# AQUILA - Microsoft Office 365 Integration

#### <span style="color: rgb(53, 152, 219);">**<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">Overview</span></span>**</span>

<span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">This integration with Microsoft Office 365 supports the ingestion of user, administrator, system, and policy-related events. It leverages the Office 365 Management Activity API to retrieve activity logs from both Office 365 and Azure Active Directory (Azure AD).</span></span></span>

<span style="color: rgb(0, 0, 0);">This guide outlines the required steps to integrate with **Microsoft Office 365 and Azure AD** using the **Office 365 Management Activity API**. It covers application registration, permission setup, audit log configuration, and retrieval of key credentials for secure API access.</span>

---

#### <span style="color: rgb(53, 152, 219);">**Summary of Actions Required:**</span>

1. <span style="color: rgb(0, 0, 0);">**Register an Application** in Microsoft Entra ID (formerly Azure AD) to establish identity and enable API access.</span>
2. <span style="color: rgb(0, 0, 0);">**Configure API Permissions** for Microsoft Graph and Office 365 Management APIs to authorize required data access.</span>
3. <span style="color: rgb(0, 0, 0);">**Grant Admin Consent** to ensure permissions are applied tenant-wide.</span>
4. <span style="color: rgb(0, 0, 0);">**Collect Key Credentials** such as Application ID, Tenant ID, and Client Secret for use in your integration.</span>
5. <span style="color: rgb(0, 0, 0);">**Verify if Unified Audit Logging is Enabled** in Microsoft 365 to ensure activity data is available via the API.</span>

---

#### <span style="color: rgb(53, 152, 219);">**Action Items Before Proceeding:**</span>

- <span style="color: rgb(0, 0, 0);">Ensure you have **Global Admin** access to your Azure/Microsoft 365 tenant.</span>
- <span style="color: rgb(0, 0, 0);">Prepare to create or use an existing **App Registration** in Microsoft Entra ID.</span>
- <span style="color: rgb(0, 0, 0);">Confirm that **Unified Audit Logging** is enabled; otherwise, prepare to activate it via the Microsoft 365 portal or PowerShell.</span>
- <span style="color: rgb(0, 0, 0);">Take note of your **admin email address** for PowerShell commands if using CLI to manage audit log settings.</span>

---

<div class="euiFlexGroup css-1tueyet-euiFlexGroup-responsive-xs-flexStart-flexEnd-row" id="bkmrk-client-secret-value%3A"></div>#### <span style="color: rgb(53, 152, 219);">**Steps to Configure Office 365 Integration for the Client**</span>

##### <span style="color: rgb(53, 152, 219);">**<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 4">Step 1: Microsoft Entra ID</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335559738":319,"335559739":319}"> - App Registration</span>**</span>

<span style="color: rgb(0, 0, 0);">**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Register Your Application in Microsoft Entra ID:</span></span>**</span>

<div class="SCXW264382529 BCX0" id="bkmrk-how-to-locate%3A%C2%A0-log-"><div class="ListContainerWrapper SCXW264382529 BCX0">- - <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Log in to your Azure Account, click here - </span></span>**<span style="color: rgb(53, 152, 219);">[Azure Portal Link](https://portal.azure.com/#home)</span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">.</span></span> </span>
    - <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Navigate to </span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Azure Active Directory</span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0"> &gt; </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">App registrations</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">.</span></span> </span>
    - <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Click </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">New Registration</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">.</span></span> </span>
    - <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Provide a </span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Name</span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0"> for the application, we can suggest "**CyTechAQUILA-Monitoring**".</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></span>
    - <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Click </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Register</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">.</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></span>

</div><div class="ListContainerWrapper SCXW264382529 BCX0">  
</div></div>##### <span style="color: rgb(53, 152, 219);">**<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 4">Step 2: API Permissions</span></span>**</span>

<span style="color: rgb(0, 0, 0);">**<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 4"><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}">Microsoft Graph API Permissions:</span></span></span>**</span>

<span style="color: rgb(0, 0, 0);">If **User.Read** permission under **Microsoft Graph** tile is not added by default, add this permission.</span>

<div class="SCXW264382529 BCX0" id="bkmrk-how-to-locate%3A%C2%A0-navi"><div class="ListContainerWrapper SCXW264382529 BCX0">- - <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Navigate to </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">App registrations</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0"> in the Azure Portal.</span></span> </span>
    - <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Select the App you just created, then go to </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">API Permissions</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">.</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></span>
    - <span style="color: rgb(0, 0, 0);"><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}">Search for **Microsoft Graph.**</span></span>
    - <span class="NormalTextRun SCXW264382529 BCX0">Click </span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Add </span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW264382529 BCX0">a permission</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">.</span></span>
    - <span class="NormalTextRun SCXW264382529 BCX0">Select </span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Microsoft Graph</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0"> **&gt;** </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Delegated permissions</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">.</span></span>
    - <span class="NormalTextRun SCXW264382529 BCX0">Search for and add </span>**<span class="NormalTextRun SpellingErrorV2Themed SCXW264382529 BCX0">User.Read</span>**<span class="NormalTextRun SCXW264382529 BCX0">.</span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</div></div><span style="color: rgb(0, 0, 0);">**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Office 365 Management API Permissions:</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"> </span>**</span>

<div class="SCXW264382529 BCX0" id="bkmrk-how-to-locate%3A%C2%A0-in-a"><div class="ListContainerWrapper SCXW264382529 BCX0">- - <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Search for </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Office 365 Management APIs</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0"> and add the required permissions.</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></span>
    - <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">In </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Application Permissions</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">, look for permissions.</span></span></span>
    - <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SpellingErrorV2Themed SCXW264382529 BCX0">Under ActivityFeed select: </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SpellingErrorV2Themed SCXW264382529 BCX0">ActivityFeed.Read</span></span>** </span>
    - Optionally, select **ActivityFeed.ReadDLP** to read DLP policy events.

</div><div class="ListContainerWrapper SCXW264382529 BCX0">  
</div></div><span style="color: rgb(0, 0, 0);">**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Grant Admin Consent:</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"> </span>**</span>

<div class="SCXW264382529 BCX0" id="bkmrk-in-api-permissions%2C-"><div class="ListContainerWrapper SCXW264382529 BCX0">- - <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">In </span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">API Permissions</span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">, click </span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">**Grant admin consent** for &lt;tenant name&gt;</span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">.</span></span> </span>
    - <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">**Confirm** the action.</span></span></span><span style="color: rgb(0, 0, 0);"><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></span>

</div></div>[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/j87rAOhhKu89leDM-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/j87rAOhhKu89leDM-image.png)

##### <span style="color: rgb(53, 152, 219);">**<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 4">Step 3: Integration Requirements for Office 365</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335559738":319,"335559739":319}"> </span>**</span>

<span style="color: rgb(0, 0, 0);">**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Application (Client) ID:</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"> </span>**</span>

<div class="SCXW264382529 BCX0" id="bkmrk-how-to-locate%3A%C2%A0-go-t"><div class="ListContainerWrapper SCXW264382529 BCX0">- - <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Go to </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">App registrations</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0"> &gt; **Select your application**.</span></span> </span>
    - <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Copy the </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Application (client) ID</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0"> from the overview page.</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></span>

</div></div><span style="color: rgb(0, 0, 0);">**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Directory (Tenant) ID:</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"> </span>**</span>

<div class="SCXW264382529 BCX0" id="bkmrk-in-the-azure-portal%2C"><div class="ListContainerWrapper SCXW264382529 BCX0">- - <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">In the Azure Portal, navigate to </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Azure Active Directory</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0"> &gt; </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Overview</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">.</span></span> </span>
    - <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Copy the </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Directory (tenant) ID</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">.</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></span>

</div></div>[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/cxxxBJdvPcIbiMHV-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/cxxxBJdvPcIbiMHV-image.png)

<span style="color: rgb(0, 0, 0);">**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Create New Client Secret (Value):</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"> </span>**</span>

<div class="SCXW264382529 BCX0" id="bkmrk-in-app-registrations"><div class="ListContainerWrapper SCXW264382529 BCX0">- - <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">In </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">App registrations &gt; Select your application</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">, go to </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Certificates &amp; secrets</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">.</span></span> </span>
    - <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Click </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">New client secret</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">.</span></span> </span>
    - <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Add a description and </span><span class="NormalTextRun SCXW264382529 BCX0">expiration</span><span class="NormalTextRun SCXW264382529 BCX0"> period, then click </span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Add</span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">.</span></span> </span>
    - <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Copy the </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Value</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0"> **(displayed only once)**.</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></span>

</div></div>[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/fjoxX4o659L9qigQ-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/fjoxX4o659L9qigQ-image.png)

##### <span style="color: rgb(53, 152, 219);">**<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">Step </span><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">4:</span><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3"> Verify Unified Audit Logging</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335559738":281,"335559739":281}"> is Enabled</span>**</span>

<span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Unified Audit Logging must be enabled before accessing data via the Office 365 Management Activity API.</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"> </span></span>

<span style="color: rgb(0, 0, 0);">**<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">Method 1: Using Microsoft 365 Security &amp; Compliance Center</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335559738":281,"335559739":281}"> </span>**</span>

<div class="SCXW264382529 BCX0" id="bkmrk-sign-in-to-microsoft"><div class="ListContainerWrapper SCXW264382529 BCX0">1. <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Sign in to Microsoft 365:</span></span> </span>
    
    
    - <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Go to </span></span>[<span class="TextRun Underlined SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-charstyle="Hyperlink">https://admin.microsoft.com</span></span>](https://admin.microsoft.com/)<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0"> and sign in with your Global Admin credentials.</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></span>

</div></div><div class="SCXW264382529 BCX0" id="bkmrk-access-the-security-"><div class="ListContainerWrapper SCXW264382529 BCX0">2. <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Access the Security &amp; Compliance Center:</span></span> </span>
    
    
    - <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">In the left-hand menu, under </span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Admin centers</span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">, click on </span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Security</span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0"> (or go directly to </span></span>[<span class="TextRun Underlined SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-charstyle="Hyperlink">https://security.microsoft.com</span></span>](https://security.microsoft.com/)<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">).</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></span>

</div><div class="ListContainerWrapper SCXW264382529 BCX0">3. <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Navigate to Audit Log Search:</span></span> </span>
    
    
    - <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">In the Security &amp; Compliance Center, go to </span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Search</span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0"> in the left-hand menu and click on </span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Audit log search</span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">.</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></span>

</div><div class="ListContainerWrapper SCXW264382529 BCX0">4. <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Check Audit Log Status:</span></span> </span>
    
    
    - <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">If you see </span><span class="NormalTextRun SCXW264382529 BCX0">an option</span><span class="NormalTextRun SCXW264382529 BCX0"> to search the audit log, then audit logging is already enabled.</span></span></span> <span style="color: rgb(0, 0, 0);"><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}">[![image (2).png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/WHIm6mw3MmYsEzmv-image-2.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/WHIm6mw3MmYsEzmv-image-2.png)</span></span>

</div></div><div class="SCXW264382529 BCX0" id="bkmrk-if-you-see-a-banner-"><div class="ListContainerWrapper SCXW264382529 BCX0">- - <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">If you see a banner that says "Start recording user and admin activity" or a prompt to enable auditing, it means that audit logging is not yet enabled.</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></span><span style="color: rgb(0, 0, 0);"><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-05/scaled-1680-/iouUelw3mFkmCdPj-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-05/iouUelw3mFkmCdPj-image.png)</span></span>

</div></div><div class="SCXW264382529 BCX0" id="bkmrk--6"></div><div class="SCXW264382529 BCX0" id="bkmrk-enable-audit-logging"><div class="ListContainerWrapper SCXW264382529 BCX0">5. <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Enable Audit Logging:</span></span></span>
    
    
    - <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">If audit logging is not enabled, you can click on the prompt to enable it. This will enable auditing for all activities within your Microsoft 365 environment. The process may take a few hours to be fully operational.</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></span>

</div></div><span style="color: rgb(0, 0, 0);">**<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 4">Method 2: Using </span><span class="NormalTextRun SpellingErrorV2Themed SCXW264382529 BCX0" data-ccp-parastyle="heading 4">Powershell</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134245418":true,"134245529":true,"335559738":80,"335559739":40}"> </span>**</span>

<span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 4">1.</span><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 4">Install and Update Exchange Online Management Module</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134245418":true,"134245529":true,"335559738":80,"335559739":40}"> </span></span>

<div class="SCXW264382529 BCX0" id="bkmrk-open-powershell-as-a"><div class="ListContainerWrapper SCXW264382529 BCX0">- <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Open PowerShell as Administrator.</span></span> </span>
- <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Install the module:</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></span>

</div></div>```
Install-Module -Name ExchangeOnlineManagement
```

<div class="SCXW264382529 BCX0" id="bkmrk-update-the-module%3A%C2%A0"><div class="ListContainerWrapper SCXW264382529 BCX0">- <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Update the module:</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></span>

</div></div>```
Update-Module -Name ExchangeOnlineManagement
```

<div class="SCXW264382529 BCX0" id="bkmrk-import-the-module%C2%A0"><div class="ListContainerWrapper SCXW264382529 BCX0">- <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Import the module</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></span>

</div></div>```
Import-Module ExchangeOnlineManagement 
```

<span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 4">2.</span><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 4">Connect to Exchange Online</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335559738":319,"335559739":319}"> </span></span>

<div class="SCXW264382529 BCX0" id="bkmrk-run-the-following-co"><div class="ListContainerWrapper SCXW264382529 BCX0">- <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Run the following command:</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></span>

</div></div>```
Connect-ExchangeOnline -UserPrincipalName <admin-email-address>
```

<div class="SCXW264382529 BCX0" id="bkmrk-replace-%3Cadmin-email"><div class="ListContainerWrapper SCXW264382529 BCX0">- <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Replace &lt;admin-email-address&gt; with the admin email. Authenticate if </span><span class="NormalTextRun SCXW264382529 BCX0">required</span><span class="NormalTextRun SCXW264382529 BCX0">.</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></span>

</div></div><span style="color: rgb(0, 0, 0);">**<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 4">3.</span><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 4">Check and Enable Unified Audit Logging</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134245418":true,"134245529":true,"335559738":80,"335559739":40}"> </span>**</span>

<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" style="color: rgb(0, 0, 0);" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Check Status:</span></span>

<div class="SCXW264382529 BCX0" id="bkmrk-run%3A%C2%A0"><div class="ListContainerWrapper SCXW264382529 BCX0">- <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Run:</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></span>

</div></div>```
Get-AdminAuditLogConfig | Format-List UnifiedAuditLogIngestionEnabled
```

<div class="SCXW264382529 BCX0" id="bkmrk-if-the-output-is-tru"><div class="ListContainerWrapper SCXW264382529 BCX0">- <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">If the output is True, Unified Audit Logging is already enabled.</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></span>

</div></div><span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Enable Logging (if needed):</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"> </span></span>

<div class="SCXW264382529 BCX0" id="bkmrk-if-the-output-is-fal"><div class="ListContainerWrapper SCXW264382529 BCX0">- <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">If the output is False, enable it:</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></span>

</div></div>```
Set-AdminAuditLogConfig -UnifiedAuditLogIngestionEnabled $true
```

<div class="SCXW264382529 BCX0" id="bkmrk-verify-again%3A%C2%A0"><div class="ListContainerWrapper SCXW264382529 BCX0">- <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Verify again:</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></span>

</div></div>```
Get-AdminAuditLogConfig | Format-List UnifiedAuditLogIngestionEnabled 
```

#### <span style="color: rgb(53, 152, 219);"><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>**AQUILA – Microsoft 365 Integration <span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">Requirements</span></span>**</span>

<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" style="color: rgb(0, 0, 0);" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">Please saved and provide this values to AQUILA Support Team.</span></span>

1. <span style="color: rgb(0, 0, 0);">**<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">Directory (tenant) ID: </span></span>**</span>
2. <span style="color: rgb(0, 0, 0);">**<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">Application (client) ID:</span></span>**</span>
3. <div aria-label="Client Secret" class="euiFlexItem css-kpsrin-euiFlexItem-growZero"><span style="color: rgb(0, 0, 0);">**Client Secret Value:**</span><span style="color: rgb(0, 0, 0);"><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></span></div>

#### <span style="color: rgb(53, 152, 219);">**AQUILA – Microsoft 365 Integration**</span>

<span style="color: rgb(0, 0, 0);">**1.** Log in to AQUILA click here - <span style="color: rgb(53, 152, 219);">**[CyTech - AQUILA](https://cytechint.io/)**</span>. Choose **Cyber Monitoring** and click the **small arrow icon** to redirect you to the Cyber Monitoring Dashboard.</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/QUruqc4qZzjj39A2-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/QUruqc4qZzjj39A2-image.png)</span>

<span style="color: rgb(0, 0, 0);">2. In the dashboard, choose **Cyber Incident Management (SIEM and XDR)**.</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/i68EMO7YfIStKeyl-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/i68EMO7YfIStKeyl-image.png)</span>

<span style="color: rgb(0, 0, 0);">3. Navigate through the leftmost top and click **Cyber Incident Monitoring**.</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/KgRo0wYa67PKNCws-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/KgRo0wYa67PKNCws-image.png)</span>

<span style="color: rgb(0, 0, 0);">4. Navigate through **Settings&gt;Log Source&gt;Search Bar&gt;Add to Agent**.</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/fWvdjNBxjAB77OEo-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/fWvdjNBxjAB77OEo-image.png)

<span style="color: rgb(0, 0, 0);">5. Choose your **Log Collector**. *(If you not yet installed your **Log Collector** please refer to this link -*</span><span style="color: rgb(0, 0, 0);"> [**Log Collector** **Installation.**](https://docs.cytechint.io/books/log-collector-installations)</span><span style="color: rgb(0, 0, 0);">)</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/1VIERSAN80moG8fG-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/1VIERSAN80moG8fG-image.png)</span>

<span style="color: rgb(0, 0, 0);">6. In the integration settings follow the instructions given below.</span>

- <span style="color: rgb(0, 0, 0);">Click the **drop arrow** to display the contents needed for the integration setup.</span>
- <span style="color: rgb(0, 0, 0);">In the **Office 365 logs section** &gt; **Disable** &gt; **Collect Office 365 audit logs**</span>

<span style="color: rgb(0, 0, 0);">**[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/exwrKGAswsASVPAr-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/exwrKGAswsASVPAr-image.png)**</span>

- <span style="color: rgb(0, 0, 0);">Scroll down and go to **Microsoft Office 365 audit logs section**.</span>
- <span style="color: rgb(0, 0, 0);">Input the credentials for **Directory(tenant) ID, Application(client) ID and the Client Secret Value**.</span>
- <span style="color: rgb(0, 0, 0);">Finally, click **Next** to install the log source integration.</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/Tbrp2u6d1RtjobOm-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/Tbrp2u6d1RtjobOm-image.png)

<span style="color: rgb(0, 0, 0);">7. Wait for the **Successfull** window to display, this will confirm the successfull integration.</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/CNFzJRIuFuvZIEdI-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/CNFzJRIuFuvZIEdI-image.png)</span>

<span style="color: rgb(0, 0, 0);">*If you need further assistance, kindly contact our support at* <span style="color: rgb(53, 152, 219);">***support@cytechint.com***</span> *for prompt assistance and guidance.*</span>