RM Logo
Technical Rating: 
Support Home PageSupport
Print This PagePrint This Page
Add to 'My Library' Add to 'My Library'

List of Microsoft 365 alerts for RM Proactive Monitoring
Published Date : 31 May 2018   Last Updated : 03 Oct 2024   Content Ref: TEC6278912  





More Information

The RM Proactive Alert Monitoring service enables RM to receive alerts from your Microsoft® 365™ tenancy, whereupon we will investigate the alert and provide you with guidance enabling you to act upon the cause of the alert. Alerts will be generated based on a pre-defined, standard configuration applied through our delivery of service for Microsoft 365 Security Monitoring Alert Config.

The list below details the type of alerts covered by this service.

Note: Configuration of alerts and policies is subject to the active licences/subscriptions of your Microsoft 365 tenancy.

Alert / Policy type

Details

RM category

Creation of forwarding/redirect rule Someone in your organisation creates an email forwarding or redirects inbox rules. Data Protection Alert
Elevation of Exchange admin privilege Someone in your organisation becomes an Exchange admin or gets new Exchange admin permissions. Security Alert
Malware campaign detected and blocked  Unusual amount of malware attacks were detected and blocked by Microsoft 365. Security Alert
Malware campaign detected after delivery Microsoft 365 detected malware in email messages delivered to users in your organisation. Security Alert
Malware campaign detected in SharePoint and OneDrive This alert is triggered when the volume of malware/virus campaign detected in SharePoint and OneDrive in your organisation becomes unusual. Security Alert
Mails have been delayed When Microsoft 365 cannot deliver a message to your on-premises or partner servers via a connector, the message is queued in Microsoft 365. Security Alert
Unusual external user file activity This alert is triggered when the volume of external user file activities in your organisation becomes unusual. Security Alert
Unusual external user file activity This alert is triggered when the volume of external user file activities in your organisation becomes unusual. Data Protection Alert
Unusual volume of file deletion This alert is triggered when the volume of files deleted in your organisation becomes unusual. Data Protection Alert
Multiple failed user logon attempts to an app A single user attempts to log on to a single app and fails more than ten times within five minutes. Security Alert
General anomaly detection An anomalous session is detected in one of the sanctioned apps, such as impossible travel, logon pattern, inactive account. Security Alert
Mass download by a single user When a single user performs more than 50 downloads within one minute. Data Protection Alert
Logon from a risky IP address When a user logs on to your sanctioned apps from a risky IP address. By default, the risky IP address category contains addresses that have IP address tags of anonymous proxy, TOR or Botnet. Security Alert
Administrative activity from a non-corporate IP address When an admin user performs an administrative activity from an IP address that is not included in the corporate IP address range category. Security Alert
Potential ransomware activity When a user uploads files to the cloud that might be infected with ransomware. Security Alert
File shared with personal email addresses When a file is shared with a user's personal email address. Data Protection Alert



FEEDBACK
Did the information in this article help answer your question?
 Yes
 No
Please add any comments about this article in the box below. If you answered No then it is important you tell us why so that we can change the article if required. We can only respond if you log in to the RM Support website or provide your contact details. Note: If you need help with a technical query, please log a call online or telephone our support team.
Thank you for your feedback, which is sent directly to the RM Knowledge team. We address every message received with the intention of improving our Knowledge Library articles. If you have an unresolved technical issue, please contact RM Support.


If this article has not helped provide a solution then it is also possible to log a call...



Document Keywords: o365, o365 alerts, rm proactive, m365, TEC6278912


Please read - important disclaimer information.
http://www.rm.com/_RMVirtual/Includes/csredirect.asp?cref=&title=Standard Content Disclaimer


Top Of PageTop of page