been added.
