Enable Cloud Access Security Broker Protection for Microsoft 365 Tenants

Secure Access supports two Cloud Access Security Broker (CASB) features for Microsoft 365:

  • Cloud Malware protection for OneDrive and SharePoint sites within your Microsoft 365 deployment.

Note on running both MS365 and Cloud Malware: MS365 and Cloud Malware both protect users against malware. However, their functionalities are not redundant. MS365 might discover malware that Cloud Malware does not find. Cloud Malware also finds malware that MS365 overlooks. There is value to running MS365 and Cloud Malware simultaneously.

  • Detection of third-party cloud applications that have been granted OAuth-based permission to access a user's protected resources on Microsoft 365. For more information, see Third-Party Apps Report.

Table of Contents

Prerequisites

  • Full Admin user role. For more information, see Manage Accounts.
  • Chrome or Firefox (recommended) with pop-up blockers and ad blockers disabled (only for the duration of authorization)
  • The user performing the installation must use a service account with a Microsoft 365 Global Admin and active license
  • Audit log must be enabled for Microsoft 365. For more information, refer to Microsoft Technical documentation and search for Turn auditing on or off.
  • Sharepoint Online and OneDrive must be enabled for the organization.
  • The following IP addresses must be allowed if there are Firewall rules that prevent third-party applications:
    • 146.112.161.0/24
    • 146.112.163.0/24
    • 146.112.165.0/24
    • 146.112.167.0/24
  • Users must have the following API permissions for Microsoft:
API/ Permissions NameTypeDescriptionAdmin Consent Required
Microsoft Graph
1. Directory.AccessAsUser.AllDelegatedAccess directory as the signed-in userYes
2. Directory.Read.AllApplicationRead directory dataYes
3. Files.Read.AllDelegatedRead all files that user can accessNo
4. Files.Read.AllApplicationRead files in all site collectionsYes
5. Sites.Read.AllDelegatedRead items in all site collectionsNo
6. User.ReadDelegatedSign in and read user profileNo
7. User.Read.AllApplicationRead all users' full profilesYes
Microsoft 365 Management APIs
1. AcitivityFeed.ReadApplicationRead activity data for the OrganizationYes
SharePoint
1. Site.FullControl.AllApplicationFull control of all site collectionsYes
2. User.Read.AllApplicationRead user profilesYes

Authorize a Tenant

  1. Navigate to Admin > Authentication.
  2. Click to expand Microsoft 365 in the list of Platforms.
  3. Click Authorize New Tenant in the Cloud Access Security Broker subsection to add a Microsoft 365 tenant to your Secure Access environment.
  1. Check the boxes to confirm that you meet all three Authentication Requirements in the Microsoft 365 Authorization Prerequisites dialog, then click Next.
  1. Create a name for your tenant, then click Next.
  2. Select one or both Cloud Access Security Broker (CASB) features to authenticate: Cloud Malware and Third-Party Apps. Select the Monitor or Quarantine response action for Cloud Malware only. Click Next.

For more information on Cloud Malware monitoring and quarantine features, see Manage Cloud Malware Protection. For more information on Third-Party Apps detection features, see Third-Party Apps Report.

  1. Click Next and log into Microsoft 365 with admin credentials to authorize your Microsoft 365 account as a Secure Access CASB.

Secure Access displays a message when the authorization is complete. It can take up to 24 hours for the CASB integration status in Secure Access to show that authorization is complete.

  1. Click Done to complete.

Revoke Authorization

  1. Under Action, click Revoke. You can revoke any authorized tenant.
1550
  1. Confirm to proceed. The selected account is not authorized.
1032

Enable Cloud Malware Protection for Google Drive < Enable Cloud Access Security Broker Protection for Microsoft 365 Tenants > Enable Cloud Malware Protection for ServiceNow Tenants