Skip to main content

CollectorsCloud Collectors Administration Guide

Configure the Microsoft 365 Exchange Admin Reports Cloud Collector

Set up the Microsoft 365 Exchange Admin Reports Cloud Collector to continuously ingest events from data sources: MessageTrace, MailDetailDlpPolicy, SpoofMailReports, MailDetailATP.

  1. Before you configure the Microsoft 365 Exchange Admin Reports collector, ensure that you complete the Prerequisite tasks.

  2. Log into the Exabeam Security Operations Platform with your registered credentials as an administrator.

  3. Navigate to Collectors > Cloud Collectors.

  4. Click the Collectors tab.

    MS_Exchange_Admin_reports.png
  5. Click the Microsoft 365 Exchange Admin Reports tile. A configuration pane opens on the right.

  6. Enter the following information for the cloud collector, as shown in the image below:

    • Name – Specify a name for the Cloud Collector instance.

    • Account – Click New Account to add a new Microsoft service account or select an existing account. You can use the same account information across multiple Microsoft cloud collectors. For more information, see Add Accounts for Microsoft Cloud Collectors.

    • Data Sources – Select the endpoints from which you want to collect data. Options include MessageTrace, MailDetailDlpPolicy, SpoofMailReport and MailDetailATP.

      Note

      Make sure the required permissions are configured for each data source, as defined in Assign API Permissions.

    • Ingest From – Select the time and date to provide a threshold before which the collector will exclude events. If you leave this field blank and do not provide a threshold, all logs are ingested.

    ms-exchange-admin-reports.png
  7. To confirm that the Exabeam Security Operations Platform communicates with the service, click Test Connection. If the connection is successful a success message displays at the top of the screen.

  8. Click Install. A confirmation message informs you that the new Cloud Collector is created.

    success-message.png