↳ GitHub sourceConnector

Microsoft 365 Assets (formerly, Office 365)

Description

The Microsoft 365 (formerly, Office 365) asset connector gives richer insights into ongoing user activities in Microsoft Sentinel by supplementing activity logs with details such as owners, permissions, retention policies and sensitivity labels. Data from this connector is used to build data risk graphs in Purview. If you've enabled those graphs, deactivating this connector will prevent the graphs from being built. [Learn about the data risk graph](https://go.microsoft.com/fwlink/?linkid=2320023). This connector is in limited private preview.
Declared status
2
Declared author / publisher
Microsoft

Declared permissions

OfficeActivity table availability
Enable the OfficeActivity table in Log Analytics.

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

1.Connect Microsoft 365 assets (formerly, Office 365) to Microsoft Sentinel.
SharePoint and OneDrive

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
M365Assets
Additional source files 2Solutions/Microsoft 365 Assets/Data Connectors/M365Asset_DataConnectorDefinition.jsonsource ↗Solutions/Microsoft 365 Assets/Data/Solution_Microsoft365Assets.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.