Skip to content

Commit 5894344

Browse files
authored
Update ms-office-audit-source.md
During the on-boarding of the o365 sources, requesting global admin role account has raised security risk concerns. To avoid that it is recommended to use the global reader role
1 parent c22b5f4 commit 5894344

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

docs/send-data/hosted-collectors/microsoft-source/ms-office-audit-source.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -49,6 +49,7 @@ Office 365 comes with a set of admin roles that you can assign to users in you
4949
When you configure a Microsoft Office 365 Audit Source in Sumo you will need to authenticate with Microsoft using standard OAuth v2. The user who authenticates must have Microsoft Office 365 admin rights for the content that is being audited. For the sake of the principle of least privilege (PoLP), the authenticating account should be as restrictive as possible while enabling appropriate access. What's appropriate for you depends on which Office 365 edition you use and your security policies.
5050

5151
Using the Global Administrator role is recommended:
52+
However, you can also use the Global reader role
5253

5354
| Role  | Description |
5455
|:-----------------------|:-------------|

0 commit comments

Comments
 (0)