# Microsoft 365

<div class="SCXW268368253 BCX8" id="bkmrk-"><div class="ListContainerWrapper SCXW268368253 BCX8">  
</div></div><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW268368253 BCX8" data-ccp-charstyle="Style (Complex) Open Sans">Microsoft</span><span class="NormalTextRun SCXW268368253 BCX8" data-ccp-charstyle="Style (Complex) Open Sans"> Office 365</span><span class="NormalTextRun SCXW268368253 BCX8" data-ccp-charstyle="Style (Complex) Open Sans"> integration</span> <span class="NormalTextRun SCXW268368253 BCX8" data-ccp-charstyle="Style (Complex) Open Sans">currently supports user, admin, system, and policy actions and events from Office 365 and Azure AD activity logs exposed by the Office 365 Management Activity API.</span></span>

##### **<span class="TextRun SCXW268368253 BCX8" data-contrast="none" lang="EN-US" style="color: rgb(53, 152, 219);" xml:lang="EN-US"><span class="NormalTextRun SCXW268368253 BCX8" data-ccp-charstyle="Style (Complex) Open Sans">Procedures</span></span><span class="EOP SCXW268368253 BCX8" data-ccp-props="{"134245418":true,"134245529":true,"201341983":0,"335559738":40,"335559739":0,"335559740":259}"> </span>**

<span style="color: rgb(53, 152, 219);"><span class="TextRun SCXW268368253 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW268368253 BCX8" data-ccp-charstyle="Intense Emphasis">To perform the setup, please confirm that you have the following access:</span></span><span class="EOP SCXW268368253 BCX8" data-ccp-props="{"201341983":0,"335559685":720,"335559739":160,"335559740":259}"> </span></span>

<div class="SCXW268368253 BCX8" id="bkmrk-a-microsoft-office-3"><div class="ListContainerWrapper SCXW268368253 BCX8">1. <span class="TextRun SCXW268368253 BCX8" data-contrast="none" lang="EN-CA" xml:lang="EN-CA"><span class="NormalTextRun SCXW268368253 BCX8" data-ccp-charstyle="Style (Complex) Open Sans">A Microsoft Office 365 account with Administrative Privileges</span></span>
2. <span class="TextRun SCXW268368253 BCX8" data-contrast="none" lang="EN-CA" xml:lang="EN-CA"><span class="NormalTextRun SCXW268368253 BCX8" data-ccp-charstyle="Style (Complex) Open Sans">A Microsoft Azure account with Administrative Privileges</span></span><span class="EOP SCXW268368253 BCX8" data-ccp-props="{"201341983":0,"335559685":1080,"335559739":160,"335559740":360}"> </span>

</div><div class="ListContainerWrapper SCXW268368253 BCX8">  
</div></div><span style="color: rgb(53, 152, 219);"><span class="TextRun SCXW268368253 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW268368253 BCX8" data-ccp-charstyle="Style (Complex) Open Sans">Register a new Office 365 web application</span></span> <span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">To get started collecting Office 365 logs, register an Office 365 web application:</span></span><span class="EOP SCXW268368253 BCX8" data-ccp-props="{"201341983":0,"335559685":720,"335559739":160,"335559740":259}"> </span></span>

<div class="SCXW268368253 BCX8" id="bkmrk-log-into-the-office-"><div class="ListContainerWrapper SCXW268368253 BCX8">1. <span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">Log into the Office 365 portal as an Active Directory tenant administrator.</span></span>
2. <span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">Click </span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">Show all</span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8"> to expand the left navigation area, and then click </span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">Azure Active Directory</span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">.</span></span>
3. <span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">Select </span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">App Registrations</span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">, and then click </span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">+ New application registration</span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">.</span></span><span class="EOP SCXW268368253 BCX8" data-ccp-props="{"201341983":0,"335559685":1440,"335559739":160,"335559740":259}"> </span>
4. <span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">Provide the following information in the fields:</span></span><span class="EOP SCXW268368253 BCX8" data-ccp-props="{"201341983":0,"335559685":1440,"335559739":160,"335559740":259}"> </span>

</div><div class="ListContainerWrapper SCXW268368253 BCX8">1. 1. - <span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">Name – for example, o365</span><span class="NormalTextRun SCXW268368253 BCX8">cytech</span><span class="NormalTextRun SCXW268368253 BCX8">.</span></span>
        - <span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">Select </span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">Single tenant</span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8"> for supported account types.</span></span>
        - <span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">Leave the Redirect URI blank.</span></span>
        - <span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">The </span></span><span class="TextRun Highlight SCXW268368253 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW268368253 BCX8">Audit Log Search</span> </span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">needs to be enabled.</span></span>
        - <span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">Click </span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">Register</span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8"> and note the Application (client) ID.</span></span><span class="EOP SCXW268368253 BCX8" data-ccp-props="{"201341983":0,"335559685":1440,"335559739":160,"335559740":259}"> </span>

</div><div class="ListContainerWrapper SCXW268368253 BCX8">  
</div></div><span style="color: rgb(53, 152, 219);"><span class="TextRun SCXW268368253 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW268368253 BCX8" data-ccp-charstyle="Style (Complex) Open Sans">Setup Active Directory security permissions</span></span> </span>

<span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">The Active Directory security permissions allow the application you created to read threat intelligence data and activity reports for your organization.</span></span><span class="EOP SCXW268368253 BCX8" data-ccp-props="{"201341983":0,"335559685":720,"335559739":160,"335559740":259}"> </span>

<span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">To set up Active Directory permissions:</span></span><span class="EOP SCXW268368253 BCX8" data-ccp-props="{"201341983":0,"335559685":720,"335559739":160,"335559740":259}"> </span>

<div class="SCXW268368253 BCX8" id="bkmrk-on-the-main-panel-un"><div class="ListContainerWrapper SCXW268368253 BCX8">1. <span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">On the main panel under the new application, click </span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">API Permissions</span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">, and then click </span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">+ Add </span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW268368253 BCX8">a permission</span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">.</span></span>
2. <span class="NormalTextRun SCXW268368253 BCX8">Locate and click on </span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">Office 365 Management APIs</span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">.</span></span>
3. <span class="NormalTextRun SCXW268368253 BCX8">In </span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">Application permissions</span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">, expand and select </span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SpellingErrorV2Themed SCXW268368253 BCX8">ActivityFeed.Read</span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">, </span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SpellingErrorV2Themed SCXW268368253 BCX8">ActivityFeed.ReadDlp</span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">, </span></span><span class="TrackedChange SCXW268368253 BCX8"><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SpellingErrorV2Themed SCXW268368253 BCX8">ActivityReports.Read</span></span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">, and </span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SpellingErrorV2Themed SCXW268368253 BCX8">ServiceHealth.Read</span></span>
4. <span class="NormalTextRun SCXW268368253 BCX8">Ensure all necessary permissions are selected, and then click </span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">Add permissions</span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">.</span></span>
5. <span class="NormalTextRun SCXW268368253 BCX8">Click </span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">Grant admin consent</span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">, and then click </span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">Accept</span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8"> to confirm.</span></span>
6. <span class="NormalTextRun SCXW268368253 BCX8">On the left navigation area, select </span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">Certificates &amp; secrets</span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">, and then click </span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">+ New client secret</span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">.</span></span>
7. <span class="NormalTextRun SCXW268368253 BCX8">Make Sure to Copy the </span><span class="NormalTextRun SCXW268368253 BCX8">Value </span><span class="NormalTextRun SCXW268368253 BCX8">(</span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">Client Secret (Api Key</span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">)</span><span class="NormalTextRun SCXW268368253 BCX8"> will </span><span class="NormalTextRun SCXW268368253 BCX8">disappear</span></span><span class="EOP SCXW268368253 BCX8" data-ccp-props="{"201341983":0,"335559685":1440,"335559739":160,"335559740":259}"> </span>

</div></div><div class="SCXW268368253 BCX8" id="bkmrk-type-a-key%E2%80%AFdescripti"><div class="ListContainerWrapper SCXW268368253 BCX8">8. <span class="SCXW268368253 BCX8"><span class="WACImageContainer NoPadding DragDrop BlobObject SCXW268368253 BCX8" role="presentation">![](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2024-04/embedded-image-u6xezwro.png)</span></span>
9. <span class="NormalTextRun SCXW268368253 BCX8">Type a key </span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">Description</span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8"> and set the duration to </span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">Never</span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8"> or Maximum Grant time</span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">.</span></span>
10. <span class="NormalTextRun SCXW268368253 BCX8">Click </span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">Add</span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">.</span></span>
11. <span class="NormalTextRun SCXW268368253 BCX8">Click </span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">Overview</span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8"> to return to the application summary, and then click the link under </span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">Managed application in local directory</span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">.</span></span>
12. <span class="NormalTextRun SCXW268368253 BCX8">Click </span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">Properties</span></span><span class="TextRun SCXW268368253 BCX8" data-contrast="auto" lang="EN-PH" xml:lang="EN-PH"><span class="NormalTextRun SCXW268368253 BCX8">, and then note the Object ID associated with the application.</span></span><span class="EOP SCXW268368253 BCX8" data-ccp-props="{"201341983":0,"335559685":1440,"335559739":160,"335559740":259}"> </span>

</div></div>##### **Steps to Renew the Client Secret (API Key):**

1. **Log into the Azure Portal**:
    
    
    - Go to the Azure Portal and log in using an account with administrative privileges.
2. **Navigate to Azure Active Directory**:
    
    
    - In the left navigation pane, select **Azure Active Directory**.
    - If it's not visible, click **Show all** to expand the list and find it.
3. **Go to App Registrations**:
    
    
    - Under **Azure Active Directory**, select **App Registrations**.
    - Find your registered application (e.g., "o365cytech") in the list, or use the **search bar** to locate it.
4. **Open Certificates &amp; Secrets**:
    
    
    - Click on the registered app to open its details page.
    - In the left-hand menu, select **Certificates &amp; Secrets**.
5. **Generate a New Client Secret**:
    
    
    - Under **Client Secrets**, you'll see a list of previously created secrets, along with their expiration dates.
    - Click **+ New client secret** to create a new one.
6. **Configure the New Secret**:
    
    
    - Enter a description for the new key (e.g., "Renewed Key for o365cytech").
    - Set the duration for the new client secret:
7. **Save and Copy the New Secret**:
    
    
    - Click **Add**.
    - Once the new secret is generated, **copy the value immediately**. This is your new client secret (API key). The secret value will be hidden after you leave this page, so make sure to store it securely.
8. **Update Any Services Using the Key**:
    
    
    - If any services or scripts are using the previous client secret, you'll need to update them with the new one.
9. **Remove the Old Secret (Optional)**:
    
    
    - If the old client secret is no longer needed, you can delete it to avoid confusion. Simply click the **trash icon** next to the old key under **Client Secrets**.