11 May, 2021
Protect Office 365 with Azure Sentinel
Nanddeep Nachan
@NanddeepNachan
Smita Nachan
@SmitaNachan
AGENDA
 Challenges with Microsoft 365 environment monitoring
 Monitor Office 365 Logs from Azure Sentinel
 Threat detection with Azure Sentinel analytics
 Respond to Threats
 Q&A
Office 365 Consultant
Speaker | Author | Blogger
Nanddeep Nachan
 Pune, India
 Twitter Handle: @NanddeepNachan
 LinkedIn: /in/NanddeepNachan
 Microsoft MVP, MCT
 SharePoint, Microsoft 365, MS Azure
 Pune, India
 Twitter Handle: @SmitaNachan
 LinkedIn: /in/SmitaNachan
 Microsoft MVP, MCT
 SharePoint, Microsoft 365
Lead Software Engineer @TietoEVRY
Speaker | Author
Smita Nachan
Challenges with Microsoft 365
environment monitoring
 With the increase in usage, it is essential to keep track of user activities
 Potential security risk with admin activities
 Audit logs in the compliance center
Monitoring Microsoft 365 environments
Demo
Audit log in the compliance center
License Retention period
Office 365 E5 or Microsoft 365 E5 1 Year
(non-E5) Office 365 or Microsoft 365 90 Days
O365 Audit logs retention
 Auditing & Historical purpose
 Compliance
 Legal
Why we need O365 logs?
Azure Sentinel
Cloud-native SIEM platform
 Security Information and Event Manager (SIEM)
 Security Orchestration Automated Response (SOAR)
Azure Sentinel Overview
Image reference: https://docs.microsoft.com/azure/sentinel/overview
Demo
Set up Azure Sentinel
Connect Office 365 logs to Azure Sentinel
O365 Audit
Logs
User / Admin
Activities
O365 Data
Connector
Azure Sentinel
Log Analytics
Workspace
Office 365
 Read and write permissions on your Azure Sentinel workspace.
 Global administrator or security administrator rights on Office 365 tenant.
 Office 365 deployment must be on the same tenant as your Azure Sentinel workspace.
Prerequisites
Demo
Connect Office 365 logs to Azure Sentinel
Workbooks
Monitor the data
 Monitor data using the Azure Sentinel integration with Azure Monitor Workbooks
 Create custom workbooks across your data
 Combine data from various data sources and data types
 Visualize related data in a single interactive report
Workbooks
Demo
Azure Sentinel Workbooks
Analytics
Monitor the data
 Detect, investigate, and remediate cyber security threats
 Analyzes data from various sources to identify correlations and anomalies
 Trigger alerts based on the attack techniques
 Get insights of attack
 Create rule from Rule templates
Analytics
Demo
Create Analytics Rule
Respond to Threats
Use playbooks with automation rules in Azure Sentinel
 Create an automation rule
 Create a playbook
 Add actions to a playbook
 Attach a playbook to an automation rule or an analytics rule to automate threat response
Automate your incident response
Demo
Use playbooks with automation rules
 Azure Sentinel
 https://docs.microsoft.com/en-us/azure/sentinel/overview
 Monitor Office 365 Logs from Azure Sentinel
 https://nanddeepnachanblogs.com/posts/2021-03-14-monitor-o365-logs-azure-sentinel/
 Threat detection with Azure Sentinel analytics
 https://nanddeepnachanblogs.com/posts/2021-04-15-threat-detection-with-azure-sentinel-analytics/
 Log analytics samples (KQL queries) by Brian T. Jackett
 https://github.com/BrianTJackett/log-analytics-samples
References
Q&A
Thank You!
@NanddeepNachan
/in/NanddeepNachan
Nanddeep Nachan
@SmitaNachan
/in/SmitaNachan
Smita Nachan

More Related Content

PPTX
Azure sentinel
PPTX
Getting Started with Azure Sentinel
PPTX
Threat Hunting on AWS using Azure Sentinel
PPTX
Azure sentinal
PPTX
Journey to Azure Sentinel
PPTX
Azure Sentinel with Office 365
PPTX
Azure Sentinel
PDF
7 Experts on Implementing Azure Sentinel
Azure sentinel
Getting Started with Azure Sentinel
Threat Hunting on AWS using Azure Sentinel
Azure sentinal
Journey to Azure Sentinel
Azure Sentinel with Office 365
Azure Sentinel
7 Experts on Implementing Azure Sentinel

What's hot (20)

PPTX
Modernize your Security Operations with Azure Sentinel
PDF
Introduction to Azure Sentinel
PPTX
Remediate and secure your organization with azure sentinel
PDF
Haal de mist uit de monitoring van je cloud met System Center 2012 R2 Operati...
PDF
introduction to Azure Sentinel
PPTX
Azure Sentinel Jan 2021 overview deck
PPTX
Microsoft Azure News - April 2021
PDF
Azure Day Rome Reloaded 2019 - Azure Sentinel: set up automated threat respon...
PDF
Azure Sentinel Tips
PPTX
Azure Security Center- Zero to Hero
PDF
Elastic SIEM (Endpoint Security)
PDF
ISC2 Secure Summit EMEA - Top Microsoft Azure security fails and how to avoid...
PDF
Global Azure Bootcamp 2018 - Azure Security Center
PDF
Getting Started with Azure Security Center
PPTX
Document fingerprinting in Microsoft 365 Compliance
PPTX
MCAS High Level Architecture May 2021
PDF
Elastic Security: Proteção Empresarial construída sobre o Elastic Stack
PDF
Elastic Security: Enterprise Protection Built on the Elastic Stack
PPTX
20171207 we are moving to the cloud what about security
PPTX
Using m365 defender to protect against solorigate
Modernize your Security Operations with Azure Sentinel
Introduction to Azure Sentinel
Remediate and secure your organization with azure sentinel
Haal de mist uit de monitoring van je cloud met System Center 2012 R2 Operati...
introduction to Azure Sentinel
Azure Sentinel Jan 2021 overview deck
Microsoft Azure News - April 2021
Azure Day Rome Reloaded 2019 - Azure Sentinel: set up automated threat respon...
Azure Sentinel Tips
Azure Security Center- Zero to Hero
Elastic SIEM (Endpoint Security)
ISC2 Secure Summit EMEA - Top Microsoft Azure security fails and how to avoid...
Global Azure Bootcamp 2018 - Azure Security Center
Getting Started with Azure Security Center
Document fingerprinting in Microsoft 365 Compliance
MCAS High Level Architecture May 2021
Elastic Security: Proteção Empresarial construída sobre o Elastic Stack
Elastic Security: Enterprise Protection Built on the Elastic Stack
20171207 we are moving to the cloud what about security
Using m365 defender to protect against solorigate
Ad

Similar to Protect Office 365 with Azure Sentinel (20)

PDF
Planning and implementing. Unveiling the advanced technology of Microsoft Azu...
PPTX
Azure Sentinel.pptx
PPTX
Adam ochs sentinel
PPTX
NVS_Sentinel
PPTX
Microsoft Sentinel and Its Components.pptx
PPTX
TechTalksUtah-Sentinel-20191108.pptx
PPTX
07 - Defend Against Threats with SIEM Plus XDR Workshop - Microsoft Sentinel ...
PDF
Microsoft Azure Sentinel
PPTX
Microsoft Sentinel Deployment V1.pptx
PPTX
SEIM-Microsoft Sentinel.pptx
PDF
Azure Sentinel
PPTX
Purview Days 2023 - Graph Notifications - A better way to process M365 Audit ...
PDF
Microsoft Sentinel- a cloud native SIEM & SOAR.pdf
PDF
L400-P1 Overview.pdf
PDF
How to get deeper administration insights into your tenant
PDF
do you want to know about what is Microsoft Sentinel.pdf
PPTX
SC-900 Capabilities of Microsoft Security Solutions
PDF
Security management
PPTX
Cloudbrew 2019 - Threat hunting with the Microsoft Cloud
PDF
Thr30117 - Securely logging to Microsoft 365
Planning and implementing. Unveiling the advanced technology of Microsoft Azu...
Azure Sentinel.pptx
Adam ochs sentinel
NVS_Sentinel
Microsoft Sentinel and Its Components.pptx
TechTalksUtah-Sentinel-20191108.pptx
07 - Defend Against Threats with SIEM Plus XDR Workshop - Microsoft Sentinel ...
Microsoft Azure Sentinel
Microsoft Sentinel Deployment V1.pptx
SEIM-Microsoft Sentinel.pptx
Azure Sentinel
Purview Days 2023 - Graph Notifications - A better way to process M365 Audit ...
Microsoft Sentinel- a cloud native SIEM & SOAR.pdf
L400-P1 Overview.pdf
How to get deeper administration insights into your tenant
do you want to know about what is Microsoft Sentinel.pdf
SC-900 Capabilities of Microsoft Security Solutions
Security management
Cloudbrew 2019 - Threat hunting with the Microsoft Cloud
Thr30117 - Securely logging to Microsoft 365
Ad

More from Nanddeep Nachan (20)

PPTX
Building Copilot for Microsoft 365 with Teams Toolkit
PPTX
PnP Demo - Streamlining Internal Marketplaces using Microsoft Copilot and a T...
PPTX
MS Copilot expands with MS Graph connectors
PPTX
Prompt to Pixel: DALL-E Magic
PPTX
Knowledge Quest Teams Bot.pptx
PPTX
Building Bots with Teams Toolkit
PPTX
Power Apps for Azure Cloud Professionals
PPTX
aMS Pune - Building apps for Teams meetings
PPTX
Universal Actions for Adaptive Cards on Microsoft Teams
PPTX
Building Bots with Azure and consume anywhere.pptx
PPTX
Power Platform Custom Connector Deep Dive.pptx
PPTX
Sessionize Custom Connector
PPTX
SharePoint PnP Viva Connections & SPFx JS SIG Call - My M365 Groups
PPTX
Bring your SharePoint apps to MS Teams
PPTX
Microsoft Viva Connections - Set up and Extend with SPFx
PPTX
Information Barriers in MS Teams
PPTX
PL-100 Microsoft Power Platform App Maker
PPTX
Explore Microsoft Power Platform Center of Excellence
PPTX
SharePoint PnP Demo - Questionnaire Teams Meeting App with SPFx
PPTX
SharePoint PnP Demo - react-manage-o365-groups
Building Copilot for Microsoft 365 with Teams Toolkit
PnP Demo - Streamlining Internal Marketplaces using Microsoft Copilot and a T...
MS Copilot expands with MS Graph connectors
Prompt to Pixel: DALL-E Magic
Knowledge Quest Teams Bot.pptx
Building Bots with Teams Toolkit
Power Apps for Azure Cloud Professionals
aMS Pune - Building apps for Teams meetings
Universal Actions for Adaptive Cards on Microsoft Teams
Building Bots with Azure and consume anywhere.pptx
Power Platform Custom Connector Deep Dive.pptx
Sessionize Custom Connector
SharePoint PnP Viva Connections & SPFx JS SIG Call - My M365 Groups
Bring your SharePoint apps to MS Teams
Microsoft Viva Connections - Set up and Extend with SPFx
Information Barriers in MS Teams
PL-100 Microsoft Power Platform App Maker
Explore Microsoft Power Platform Center of Excellence
SharePoint PnP Demo - Questionnaire Teams Meeting App with SPFx
SharePoint PnP Demo - react-manage-o365-groups

Recently uploaded (20)

PPTX
Configure Apache Mutual Authentication
PDF
Five Habits of High-Impact Board Members
PPTX
Build Your First AI Agent with UiPath.pptx
PDF
Consumable AI The What, Why & How for Small Teams.pdf
PPTX
Microsoft Excel 365/2024 Beginner's training
PDF
How IoT Sensor Integration in 2025 is Transforming Industries Worldwide
PDF
Improvisation in detection of pomegranate leaf disease using transfer learni...
PDF
Architecture types and enterprise applications.pdf
PPTX
The various Industrial Revolutions .pptx
PDF
STKI Israel Market Study 2025 version august
PDF
CloudStack 4.21: First Look Webinar slides
PDF
Comparative analysis of machine learning models for fake news detection in so...
PPTX
Modernising the Digital Integration Hub
PDF
Accessing-Finance-in-Jordan-MENA 2024 2025.pdf
PPTX
AI IN MARKETING- PRESENTED BY ANWAR KABIR 1st June 2025.pptx
PPTX
GROUP4NURSINGINFORMATICSREPORT-2 PRESENTATION
PPTX
Training Program for knowledge in solar cell and solar industry
PPT
Galois Field Theory of Risk: A Perspective, Protocol, and Mathematical Backgr...
PDF
Enhancing plagiarism detection using data pre-processing and machine learning...
PDF
OpenACC and Open Hackathons Monthly Highlights July 2025
Configure Apache Mutual Authentication
Five Habits of High-Impact Board Members
Build Your First AI Agent with UiPath.pptx
Consumable AI The What, Why & How for Small Teams.pdf
Microsoft Excel 365/2024 Beginner's training
How IoT Sensor Integration in 2025 is Transforming Industries Worldwide
Improvisation in detection of pomegranate leaf disease using transfer learni...
Architecture types and enterprise applications.pdf
The various Industrial Revolutions .pptx
STKI Israel Market Study 2025 version august
CloudStack 4.21: First Look Webinar slides
Comparative analysis of machine learning models for fake news detection in so...
Modernising the Digital Integration Hub
Accessing-Finance-in-Jordan-MENA 2024 2025.pdf
AI IN MARKETING- PRESENTED BY ANWAR KABIR 1st June 2025.pptx
GROUP4NURSINGINFORMATICSREPORT-2 PRESENTATION
Training Program for knowledge in solar cell and solar industry
Galois Field Theory of Risk: A Perspective, Protocol, and Mathematical Backgr...
Enhancing plagiarism detection using data pre-processing and machine learning...
OpenACC and Open Hackathons Monthly Highlights July 2025

Protect Office 365 with Azure Sentinel

  • 1. 11 May, 2021 Protect Office 365 with Azure Sentinel Nanddeep Nachan @NanddeepNachan Smita Nachan @SmitaNachan
  • 2. AGENDA  Challenges with Microsoft 365 environment monitoring  Monitor Office 365 Logs from Azure Sentinel  Threat detection with Azure Sentinel analytics  Respond to Threats  Q&A
  • 3. Office 365 Consultant Speaker | Author | Blogger Nanddeep Nachan  Pune, India  Twitter Handle: @NanddeepNachan  LinkedIn: /in/NanddeepNachan  Microsoft MVP, MCT  SharePoint, Microsoft 365, MS Azure
  • 4.  Pune, India  Twitter Handle: @SmitaNachan  LinkedIn: /in/SmitaNachan  Microsoft MVP, MCT  SharePoint, Microsoft 365 Lead Software Engineer @TietoEVRY Speaker | Author Smita Nachan
  • 5. Challenges with Microsoft 365 environment monitoring
  • 6.  With the increase in usage, it is essential to keep track of user activities  Potential security risk with admin activities  Audit logs in the compliance center Monitoring Microsoft 365 environments
  • 7. Demo Audit log in the compliance center
  • 8. License Retention period Office 365 E5 or Microsoft 365 E5 1 Year (non-E5) Office 365 or Microsoft 365 90 Days O365 Audit logs retention
  • 9.  Auditing & Historical purpose  Compliance  Legal Why we need O365 logs?
  • 11.  Security Information and Event Manager (SIEM)  Security Orchestration Automated Response (SOAR) Azure Sentinel Overview Image reference: https://docs.microsoft.com/azure/sentinel/overview
  • 12. Demo Set up Azure Sentinel
  • 13. Connect Office 365 logs to Azure Sentinel O365 Audit Logs User / Admin Activities O365 Data Connector Azure Sentinel Log Analytics Workspace Office 365
  • 14.  Read and write permissions on your Azure Sentinel workspace.  Global administrator or security administrator rights on Office 365 tenant.  Office 365 deployment must be on the same tenant as your Azure Sentinel workspace. Prerequisites
  • 15. Demo Connect Office 365 logs to Azure Sentinel
  • 17.  Monitor data using the Azure Sentinel integration with Azure Monitor Workbooks  Create custom workbooks across your data  Combine data from various data sources and data types  Visualize related data in a single interactive report Workbooks
  • 20.  Detect, investigate, and remediate cyber security threats  Analyzes data from various sources to identify correlations and anomalies  Trigger alerts based on the attack techniques  Get insights of attack  Create rule from Rule templates Analytics
  • 22. Respond to Threats Use playbooks with automation rules in Azure Sentinel
  • 23.  Create an automation rule  Create a playbook  Add actions to a playbook  Attach a playbook to an automation rule or an analytics rule to automate threat response Automate your incident response
  • 24. Demo Use playbooks with automation rules
  • 25.  Azure Sentinel  https://docs.microsoft.com/en-us/azure/sentinel/overview  Monitor Office 365 Logs from Azure Sentinel  https://nanddeepnachanblogs.com/posts/2021-03-14-monitor-o365-logs-azure-sentinel/  Threat detection with Azure Sentinel analytics  https://nanddeepnachanblogs.com/posts/2021-04-15-threat-detection-with-azure-sentinel-analytics/  Log analytics samples (KQL queries) by Brian T. Jackett  https://github.com/BrianTJackett/log-analytics-samples References
  • 26. Q&A

Editor's Notes

  • #11: https://docs.microsoft.com/en-us/azure/sentinel/overview
  • #17: https://docs.microsoft.com/en-us/azure/azure-monitor/visualize/workbooks-overview
  • #23: https://docs.microsoft.com/en-us/azure/sentinel/tutorial-respond-threats-playbook