Bỏ qua

MS365 Integrate

Hướng dẫn cấu hình MS365 trên Portal

B1: Truy cập vào portal và làm theo hướng dẫn phía dưới để cấu hình liên kết MS365

  1. Trên Menu vào Custom file
  2. Chọn Org tương ứng
  3. Chọn Office tương ứng
  4. Chọn file ossec.conf để cấu hình
  5. Paste đoạn mã dưới vào và thay tenant_id, client_id, client_secret của khách hàng
  6. Ấn update
<ossec_config>
 <office365>
   <enabled>yes</enabled>
   <interval>1m</interval>
   <curl_max_size>1M</curl_max_size>
   <only_future_events>yes</only_future_events>
   <api_auth>
     <tenant_id>XXXXXXXXXXXXXXX</tenant_id>
     <client_id>XXXXXXXXXXXXXXX</client_id>
     <client_secret>XXXXXXXXXXXX</client_secret>
     <api_type>commercial</api_type>
   </api_auth>
   <subscriptions>
     <subscription>Audit.AzureActiveDirectory</subscription>
     <subscription>Audit.General</subscription>
     <subscription>Audit.Exchange</subscription>
     <subscription>Audit.SharePoint</subscription>
     <subscription>DLP.All</subscription>
   </subscriptions>
 </office365>
</ossec_config>

B2. Kiểm tra trên event

  1. Truy cập Menu event
  2. Chọn ORG
  3. Chọn Sensor
  4. Chọn Agent
  5. Chọn All Level
  6. Chọn ngày
  7. Nhập field “data.integration:office365” ấn Search để tìm kiếm
  8. Ra được kết quả của Office 365

Tham khảo

https://documentation.wazuh.com/4.7/cloud-security/office365/monitoring-office365-activity.html#configuring-wazuh-with-office-365-apis