Microsoft 365 environments can contain a huge amount of security information:

  • connections
  • user activities
  • modifications
  • access
  • identity-related events
  • email events
  • application-related events.

This data can be particularly useful for identifying:

  • an account compromise
  • unusual connections
  • abnormal use of a privileged account
  • configuration changes
  • certain persistence activities.

A SIEM allows these events to be correlated with those coming from the rest of the infrastructure.

Categories: