Microsoft sentinel not ingesting M365 connector data

Brandon DeVane 0 Reputation points
2025-05-01T11:58:52.87+00:00

Greetings, we have this situation where the data connector for M365 isn't ingesting logs to sentinel. The connector shows as connected, but no logs are being ingested

From the health data, they give this message: "Tenant does not exist in the O365 Management API." With the recommended action: "Unified auditing is not enabled for the tenant in O365. Enable unified auditing in O365."

The status code for this is: SC20011

I verified that unified auditing IS enabled in our tenant. This happens for all of the connector types, exchange, sharepoint, and teams. Any idea how to correct this issue? The Microsoft Entra ID connector, and the Azure Activity connector are working fine. It just seems to be an issue with M365

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,274 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Raja Pothuraju 22,475 Reputation points Microsoft External Staff Moderator
    2025-05-06T02:23:27.8+00:00

    Hello @Brandon DeVane,

    After installing the Microsoft 365 (formerly Office 365) Data Connector, how long did you wait to check if the logs were being ingested? Typically, it can take 2–3 hours for the logs to start appearing.

    Please wait at least 3 hours and verify if the logs are being ingested. If you're still not seeing any data, kindly share a screenshot of your connector page for further review.User's image


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.