• English
  • 日本語
Log inRequest demo
Back to Technology Partners

Exaforce + Microsoft 365 E5

Put E5 protection to work across your environment

Get more from your Microsoft 365 E5 investment with AI agents that triage supported Defender detections, connect evidence across Microsoft and other tools, and coordinate governed response. Follow identities through email, endpoints, shared files, SaaS, and Azure to understand the threat and decide what to do next.

Exaforce investigating a Microsoft 365 finding: a departing global administrator changing a Teams role and deleting an Entra ID user, with the attack chain and the connected Microsoft services

Better together

Get more value from Microsoft 365 E5

Microsoft 365 E5 provides protection across identities, email, endpoints, and data. Understanding the full scope of a threat often requires connecting that Microsoft activity with evidence from other SaaS applications and cloud services.

Analysts must piece together the affected user’s access, device posture, application permissions, and subsequent activity, then determine whether it reflects normal behavior or a developing attack. That work delays response decisions and leaves less capacity for high-priority threats.

Exaforce adds AI agents, called Exabots, that continuously triage, investigate, hunt, and coordinate governed response. They connect directly to supported Microsoft services and other data sources, combine alerts with activity history and current context, and present a verdict with supporting evidence and reasoning.

E5 detections become the starting point for investigations that follow an identity through suspicious sign-ins, mailbox changes, shared files, and cloud access. Microsoft protection and controls remain in place, with response governed by your policies and required approvals.

  • Existing SIEM workflows

    Already using Microsoft Sentinel?

    Exaforce can add an AI investigation layer on top of your existing SIEM. Combine supported Sentinel incidents and Log Analytics history with direct source context, while keeping established connectors, custom detections, retained history, and playbooks in place.

Microsoft integrations

Integrations across E5 and the Microsoft ecosystem

Build on Microsoft’s security capabilities to connect evidence, investigate threats, and coordinate approved response. Exaforce connects directly across supported Microsoft 365 E5 services and Azure, with support for existing Microsoft Sentinel workflows. Available data and actions depend on licensing, enabled sources, and approved permissions.

  • E5 threat protection

    Microsoft Defender XDR

    Use E5 protection from Defender for Endpoint P2, Defender for Office 365 P2, Defender for Identity, and Defender for Cloud Apps. Exaforce triages supported incidents and alerts, queries hunting data, and adds connected-source context to extend native Defender investigations across your wider environment.

  • Identity, access, and applications

    Microsoft Entra ID

    Correlate sign-ins, risky identities, audit activity, roles, applications, and OAuth grants. Add identity risk and access context to assess who gained access and what they could reach. Approved actions include session revocation and delegated OAuth consent removal.

  • Email, files, collaboration, and audit

    Microsoft 365 and Purview

    Combine supported Exchange Online, SharePoint, OneDrive, and Teams activity with identity and sharing context. Purview supplies audit capabilities; Exaforce investigates mailbox and file access. Determine which mailboxes and files were affected and remediate harmful mailbox or sharing changes under policy.

  • Managed devices and posture

    Microsoft Intune

    Add managed-device inventory, compliance, applications, and configuration context to investigations. Assign approved management scripts through Intune for execution at device check-in, supporting governed remediation through existing Intune workflows.

  • Cloud resources, activity, and alerts

    Microsoft Azure and Defender for Cloud

    Combine Azure resource inventory, activity, and access context with supported Defender for Cloud alerts. Follow a compromised Microsoft identity into Azure to assess the resources, access, and permissions involved in cloud exposure.

  • Existing SIEM workflows

    Microsoft Sentinel

    Build on existing Sentinel connectors, custom detections, retained history, and playbooks. Exaforce investigates supported incidents and queries Log Analytics history alongside direct source context, adding AI investigation and broader context to established SIEM workflows.

What we understand

Exaforce connects users, devices, applications, permissions, and cloud resources into a shared investigation. A sign-in can be examined alongside endpoint evidence, a new inbox rule, an OAuth grant, and subsequent file access. Analysts can assess the sequence, compare it with the available activity history, and see which evidence supports the verdict.

What we can act on

Approved workflows can revoke Entra ID sign-in sessions or remove delegated OAuth consent. In Microsoft 365, they can remove inbox rules that forward or redirect mail and selected file-sharing permissions. Exaforce can also update Defender incident status.

For managed devices, Exaforce can assign approved management scripts through Intune. Execution follows device check-in. Your team defines the available actions, permissions, and approval requirements, then reviews the returned results.

Every signal in context

Follow the investigation across your environment

E5 detections can begin an investigation that continues across Microsoft 365, Azure, and connected SaaS tools. Exabots combine Defender hunting data with identity, mailbox, file, device, and cloud resource evidence to assess what happened and what the affected account could reach. Illustrative investigation: E5 detection → Investigation → Response.

  1. 01 / Detect

    Start with a Defender incident

    A Defender for Office 365 alert is correlated into a Defender XDR incident. Exaforce receives the supported incident and evidence directly.

  2. 02 / Triage

    Assess whether the account was compromised

    Exabots examine the message and affected user, then correlate Entra ID sign-ins and endpoint evidence.

  3. 03 / Scope

    Follow the identity through Microsoft and beyond

    Inspect Microsoft 365 mailbox rules, file activity, and sharing permissions, then follow the identity into connected SaaS and Azure resources.

  4. 04 / Ask

    Ask the next question

    “What did this user access after the suspicious sign-in?” Exaforce queries supported Microsoft and connected sources, then returns an answer with evidence.

  5. 05 / Verdict

    Review the evidence and recommended action

    Exaforce presents the activity timeline, affected assets, supporting evidence, and recommended actions for analyst review.

  6. 06 / Respond

    Apply Microsoft controls under policy

    With required approvals, revoke Entra ID sessions, remove unauthorized delegated OAuth grants or inbox forwarding rules, and update Defender incident status.

Connect the activity across your environment

From Microsoft 365 to Azure. Follow a compromised Microsoft identity into Azure and assess the resources, access, and permissions involved in cloud exposure.

Across connected SaaS tools. Combine Microsoft evidence with activity from other applications to scope the incident and answer security questions without manually searching each source.

Put it to work

Use cases

Triage 01

Autonomous triage of E5 detections

Exabot Triage evaluates supported Defender alerts and incidents, adds identity and asset context from Microsoft and connected tools, and distinguishes benign activity from threats with a rationale supported by evidence.

Put E5 threat protection to work while reducing repetitive review. Analysts can inspect the verdict and reasoning, then focus on the threats that need attention.

Investigate 02

Natural-language investigation and threat hunting

Ask, “What did this user access after the suspicious sign-in?” Exabots combine Defender hunting data with Entra ID, Microsoft 365 activity, and connected SaaS and cloud evidence.

Follow the account through sign-ins, endpoint activity, email, files, and connected services. Scope incidents faster and answer security questions without manually searching each source.

Respond 03

Governed identity and data response

Exabot Respond can revoke Entra ID sessions and delegated OAuth access, remove Microsoft 365 inbox forwarding rules or selected file-sharing permissions, and update Defender incident status under customer policy.

Use Microsoft controls to limit further access and remove harmful changes. Your team defines permissions and required approvals, keeping analysts in control of response decisions.

Results

Put more of your E5 investment to work

Use licensed signals and controls in investigations that connect Microsoft activity with your wider environment. Reduce manual evidence gathering, make clearer decisions, and coordinate response with human oversight.

More value from E5

Put licensed signals and controls to work in investigations.

Broader context

Connect the same user and device across Microsoft and other tools.

Clearer decisions

Review the verdict, supporting evidence, and recommended action.

Governed response

Apply approved actions with policy controls and human oversight.

Joint solution brief

See E5 and Exaforce working together

Explore how your E5 investment becomes investigations with supporting evidence and governed actions across Microsoft and connected tools. The joint solution brief covers the integrations, use cases, and an illustrative account-compromise investigation.

Download the solution brief (PDF)

Compliance

Commitment to data protection

Exaforce is audited and certified by industry-leading third party standards.

  • SOC 2 Type 2Compliant
  • SOC 2 Type 1Compliant
  • ISO 27001Certified
  • PCI DSSCompliant
  • HIPAACompliant
  • GDPRCompliant
  • USDPCompliant
  • HITRUSTCertified