---
title: Microsoft365 Security Integration
description: AgileBlue can monitor and respond across your Microsoft365 environment by leveraging a single application's API permissions. The full setup instructions and requirements of the various datasets can be found below.
---

[Skip to content](https://help.agileblue.com/microsoft365-security-integration#main-content)

English

Show submenu for translations

[Contact AgileBlue Support](https://help.agileblue.com/kb-tickets/new?hsLang=en) [Customer portal](https://help.agileblue.com/support-ticket-status?hsLang=en)

![FullColor-800px-Aug-04-2025-07-56-16-5066-PM.png\]](https://help.agileblue.com/hs-fs/hubfs/FullColor-800px-Aug-04-2025-07-56-16-5066-PM.png?height=32&name=FullColor-800px-Aug-04-2025-07-56-16-5066-PM.png)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- [Contact AgileBlue Support](https://help.agileblue.com/kb-tickets/new)
- [Customer portal](https://help.agileblue.com/support-ticket-status)
- AgileBlue Portal

 AgileBlue Portal

 Hello. How can we help you?

- There are no suggestions because the search field is empty.

1. [Help Center](https://help.agileblue.com/?hsLang=en)
2. [Application Integrations](https://help.agileblue.com/application-integrations?hsLang=en)
3. [Microsoft Tools](https://help.agileblue.com/application-integrations?hsLang=en#microsoft-tools)

# Microsoft365 Security Integration

## AgileBlue can monitor and respond across your Microsoft365 environment by leveraging a single application's API permissions. The full setup instructions and requirements of the various datasets can be found below.

***Please note: Auditing must be enabled for your organization in order to ensure data collection. For more information, [click here](https://docs.microsoft.com/en-us/microsoft-365/compliance/turn-audit-log-search-on-or-off?view=o365-worldwide).***

### Configure Your Azure Application

1. Log in to the [Azure Portal](https://portal.azure.com/) using your Global Administrator credentials. (E.g. an account that is marked as Global Administrator.)
2. Navigate to the **Microsoft Entra ID** under Azure services
3. Select **App Registrations** in the left-hand menu
4. Click **New registration** 
     1. **Name:** AgileBlue M365 Security
     2. **Supported account types:** Accounts in this organizational directory only (Your tenant only - Single tenant)
     3. **Redirect URI:** No value/not neededConfigure the options for this **App Registration** as shown below:

---

### Add Required Permissions

Within the application created in the previous section, you will need to add specific permissions sets in order for AgileBlue to monitor various portions of your environment. These permission sets are detailed by integration below:

1. Select **View API permissions**
2. Click **Add a permission**
3. Select all permissions detailed below for desired integration points
4. After permissions have been selected, click **Add permissions**
5. Select **Grant admin consent for \[your tenant name\]**

#### Office365

- **Permission Set:** Office365 Management APIs (Application Permissions) 
    - ActivityFeed.Read
    - ActivityFeed.ReadDlp
- **Permission Set:** Microsoft Graph (Application Permissions; Required for account disablement actions)  
    - AuditLog.Read.All
    - User.Read (typically added by default)
    - Directory.ReadWrite.All
    - User.EnableDisableAccount.All
    - User.ReadWrite.All
    - User.RevokeSessions.All

#### M365 Defender

- **Permission Set:** Microsoft Graph (Application Permissions)  
    - - SecurityIncident.Read.All

#### Microsoft Defender for Endpoint

- **Permission Set:** WindowsDefenderATP (Application Permissions)
- - Alert.Read.All
    - Alert.ReadWrite.All
    - Machine.Isolate
    - Machine.ReadWrite.All

---

### **Create Client Secret Key & Collect Account Details**

1. Select **Certificates & secrets** from the left-hand menu
2. Once the page loads, click **New client secret**
3. On the pop out that appears, provide a **Description** of **AgileBlue Collection Service** and select your desired timeframe for expiration 
     1. Please note this expiration date of the secret value
4. Click **Add**
   
   ***CAUTION! Depending on your version of Azure/Office365 and/or your security configurations, you may only have ONE CHANCE to grab this value. Be sure to copy this value and store it somewhere safe immediately.***
5. Copy the **Secret Value** to a secure location 
     1. NOTE: The Secret Value is different than the Secret ID. The required value may have numbers, letters, and special characters. The Secret ID will only include numbers, letters, and hyphens. Please ensure the **Secret Value** is collected, not the Secret ID.
6. Navigate back to the **Overview **page and copy the following values: 
     1. Application (client) ID
     2. Directory (tenant) ID

---

### **Submitting Sensitive Data**

The final step is to submit these sensitive details to AgileBlue. Once ready, please email support@agileblue.com and a specialist will send back an encrypted message. You will be able to respond to that message with the following values:

1. 1. Secret Value
     2. Application (client) ID
     3. Directory (tenant) ID
     4. Secret Value expiration date

---

### **Need Help?**

AgileBlue is always here to support you and ensure you are 100% successful. If there are any issues with the installation or if you have any questions, please reach out to [**AgileBlue Support**](https://help.agileblue.com/kb-tickets/new?hsLang=en).

*Email: support@agileblue.com   
Phone: (216) 606-9400🚨*

- [Agent Installation](https://help.agileblue.com/agent-installation?hsLang=en#main-content)

    - [Windows](https://help.agileblue.com/agent-installation?hsLang=en#windows)
    - [Mac](https://help.agileblue.com/agent-installation?hsLang=en#mac)
    - [Linux](https://help.agileblue.com/agent-installation?hsLang=en#linux)
    - [Syslog Collection](https://help.agileblue.com/agent-installation?hsLang=en#syslog-collection)
    - [Agent Management](https://help.agileblue.com/agent-installation?hsLang=en#agent-management)
- [Application Integrations](https://help.agileblue.com/application-integrations?hsLang=en#main-content)

    - [Microsoft Tools](https://help.agileblue.com/application-integrations?hsLang=en#microsoft-tools)
    - [Third-Party EDR](https://help.agileblue.com/application-integrations?hsLang=en#third-party-edr)
    - [Other Security Tools](https://help.agileblue.com/application-integrations?hsLang=en#other-security-tools)
- [Cloud Integrations](https://help.agileblue.com/cloud-integrations?hsLang=en)
- [AgileBlue Features](https://help.agileblue.com/agileblue-features?hsLang=en#main-content)

    - [Portal Management](https://help.agileblue.com/agileblue-features?hsLang=en#portal-management)
    - [Support Systems](https://help.agileblue.com/agileblue-features?hsLang=en#support-systems)
- [Vulnerability Scanning](https://help.agileblue.com/vulnerability-scanning?hsLang=en)
- [Release Notes](https://help.agileblue.com/release-notes?hsLang=en)

[![AgileBlue](https://help.agileblue.com/hs-fs/hubfs/Current-Website-Logo-Replacement.png?width=1321&height=648&name=Current-Website-Logo-Replacement.png "AgileBlue")](http://www.agileblue.com)

AgileBlue Support Phone: 216.606.9400

Copyright © 2026, AgileBlue