Microsoft 365 Integration with WatchGuard CloudDR

Applies To: WatchGuard CloudDR

Microsoft 365 is a suite of productivity tools and cloud-based services developed by Microsoft. Microsoft 365 is designed to help individuals, businesses, and organizations collaborate in various ways. This topic describes how to integrate Microsoft 365 with CloudDR.

Available Features

  • Misconfiguration Rules (Auto-Fix Available)
  • Identity Rules (Auto-Fix Available)
  • Discovered Application Rules (Auto-Fix Available)
  • Discovered Application (Auto-Fix Available)
  • User Inventory (Auto-Fix Available)
  • Shared Data Rules (Auto-Fix Available)
  • Shared Data Inventory (Auto-Fix Available)
  • Devices Inventory

For a list of auto-fix rules available with Microsoft 365 integration, go to Available Auto-Fix Rules.

Prerequisites

To configure this integration, you must have:

  • A user account with a Microsoft 365 Business Basic subscription license (or higher).
  • (Optional) An active Microsoft Teams Essentials subscription license if you want to include Teams in the integration.
  • Active OneDrive and SharePoint licenses if OneDrive and SharePoint data is required in the shared data inventory.
  • (Optional) Unified audit logging enabled for Microsoft 365 to view extended logs for your Microsoft 365 accounts.
  • A user account with these roles:
  • Global Reader
  • Privileged Role Administrator
  • Exchange Administrator
  • Application-specific administrator roles (for example, Teams Administrator and SharePoint Administrator). Alternatively, you can use the Global Administrator role.

Before You Begin — Enable Unified Audit Logging

To view extended unified log messages for your Microsoft 365 accounts in CloudDR, you must have active Business Premium or higher licenses of SharePoint and OneDrive. When you open the Microsoft Purview portal for the first time, you must enable auditing of user and admin activity.

To enable recording of user and admin activity in the Microsoft Purview portal:

  1. Go to https://purview.microsoft.com/ (external) and log in with your Microsoft 365 credentials.
  2. Select the Audit solution card. If the Audit solution card is not available, select View All Solutions, and in the Core section, select Audit.
    A banner prompts you to record user and admin activity.
  3. Click the Start Recording User and Admin Activity banner to enable unified audit logging.

If you have previously opened the Purview portal and the banner does not appear, complete the next procedure to enable auditing.

To enable auditing through the Windows PowerShell command-line interface (CLI):

  1. Open a Windows PowerShell command prompt.
  2. Type these commands:

Connect-ExchangeOnline

Get-AdminAuditLogConfig | Format-List UnifiedAuditLogIngestionEnabled

Set-AdminAuditLogConfig -UnifiedAuditLogIngestionEnabled $true

Required Permissions

The user account requires permissions for the base, SharePoint, and Entra ID integrations.

Permissions for Base Integration

Scope Use
Mail.ReadBasic.All Read access to basic mail properties for all mailboxes
Mail.ReadBasic Read access to basic mail properties
Files.ReadWrite.All Read access to basic file information for all users and sites
AuditLogsQuery-SharePoint.Read.All Read access to audit log data from SharePoint
AuditLogsQuery-OneDrive.Read.All Read access to audit log data from OneDrive
Exchange.Manage Read access to Exchange, Threat, Data Loss Prevention Policies, and Configurations
User.Read.All Read access to all user profiles
Read SharePoint and OneDrive tenant settings Read access to SharePoint and OneDrive configurations and settings for an organization
TeamMember.Read.All Read access to the members of all teams
Team.ReadBasic.All Read access to the list of all teams
Sites.Read.All Read access to documents and list items in all list collections
SharePointTenantSettings.Read.All Read access to tenant-level configurations for SharePoint and OneDrive
RoleManagement.Read.Directory Read access to roles and role assignments
Reports.Read.All Read access to all service usage reports
Policy.Read.All Read access to all policies for an organization
Directory.Read.All Read access to directory information such as users, groups, and apps
DelegatedPermissionGrant.ReadWrite.All Read access to all delegated permission grants
AuditLog.Read.All Read access to audit log activities

SharePoint Permissions

Scope Use
Read directory data Read access to organization information, roles, role assignments, and third-party apps
Read SharePoint and OneDrive tenant settings Read access to SharePoint configurations and settings for the organization
Read items in all site collections Read access to metadata for sites in the organization
Read directory RBAC settings Read access to role and access-related information for users
Read managed metadata Read access to metadata for public sites
Read and query your audit log activities Read access to audit log messges for the organization
Read Reports Read access to reports

Entra ID Permissions

Scope Use
Read directory data Read access to organization information, roles, role assignments, and third-party apps
Read your organization's policies Read access to organization policies and configurations

Read the names and descriptions of teams

Read access to teams in the organization

Read all users' full profiles

Read access to detailed profiles for users

Configure the Microsoft 365 Integration in CloudDR

The integration of Microsoft 365 includes all of the individual apps in the suite. Additional integration of individual apps such as Microsoft Teams that is part of the Microsoft 365 license is not required.

Service Providers can configure integration in CloudDR for a single organization or for all of their managed organizations. If you select a managed Service Provider from Account Manager, you can configure integration for all organizations managed by the Service Provider.

Before you begin, select the account you want to configure integration for:

  • To configure integration for all organizations, from Account Manager, select Overview.
  • To configure integration for a single organization, from Account Manager, select the account you want to integrate the application in CloudDR.

To configure the Microsoft 365 integration in CloudDR, from WatchGuard Cloud:

  1. Select Configure > CloudDR.
  2. Select Integrations > SaaS Services.
  3. (Service Providers) Click Add Integration.
    1. Select the product you want to integrate.
    2. Click Next.
    3. Select the organization where you want to integrate the product.
    4. Click Start Integration.
  1. In the Microsoft 365 widget, click Add.
  2. Click Start Integration.
  3. Select the services you want to include in the integration.
  4. Click Next.
  5. To give CloudDR access to Entra ID (previously called Azure AD), on the Base Integration – Step 1 of 2 page of the wizard, click Sign In with Microsoft 365, then log in with a user account that meets the prerequisites.
  6. Click Next.
  7. To give CloudDR access to Microsoft Exchange through the command-line interface (CLI), on the Base Integration – Step 2 of 2 page of the wizard, click Sign In with Microsoft 365, then log in with a user account that meets the prerequisites.
  8. Click Next.
  9. If you selected Data, Email Scanning, and Extended Unified Logs in step 6, to give CloudDR extended access to read those files in your Microsoft 365 environment, on the Data, Email Scanning, and Extended Unified Logs page of the wizard, click Sign In With Microsoft 365, then log in with a user account that meets the prerequisites.
    This feature reads email subject lines and file metadata to detect unauthorized app connections and security risks. Email body content is not read.
  10. Click Next.
  11. If you selected Include Teams in the Integration in step 6, to give CloudDR extended access to your Microsoft Teams configuration, on the Teams OAuth page of the wizard, click Sign In with Microsoft 365, then log in with a user account that meets the prerequisites.
  12. Click Finish.

You can use the Domain Management page in WatchGuard CloudDR to specify which of the domains discovered from your directory and IdP applications are internal and external domains. For more information, go to Domain Management in WatchGuard CloudDR.

Synchronization with Microsoft 365

The Service Level Agreement with Microsoft 365 specifies that synchronization starts every 24 hours. This includes files that are pulled as a delta after the initial synchronization. Activity synchronizations start every hour. An hourly schedule is kept for each individual organization.

Synchronization is based on polling. The polling interval varies based on the data type. For example, for configurations and identities, the polling interval is every 24 hours. For event log messages, it is approximately every hour and for shared files, it is approximately every 4 to 6 hours.

How frequently the synchronization completes or whether data is up to date in CloudDR depends on the information available from Microsoft. This can include many variables, such as how much information must be collected, API throttling by Microsoft, and whether the Microsoft log messages and configuration data are up to date.

Data Synchronization Issues — SharePoint and OneDrive

Data synchronization can fail after integration when the Microsoft 365 user account used for the integration with CloudDR does not have an active SharePoint and OneDrive license. To complete integration successfully, you must use a Microsoft 365 user with an active license that includes OneDrive and SharePoint.

If OneDrive has never been initialized for the user, Microsoft does not grant the required OneDrive scopes during the OAuth process. To activate the service, the user must log in to office.com and open OneDrive at least once so that Microsoft can provision the OneDrive environment.

If data synchronization fails:

  1. Confirm that you have met these requirements:
  • Account with an application-specific administrator role (or Global Administrator role)
  • Active SharePoint and OneDrive licenses
  • Completed OneDrive initialization
  1. Re-authenticate the Microsoft 365 integration in CloudDR.
    CloudDR can then obtain the required OneDrive permissions and enable data synchronization to work correctly.

Available Auto-Fix Rules

There are many misconfiguration rules for Microsoft 365 that include auto-fix options. This section lists the available rules.

Identity and Authentication Rules

These rules protect user identities and makes sure only authorized users have access to Microsoft 365 resources. These rules strengthen password security, prevent credential-based attacks, and enforce modern authentication methods that reduce reliance on legacy protocols.

  • Password History is Not being Checked Properly
  • Password does Not Include an Alphanumeric Character
  • Use of Common Passwords is Not Restricted
  • Minimum Length of Password is Too Short
  • Ensure password protection is enabled for on-prem Active Directory
  • Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)'
  • Ensure modern authentication for Exchange Online is enabled

Device and Endpoint Security Rules

These rules protect corporate data on managed devices by enforcing security rules such as encryption, password requirements, device lock settings, and endpoint protections. These rules help reduce the risk of data loss from compromised or stolen devices.

  • Device Data Encryption is Not Enabled
  • Mobile Device Password Policy is Not Enforced
  • Maximum Unsuccessful Login Attempts Before Which the Device Gets Wiped is Excessive
  • Minimum Inactivity Duration before the Device Gets Locked is Too Long
  • Turn on Safe Documents for Office Clients

Email Security and Defender for Office 365 Rules

These rules protect users from phishing, malware, spoofing, malicious links, and email-borne threats. These rules leverage Microsoft Defender for Office 365 and Exchange Online Protection to inspect, filter, quarantine, and remediate suspicious messages and content.

  • Ensure that an anti-phishing policy has been created
  • Phishing Protection with Spoof Intelligence is Not Enabled
  • Enable impersonated domain protection
  • Enable impersonated user protection
  • Ensure that intelligence for impersonation protection is enabled
  • Ensure that mailbox intelligence is enabled
  • Set the phishing email level threshold at 2 or higher
  • Enable the user impersonation safety tip
  • Enable the user impersonation unusual characters safety tip
  • Enable the domain impersonation safety tip
  • Quarantine messages that are detected from impersonated domains
  • Quarantine messages that are detected from impersonated users
  • Move messages that are detected as impersonated users by mailbox intelligence
  • Pre-Delivery URL Scanning is Not Enabled
  • Ensure Safe Links for Office Applications is Enabled
  • Create Safe Links policies for email messages
  • Turn on Safe Attachments in block mode
  • Ensure Safe Attachments policy is enabled
  • Ensure the Common Attachment Types Filter is enabled
  • Create zero-hour auto purge policies for malware
  • Create zero-hour auto purge policies for phishing messages
  • Create zero-hour auto purge policies for spam messages
  • Turn on Microsoft Defender for Office 365 in SharePoint, OneDrive, and Microsoft Teams
  • Ensure internal phishing protection for Forms is enabled
  • Set action to take on spam detection
  • Set action to take on high confidence spam detection
  • Set action to take on high confidence phishing detection
  • Set action to take on bulk spam detection
  • Retain spam in quarantine for 30 days
  • Ensure Exchange Online Spam Policies are set to notify administrators
  • Set the email bulk complaint level (BCL) threshold to be 6 or lower
  • Ensure that no sender domains are allowed for anti-spam policies
  • Ensure Spam confidence level (SCL) is configured in mail transport rules with specific domains

Mail Flow and Messaging Control Rules

These rules control how email is transmitted, routed, and restricted within the organization. These settings help prevent abuse of email systems, reduce spam propagation, secure message transport, and limit data exfiltration through forwarding and mass-email activities.

  • SMTP Authentication Protocol is Not Disabled
  • Legacy Transport Layer Security (TLS) Applications are Not Disabled
  • Set automatic email forwarding rules to be system controlled
  • Ensure all forms of mail forwarding are blocked and/or disabled
  • Set a daily message limit
  • Block users who reached the message limit
  • Set maximum number of internal recipients that a user can send to within an hour
  • Set maximum number of external recipients that a user can email per hour
  • Ensure MailTips are enabled for end users

Collaboration and Application Governance Rules

These rules govern how users collaborate with external parties, create groups, and have access to third-party applications and services. These rules reduce the risk of data exposure and unauthorized access through guest sharing, user-installed apps, and unmanaged integrations.

  • Ability to Invite Guests is Not Restricted
  • Ensure 'External sharing' of calendars is not available
  • Ensure additional storage providers are restricted in Outlook on the web
  • Ensure that only organizationally managed/approved public groups exist
  • Ensure user consent to apps accessing company data on their behalf is not allowed
  • Ensure 'User owned apps and services' is restricted
  • Ensure users installing Outlook add-ins is not allowed

Data Protection and Compliance Rules

These rules protect sensitive organizational data and support regulatory compliance requirements. These rules focus on data classification, sensitivity labeling, and data loss prevention to make sure that information is identified, governed, and protected throughout its lifecycle.

  • Ensure DLP policies are enabled
  • Ensure DLP policies are enabled for Microsoft Teams
  • Publish M365 sensitivity label data classification policies
  • Extend M365 sensitivity labeling to assets in Microsoft Purview data map

Auditing, Monitoring, and Administrative Security Rules

These rules provide visibility into user and administrator activity while they enforce governance over privileged operations. These rules support security investigations, compliance reporting, accountability, and protection of administrative access.

  • Ensure Microsoft 365 audit log search is Enabled
  • Ensure mailbox auditing for all users is Enabled
  • Ensure customer lock box feature is enabled
  • Ensure 'Microsoft Azure Management' is limited to administrative roles
  • Don't add allowed IP addresses in the connection filter policy

Related Topics

About WatchGuard CloudDR Integrations

Domain Management in WatchGuard CloudDR