<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: O365 Email integration question in Cortex XSIAM Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/o365-email-integration-question/m-p/1247887#M330</link>
    <description>&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
    <pubDate>Tue, 10 Feb 2026 18:32:33 GMT</pubDate>
    <dc:creator>susekar</dc:creator>
    <dc:date>2026-02-10T18:32:33Z</dc:date>
    <item>
      <title>O365 Email integration question</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/o365-email-integration-question/m-p/1246714#M312</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;Anyone done o365 email ingestion with no adv email security license?&lt;/P&gt;
&lt;P&gt;having a hard time with the pan documentation as alot of the azure naming conventions seems to have changed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;q1 - if just using the o365 datasource and enabling the 'exchange online' option, will this be enough or do i need a separate 0365 email collector to deploy (of which i can find no documentation on the process)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the use case ultimately will be do detect and manage phishing emails.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks in adv.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jan 2026 10:18:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/o365-email-integration-question/m-p/1246714#M312</guid>
      <dc:creator>PA_nts</dc:creator>
      <dc:date>2026-01-27T10:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: O365 Email integration question</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/o365-email-integration-question/m-p/1247872#M323</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/306035"&gt;@PA_nts&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, you can ingest &lt;STRONG&gt;Microsoft 365 email data&lt;/STRONG&gt; into &lt;STRONG&gt;Cortex XSIAM&lt;/STRONG&gt; without an &lt;STRONG&gt;Advanced Email Security (AES)&lt;/STRONG&gt; license, but there are important functional differences in terms of email content visibility and detection capabilities.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;1. Collector Requirements (Q1 Answer)&lt;/H4&gt;
&lt;P&gt;To ingest email data for phishing analysis, enabling the &lt;STRONG&gt;Exchange Online&lt;/STRONG&gt; option in the legacy &lt;STRONG&gt;Office 365&lt;/STRONG&gt; data source is not sufficient and is now deprecated for email collection.&lt;/P&gt;
&lt;P&gt;Instead, you must use the dedicated &lt;STRONG&gt;Microsoft 365 data collector&lt;/STRONG&gt;, which was introduced in &lt;STRONG&gt;XSIAM 2.4&lt;/STRONG&gt; as the supported collector for email data. This collector uses the &lt;STRONG&gt;Microsoft Graph API&lt;/STRONG&gt; to retrieve detailed email metadata.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Office 365 Collector:&lt;/STRONG&gt;&lt;BR /&gt;Primarily collects audit logs and sign-in activity, which are populated in the &lt;CODE&gt;msft_o365_exchange_online_raw&lt;/CODE&gt; dataset.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft 365 Collector:&lt;/STRONG&gt;&lt;BR /&gt;Designed specifically for email-related data and populates the &lt;CODE&gt;msft_o365_emails_raw&lt;/CODE&gt; dataset.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;2. Ingestion Without an AES License&lt;/H4&gt;
&lt;P&gt;The Microsoft 365 collector will function without the &lt;STRONG&gt;Advanced Email Security&lt;/STRONG&gt; license, but data visibility is limited.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Without an AES License:&lt;/STRONG&gt;&lt;BR /&gt;Only email metadata is ingested, such as sender, recipient, timestamps, and headers. Email bodies, subjects, and attachment contents remain hidden or encrypted and are not available for XQL searches or deep analysis.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;With an AES License:&lt;/STRONG&gt;&lt;BR /&gt;Full email content, including message bodies and attachments, becomes available for advanced threat detection and analysis.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Important Licensing Note:&lt;/STRONG&gt;&lt;BR /&gt;Even without the AES license, ingested email data volume (including protected email telemetry) still counts toward your overall &lt;STRONG&gt;Cortex XSIAM Pro Per GB&lt;/STRONG&gt; ingestion usage.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;3. Use Case: Detecting and Managing Phishing&lt;/H4&gt;
&lt;P&gt;Without the AES license, phishing detection is limited to &lt;STRONG&gt;metadata-based indicators&lt;/STRONG&gt;, such as suspicious senders, abnormal sending patterns, or unusual timestamps. Advanced phishing detection that requires inspecting email content, embedded URLs, or attachments generally requires the &lt;STRONG&gt;Advanced Email Security&lt;/STRONG&gt; license.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Tue, 10 Feb 2026 13:52:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/o365-email-integration-question/m-p/1247872#M323</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-02-10T13:52:36Z</dc:date>
    </item>
    <item>
      <title>Re: O365 Email integration question</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/o365-email-integration-question/m-p/1247876#M326</link>
      <description>&lt;P&gt;&lt;BR /&gt;Thanks Susekar,&lt;/P&gt;
&lt;P&gt;yeah managed to work it out eventually. will integrate M365 without EAS license and work on what we can see... ultimately will have to look at the eas license if the client wants that level of detection..&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Tue, 10 Feb 2026 14:20:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/o365-email-integration-question/m-p/1247876#M326</guid>
      <dc:creator>PA_nts</dc:creator>
      <dc:date>2026-02-10T14:20:08Z</dc:date>
    </item>
    <item>
      <title>Re: O365 Email integration question</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/o365-email-integration-question/m-p/1247887#M330</link>
      <description>&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Tue, 10 Feb 2026 18:32:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/o365-email-integration-question/m-p/1247887#M330</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-02-10T18:32:33Z</dc:date>
    </item>
  </channel>
</rss>

