Connect the Microsoft Office 365 connector

Completed

The Microsoft Defender XDR connector provides insight into the suite of Microsoft Defender products including Microsoft Defender for Office 365. You'll collect data on ongoing user activities such as file downloads, access requests sent, changes to group events, set-mailbox, and details of the user who performed the actions.​

To view the connector page, do these steps:

  1. In the Microsoft Sentinel left navigation menu expand Configuration, and Select Data connectors.

  2. Select Microsoft Defender XDR.

  3. Then select the Open connector page on the preview pane.

  4. Review the Description and Data types tabs to understand the data that is ingested.

  5. In the Instructions tab, verify that you meet the Prerequisites.

  6. In the Instructions tab, under the section labeled Configuration, select the Connect incidents and alerts button.

  7. Wait until validation is complete and the button changes to Disconnect.

Screen shot of the Microsoft Defender XDR Connector page.