Skip to main content

Office 365 Business Premium licenses - Impact on the logging capabilities

  • February 15, 2024
  • 2 replies
  • 14 views

TheSecOpsGuy
Forum|alt.badge.img+7

What will be Impact on the logging capabilities if we have Office 365 Business Premium licenses (and not E3 or E5) for Chronicle SIEM and SOAR.

2 replies

Forum|alt.badge.img+4
  • Bronze 1
  • March 26, 2024

Microsoft forums might have more insight into what data each of their plans collects. On the Chronicle end anything that feeds through the parsers is enriched that can be. The O365 and Premium Defender ATP logs should com through to Chronicle same as E3-E5 Defender logs would. Unless there is some unusual caveat regarding their premium plan.  


TheSecOpsGuy
Forum|alt.badge.img+7
  • Author
  • Bronze 5
  • March 27, 2024

@DanHansen Thank you !