Microsoft 365 environments can contain a huge amount of security information:
- connections
- user activities
- modifications
- access
- identity-related events
- email events
- application-related events.
This data can be particularly useful for identifying:
- an account compromise
- unusual connections
- abnormal use of a privileged account
- configuration changes
- certain persistence activities.
A SIEM allows these events to be correlated with those coming from the rest of the infrastructure.