> ## Documentation Index
> Fetch the complete documentation index at: https://docs.insecureweb.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Integration guide for Office365

> Microsoft 365, formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line

## To connect UTMStack with Office365:

#### 1. Open the Azure

<Tip>
  [Azure’s Portal](https://portal.azure.com/). Click on Microsoft Entra ID.
</Tip>

<img height="200" className="block rounded-xl" src="https://mintcdn.com/insecurewebllc/lfYYvC-pPoHEyH8F/images/integrations/office365/o365-portal.png?fit=max&auto=format&n=lfYYvC-pPoHEyH8F&q=85&s=f309914426493db1a1da1a31ed6a4f59" alt="Office365" data-path="images/integrations/office365/o365-portal.png" />

#### 2. Go to App registrations

<img height="200" className="block rounded-xl" src="https://mintcdn.com/insecurewebllc/lfYYvC-pPoHEyH8F/images/integrations/office365/o365-app-registration.png?fit=max&auto=format&n=lfYYvC-pPoHEyH8F&q=85&s=bc3e772a5001447026bec4d5590ee658" alt="Office365" data-path="images/integrations/office365/o365-app-registration.png" />

#### 3. Add a new app

<Tip>
  Clicking the **"New registration"** button and fill-up the form, with the name **"UTMStack O365 Agent", and select the option "Accounts in this organizational directory only to (Single-tenant)"** and click on register.
</Tip>

<img height="200" className="block rounded-xl" src="https://mintcdn.com/insecurewebllc/lfYYvC-pPoHEyH8F/images/integrations/office365/o365-register-app.png?fit=max&auto=format&n=lfYYvC-pPoHEyH8F&q=85&s=3305da3e93f7f794755bbc9429745e51" alt="Office365" data-path="images/integrations/office365/o365-register-app.png" />

#### 4.In the newly created App registration

<Tip>
  Go to Certificates & Secrets, and create a new one by clicking on "New client secret". Add a description. Set it to expires in 730 days (24 months) and click on Add. Copy the value in a safe place.
</Tip>

<img height="200" className="block rounded-xl" src="https://mintcdn.com/insecurewebllc/lfYYvC-pPoHEyH8F/images/integrations/office365/o365-certificate-secret.png?fit=max&auto=format&n=lfYYvC-pPoHEyH8F&q=85&s=1258be713b5ea854416b4cbf8240b791" alt="Office365" data-path="images/integrations/office365/o365-certificate-secret.png" />

#### 5. From the same App registration menu, look for "API Permissions" and click on "Add Permissions" and look for "Office 365 Management API".

<img height="200" className="block rounded-xl" src="https://mintcdn.com/insecurewebllc/lfYYvC-pPoHEyH8F/images/integrations/office365/o365-api-permission.png?fit=max&auto=format&n=lfYYvC-pPoHEyH8F&q=85&s=3add34d34069585c9663b7f3225e977e" alt="Office365" data-path="images/integrations/office365/o365-api-permission.png" />

#### 6. Select "Application Permissions" and, add the ActivityFeed.Read and ActivityFeed.ReadDlp permissions. Then click on "Grant admin consent for X" and confirm.

<img height="200" className="block rounded-xl" src="https://mintcdn.com/insecurewebllc/lfYYvC-pPoHEyH8F/images/integrations/office365/o365-api-permission-request.png?fit=max&auto=format&n=lfYYvC-pPoHEyH8F&q=85&s=d564c72ed23a53c79ab59bd719935e40" alt="Office365" data-path="images/integrations/office365/o365-api-permission-request.png" />

#### 7. From the same "Request API Permissions" click on "Microsoft Graph"

<img height="200" className="block rounded-xl" src="https://mintcdn.com/insecurewebllc/lfYYvC-pPoHEyH8F/images/integrations/office365/o365-activity-feed.png?fit=max&auto=format&n=lfYYvC-pPoHEyH8F&q=85&s=5246e4c5f6ffd49b45b174a7739952b7" alt="Office365" data-path="images/integrations/office365/o365-activity-feed.png" />

#### 8. Select "Delegated Permissions" and, add the SecurityAlert.Read.All and SecurityAlert.ReadWrite.All permissions. Then click on "Grant admin consent for X" and confirm.

<img height="200" className="block rounded-xl" src="https://mintcdn.com/insecurewebllc/lfYYvC-pPoHEyH8F/images/integrations/office365/o365-delegated-permission.png?fit=max&auto=format&n=lfYYvC-pPoHEyH8F&q=85&s=3c4d83e5a9e4f6387d06f9dcff4d2d41" alt="Office365" data-path="images/integrations/office365/o365-delegated-permission.png" />

#### 9. Select "Application Permissions" and, add the SecurityAlert.Read.All and SecurityAlert.ReadWrite.All permissions. Then click on "Grant admin consent for X" and confirm.

<img height="200" className="block rounded-xl" src="https://mintcdn.com/insecurewebllc/lfYYvC-pPoHEyH8F/images/integrations/office365/o365-app-permission.png?fit=max&auto=format&n=lfYYvC-pPoHEyH8F&q=85&s=f8b38e90fd76a8e0673d2dd1b4e71d2e" alt="Office365" data-path="images/integrations/office365/o365-app-permission.png" />

#### 10. Go to [https://compliance.microsoft.com](https://compliance.microsoft.com) and sign in.

#### 11. In the left navigation pane of the compliance portal, select Audit.

<Note>
  If auditing isn't turned on for your organization, a banner is displayed prompting you start recording user and admin activity.
</Note>

<img height="200" className="block rounded-xl" src="https://mintcdn.com/insecurewebllc/lfYYvC-pPoHEyH8F/images/integrations/office365/o365-auditing-banner.png?fit=max&auto=format&n=lfYYvC-pPoHEyH8F&q=85&s=3a1fa8f4220b7a553182ca6f3eec8e12" alt="Office365" data-path="images/integrations/office365/o365-auditing-banner.png" />

#### 12. Select the Start recording user and admin activity banner. It may take up to 60 minutes for the change to take effect.

#### 13. Return to Azure Active Directory and go to the Registered Apps (step number 3) and make a note the info that appears in the Overview section (client ID, tenant ID) and the secret.

<img height="200" className="block rounded-xl" src="https://mintcdn.com/insecurewebllc/lfYYvC-pPoHEyH8F/images/integrations/office365/o365-overview-client.png?fit=max&auto=format&n=lfYYvC-pPoHEyH8F&q=85&s=8abff2ec0de05aecf039ed5b6717e605" alt="Office365" data-path="images/integrations/office365/o365-overview-client.png" />

#### 14. Insert information in the following inputs.You can add more than one o365 configuration by clicking on Add tenant button.

<img height="200" className="block rounded-xl" src="https://mintcdn.com/insecurewebllc/lfYYvC-pPoHEyH8F/images/integrations/office365/step14.png?fit=max&auto=format&n=lfYYvC-pPoHEyH8F&q=85&s=5876badb742b0d3520bd015fce2bec52" alt="Office365" data-path="images/integrations/office365/step14.png" />

#### 15. Click on the button shown below, to activate the UTMStack features related to this integration
