{
  "Name": "Microsoft Exchange Security - Exchange Online",
  "Author": "Microsoft - support@microsoft.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Azure_Sentinel.svg\"width=\"75px\"height=\"75px\">",
  "Description": "The Exchange Security Audit and Configuration Insight solution analyze Exchange Online configuration and logs from a security lens to provide insights and alerts.\n\n**Underlying Microsoft Technologies used:**\n\nThis solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs:\n\na. [Custom logs ingestion via Data Collector REST API](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/data-collector-api?tabs=powershell)",
  "Data Connectors": [
	"Data Connectors/ESI-ExchangeOnlineCollector.json"
  ],
  "Parsers": [
	"Parsers/ExchangeConfiguration.yaml",
	"Parsers/ExchangeEnvironmentList.yaml",
  "Parsers/MESCheckOnlineVIP.yaml",
  "Parsers/MESCompareDataMRA.yaml",
  "Parsers/MESOfficeActivityLogs.yaml"
  ],
   "Workbooks": [
    "Workbooks/Microsoft Exchange Least Privilege with RBAC - Online.json",
	"Workbooks/Microsoft Exchange Security Review - Online.json",
	"Workbooks/Microsoft Exchange Admin Activity - Online.json",
	"Workbooks/Microsoft Exchange Search AdminAuditLog - Online.json"
  ],
  "Analytic Rules": [],
  "Watchlists": [
    "Watchlists/ExchOnlineVIP.json"
  ],
  "WatchlistDescription": "ExchOnlineVIP Watchlists contains a list of VIP users identified in Exchange Online that would be more monitored than others. This watchlist is used in the Audit log workbooks to filter activities on those users.",
  "BasePath": "C:\\Github\\Azure-Sentinel\\Solutions\\Microsoft Exchange Security - Exchange Online",
  "Version": "3.1.7",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": true,
  "Is1Pconnector": false
}