Microsoft Defender | Threat Management | Explorer | Email preview

Oscar 177 Reputation points
2024-08-27T06:49:43.4033333+00:00

Hello,

Using Microsoft Defender, it is possible to use Explorer to preview emails if a specific role is granted.

We would like to monitor such activity, preferably via Sentinel, and trigger an email alert if someone is previewing the emails of the end users.

Where is this activity being logged? How to integrate this log with Sentinel?

Best regards,

Oscar

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
0 comments No comments
{count} votes

Accepted answer
  1. Givary-MSFT 35,626 Reputation points Microsoft Employee Moderator
    2024-09-03T10:18:45.0833333+00:00

    @Oscar Thank you for reaching out to us, came across this tech community blog - https://techcommunity.microsoft.com/t5/microsoft-defender-xdr/email-entity-preview-email/m-p/3662612 where similar ask has been discussed, just check if the approach discussed here helps you or not.

    Let me know if you have any further questions, feel free to post back.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.