Note: In addition to setting up this Microsoft Office 365 integration, please also configure the Entra ID integration and Microsoft Graph integration to ensure you have the most complete and accurate data in Zscaler MDR.
Zscaler MDR monitors your Office 365 environment by integrating with the Office 365 Management API, which sources data from the Microsoft Unified Audit Log. The Unified Audit Log (UAL) is an aggregation of audited activities that occur within your Microsoft 365 environment. By connecting your Unified Audit Log to Zscaler MDR as an external service, Zscaler MDR will have the enhanced ability to analyze and detect threats related to email events, user sign-ins, and more, supplementing the investigation of your Microsoft email- and identity-based alerts. Supporting artifacts from the Unified Audit Log will appear alongside endpoint activity in your threat timeline where applicable.
Zscaler MDR collects and stores all event types from the Unified Audit Log for investigations and hunting, and we pay special attention to the following logs for detection purposes:
EmailRuleModificationMailboxSettingsModificationLogonAttemptMailboxAccessDelegatedMailboxFolderPermissions
Prerequisites
Before you start the Microsoft Office 365 integration, please make sure the following requirements are met:
You’re a Global Administrator user
You have an active Microsoft subscription that includes Microsoft Office 365. To check if your subscription plan includes Office 365, refer to Microsoft's Subscription Matrix.
You consent to granting Zscaler MDR permissions to your Microsoft environment. For more information on which permissions we require, see Permission Requirements for Microsoft.
You have audit logging turned on for your organization
Note
We recommend that you have the following operations turned on in your mailbox audit log section in Office 365 in addition to the operations enabled by default:
MoveSearchQueryInitiated
1 Zscaler MDR | Add the Integration
In the Zscaler MDR portal, go to the Integrations page, then click Add Integration.

On the Add integration dialog, search for Microsoft Office 365, then click Configure.

2 Zscaler MDR / Microsoft 365 | Enable Auditing and Grant Permissions
Before configuring the integration, you’ll need to enable auditing and grant Zscaler MDR permissions to access your Office 365 data:
Verify that you have auditing enabled for your organization by following the steps detailed here.
Check the box indicating that auditing is turned on and Zscaler MDR has access to your Office 365 account.

Grant Zscaler MDR permissions:
Navigate to this URL, and then log in to your Global Administrator account.
Approve the permissions requested by Zscaler MDR + Office365.
3 Zscaler MDR | Provide Your Microsoft 365 Tenant ID
Find and copy your Microsoft 365 Tenant ID. To find your ID, follow the steps in Find your Microsoft 365 tenant ID.
On the Zscaler MDR integration page, paste it into the Microsoft Office365 Tenant ID field.

4 Zscaler MDR | Customize How This Data Is Retained
[OPTIONAL] If you’re subscribed to the Zscaler MDR Security Data Lake managed storage solution, you can choose to copy the telemetry generated by the integration to long-term storage for later query or retrieval.
Check the Store in the Security Data Lake box.

Enter your desired data retention period in days. The maximum is 1095 days (three years).
[OPTIONAL] Click Advanced Configuration to exclude selected Entra ID identity groups from being counted as monitored identities.
Tip
When marking a large number of groups as out-of-scope, you can save time by designating a parent group as out-of-scope — this will automatically apply to all sub-groups nested within it, without needing to mark each one individually.
Note
Excluded groups and identities may still be included in Investigations and Threats, but will not be included in the MDR Identities count on the License Usage page.

Click Save.
FAQ
How do I know Zscaler MDR is connected to Office 365?
It can take some time before Zscaler MDR starts ingesting your audit logs. Confirmed threats from Office 365 will appear alongside endpoint activity in your threat timeline. To check the status of the integration:
In Zscaler MDR, go to Integrations.
From the table, click the Office365 integration.

From the Integrations table, click your newly created Microsoft Office 365 integration. If successful, you’ll see
Audit.Exchangeenabled in the Office365 Subscriptions table. If you don’t see any subscriptions, wait a few minutes, and then refresh the page.
How is this integration different from the Microsoft Graph for Microsoft Entra ID Protection?
The Microsoft Entra ID Identity Protection alert source and the Microsoft Entra ID and Microsoft Azure integrations are loosely related.
The alert source is focused on ingesting the alerts generated by the Identity Protection service. Zscaler MDR then analyzes the alerts to determine if a threat has occurred.
The Entra and Azure integrations ingest logs and telemetry, which flows through the Zscaler MDR detection engine and generates threats when merited.
The Microsoft Entra ID Identity Protection Alert Source and the Microsoft Entra ID and Microsoft Azure integrations work together. Suppose Zscaler MDR receives a Microsoft Entra ID log and publishes a threat for it, and we also receive an MS Graph Identity Protection alert, or vice versa. In that case, we can correlate the alert and the threat and offer extended coverage.
Why would the Entra ID integration stop receiving data after configuring the Azure integration?
This is expected behavior when both integrations are exporting data from the same Log Analytics Workspace, to account for duplicated data sets.
When Entra ID is the only integration configured, a data export is created in Log Analytics Workspace to send data to Zscaler MDR. This data is received under the Entra ID integration.
If an Azure integration is also configured using the same Log Analytics Workspace, a data export is created for this service and the data export for Entra ID is deleted. The data is then received by Zscaler MDR under the Azure integration, and the telemetry volume reported under Entra ID will drop to zero.
Because of the overlap in telemetry Zscaler MDR collects from Entra ID and collects from Azure in the same Log Analytics Workspace, a single data export is used to avoid Microsoft egress charges for redundant data.
Why is my MDR Identities license count higher than my MDR Email and Productivity Suites count?
This is due to object counting differences. MDR Identities (Entra ID) counts both User and Application objects, while MDR Email and Productivity Suites (Office 365) counts only User objects.