Overview
Authorization/setup steps
Connection Method: API
Setup Time: 15-20 minutes
Access Required: Administrator account
Setup Time: 15-20 minutes
Access Required: Administrator account
Data collected
This integration provides:- Security event data
- Threat intelligence
- Asset visibility
- Compliance information
Setup instructions
1
Log in to your account
Access your Microsoft 365 dashboard with administrator credentials.
2
Create API credentials
Generate API credentials or tokens for ThreatAware integration:
- Navigate to API or integrations settings
- Create new API key/token
- Copy credentials securely
3
Configure in ThreatAware
Complete the integration setup in ThreatAware:
- Open ThreatAware and navigate to Settings > Integrations
- Search for and select Microsoft 365
- Enter the required credentials
- Click Connect to establish the integration
4
Verify Connection
After connecting, ThreatAware will begin syncing data.
- Check that the Integration Status shows as Active
- Verify data is appearing in ThreatAware within 30 minutes
Required credentials
API Key
API Key
Field Name: Microsoft 365 API Key
Type: String (encrypted)
Description: The API key or token generated in Microsoft 365
Type: String (encrypted)
Description: The API key or token generated in Microsoft 365
Endpoint URL
Endpoint URL
Field Name: Microsoft 365 Endpoint
Type: String
Description: The API endpoint or URL for your Microsoft 365 instanceFormat: Typically your instance URL or API endpoint
Example:
Type: String
Description: The API endpoint or URL for your Microsoft 365 instanceFormat: Typically your instance URL or API endpoint
Example:
https://api.microsoft 365.com or your instance URLVerification and testing
After setup, verify the integration is working correctly:-
Check Integration Status
- Navigate to Settings > Integrations in ThreatAware
- Confirm the Microsoft 365 integration shows Active status
- Check the last sync timestamp
-
Verify Data Collection
- Wait 30-60 minutes for the initial data sync
- Search for known devices or assets in ThreatAware
- Verify the Microsoft 365 data is present
-
Test Queries
- Create a test query to filter devices with Microsoft 365 data
- Verify the data matches your expectations
Troubleshooting
Invalid Credentials Error
Invalid Credentials Error
Symptoms: Integration status shows authentication failureSolutions:
- Verify the API key/token is correct and not expired
- Check if the API credentials have sufficient permissions
- Ensure the credentials were not modified or rotated
- Regenerate credentials if needed and update ThreatAware
Connection Timeout
Connection Timeout
Symptoms: Integration fails to connect or times outSolutions:
- Verify the endpoint URL is correct and accessible
- Check firewall rules allow outbound HTTPS (443) to the endpoint
- Confirm the Microsoft 365 service is operational
- Test the URL in a browser to ensure it’s reachable
No Data After 1 Hour
No Data After 1 Hour
Symptoms: Integration shows active but no data appearsSolutions:
- Verify there is data available in Microsoft 365 to collect
- Check API permissions allow access to the required data
- Contact support for integration logs and debugging
- Confirm devices/assets exist in your Microsoft 365 account
Additional resources
Microsoft 365 API Documentation
Official Microsoft 365 API documentation
ThreatAware Support
Contact support for integration assistance