Configure Microsoft 365 for Arctic Wolf Active Response
With the Active Response service, Arctic Wolf® can perform email-based response actions in your network using Microsoft 365.
Microsoft 365 supports these response actions:
- Delete a malicious email
For more information, see Response action descriptions.
Note: Arctic Wolf does not support active response actions in Office 365 Government Community Cloud (GCC) environments.
These resources are required:
- A user account with Global Administrator permissions
- An Owner or User Access Administrator role on the subscription with
Microsoft.Authorization/*/Writepermissions - An Office 365 E1 license or higher
- A Microsoft Defender for Office 365 integration
For more information, see Configure Microsoft Defender for Office 365 for Arctic Wolf monitoring.
- A Microsoft Entra ID P2 license
- Contact your CST to validate the Active Response integration. Have an account or environment ready that Arctic Wolf can use to validate the desired response actions without causing interruptions.