category: Email provider: Microsoft sectionorder: - Connect - Collect commonfields: id: EWSO365 version: -1 configuration: - display: Azure Cloud name: azure_cloud type: 15 required: false defaultvalue: Worldwide options: - Worldwide - US GCC - US GCC-High - DoD - Germany - China section: Connect advanced: true additionalinfo: More information about National clouds can be found here - https://xsoar.pan.dev/docs/reference/articles/microsoft-integrations---authentication#using-national-cloud - additionalinfo: ID can be received from the admin consent procedure - see Detailed Instructions. display: ID / Application ID name: _client_id type: 0 section: Connect required: false - additionalinfo: Token can be received from the admin consent procedure - see Detailed Instructions. display: Token / Tenant ID name: _tenant_id type: 0 section: Connect required: false - additionalinfo: Key can be received from the admin consent procedure - see Detailed Instructions. displaypassword: Key / Application Secret name: credentials type: 9 hiddenusername: true section: Connect display: '' required: false - additionalinfo: Mailbox to run commands on and to fetch incidents from. To use this functionality, your account must have delegation for the account specified. For more information, see https://xsoar.pan.dev/docs/reference/integrations/ewso365#additional-information display: Email Address name: default_target_mailbox required: true type: 0 section: Connect - additionalinfo: If this parameter is given, the commands will run with the UPN mailbox instead of the default target mailbox. display: UPN Address name: upn_mailbox type: 0 section: Connect advanced: true required: false - defaultvalue: Inbox display: Name of the folder from which to fetch incidents name: folder required: false type: 0 additionalinfo: Supports Exchange Folder ID and sub-folders e.g. Inbox/Phishing. section: Collect - defaultvalue: 'Impersonation' display: Access Type (Impersonation is deprecated as of February 2025) name: access_type type: 15 options: - Impersonation - Delegate section: Connect advanced: true required: false - display: Public Folder name: is_public_folder type: 8 section: Connect advanced: true defaultvalue: 'false' required: false - display: Fetch incidents name: isFetch type: 8 section: Collect required: false supportedModules: - agentix - xsiam - display: Incident type name: incidentType type: 13 section: Connect required: false supportedModules: - agentix - xsiam - defaultvalue: '10 minutes' display: First fetch timestamp (