Logo
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Sign in
  1. Guardsix Servicedesk
  2. Products Hub
  3. Marketplace

Office365

The Office365 integration fetches and analyzes logs from Microsoft 365 Management APIs and normalizes them for search, dashboards, alerts, and reporting in Logpoint.

 

Release Details

Version: v6.1.0
Release date: May 27, 2026
Supported On: Logpoint v7.9.0 or later
SHA 256: 4b40eb28c5ee0f838612df78bbb31dc5fa6a6c1233937291e814ab96396dc111
Office365 user guide
Download

Package Details

Office365 components:

  1. Fetcher
    • Office365Fetcher
  2. Compiled Normalizer
    • Office365CompiledNormalizer
  3. Normalization package
    • LP_O365 Exchange MT
  4. Log Source Template
    • Microsoft365
  5. Search template
    • LP_Office365
  6. KB list
    • Executables
  7.  Reports
    • LP_Office365 OneDrive Overview 
    • LP_Office365 SharePoint Overview
    • LP_Office365 Exchange Overview
    • LP_Office365 Overview
    • LP_Office365 OneDrive Anonymous Link Activities
    • LP_Office365 Azure AD Login Activities
    • LP_Office365 Azure AD User Account Management
    • LP_Office365 OneDrive File Activities
    • LP_Office365 OneDrive Folder Activities
    • LP_Office365 Operations by File Category
    • LP_Office365 SharePoint File Activities
    • LP_Office365 SharePoint Folder Activities 
  8.  Dashboards
    • LP_Office365 Security and Compliance Alerts
    • LP_Office365 Azure AD Login Activities
    • LP_Office365 Azure AD User Account Management
    • LP_Office365 Exchange Overview
    • LP_Office365 OneDrive Anonymous Link Activities
    • LP_Office365 OneDrive File Activities
    • LP_Office365 OneDrive Folder Activities
    • LP_Office365 OneDrive Overview
    • LP_Office365 Operations by File Category
    • LP_Office365 Overview
    • LP_Office365 SharePoint File Activities
    • LP_Office365 SharePoint Folder Activities
    • LP_Office365 SharePoint Overview 
  9.  Alerts
    • LP_Office365 Global Administrator Role Assigned to User
    • LP_Office365 MailItemAccessed Logging Disabled
    • LP_Office365 Security and Compliance Alert related to Access Governance
    • LP_Office365 Security and Compliance Alert related to Data Governance
    • LP_Office365 Security and Compliance Alert related to Data Loss Prevention
    • LP_Office365 Security and Compliance Alert related to Mail Flow
    • LP_Office365 Security and Compliance Alert related to Other Category
    • LP_Office365 Security and Compliance Alert related to Threat Management

Enhancement

PLUG-17680
Added RESTful configuration APIs for the Office365 Fetcher to support creating, updating, retrieving, listing, and deleting log source configurations through API workflows. This release also adds support for file uploads via the configuration APIs, simplifying secure, automated integration management.

Past Releases

Office365 v6.0.2 ▾
Version: v6.0.2
Release date: Jan 22, 2026
Supported On: Logpoint v7.5.0 and later; Director v2.6.0 and later
SHA 256: 48a3df3b5a84c7c21ade774bb7fd32a57d2ab19d7783a769099e01b9eb50ff92
Download

Enhancement

PLUG-17420
The Subscription ID field has been removed from the Office 365 configuration as it was not available in certain customer environments and could prevent successful setup.

Bug Fix

PLUG-17138
In some cases, Office365 suddenly stopped fetching logs and stayed stuck until a manual restart.
Office365 v6.0.1 ▾
Version: v6.0.1
Release date: April 10, 2025
Supported On: Logpoint v7.5.0 and later; Director v2.6.0 and later
SHA 256: 8e2f10cbd3ee589d8602650518740ab88cd97aace62d67459d568bf8b33ec311
Download

Bug Fixes

PLUG-11684
If the Log Collection Policy on localhost was updated, the Office365 UI only displayed the details of the first account, even when users clicked on other listed accounts.
PLUG-11714
The fetcher became unresponsive due to missing timeout values, causing log collection to stop.
PLUG-16289
The values for the field target_user were not normalized.
Office365 v6.0.0 ▾
Version: v6.0.0
Release date: October 30, 2024
Supported On: Logpoint v7.5.0 and later; Director v2.6.0 and later
SHA 256: 0066bd14dae87092869b71eba455e1592321ad5b884334187a8ba9120655b7a4
Download

Enhancement

PLUG-10846
You can now configure Office365 from Log Sources, which provides a centralized user interface for all log collection configurations.

Comments

  • Avatar
    Manjul Bhattarai
    June 17, 2019 08:57

    Office365 v3.5.0 has been publicly released.

    Comment actions Permalink
  • Avatar
    Daniel Hainich
    August 01, 2019 09:03

    It seems there is an Problem with the fetcher.

    127.0.0.1
    AADSTS7000218: The request body must contain the following parameter: 'client_assertion' or 'client_secret'. Trace ID: 060389f5-9662-4e29-b59b-eeb5d9981100 Correlation ID: 0e03bd28-f2c6-4386-a209-15473bd4fa52 Timestamp: 2019-08-01 09:03:24Z

    Comment actions Permalink
  • Avatar
    Jouni Peltonen
    September 18, 2019 07:25

    Same here.

    Comment actions Permalink
  • Avatar
    Janne Nyman
    September 18, 2019 11:01

    Hi Daniel, did you raise a ticket for this? Did you get it resolved?

    Best regards,
    Janne

    Comment actions Permalink
  • Avatar
    Phung Nguyen
    September 19, 2019 11:08

    Which privileges does the service account in O365 need? Reading permission to the auditlogs?

    Comment actions Permalink
  • Avatar
    Nils Krumrey
    September 19, 2019 11:18

    In addition to the permissions of the O365 Management API, I think the user just needs to be able to log in to Office 365 - so a standard domain user account should work?

    Comment actions Permalink

Article is closed for comments.

Follow

Related articles

  • Microsoft Exchange
  • Azure Log Analytics
  • Logpoint Agent (Standalone)
  • Microsoft Defender ATP
  • AWSServices
Consent Required To Proceed
By clicking “I Agree & Download”, you confirm that you are authorized to act on behalf of your organization and you give explicit consent for Guardsix to share your organization’s customer name and log source count with NXLog for the sole purposes of entitlement management, compliance verification, and support delivery related to the embedded NXLog technology in the Guardsix SIEM solution.

This data will not be used for sales or marketing and will not be shared with other third parties. You may withdraw your consent at any time by contacting Guardsix Support; withdrawal will not affect processing already performed.
Cancel I Agree & Download
Privacy policy    EULA    Terms of service   
Copyright © , Guardsix. All rights reserved.

Note: We use cookies that are essential for the smooth functioning of our website.