Detecting Threats in Office 365

Understand how Oracle CASB Cloud Service detects threats for Office 365.

Oracle CASB Cloud Service detects behaviors that indicate an insider or external threat (for example, access from a suspicious IP address, excessive mass transfers and deletes of sales data, or a user hopping between IP addresses and geographical locations). For more information, see Managing Behavioral Anomalies and Threats.

Threat detection can alert you, for example, when a user is sending an unusual amount of email, has a suspicious number of failed logins (suggesting a brute-force attack), or appears to be accessing their Office 365 account from an anonymizing proxy.

Oracle CASB Cloud Service currently generates behavioral threats for the following:

  • Exchange Online

  • SharePoint/OneDrive

  • Azure AD