Lookout Product Documentation

Find answers about using and optimizing Lookout products.

Microsoft 365 application suite

Secure Cloud Access can provide protection options to the entire suite of Microsoft 365 applications, including Exchange, Microsoft Teams, and Yammer, in addition to OneDrive and SharePoint.

The Microsoft 365 cloud type is an application suite. You can onboard the suite, and then select the applications for which to apply protection. Some configurations, such as key management, will apply to

the entire suite and cannot be specified by application. Other configurations can be customized for each application in the suite.

Secure Cloud Access provides a dedicated dashboard for monitoring activity in the Microsoft 365 suite applications. Select the Office 365 dashboard from the Monitor menu.

Turn on audit log search and verifying mailbox management by default

For monitoring of applications in the Microsoft 365 suite, you must configure settings for these options:

Turn on audit log search. You must turn on audit logging in the Microsoft Security & Compliance Center before you can start searching the Microsoft 365 audit log. Turning on this option enables user and administrator activity from your organization to be recorded in the audit log. The information is retained for 90 days.

For more details and instructions about how to turn on audit log search and turn it off, see

https://docs.microsoft.com/en-us/office365/securitycompliance/turn-audit-log-se arch-on-or-off

Verify that management of mailboxes by default is enabled. Microsoft now turns on mailbox audit logging by default. With mailbox management enabled, certain actions performed by mailbox owners, delegates, and administrators are logged automatically. The corresponding mailbox audit records will be available when you search for them in the mailbox audit log.

To verify that management of mailboxes is enabled, you must run the following command in the Exchange Online PowerShell:

Get-OrganizationConfig | FL AuditDisabled

A value of False (FL) indicates that mailbox auditing by default is enabled.

For more details, refer to

https://docs.microsoft.com/en-us/office365/securitycompliance/enable-mailbox-au diting