For the complete documentation index, see llms.txt. This page is also available as Markdown.

Cloud Monitor Settings

Cloud Monitor audits user activities within your organisation’s Microsoft 365 environment, including Exchange Online and SharePoint Online.

To set up Cloud Monitor, you need an Azure Global Administrator account. Cloud Monitor uses a registered Azure application and certificate-based authentication to securely access activity data from Microsoft 365. These data are then analysed within GuardWare INSIGHT to provide dashboards, alerts, and reports on cloud usage and potential security incidents.

It monitors key cloud events such as:

  • Files accessed or downloaded from sensitive libraries

  • Access and download actions by anonymous, invited, or mobile users

  • Files accessed via links shared on Teams

  • Creation of anonymous links and external file access activities

  • SharePoint file access, download, and link creation activities

  • Outgoing Microsoft 365 emails

Set up Cloud Monitor

  1. Navigate to ORGANISATION > Integrations.

  2. Click Connect Microsoft 365. You'll be redirected to Microsoft's sign-in page.

  1. Select your Global Administrator account or click Use another account if it is not listed.

  1. Enter your Global Administrator email address and password. Click Next and sign in.

  2. If your account is protected by multi-factor authentication (MFA), you'll need to approve the sign-in request. This might involve:

    1. Approving a notification in the Microsoft Authenticator app.

    2. Entering the code from your authenticator app.

    3. Responding to a text message or phone call, depending on your MFA settings.

  1. After authenticating, you'll see a permissions consent screen listing what DISCOVER is requesting access to. Select Consent on behalf of your organisation and click Accept.

  1. You'll be redirected back to the GuardWare Management Console. A confirmation message will appear stating “Microsoft 365 monitoring configured successfully.”

Once the setup is complete, Cloud Monitor starts monitoring cloud activities, which are then displayed in INSIGHT dashboards, reports, and alerts.

Cloud Monitoring Settings

Cloud Monitoring Settings lets you enable or disable monitoring for Microsoft 365 services and manage the users whose activities are monitored. You can also view the configured primary domain and manually sync cloud data.

To access cloud monitoring settings, navigate to INSIGHT > Cloud Monitoring.

Exchange Monitoring

Use this option to enable or disable monitoring of Microsoft Exchange activities.

  1. Enable Exchange Monitoring to monitor Exchange-related activities.

  2. Disable Exchange Monitoring to stop monitoring Exchange activities.

  3. Click Save to apply the configuration.

Security Group

The Security Group identifies the Microsoft 365 group used for Exchange monitoring.

When Exchange Monitoring is enabled, a security group is displayed.

To assign users:

  1. Click Assign Users.

  2. Select the users to be included in the monitoring group.

  1. Click Save to assign the selected users, or click Assign All Users to assign all the listed users.

SharePoint Monitoring

Use this option to enable or disable monitoring of SharePoint activities.

  1. Enable SharePoint Monitoring to monitor SharePoint-related activities.

  2. Disable SharePoint Monitoring to stop monitoring SharePoint activities.

  3. Click Save to apply the configuration.

Sync Cloud Monitor

Use the Sync button to manually synchronise the latest configuration and user information from Microsoft 365.

The Last Synced field displays the date and time of the most recent successful synchronisation.

Last updated