The Microsoft O365 Management Activity API provides information from what is referred to as the ‘Unified Audit Log’. This is a single audit log that covers actions across all the various Microsoft products and records what is done.

Sophos MDR and Sophos XDR customers using Microsoft 365 can strengthen their defenses against advanced threats. The integration sends Microsoft 365 alerts to the Sophos Central platform, which are then filtered, cleaned, correlated, and in some cases, escalated for investigation by analysts.

