Skip to main content

CollectorsCloud Collectors Administration Guide

Supported Sources for Microsoft Security Alerts

This table lists the service sources and from which the Microsoft Security Alerts collector can receive alerts. You must have the minimum required subscriptions associated with your Microsoft account in order to receive alerts from the service sources supported by the collector.

Service Covered

Endpoint/API 

Notes

Security Alerts

Graph Security API

Alerts generated from the following are supported:

  • Azure Active Directory Identity Protection

  • Microsoft 365 Defender

  • Microsoft App Governance

  • Microsoft Defender for Cloud

  • Microsoft Defender for Cloud Apps

  • Microsoft Defender for Endpoint

  • Microsoft Defender for Identity

  • Microsoft Defender For Office365

  • Microsoft Purview Data Loss Prevention