Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Configure Microsoft Defender for Office 365 integration

Gain valuable insights into phishing simulation metrics directly within the Cybersecurity Executive Dashboard through seamless integration with Microsoft Defender for Office 365.

Before you begin

Role required: sn_sec_phish_msatk.ms_admin

About this task

To learn more about simulating a phishing attack and setting up a tenant, see:

Procedure

  1. Navigate to All > Microsoft Attack Integration > Microsoft Attack Configurations.

  2. Select New.

  3. On the form, fill in the details:

    FieldDescription
    Integration InstanceName of the integration instance. Select the integration instance using the Lookup icon.
    Tenant IDTenant ID of the application created on the Microsoft Azure portal.
    Client IDClient ID of the application created on the Microsoft Azure portal.
    Client SecretClient secret of the application created on the Microsoft Azure portal.
    BookmarkDate from which the simulations must be fetched.
    Token UrlBase URL from where the token is created to access the Microsoft Simulations API.
    All Simulation UrlBase URL of the Microsoft Simulations API.
    1. Select New if no integration instance is available.

    2. On the form, fill in the details:

      FieldDescription
      NameName of the integration instance.
      ApplicationName of the application (Microsoft Defender for Office 365).
      IntegrationThird-party integration reference (Microsoft Attack Integration).
      ActiveDefault is activated (selected). If cleared, the instance isn't active.
      DescriptionShort description of the integration instance.
  4. Select Submit.

  5. Navigate to All > Security Simulation and Training > Integrations.

  6. Select Microsoft Attack integration.

  7. Select Execute Now to execute and collect data from Microsoft.