Alert Profiles
This section allows you to add a new alert profile under a particular category. You can also choose severity and actions for the alerts. The profile can then be viewed in the Alert Tab, under the configured Service and Category.
Under this section you can:
Prerequisite: Please ensure if you have enabled auditing to be able to add an alert profile.
To add a new alert profile
- Go to the Settings tab.
- Select Configuration → Audit Configuration → Alert Profiles in the left pane.
- Click Add Alert Profile.
- Enter the alert Profile Name.
- Enter the Description.
- Choose Severity.
- Choose the desired Office 365 Service from the drop-down box.
- Choose a Category.
- Now you can select Actions, corresponding to the category chosen.
- You can customize the Alert Message. Click Macros and choose the ones you want to add.
Note: Macros are pre-defined keywords that auto-fill entries and can be used to customize mailers specific to the recipient.
- If you wish to notify users via email, click on Advanced Configuration.
- Enable Email every alerts corresponding to this profile checkbox.
- Select the Notification Template to be used using the + option.
- You can customize your Target Objects and choose users or groups to which you want to generate the audit for.
- You can also customize your Target Callers, similarly.
- Click Add to complete the process.
Note: The audit report generated for the group will constitute all the members present in the group, at the time of view.
View an existing profile
- Go to the Settings tab.
- Select Configuration → Audit Configuration → Alert Profiles in the left pane.
- Click Search icon if you are looking for a specific alert.
- You can view alerts of a specific Office 365 Service or/and Category by clicking the corresponding tab
- You can also view Enabled/Disabled alerts using the Filter option found at the top right corner of the table.
Modify an existing profile
- Go to the Settings tab.
- Select Configuration → Audit Configuration → Alert Profiles in the left pane.
- Select the checkbox corresponding to the alert that you wish to modify. You can select multiple alerts.
- Select Manage drop-down found at the left corner of the table.
- Click Enable icon under Actions column, if you wish to enable a disabled alert.
- Click Disable under Actions column, if you wish to disable an enabled alert.
- Click Edit under Actions column, to make any changes to the existing alert.
Delete an existing profile
- Go to theSettings tab.
- Select Configuration → Audit Configuration → Alert Profiles in the left pane.
- Click Delete, if you wish to remove an existing profile.You can perform bulk operations by choosing multiple profiles.
- Click on Alert Settings to delete alters older than days you specify.
Configure retention period for alerts
You need to configure the number of days for which the alert messages must be retained, for better disk space management. Once configured the alert messages older than the retention period will be automatically deleted.
- Go to theSettings tab.
- Choose Configuration → Audit Configuration → Alert Profiles from the left pane.
- In the page you see, select the Alert Settings option found in the top right corner.
- Select theĀ Delete alerts older than check box, andĀ provide the number of days for which the alert messages must be retained in the text box found.
Target Objects:
These are objects on which mailbox login, delete modification and more such events can be performed. They are further classified as users and groups.Target users constitute all the Azure Active Directory user accounts. Target groups are the Active Directory groups.
Target Callers:
These are objects who perform events like mailbox login, deletion, creation and much more on the Target Objects.
They are further classified as users and groups.Target users constitute all the Azure Active Directory user accounts. Target groups are the Active Directory groups.
Report Generation:
When you want to generate a report, you can choose the corresponding users as well as groups and a cumulative report will be generated. For Target Groups, the report will be generated only for current group members.
For example, assume that mailbox 'A' has been delegated to user 'X' and 'Y'. In order to create a profile, which will report the non-owner accesses of mailbox "A", the Target Object will be Mailbox A and the Target Callers will be Users X and Y.