Skip to main content

forward all received emails in Microsoft 365 (including header, body and attachments) to soar

  • June 11, 2025
  • 5 replies
  • 32 views

NASEEF
Forum|alt.badge.img+8

Hello Team ,

Greetings..!!

How can I forward all received emails in Microsoft 365 (including header, body and attachments) to secops soar

thanks in advance

Naseef

5 replies

cmorris
Staff
Forum|alt.badge.img+10
  • Staff
  • June 11, 2025

Take a look at the email integrations and connectors - ex. https://cloud.google.com/chronicle/docs/soar/marketplace-integrations/microsoft-graph-mail. Are you trying to ingest email from a specific mailbox?


NASEEF
Forum|alt.badge.img+8
  • Author
  • Bronze 5
  • June 11, 2025

No, I’m working on creating a playbook that should run on all emails received within my infrastructure. For that, I need every incoming email—regardless of the specific mailbox—to be ingested.


NASEEF
Forum|alt.badge.img+8
  • Author
  • Bronze 5
  • June 11, 2025

for example we are able to preview anymail from defender email explorer right i am looking for a similar approach


ScottieJ
Staff
Forum|alt.badge.img+4
  • Staff
  • June 11, 2025

NASEEF,

You may want to consider configuring Microsoft 365 Journaling mailbox. Setting up a journal rule to send a copy of all incoming and outgoing emails (including headers, body, and attachments) to a dedicated journaling mailbox within your Microsoft 365 tenant. This ensures comprehensive capture of all emails regardless of the specific user mailbox. Then when you set up the Microsoft Graph Mail Connector, you can configure it to read emails from the dedicated journaling mailbox.


Forum|alt.badge.img

NASEEF,

You may want to consider configuring Microsoft 365 Journaling mailbox. Setting up a journal rule to send a copy of all incoming and outgoing emails (including headers, body, and attachments) to a dedicated journaling mailbox within your Microsoft 365 tenant. This ensures comprehensive capture of all emails regardless of the specific user mailbox. Then when you set up the Microsoft Graph Mail Connector, you can configure it to read emails from the dedicated journaling mailbox.


Thank you