Collect Microsoft Defender logs
Overview
The following article outlines a basic data flow from Microsoft Defender for Office 365 (MDO) to the Office 365 Listener.
Prerequisites
Administrative access to the Microsoft Defender portal
Contact Onum to get the required JWT token, which will be needed on the Listener setup.
You can also contact us if you cannot generate the required TLS certificates. Note that these certificates must be signed by a recognized Certificate Authority (CA). Self-signed certificates are not accepted.
Defender for Cloud Apps Setup
Microsoft Defender for Office 356 (MDO) can be configured to send logs to Onum. Here's how to set it up:
Access the Microsoft Defender for Office 365 portal.
Go to Azure Active Directory > App registrations
Click New registration and give it a name.
Supported account type - Accounts in this organizational directory only
Redirect URI - Leave blank for now
Click "Register"
Retrieve the Application (Client) ID
Go to the All Applications tab and click on the application name.
On the overview page, you'll see "Application (client) ID" displayed prominently. This is the GUID you need for Onum.
In your new app registration, go to API permissions
Click Add a permission and select Microsoft Graph > Application permissions
Add these permissions
SecurityEvents.Read.AllSecurityEvents.ReadWrite.AllSecurityIncident.Read.AllThreatIntelligence.Read.All
For Office 365 Management API, add
ActivityFeed.ReadActivityFeed.ReadDlpServiceHealth.Read
Click Grant admin consent
Create a client secret
Go to Certificates & secrets
Click New client secret
Add a description and select expiration
Copy the secret value immediately (it won't be shown again)
Locate and save your Tenant ID
Go to Azure Active Directory > App registrations
On the Azure AD overview page, look for Tenant ID in the basic information section. It will be displayed as a GUID (e.g., 12a34567-89b0-12c3-d456-789012ef3456).
Keep it somewhere safe to paste it into the Listener.
Start/stop a subscription
The Office 365 Listener supports the start/stop subscription feature. You can start/stop a subscription using some other Office 365 API or using this curl command:
You should get a response like this:
Use the access_token value to start or stop a subscription. These are the available content values:
Audit.AzureActiveDirectoryAudit.ExchangeAudit.SharePointAudit.GeneralDLP.All
These are some of the requests you can perform:
Start a subscription to begin receiving notifications and retrieving activity data for a tenant.
Stop a subscription to discontinue retrieving data for a tenant:
Content type example (this will subscribe you to active directory and exchange):
Here is the list of all the API requests you can use. Once you start subscription, you can use the Listener to fetch your data.
For easier testing, here is the curl command to fetch the list of updates:
Onum Setup
Log in to your Onum tenant and click Listeners > New listener. Double-click the Azure Event Hubs Listener. See the configuration steps in this article.
Last updated
Was this helpful?

