You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The Sumo Logic App for Azure Security – Microsoft Defender for Office 365 provides visibility into threats and alerts across Microsoft 365. It includes dashboards to monitor alert activity, geographic trends, detection sources, and user-level details, enabling quick identification of phishing, malware, and suspicious sign-ins. High-severity alerts, malicious IPs, compromised accounts, and targeted devices are highlighted to support rapid response. The app helps strengthen Office 365 security posture, prioritize incidents, and detect potential compromises across users and devices.
11
+
The Sumo Logic app for Azure Security – Microsoft Defender for Office 365 provides visibility into threats and alerts across Microsoft 365. It includes dashboards to monitor alert activity, geographic trends, detection sources, and user-level details, enabling quick identification of phishing, malware, and suspicious sign-ins. High-severity alerts, malicious IPs, compromised accounts, and targeted devices are highlighted to support rapid response. The app helps strengthen Office 365 security posture, prioritize incidents, and detect potential compromises across users and devices.
12
12
13
13
## Log types
14
14
@@ -169,15 +169,15 @@ import ViewDashboards from '../../reuse/apps/view-dashboards.md';
169
169
170
170
### Overview
171
171
172
-
The **Azure Security - Microsoft Defender for Office 365 - Overview** dashboard provides
172
+
The **Azure Security - Microsoft Defender for Office 365 - Overview** dashboard offers a high-level summary of security alerts detected by Microsoft Defender for Office 365. It showcases key metrics such as total alert volume, geographic distribution, and breakdowns by status, detection source, determination, and classification. Security analysts can quickly spot top alert categories like phishing and malware, identify affected users, and monitor the most active analysts involved in investigations. The dashboard also features a top action plan and recent alerts panel to help prioritize response efforts and investigate high-risk activities such as anomalous sign-ins, suspicious tokens, and potential account compromises.
173
173
174
-
<br/><imgsrc=''alt="Azure Security - Microsoft Defender for Office 365 - Overview" />
174
+
<br/><imgsrc='https://sumologic-app-data-v2.s3.us-east-1.amazonaws.com/dashboards/Azure+Security+-+Microsoft+Defender+for+Office+365/Azure+Security+-+Microsoft+Defender+for+Office+365+-+Overview.png'alt="Azure Security - Microsoft Defender for Office 365 - Overview" />
175
175
176
176
### Security
177
177
178
-
The **Azure Security - Microsoft Defender for Office 365 - Security** dashboard provides
178
+
The **Azure Security - Microsoft Defender for Office 365 - Security** dashboard focuses on high-severity alerts and threats associated with risky IP addresses, suspicious geographies, and compromised accounts. It provides visibility into alerts by severity over time, helping analysts detect spikes in high-priority incidents. The dashboard also highlights countries with malicious IP verdicts, top user accounts with compromised roles, and top attacked devices along with their risk posture and health status. This view enables teams to quickly pinpoint the most critical threats targeting their Office 365 environment and take immediate mitigation steps.
179
179
180
-
<br/><imgsrc=''alt="Azure Security - Microsoft Defender for Office 365 - Security" />
180
+
<br/><imgsrc='https://sumologic-app-data-v2.s3.us-east-1.amazonaws.com/dashboards/Azure+Security+-+Microsoft+Defender+for+Office+365/Azure+Security+-+Microsoft+Defender+for+Office+365+-+Security.png'alt="Azure Security - Microsoft Defender for Office 365 - Security" />
181
181
182
182
## Upgrade/Downgrade the Azure Security - Microsoft Defender for Office 365 app (Optional)
183
183
@@ -189,4 +189,4 @@ import AppUpdate from '../../reuse/apps/app-update.md';
189
189
190
190
import AppUninstall from '../../reuse/apps/app-uninstall.md';
0 commit comments