Microsoft 365 (formerly Office 365) is Microsoft’s cloud productivity suite. Because it’s the backbone of daily business communication and collaboration, its audit logs and security signals are a critical data source for detecting business email compromise, phishing, and insider threats.
How it works
Direct API integration (office365) pulling mailbox and admin activity logs.
Data ingested
Email phishing signals, mailbox audit logs, M365 admin activity
Frequently asked questions
You connect Expel to Microsoft 365 through an OAuth-based authorization, linking your tenant to Expel’s registered Azure app rather than handing over credentials. The connection requests Microsoft Graph API, Azure AD, and O365 Management API permissions, and Expel never stores customer credentials since access runs entirely on OAuth tokens.
Expel’s Microsoft 365 integration connects through OAuth to your tenant using Microsoft Graph API, Azure AD, and O365 Management API permissions, then ingests signals into Workbench for analyst investigation. When Expel confirms a phishing email, it can remove that message from affected mailboxes automatically through API commands to the mail service.
Expel differs from relying only on Microsoft 365’s native alerting by investigating confirmed threats and acting on them directly. Expel connects via OAuth using Graph API and O365 Management API permissions, ingests signals into Workbench, and can remove malicious email from mailboxes automatically through API commands, closing the loop that native alerting alone leaves open.
Expel can automatically remove phishing emails flagged in Microsoft 365 by sending API commands directly to the mail service, pulling the malicious message from affected mailboxes. This remediation follows Expel’s investigation of the threat in Workbench and runs on the same OAuth-based access Expel uses to connect to your tenant, without ever storing credentials.
Expel walks through its Microsoft 365 integration in a live demo you can request at expel.com/request-demo. The session shows how OAuth-based onboarding connects your tenant to Expel’s registered Azure app, how signals flow into Workbench, and how Expel removes malicious email from mailboxes automatically once a phishing threat is confirmed.
