Prerequisites
To follow these instructions, you’ll need:
- Azure subscription.
- A Microsoft Entra ID tenant.
- A user account that is a Global Administrator or Security Administrator for the Microsoft Entra ID tenant.
Configure Microsoft 365 Defender
To stream events from Microsoft 365 Defender to Event Hubs, you need to:
- Create a resource group in Azure Portal.
- Create a Microsoft Entra App Registration.
- Create an Event Hubs namespace within the new resource group.
- Create an event hub in the new namespace.
- Configure roles to export data to the new event hub.
- Configure Microsoft 365 Defender.
- Retrieve the connection string for your new event hub.
- Send the connection string and consumer group name to SOC.