Microsoft 365

Email threat signals & M365 activity logs

Microsoft 365 (formerly Office 365) is Microsoft’s cloud productivity suite. Because it’s the backbone of daily business communication and collaboration, its audit logs and security signals are a critical data source for detecting business email compromise, phishing, and insider threats.

How it works

Direct API integration (office365) pulling mailbox and admin activity logs.

Data ingested

Email phishing signals, mailbox audit logs, M365 admin activity

Frequently asked questions

How do I connect Expel to Microsoft 365 or Office 365?

You connect Expel to Microsoft 365 through an OAuth-based authorization, linking your tenant to Expel’s registered Azure app rather than handing over credentials. The connection requests Microsoft Graph API, Azure AD, and O365 Management API permissions, and Expel never stores customer credentials since access runs entirely on OAuth tokens.

What does Expel's integration with Microsoft 365 actually do?

Expel’s Microsoft 365 integration connects through OAuth to your tenant using Microsoft Graph API, Azure AD, and O365 Management API permissions, then ingests signals into Workbench for analyst investigation. When Expel confirms a phishing email, it can remove that message from affected mailboxes automatically through API commands to the mail service.

How is Expel different from relying only on Microsoft 365's native alerting?

Expel differs from relying only on Microsoft 365’s native alerting by investigating confirmed threats and acting on them directly. Expel connects via OAuth using Graph API and O365 Management API permissions, ingests signals into Workbench, and can remove malicious email from mailboxes automatically through API commands, closing the loop that native alerting alone leaves open.

Can Expel automatically remove phishing emails flagged in Microsoft 365?

Expel can automatically remove phishing emails flagged in Microsoft 365 by sending API commands directly to the mail service, pulling the malicious message from affected mailboxes. This remediation follows Expel’s investigation of the threat in Workbench and runs on the same OAuth-based access Expel uses to connect to your tenant, without ever storing credentials.

How do I request a demo of Expel with Microsoft 365?

Expel walks through its Microsoft 365 integration in a live demo you can request at expel.com/request-demo. The session shows how OAuth-based onboarding connects your tenant to Expel’s registered Azure app, how signals flow into Workbench, and how Expel removes malicious email from mailboxes automatically once a phishing threat is confirmed.