Microsoft 365 Integration
Last updated
This guide shows how to enable Microsoft 365 API access in CybrHawk SIEM.
Requirements:
Access to Microsoft 365 services, including Microsoft 365 Compliance Center and Microsoft Entra ID
Any Microsoft 365 licensing tier
Click any screenshot to open the full-size image.
Enable auditing before you continue. Follow Microsoft’s guide to turn auditing on or off.
Download CybrHawk’s Entra ID integration certificate from the SOC team.
Sign in to the Entra ID portal.
Open Microsoft Entra ID

Select App registrations and click New registration

Enter the required details, then click Register

Save the Application (client) ID and Directory (tenant) ID for later

Open Certificates & secrets.

Click Upload certificate

Upload the certificate from step 1, then click Add.
After creating the application, grant permissions to the Office 365 Management APIs

Open API permissions and select Office 365 Management APIs

Select Application permissions and enable the following:
Click Grant admin consent and confirm

Log in to the CybrHawk SIEM Portal.
Go to Deployments > Integrations.
Click Add and select Microsoft 365.
For advanced security auditing, Defender event ingestion, and user isolation features, complete the MS365 Graph API.
Last updated
ActivityFeed.Read
ActivityFeed.ReadDlp