Guides
ProductDeveloperPartnerPersonal
Guides

Enable SaaS API Data Loss Protection for Microsoft 365 Tenants

Table of Contents

Prerequisites

  • Chrome or Firefox (recommended) with pop-up blockers and ad blockers disabled (only for the duration of authorization)
  • The user performing the installation must use a service account with a Microsoft 365 Global Admin and active license
  • SharePoint Online and OneDrive must be enabled
  • Audit log must be enabled for Microsoft 365. For more information, refer to Microsoft technical documentation and search for Turn auditing on or off.
  • The following IP addresses must be allowed if there are Firewall rules that prevent third-party applications:
    146.112.161.0/24
    146.112.163.0/24
    146.112.165.0/24
    146.112.167.0/24
  • Users must have the following API permissions for Microsoft:

API/ Permissions Name

Type

Description

Admin Consent Required

Microsoft Graph

  1. Directory.AccessAsUser.All

Delegated

Access directory as the signed-in user

Yes

  1. Directory.Read.All

Application

Read directory data

Yes

  1. Files.Read.All

Delegated

Read all files that user can access

No

  1. Files.Read.All

Application

Read files in all site collections

Yes

  1. Sites.Read.All

Delegated

Read items in all site collections

No

  1. User.Read

Delegated

Sign in and read user profile

No

  1. User.Read.All

Application

Read all users' full profiles

Yes

Microsoft 365 Management APIs

  1. AcitivityFeed.Read

Application

Read activity data for the Organization

Yes

SharePoint

  1. Site.FullControl.All

Application

Full control of all site collections

Yes

  1. User.Read.All
ApplicationRead user profilesYes

Authorize a Tenant

  1. Navigate to Admin > Authentication.
  2. Under Platforms, click Microsoft 365.
1700
  1. Click Authorize New Tenant in the DLP subsection to add a Microsoft 365 tenant to your Umbrella environment.
  2. In the Microsoft 365 Authorization dialog, check the checkboxes to verify you meet the prerequisites, then click Next.
1338
  1. Provide a name for your tenant, then click Next.
1414
  1. Click Next to be redirected to the Microsoft 365 login page.
1746
  1. Log in to Microsoft 365 with admin credentials to grant access.
562

You are redirected to the Umbrella Dashboard and a message appears showing the integration was successful.

  1. Click Done to complete.

Revoke Authorization

  1. Under Action, click Revoke. You can revoke any authorised tenant.
1728
  1. Confirm to proceed. The selected account will no longer be authorized.
1324

Enable SaaS API Data Loss Protection for Google Drive Tenants < Enable SaaS API Data Loss Protection for Microsoft 365 Tenants > Enable SaaS API Data Loss Protection for ServiceNow Tenants