Introducing CrowdStrike Falcon® Next-Gen Identity Security: The future is here. Learn more

Data Connector built for Microsoft Graph API

Data Connector built for Microsoft Graph API

About Microsoft Graph API data ingest for Defender for Office 365 and Azure Active Directory

Detect elusive threats with unified identity and email security data in Falcon Insight XDR. With CrowdStrike Falcon®  Insight XDR, you can easily ingest Microsoft Defender for Office 365 email alerts and Azure Active Directory Identity telemetry into the CrowdStrike®  Falcon platform to gain comprehensive cross-domain visibility of threats throughout your attack surface. See Microsoft Defender for Office 365 email alerts and Azure AD identity events via Microsoft‘s Graph API within the Falcon console alongside additional threat indicators from other domains to minimize context switching across multiple interfaces, speeding up detection and triage, while improving accuracy.

  • Enable faster cross-domain threat detection with Microsoft alerts
    Get extended visibility across email and endpoint threat vectors with Microsoft Defender for Office 365 email and Azure AD identity alert-based threat indicators within Falcon Insight XDR.
  • Get ahead of email and identity threats
    Leverage Microsoft Defender for Office 365 and Azure AD‘s visibility and intelligence of email and identity threats with your existing CrowdStrike security data to gain multi-layered threat protection.
  • Unify threat visibility in a single console
    Cut investigation and triage time down by minimizing context switching and accelerating threat detection through CrowdStrike‘s unified, threat-centric command console.

Get Started

Enhance XDR detections with Microsoft Defender for Office 365 email and Azure Active Directory identity data

  • Enable faster cross-domain threat detection with Microsoft alerts
  • Get ahead of email and identity threats
  • Unify threat visibility in a single console
Configure

Not A CrowdStrike Customer?

Try CrowdStrike

More from CrowdStrike

AbuseIPDB SOAR Actions

Identify and mitigate threats with real-time abuse data.

AlienVault OTX SOAR Actions

Ensure fast detection and response with community-powered threat intelligence

Ansible for Falcon LogScale

Log and analyze Ansible playbook data in Falcon LogScale

Marketplace resources

Our partners

Our partners

CrowdStrike partners with the leaders in cybersecurity to deliver best-in-class protection.

CrowdStrike Shopping Bag icon

Buying on Marketplace

Buying on Marketplace

Explore all the listings that are available to purchase from CrowdStrike — some even qualify for CrowdCredits.

Become a partner

Become a partner

Join our open cybersecurity ecosystem of best-of-breed solutions to drive innovation and stop breaches.