ms365 exchange online management alert.md

For the complete documentation index, see llms.txt. Markdown versions of documentation pages are available by appending .md to page URLs; this page is available as Markdown.

Microsoft 365 Exchange Online Management

{% hint style="info" %} This configuration is only required if you are using Dropzone AI to analyze Quarantined Emails in Microsoft Defender for Office 365. {% endhint %}

To enable Office 365 Exchange Online Management, you must first install Dropzone Certificate Credentials.

Some Dropzone actions use x509 certificate based authentication, for example retrieving quarantined emails during phishing analysis. In this section we will set up the Dropzone certificate as trusted by Microsoft.

{% hint style="info" %} Each Dropzone tenant uses a unique Dropzone certificate for maximum security. {% endhint %}

Integrations Dropdown

Click Available

Download your Dropzone certificate

Certificates & Secrets

Upload Certificate

Upload Certificate File

You should now see the certificate in the UI, including a 'thumbprint' (a cryptographic hash of the certificate.)

Certificate installed

Once you have installed your Dropzone credentials, you may assign the Office 365 Exchange Online Management permissions. To do so, do the following:

Office 365 Exchange Online

Add the following permissions:

Permission Purpose
Exchange.ManageAsApp Read file details

Create and Authorize Service Account

Next we need to run PowerShell commands to grant permissions. You may use whatever PowerShell environment you prefer. The examples below were performed using Azure's interactive Cloud Shell. You may find some of the Microsoft Azure Documentation useful.

Azure Cloud Shell Icon

PowerShell 7.4.5

# Connect to "AzureAD"
PS /home/wbagg> <b>Connect-AzureAD</b>
VERBOSE: Authenticating to Azure ...
VERBOSE: Building your Azure drive ...
Loading personal and system profiles took 8788ms.

# Run the following to get the object-id of our application, replacing
# application-id with the actual Application (Client) ID of our new app
#
#    PS /home/wbagg> <b>Get-AzADServicePrincipal -AppID "<application-id>" | Select-Object DisplayName, AppId, Id | Format-List
# 
# For example:
PS /home/wbagg> <b>Get-AzADServicePrincipal -AppID aaaaaaaa-1111-2222-3333-444444444444 | Select-Object DisplayName, AppId, Id | Format-List

DisplayName : Dropzone AI
AppId       : aaaaaaaa-1111-2222-3333-444444444444
Id          : 44726f70-7a6f-6e65-5761-734865726521
# Connect to ExchangeOnline
PS /home/wbagg> Connect-ExchangeOnline

# Run the following to create the service principal, replacing
# application-id and object-spid from the earlier values
#
#    PS /home/wbagg> New-ServicePrincipal -AppId "<application-id>" -ObjectId "<object-spid>" -DisplayName "Dropzone AI"
#
# for example
PS /home/wbagg> New-ServicePrincipal -AppId "aaaaaaaa-1111-2222-3333-444444444444" -ObjectId "44726f70-7a6f-6e65-5761-734865726521" -DisplayName "Dropzone AI"

DisplayName    ObjectId                               AppId
-----------    --------                               -----
Dropzone AI    44726f70-7a6f-6e65-5761-734865726521   aaaaaaaa-1111-2222-3333-444444444444
# Run the following to enable the Transport Hygiene role, replacing the
# application-id with the actual Application (Client) ID of our new app
#
#    PS /> New-ManagementRoleAssignment -App "application-id" -Role "Transport Hygiene"
#
PS /> New-ManagementRoleAssignment -App "aaaaaaaa-1111-2222-3333-444444444444" -Role "Transport Hygiene"

Name                           Role                RoleAssigneeName       RoleAssigneeType   AssignmentMethod   EffectiveUserName
----                           ----                ----------------       ----------------   ----------------   -----------------
Transport Hygiene-44726f70...  Transport Hygiene   ba0efd83-6465-48a...   ServicePrincipal   Direct

Locate Organization ID

Azure Custom Domain Names

Azure Custom Domain Names List