Configure Microsoft 365 for Arctic Wolf Active Response
With the Active Response service, Arctic Wolf® can perform email-based response actions in your network using Microsoft 365.
Microsoft 365 supports these response actions:
- Delete a malicious email
For more information, see Response action descriptions.
Note: Arctic Wolf does not support active response actions in Office 365 Government Community Cloud(GCC) environments.
These resources are required:
- A user account with Global Administrator permissions
- An Owner or User Access Administrator role on the subscription with
Microsoft.Authorization/*/Writepermissions - An Office 365 E1 license or higher
CAUTION: If Microsoft is your only email security solution, Arctic Wolf can only trigger response actions from Microsoft Defender for Office 365 alerts. To enable this functionality, complete Configure Microsoft Defender XDR with Graph API for Arctic Wolf monitoring.
- Contact your CST to validate the Active Response integration. Have an account or environment ready that Arctic Wolf can use to validate the desired response actions without causing interruptions.