Enable Cloud Malware Protection for Microsoft 365 Tenants
Secure Access supports Cloud Malware protection for both OneDrive and SharePoint sites within your Microsoft 365 deployment.
Note on running both MS365 and Cloud Malware: MS365 and Cloud Malware both protect users against malware. However, their functionalities are not redundant. MS365 might discover malware that Cloud Malware does not find. Cloud Malware also finds malware that MS365 overlooks. There is value to running MS365 and Cloud Malware simultaneously.
Table of Contents
Prerequisites
- Full Admin user role. For more information, see Manage Accounts.
- Chrome or Firefox (recommended) with pop-up blockers and ad blockers disabled (only for the duration of authorization)
- The user performing the installation must use a service account with a Microsoft 365 Global Admin and active license
- Audit log must be enabled for Microsoft 365. For more information, refer to Microsoft Technical documentation and search for Turn auditing on or off.
- SharePoint Online and OneDrive must be enabled
- The following IP addresses must be allowed if there are Firewall rules that prevent third-party applications:
52.73.52.135, 52.71.142.118, 52.40.204.69, 52.35.119.173, 52.27.150.153 - Users must have the following API permissions for Microsoft:
API/ Permissions Name | Type | Description | Admin Consent Required |
---|---|---|---|
Microsoft Graph | |||
1. Directory.AccessAsUser.All | Delegated | Access directory as the signed-in user | Yes |
2. Directory.Read.All | Application | Read directory data | Yes |
3. Files.Read.All | Delegated | Read all files that user can access | No |
4. Files.Read.All | Application | Read files in all site collections | Yes |
5. Sites.Read.All | Delegated | Read items in all site collections | No |
6. User.Read | Delegated | Sign in and read user profile | No |
7. User.Read.All | Application | Read all users' full profiles | Yes |
Microsoft 365 Management APIs | |||
1. AcitivityFeed.Read | Application | Read activity data for the Organization | Yes |
SharePoint | |||
1. Site.FullControl.All | Application | Full control of all site collections | Yes |
2. User.Read.All | Application | Read user profiles | Yes |
Authorize a Tenant
- Navigate to Admin > Authentication.
- Under Platforms, click Microsoft 365.
- Click Authorize New Tenant in the Cloud Malware subsection to add a Microsoft 365 tenant to your Secure Access environment.
- In the Microsoft 365 Authorization dialog, check the checkboxes to verify you meet the prerequisites, then click Next.
- Provide a name for your tenant, then click Next.
- Click Next to be redirected to the Microsoft 365 login page.
- Log in to Microsoft 365 with admin credentials to grant access.
You are redirected to Secure Access and a message appears showing the integration was successful. It may be up to 24 hours for the integration to be confirmed and appear as Authorized.
- Click Done to complete.
Revoke Authorization
- Under Action, click Revoke. You can revoke any authorized tenant.
- Confirm to proceed. The selected account is not authorized.
Enable Cloud Malware Protection for Box Tenants < Enable Cloud DLP Protection for Microsoft 365 Tenants > Enable Cloud Malware Protection for Webex Teams Tenants
Updated about 1 month ago