Microsoft Defender for Office 365
Email and collaboration

Siem Server Integration

In brief

The documentation now includes steps for connecting the Microsoft Defender XDR connector in Microsoft Sentinel to stream Microsoft Defender for Office 365 email event data into a SIEM.

What Defender admins need to know

Administrators can use the added guidance when setting up this integration; no action is required for existing deployments.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

author: guywi-ms audience: ITPro ms.topic: how-to ms.date: 06/15/07/03/2026 ms.localizationpriority: medium ms.collection:

  • m365-security
  • tier2 ms.custom: msecd-doc-authoring-10141016
  • Ent_Solutions
  • SIEM
  • seo-marvel-apr2020 Is your organization using or planning to get a Security Information and Event Management (SIEM) server? You might be wondering how it integrates with Microsoft 365 or Office 365. This article provides a list of resources you can use to integrate your SIEM server with Microsoft 365 services and applications.

Do I need a SIEM server?

  • Your account in Microsoft Defender for Office 365 or Microsoft Defender is a Security Administrator.
  • Verify that you have Write permissions in Microsoft Sentinel.

Connect Microsoft Sentinel to Microsoft Defender for Office 365 data

Use the following steps to connect the Microsoft Defender XDR connector in Microsoft Sentinel and stream email event data from Microsoft Defender for Office 365 into your SIEM.

  1. Navigate to Microsoft Sentinel.

  2. In the left navigation pane, select Configuration > Data connectors.

  3. Search for Microsoft Defender XDR and select the Microsoft Defender XDR (preview) connector.

  4. Scroll to Microsoft Defender for Office 365 in the Connect events section of the page.

    You can also choose tables from any other Microsoft Defender product you find helpful and applicable before you select Apply Changes in the next step::

  5. Select EmailEvents, EmailUrlInfo, EmailAttachmentInfo, and EmailPostDeliveryEvents > and Apply Changes.

Related content

The following articles provide additional guidance on integrating security solutions and alerts with your SIEM server: