Cloud Monitor Settings
Cloud Monitor audits user activities within your organisation’s Microsoft 365 environment, including Exchange Online and SharePoint Online.
To set up Cloud Monitor, you need an Azure Global Administrator account. Cloud Monitor uses a registered Azure application and certificate-based authentication to securely access activity data from Microsoft 365. These data are then analysed within GuardWare INSIGHT to provide dashboards, alerts, and reports on cloud usage and potential security incidents.
It monitors key cloud events such as:
Files accessed or downloaded from sensitive libraries
Access and download actions by anonymous, invited, or mobile users
Files accessed via links shared on Teams
Creation of anonymous links and external file access activities
SharePoint file access, download, and link creation activities
Outgoing Microsoft 365 emails
Set up Cloud Monitor
Navigate to ORGANISATION > Integrations.
Click Connect Microsoft 365. You'll be redirected to Microsoft's sign-in page.

Select your Global Administrator account or click Use another account if it is not listed.

Enter your Global Administrator email address and password. Click Next and sign in.
If your account is protected by multi-factor authentication (MFA), you'll need to approve the sign-in request. This might involve:
Approving a notification in the Microsoft Authenticator app.
Entering the code from your authenticator app.
Responding to a text message or phone call, depending on your MFA settings.

After authenticating, you'll see a permissions consent screen listing what DISCOVER is requesting access to. Select Consent on behalf of your organisation and click Accept.

You'll be redirected back to the GuardWare Management Console. A confirmation message will appear stating “Microsoft 365 monitoring configured successfully.”
Once the setup is complete, Cloud Monitor starts monitoring cloud activities, which are then displayed in INSIGHT dashboards, reports, and alerts.
Cloud Monitoring Settings
Cloud Monitoring Settings lets you enable or disable monitoring for Microsoft 365 services and manage the users whose activities are monitored. You can also view the configured primary domain and manually sync cloud data.
To access cloud monitoring settings, navigate to INSIGHT > Cloud Monitoring.
Exchange Monitoring
Use this option to enable or disable monitoring of Microsoft Exchange activities.
Enable Exchange Monitoring to monitor Exchange-related activities.
Disable Exchange Monitoring to stop monitoring Exchange activities.
Click Save to apply the configuration.

Security Group
The Security Group identifies the Microsoft 365 group used for Exchange monitoring.
When Exchange Monitoring is enabled, a security group is displayed.
To assign users:
Click Assign Users.
Select the users to be included in the monitoring group.

Click Save to assign the selected users, or click Assign All Users to assign all the listed users.
SharePoint Monitoring
Use this option to enable or disable monitoring of SharePoint activities.
Enable SharePoint Monitoring to monitor SharePoint-related activities.
Disable SharePoint Monitoring to stop monitoring SharePoint activities.
Click Save to apply the configuration.
Sync Cloud Monitor
Use the Sync button to manually synchronise the latest configuration and user information from Microsoft 365.

The Last Synced field displays the date and time of the most recent successful synchronisation.
Last updated

