Skip to content
Find out how we support MDR.

Microsoft Graph Security

API

Restriction

This feature might not be available to all users yet.

You can set up a connector to add Microsoft Graph Security alerts to the Sophos Data Lake.

This lets you query Microsoft Graph data with Sophos Live Discover.

You must be an Admin or Super Admin to add or delete connectors.

Add a connector

To add a connector, do as follows:

  1. Go to Third-party Connectors.

  2. Click Microsoft Graph Security alerts.

    Third-Party Connectors page

  3. Click Add connector.

    Connectors list

  4. Enter a Name and Description.

    Add connector dialog

  5. You’re prompted to connect to your Microsoft 365 account. Click Continue.

    Connect to Microsoft 365 dialog

  6. Select your Microsoft account and sign in to it.

    Pick an account

  7. You’re prompted to give permissions to a Master App. These permissions let us create an app that will be used as a connector. Click Accept.

    Permissions request

  8. If prompted, sign in to your Microsoft account.

  9. You’re prompted to give permissions to the newly-created Sophos XDR app so that it can run as the connector and get MS Graph Data for Sophos. Click Accept.

    Permissions request

  10. You see confirmation that the connector is set up. Click Close.

    Connected successfully message

  11. In the connectors list in Sophos Central, you see the new connector.

    Connectors list

After five minutes, the connector synchronizes Sophos Data Lake with Microsoft Graph for the first time.

Sophos Data Lake is now receiving Microsoft Graph Security alerts.

Delete a connector

To delete a connector, do as follows:

  1. Go to Third-Party connectors.

  2. On the Third-Party connectors page, click Microsoft Graph Security alerts.

    Third-Party Connectors page

  3. Find the connector and turn it off. You can't delete the connector until you do this.

    Connector On/Off

  4. Confirm that you want to turn off the connector.

  5. Click the trash can icon next to the connector.

    Trashcan icon

  6. Confirm that you want to delete the connector.