How to monitor/get the email alerts of Service accounts being used/someone tried to login to that account in M365 via Cloud app security policy alerts or any other way as I saw blogs but it was not clear to me?

Vinod Survase 4,716 Reputation points
2023-09-08T14:54:27.21+00:00

How to monitor/get the email alerts of Service accounts being used/someone tried to login to that account in M365 via Cloud app security policy alerts or any other way as I saw blogs but it was not clear to me?

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
4,217 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
118 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,353 questions
{count} votes

Accepted answer
  1. James Hamil 22,976 Reputation points Microsoft Employee
    2023-09-11T21:09:16.9566667+00:00

    Hi @Vinod Survase , you can use Azure AD sign-in logs. You can export these logs to a security information and event management (SIEM) tool, such as Microsoft Sentinel, to build alerts and dashboards.

    To set up email alerts, follow these steps:

    1. Go to the Azure portal and select the Cloud Service (extended support) deployment you want to enable alerts for.
    2. Select the Alerts blade.
    3. Click the New Alert icon.
    4. Input the desired conditions and required actions based on the metrics you are interested in tracking. You can define the rules based on individual metrics or the activity log.
    5. Configure the alert conditions, actions, and details as needed.
    6. Save the changes, and you will begin to see the Alerts blade populate over time based on the configured metrics.

    Please let me know if you have any questions and I can help you further.

    If this answer helps you please mark "Accept Answer" so other users can reference it.

    Thank you,

    James


0 additional answers

Sort by: Most helpful