-
Notifications
You must be signed in to change notification settings - Fork 3.5k
Microsoft 365 Audit General & DLP Solution v1.0.0 #13431
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
New solution with two CCF connectors to ingest M365 Audit.General and Audit.DLP events from O365 Management Activity API. Outscopes some events which are already covered by other Sentinel connectors: Teams, Dynamics, Purview Information Protection.
|
@v-shukore please initiate re-validation. there appeared to be BOM (Byte Order Mark) at the start of the file (mainTemplate.json) which likely caused many fails. |
|
@v-shukore Arm-ttk validation error "#13 9.701 DeploymentTemplate Must Not Contain Hardcoded Uri |
|
Hi @markolauren Kindly refer to the solution mentioned below for the correct folder structure and make the necessary updates. The data file and data connector files are missing, and the release notes and solution metadata are not in the proper format Thanks! |
|
@v-maheshbh added needed corrections. i hope we're getting closer :) |
|
Can we re-validate? now there's missing files and corrections done. |
|
For Solution validation error: "Error message: Invalid value for the support "tier" field. Supported values are: Microsoft, Partner, Community." => this is defined like this: "_solutionTier": "Community", "support": { |
|
How are we proceeding? |
|
Hi @markolauren Kindly attach the testing screenshot of the ccf connector in the connected state. Thanks! |
…Connectors/M365AuditDLP_DataConnectorDefinition.json to Solutions/Microsoft 365 Audit General and DLP/Data Connectors/M365Audit_CCF/M365AuditDLP_DataConnectorDefinition.json
…M365Audit_CCF/M365AuditDLP_DataConnectorDefinition.json
…M365Audit_CCF/M365AuditGeneral_DataConnectorDefinition.json
|
@v-maheshbh thanks for the feedback. changes are now done. please re-validate and guide me forward :) here's screenshot of both connectors as "connected" and data coming in: |
|
Hi @markolauren Please package the solution version 3.0.0 (Update the same in the release notes.) using the V3 tool. You can follow the steps outlined in the README linked below to complete the packaging: Thanks! |
…ditGeneral_ConnectorDefinition.json
…ral_PollerConfig.json
…LP_ConnectorDefinition.json
…Connectors/M365Audit_CCF/M365Audit_DCR.json to Solutions/Microsoft 365 Audit General and DLP/Data Connectors/M365Audit_DCR.json
|
@v-maheshbh Done.
|
|
@v-maheshbh Do we have pieces together now? |


New solution with two CCF connectors to ingest M365 Audit.General and Audit.DLP events from O365 Management Activity API.
Outscopes some events which are already covered by other Sentinel connectors: Teams, Dynamics, Purview Information Protection.
Required items, please complete
Change(s):
Reason for Change(s):
Testing Completed:
Checked that the validations are passing and have addressed any issues that are present: