Skip to main content
Version: 25.06

Exchange Online

Cyberhaven offers integration with Exchange Online to gain additional insight into data movement within Microsoft for emails that contain attachments. This integration uses an Azure Enterprise application to read events and user information from your organization's Azure tenant.

Establishing this connection is a simple process that requires elevated privileges within your Microsoft Entra environment. No service accounts are required to establish connectivity. Any user with Global Administrator rights in Entra ID can link Cyberhaven with Microsoft Exchange within the Cyberhaven console. So long as a user with the appropriate permissions creates the link, no separate credentials are required for the service to function — the link creates a new application with its own credentials in your Azure tenant.


Requirements

The application requires a number of permissions in order to function properly:


PermissionRequirement
Files.Read.AllList files on a drive
Mail.ReadTrack sent/received emails
User.ReadBasic.AllAbility to scan attachments
offline_accessTrack local file objects
Directory.Read.AllGet a list of users to allow admins to control the tracking
Directory.AccessAsUser.AllGet a list of users to allow admins to control the tracking
Reports.Read.AllReceive a list of newly uploaded files

Dependencies

Network

Security exclusions

Limitations