How to detect data exfiltration from O365 applications

Tim Gjerlufsen 5 Reputation points
2024-01-02T12:16:29.46+00:00

Hi all

I'm looking for a way to detect and report if data are being exfiltrated using Microsoft Online Services (O365) and downloaded to unmanaged PC.

Microsoft are using several IP ranges for trusted services, so a simple query (KQL in log analytics) for ClientIP different that the company public IP isnt enough.

Looking forward to see a solution.

/Tim

Microsoft 365 and Office | Development | Other
Microsoft 365 and Office | Install, redeem, activate | For business | Windows
0 comments No comments
{count} vote

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.