For the complete documentation index, see llms.txt. This page is also available as Markdown.

Collect Microsoft Defender logs

Overview

The following article outlines a basic data flow from Microsoft Defender for Office 365 (MDO) to the Office 365 Listener.

Prerequisites

  • Administrative access to the Microsoft Defender portal

Contact Onum to get the required JWT token, which will be needed on the Listener setup.

You can also contact us if you cannot generate the required TLS certificates. Note that these certificates must be signed by a recognized Certificate Authority (CA). Self-signed certificates are not accepted.

Defender for Cloud Apps Setup

Microsoft Defender for Office 356 (MDO) can be configured to send logs to Onum. Here's how to set it up:

  1. Go to Azure Active Directory > App registrations

    • Click New registration and give it a name.

    • Supported account type - Accounts in this organizational directory only

    • Redirect URI - Leave blank for now

    • Click "Register"

  2. Retrieve the Application (Client) ID

    • Go to the All Applications tab and click on the application name.

    • On the overview page, you'll see "Application (client) ID" displayed prominently. This is the GUID you need for Onum.

  3. In your new app registration, go to API permissions

    • Click Add a permission and select Microsoft Graph > Application permissions

    • Add these permissions

      • SecurityEvents.Read.All

      • SecurityEvents.ReadWrite.All

      • SecurityIncident.Read.All

      • ThreatIntelligence.Read.All

    • For Office 365 Management API, add

      • ActivityFeed.Read

      • ActivityFeed.ReadDlp

      • ServiceHealth.Read

    • Click Grant admin consent

  4. Create a client secret

    • Go to Certificates & secrets

    • Click New client secret

    • Add a description and select expiration

    • Copy the secret value immediately (it won't be shown again)

  5. Locate and save your Tenant ID

    • Go to Azure Active Directory > App registrations

    • On the Azure AD overview page, look for Tenant ID in the basic information section. It will be displayed as a GUID (e.g., 12a34567-89b0-12c3-d456-789012ef3456).

    • Keep it somewhere safe to paste it into the Listener.

Start/stop a subscription

The Office 365 Listener supports the start/stop subscription feature. You can start/stop a subscription using some other Office 365 API or using this curl command:

You should get a response like this:

Use the access_token value to start or stop a subscription. These are the available content values:

  • Audit.AzureActiveDirectory

  • Audit.Exchange

  • Audit.SharePoint

  • Audit.General

  • DLP.All

These are some of the requests you can perform:

  • Start a subscription to begin receiving notifications and retrieving activity data for a tenant.

  • Stop a subscription to discontinue retrieving data for a tenant:

  • Content type example (this will subscribe you to active directory and exchange):

Here is the list of all the API requests you can use. Once you start subscription, you can use the Listener to fetch your data.

For easier testing, here is the curl command to fetch the list of updates:

Onum Setup

Log in to your Onum tenant and click Listeners > New listener. Double-click the Azure Event Hubs Listener. See the configuration steps in this article.

Last updated

Was this helpful?