All Microsoft Licenses Required for Office 365 Apps
In order for RocketCyber to monitor *Office 365, the Microsoft admin account you use to link RocketCyber to Microsoft must have the following licenses/privileges:
- The account must have global admin rights.
- The account must have the Entra ID Security Reader Role. See the following URL for configuring the Security Reader Role: how-to-add-security-reader-role-in-azure-portal.html
- The account must have an Entra ID P1 or P2 License Assigned (see details below):
You can check if the account has an Entra ID P1 or P2 License assigned by logging into your Microsoft Admin Portal, Navigating to Users (and selecting the user) and looking at the Licenses and App tab as shown below:
If you do not own an Entra ID P1 or P2 license, the following link walks you through how to acquire the license from Microsoft: how-to-add-azure-ad-premium-p1-or-p2.html
NOTE An Entra ID P2 License is preferred for the Risk Detection app. If you apply a P1 license the following fields will be presented as "hidden" in the Risk Detection data:
- riskLevel
- riskDetail
- description
NOTE * GCC High, GCC and DOD are not supported versions of Microsoft 365 for integration.