Due to the design of the Office 365 Management Activity API, you may see events being delayed or received out of order. See Office 365 Event Latency for more information.
- In USM Anywhere, go to Data Sources > BlueApps.
- Click the Available Apps tab.
- Search for the BlueApp, and then click the tile.
- Click Configure API.
- If you have more than one deployed USM Anywhere Sensor, select the sensor that you want to use for the enabled BlueApp. BlueApps operate through a deployed sensor and use APIs to integrate with the connected third-party technology. Select the sensor that can access the integration endpoint. The HTTPS connections to the API will originate from this sensor, so it is important to make sure the sensor has network access to the BlueApp API endpoints.
-
Follow the instructions on the page to register the BlueApp for Office 365 in Azure, and then copy the Application (client) ID and Directory (tenant) ID.
This step is better conducted in a different browser.
- Enter the copied IDs in the Tenant ID and Application ID fields.
-
Select the endpoint for Office 365 Management Activity API:
- Office 365:
https://manage.office.com - Office 365 US Government:
https://manage.office365.us
- Office 365:
- Click Save.
-
Verify the connection.
After USM Anywhere completes a successful connection to the Office 365 APIs, a
icon displays in the Health column.
If the
icon displays, there is a problem with the connection. The Message column provides information about the issue. Repeat the steps to fix the configuration or troubleshoot your Office 365 connection.
- In the USM Anywhere main menu, go to Settings > Scheduler and search for the collection job for Office 365.
-
Enable the job if it is not already enabled.
When this job runs for the first time after the connection, it collects Office 365 events from the previous hour. On subsequent runs (every 20 minutes), it only collects new events since the last check. In the unlikely event that the AlienApp stops working after it is enabled, Microsoft Azure keeps Office 365 events for 7 days. The AlienApp will resume collecting events after it recovers.The BlueApp will not work if the scheduler job is not enabled.