A step-by-step guide to setting up Microsoft Exchange Online Message Trace monitoring on the AgileBlue Cerulean AI SecOps platform.
Overview
The AgileBlue Cerulean AI SecOps Platform has the ability to monitor Microsoft Exchange Online Message Trace logs by accessing the Office365 REST API.
Please note: Auditing must be enabled for your organization in order to ensure data collection. For more information, click here.
Configure Your Azure Application
- Log in to the Azure Portal using your Office365 Global Administrator credentials. (E.g. an account that is marked as Global Administrator.)
- Navigate to the Microsoft Entra ID option in the menu
- Select App Registrations in the left-hand menu
- Click New registration
- Configure the options for this App Registration as shown below:
- Name: AgileBlue Message Trace Collection
- Supported account types: Accounts in this organizational directory only (Your tenant only - Single tenant)
- Redirect URI: No value/not needed
- Select API permissions
- Click on Add a permission
- On the pop out, select Office365 Exchange Online
- Select Application permissions
- Under Office365 Application APIs Application permissions, expand and check the following options:
- ReportingWebService.Read.All
- Click Add permissions at the bottom of the pop out to save your changes
- Select Grant admin consent for [your tenant name]
Create Client Secret Key & Collect Account Details
- Select Certificates & secrets from the left-hand menu
- Once the page loads, click New client secret
- On the pop out that appears, provide a Description of AgileBlue Collection Service and select Never for expiration
- If never is not an available option, we recommend selecting 24 months. If that's the case, please note the expiration date. A new secret will need to be generated and provided to AgileBlue at that time.
- Click Add
CAUTION! Depending on your version of Azure/Office365 and/or your security configurations, you may only have ONCE CHANCE to grab this value. Be sure to copy this value and store it somewhere safe immediately. - Copy the Secret Value to a secure location
- NOTE: The Secret Value is different than the Secret ID. The required value may have numbers, letters, and special characters. The Secret ID will only include numbers, letters, and hyphens. Please ensure the Secret Value is collected, not the Secret ID.
- Navigate back to the Overview page and copy the following values:
-
Application (client) ID
- Directory (tenant) ID
-
Submitting Sensitive Data
The final step is to submit these sensitive details to AgileBlue. Once ready, please email support@agileblue.com and a specialist will send back an encrypted message. You will be able to respond to that message with the following values:
-
- Secret Value
- Application (client) ID
- Directory (tenant) ID
- Secret Value Expiration Date
Need Help?
AgileBlue is always here to support you and ensure you are 100% successful. If there are any issues with the installation or if you have any questions, please reach out to AgileBlue Support.
Email: support@agileblue.com
Phone: (216) 606-9400🚨