Security monitoring setup
Connect your Microsoft 365 security data
SubRosa Cyber monitors your Microsoft 365 environment for account compromise, data exfiltration and malicious activity. To do that we need read-only access to your security and audit logs.
What this grants
Read-onlyAuditLog.Read.AllDirectory.Read.AllIdentityRiskEvent.Read.AllSecurityAlert.Read.AllActivityFeed.Read, ActivityFeed.ReadDlpWhat this does not grant
- Read the contents of your email, files, chats or calendars
- Change any setting, policy, user or password
- Sign in as a user, or act on anyone’s behalf
- Delete or modify anything at all — every permission is read-only
Before you start
You need to be signed in as a Global Administrator of your Microsoft 365 tenant. Consent applies to the whole organisation, so no one else will be prompted afterwards.
You will be taken to Microsoft’s own consent screen. SubRosa never sees your password, and this site never asks for one.
Review and grant access at MicrosoftTakes about 30 seconds. You can revoke access at any time.
How to revoke access later
In the Microsoft Entra admin centre, go to Identity → Applications → Enterprise applications, find SubRosa Cyber M365 Security Connector, and choose Delete.
Access stops immediately. Please tell us if you do this — revocation is silent on our side, and we would otherwise only notice when your telemetry stops arriving.