Microsoft 365 Integration with WatchGuard CloudDR
Applies To: WatchGuard CloudDR
Microsoft 365 is a suite of productivity tools and cloud-based services developed by Microsoft. Microsoft 365 is designed to help individuals, businesses, and organizations collaborate in various ways. This topic describes how to integrate Microsoft 365 with CloudDR.
Available Features
- Misconfiguration Rules (Auto-Fix Available)
- Identity Rules (Auto-Fix Available)
- Discovered Application Rules (Auto-Fix Available)
- Discovered Application (Auto-Fix Available)
- User Inventory (Auto-Fix Available)
- Shared Data Rules (Auto-Fix Available)
- Shared Data Inventory (Auto-Fix Available)
- Devices Inventory
For a list of auto-fix rules available with Microsoft 365 integration, go to Available Auto-Fix Rules.
Prerequisites
To configure this integration, you must have:
- A user account with a Microsoft 365 Business Basic subscription license (or higher).
- (Optional) An active Microsoft Teams Essentials subscription license if you want to include Teams in the integration.
- Active OneDrive and SharePoint licenses if OneDrive and SharePoint data is required in the shared data inventory.
- (Optional) Unified audit logging enabled for Microsoft 365 to view extended logs for your Microsoft 365 accounts.
- A user account with these roles:
- Global Reader
- Privileged Role Administrator
- Exchange Administrator
- Application-specific administrator roles (for example, Teams Administrator and SharePoint Administrator). Alternatively, you can use the Global Administrator role.
Before You Begin — Enable Unified Audit Logging
To view extended unified log messages for your Microsoft 365 accounts in CloudDR, you must have active Business Premium or higher licenses of SharePoint and OneDrive. When you open the Microsoft Purview portal for the first time, you must enable auditing of user and admin activity.
To enable recording of user and admin activity in the Microsoft Purview portal:
- Go to https://purview.microsoft.com/ (external) and log in with your Microsoft 365 credentials.
- Select the Audit solution card. If the Audit solution card is not available, select View All Solutions, and in the Core section, select Audit.
A banner prompts you to record user and admin activity. - Click the Start Recording User and Admin Activity banner to enable unified audit logging.
If you have previously opened the Purview portal and the banner does not appear, complete the next procedure to enable auditing.
To enable auditing through the Windows PowerShell command-line interface (CLI):
- Open a Windows PowerShell command prompt.
- Type these commands:
Connect-ExchangeOnline
Get-AdminAuditLogConfig | Format-List UnifiedAuditLogIngestionEnabled
Set-AdminAuditLogConfig -UnifiedAuditLogIngestionEnabled $true
Required Permissions
The user account requires permissions for the base, SharePoint, and Entra ID integrations.
Permissions for Base Integration
| Scope | Use |
|---|---|
| Mail.ReadBasic.All | Read access to basic mail properties for all mailboxes |
| Mail.ReadBasic | Read access to basic mail properties |
| Files.ReadWrite.All | Read access to basic file information for all users and sites |
| AuditLogsQuery-SharePoint.Read.All | Read access to audit log data from SharePoint |
| AuditLogsQuery-OneDrive.Read.All | Read access to audit log data from OneDrive |
| Exchange.Manage | Read access to Exchange, Threat, Data Loss Prevention Policies, and Configurations |
| User.Read.All | Read access to all user profiles |
| Read SharePoint and OneDrive tenant settings | Read access to SharePoint and OneDrive configurations and settings for an organization |
| TeamMember.Read.All | Read access to the members of all teams |
| Team.ReadBasic.All | Read access to the list of all teams |
| Sites.Read.All | Read access to documents and list items in all list collections |
| SharePointTenantSettings.Read.All | Read access to tenant-level configurations for SharePoint and OneDrive |
| RoleManagement.Read.Directory | Read access to roles and role assignments |
| Reports.Read.All | Read access to all service usage reports |
| Policy.Read.All | Read access to all policies for an organization |
| Directory.Read.All | Read access to directory information such as users, groups, and apps |
| DelegatedPermissionGrant.ReadWrite.All | Read access to all delegated permission grants |
| AuditLog.Read.All | Read access to audit log activities |
SharePoint Permissions
| Scope | Use |
|---|---|
| Read directory data | Read access to organization information, roles, role assignments, and third-party apps |
| Read SharePoint and OneDrive tenant settings | Read access to SharePoint configurations and settings for the organization |
| Read items in all site collections | Read access to metadata for sites in the organization |
| Read directory RBAC settings | Read access to role and access-related information for users |
| Read managed metadata | Read access to metadata for public sites |
| Read and query your audit log activities | Read access to audit log messges for the organization |
| Read Reports | Read access to reports |
Entra ID Permissions
| Scope | Use |
|---|---|
| Read directory data | Read access to organization information, roles, role assignments, and third-party apps |
| Read your organization's policies | Read access to organization policies and configurations |
|
Read the names and descriptions of teams |
Read access to teams in the organization |
|
Read all users' full profiles |
Read access to detailed profiles for users |
Configure the Microsoft 365 Integration in CloudDR
The integration of Microsoft 365 includes all of the individual apps in the suite. Additional integration of individual apps such as Microsoft Teams that is part of the Microsoft 365 license is not required.
Service Providers can configure integration in CloudDR for a single organization or for all of their managed organizations. If you select a managed Service Provider from Account Manager, you can configure integration for all organizations managed by the Service Provider.
Before you begin, select the account you want to configure integration for:
- To configure integration for all organizations, from Account Manager, select Overview.
- To configure integration for a single organization, from Account Manager, select the account you want to integrate the application in CloudDR.
To configure the Microsoft 365 integration in CloudDR, from WatchGuard Cloud:
- Select Configure > CloudDR.
- Select Integrations > SaaS Services.
- (Service Providers) Click Add Integration.
- Select the product you want to integrate.
- Click Next.
- Select the organization where you want to integrate the product.
- Click Start Integration.
- In the Microsoft 365 widget, click Add.
- Click Start Integration.
- Select the services you want to include in the integration.
- Click Next.
- To give CloudDR access to Entra ID (previously called Azure AD), on the Base Integration – Step 1 of 2 page of the wizard, click Sign In with Microsoft 365, then log in with a user account that meets the prerequisites.
- Click Next.
- To give CloudDR access to Microsoft Exchange through the command-line interface (CLI), on the Base Integration – Step 2 of 2 page of the wizard, click Sign In with Microsoft 365, then log in with a user account that meets the prerequisites.
- Click Next.
- If you selected Data, Email Scanning, and Extended Unified Logs in step 6, to give CloudDR extended access to read those files in your Microsoft 365 environment, on the Data, Email Scanning, and Extended Unified Logs page of the wizard, click Sign In With Microsoft 365, then log in with a user account that meets the prerequisites.
This feature reads email subject lines and file metadata to detect unauthorized app connections and security risks. Email body content is not read. - Click Next.
- If you selected Include Teams in the Integration in step 6, to give CloudDR extended access to your Microsoft Teams configuration, on the Teams OAuth page of the wizard, click Sign In with Microsoft 365, then log in with a user account that meets the prerequisites.
- Click Finish.
You can use the Domain Management page in WatchGuard CloudDR to specify which of the domains discovered from your directory and IdP applications are internal and external domains. For more information, go to Domain Management in WatchGuard CloudDR.
Synchronization with Microsoft 365
The Service Level Agreement with Microsoft 365 specifies that synchronization starts every 24 hours. This includes files that are pulled as a delta after the initial synchronization. Activity synchronizations start every hour. An hourly schedule is kept for each individual organization.
Synchronization is based on polling. The polling interval varies based on the data type. For example, for configurations and identities, the polling interval is every 24 hours. For event log messages, it is approximately every hour and for shared files, it is approximately every 4 to 6 hours.
How frequently the synchronization completes or whether data is up to date in CloudDR depends on the information available from Microsoft. This can include many variables, such as how much information must be collected, API throttling by Microsoft, and whether the Microsoft log messages and configuration data are up to date.
Data Synchronization Issues — SharePoint and OneDrive
Data synchronization can fail after integration when the Microsoft 365 user account used for the integration with CloudDR does not have an active SharePoint and OneDrive license. To complete integration successfully, you must use a Microsoft 365 user with an active license that includes OneDrive and SharePoint.
If OneDrive has never been initialized for the user, Microsoft does not grant the required OneDrive scopes during the OAuth process. To activate the service, the user must log in to office.com and open OneDrive at least once so that Microsoft can provision the OneDrive environment.
If data synchronization fails:
- Confirm that you have met these requirements:
- Account with an application-specific administrator role (or Global Administrator role)
- Active SharePoint and OneDrive licenses
- Completed OneDrive initialization
- Re-authenticate the Microsoft 365 integration in CloudDR.
CloudDR can then obtain the required OneDrive permissions and enable data synchronization to work correctly.
Available Auto-Fix Rules
There are many misconfiguration rules for Microsoft 365 that include auto-fix options. This section lists the available rules.
Identity and Authentication Rules
These rules protect user identities and makes sure only authorized users have access to Microsoft 365 resources. These rules strengthen password security, prevent credential-based attacks, and enforce modern authentication methods that reduce reliance on legacy protocols.
- Password History is Not being Checked Properly
- Password does Not Include an Alphanumeric Character
- Use of Common Passwords is Not Restricted
- Minimum Length of Password is Too Short
- Ensure password protection is enabled for on-prem Active Directory
- Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)'
- Ensure modern authentication for Exchange Online is enabled
Device and Endpoint Security Rules
These rules protect corporate data on managed devices by enforcing security rules such as encryption, password requirements, device lock settings, and endpoint protections. These rules help reduce the risk of data loss from compromised or stolen devices.
- Device Data Encryption is Not Enabled
- Mobile Device Password Policy is Not Enforced
- Maximum Unsuccessful Login Attempts Before Which the Device Gets Wiped is Excessive
- Minimum Inactivity Duration before the Device Gets Locked is Too Long
- Turn on Safe Documents for Office Clients
Email Security and Defender for Office 365 Rules
These rules protect users from phishing, malware, spoofing, malicious links, and email-borne threats. These rules leverage Microsoft Defender for Office 365 and Exchange Online Protection to inspect, filter, quarantine, and remediate suspicious messages and content.
- Ensure that an anti-phishing policy has been created
- Phishing Protection with Spoof Intelligence is Not Enabled
- Enable impersonated domain protection
- Enable impersonated user protection
- Ensure that intelligence for impersonation protection is enabled
- Ensure that mailbox intelligence is enabled
- Set the phishing email level threshold at 2 or higher
- Enable the user impersonation safety tip
- Enable the user impersonation unusual characters safety tip
- Enable the domain impersonation safety tip
- Quarantine messages that are detected from impersonated domains
- Quarantine messages that are detected from impersonated users
- Move messages that are detected as impersonated users by mailbox intelligence
- Pre-Delivery URL Scanning is Not Enabled
- Ensure Safe Links for Office Applications is Enabled
- Create Safe Links policies for email messages
- Turn on Safe Attachments in block mode
- Ensure Safe Attachments policy is enabled
- Ensure the Common Attachment Types Filter is enabled
- Create zero-hour auto purge policies for malware
- Create zero-hour auto purge policies for phishing messages
- Create zero-hour auto purge policies for spam messages
- Turn on Microsoft Defender for Office 365 in SharePoint, OneDrive, and Microsoft Teams
- Ensure internal phishing protection for Forms is enabled
- Set action to take on spam detection
- Set action to take on high confidence spam detection
- Set action to take on high confidence phishing detection
- Set action to take on bulk spam detection
- Retain spam in quarantine for 30 days
- Ensure Exchange Online Spam Policies are set to notify administrators
- Set the email bulk complaint level (BCL) threshold to be 6 or lower
- Ensure that no sender domains are allowed for anti-spam policies
- Ensure Spam confidence level (SCL) is configured in mail transport rules with specific domains
Mail Flow and Messaging Control Rules
These rules control how email is transmitted, routed, and restricted within the organization. These settings help prevent abuse of email systems, reduce spam propagation, secure message transport, and limit data exfiltration through forwarding and mass-email activities.
- SMTP Authentication Protocol is Not Disabled
- Legacy Transport Layer Security (TLS) Applications are Not Disabled
- Set automatic email forwarding rules to be system controlled
- Ensure all forms of mail forwarding are blocked and/or disabled
- Set a daily message limit
- Block users who reached the message limit
- Set maximum number of internal recipients that a user can send to within an hour
- Set maximum number of external recipients that a user can email per hour
- Ensure MailTips are enabled for end users
Collaboration and Application Governance Rules
These rules govern how users collaborate with external parties, create groups, and have access to third-party applications and services. These rules reduce the risk of data exposure and unauthorized access through guest sharing, user-installed apps, and unmanaged integrations.
- Ability to Invite Guests is Not Restricted
- Ensure 'External sharing' of calendars is not available
- Ensure additional storage providers are restricted in Outlook on the web
- Ensure that only organizationally managed/approved public groups exist
- Ensure user consent to apps accessing company data on their behalf is not allowed
- Ensure 'User owned apps and services' is restricted
- Ensure users installing Outlook add-ins is not allowed
Data Protection and Compliance Rules
These rules protect sensitive organizational data and support regulatory compliance requirements. These rules focus on data classification, sensitivity labeling, and data loss prevention to make sure that information is identified, governed, and protected throughout its lifecycle.
- Ensure DLP policies are enabled
- Ensure DLP policies are enabled for Microsoft Teams
- Publish M365 sensitivity label data classification policies
- Extend M365 sensitivity labeling to assets in Microsoft Purview data map
Auditing, Monitoring, and Administrative Security Rules
These rules provide visibility into user and administrator activity while they enforce governance over privileged operations. These rules support security investigations, compliance reporting, accountability, and protection of administrative access.
- Ensure Microsoft 365 audit log search is Enabled
- Ensure mailbox auditing for all users is Enabled
- Ensure customer lock box feature is enabled
- Ensure 'Microsoft Azure Management' is limited to administrative roles
- Don't add allowed IP addresses in the connection filter policy