Skip to main content

How can we integrate Microsoft Defender for O365 with Chronicle SIEM ?

  • May 15, 2024
  • 3 replies
  • 178 views

TheSecOpsGuy
Forum|alt.badge.img+7

How can we integrate Microsoft Defender for O365 with Chronicle SIEM ?

Is it using Microsoft Graph Alert (Third Party API) ?

https://cloud.google.com/chronicle/docs/preview/siem-integrations/microsoft-graph-alert.

3 replies

jstoner
Staff
Forum|alt.badge.img+22
  • Staff
  • May 15, 2024

I’ve played with it previously but not recently. At one point it was outputting alerts via the graph api alert. This would be set up via feed management like other o365 and entra id logging


TheSecOpsGuy
Forum|alt.badge.img+7
  • Author
  • Bronze 5
  • May 16, 2024

@jstoner Thank you. However is it possible to get a confirmation as we do not test environment to cross verify it?


Forum|alt.badge.img+3
  • Bronze 1
  • May 21, 2024

@jstoner Thank you. However is it possible to get a confirmation as we do not test environment to cross verify it?


Agree- The documentation could be much better around the M365 integrations.

https://cloud.google.com/chronicle/docs/ingestion/default-parsers/collect-microsoft365