Skip to content

Enable Microsoft 365 response actions

If you previously configured Microsoft 365 response actions in the Threat Analysis Center (TAC), you must reconfigure those actions in the new Sophos XDR and MDR. This critical step ensures you and Sophos can continuing performing actions in your environment without interruption.

Tip

This video gives you an overview of enabling Microsoft 365 response actions in Security Operations:

Prerequisites

Before you begin, ensure the following:

  • You must be a Sophos Fusion Admin or Super Admin.
  • You must be a Microsoft 365 administrator.

Add connection

To recreate the connection needed for the response actions, do as follows:

  1. Sign in to Sophos Fusion as an Admin or Super Admin.
  2. Go to Security Operations > Integrations > Marketplace.
  3. Click the Microsoft Graph API actions card.
  4. On the Microsoft Graph API page, click Add new connection.

    Add new connection.

    Tip

    Click Supported Actions to see supported response and enrichment actions and click Connector Support Documentation to view technical details of the connection.

  5. In Add a Connection, click Add new connection.

    Add a connection.

  6. Enter a Name for the connection and an optional Description and Tags, then click Done.

    Enter connection details.

    Tip

    If you prefer manual setup or have custom requirements, click Advanced Configuration to manually enter credentials, API endpoints, and other configuration values instead of using the guided authorization flow.

  7. Click Proceed to start the secure, two-step Microsoft 365 authorization.

    Proceed to authorization.

Grant permissions

To continue configuration and grant the necessary permissions, do as follows:

  1. In Pick an account, select your administrator account.

    Pick an admin account.

  2. In Permissions requested, click Accept to grant permission to the Sophos master application.

    Accept permissions.

  3. You return to Sophos XDR where the connection is created in your environment and then are redirected to the final authorization step where you grant permissions for the response actions connection.

  4. In Pick an account, select your administrator account.
  5. In Permissions requested, click Accept to continue.
  6. You return to Sophos XDR where you can see the connection is created successfully and all available actions are listed, dependent on your environment.

    Review and save connection.

  7. Review the list and click Save when done.

  8. The new connection shows in the Configured Integrations table.

Note

If you cancel either authorization step, a connection will not be created in your environment.

Verify connection

To verify the connection, do as follows:

  1. Sign in to Microsoft Entra.
  2. Go to Manage > All applications.
  3. Click Refresh at the top of the page.
  4. Verify you see the new response actions application you created at the top of the list with an activated status.

    Verify the connection in Entra.