Abstract
Learn more about collecting logs and data from Microsoft 365.
The Microsoft 365 email collector fetches email metadata through Microsoft Graph API, using an authorized app. A compliance mailbox is not required.
Danger
A user account with the Microsoft Azure Account Administrator role is required to set up a new Microsoft 365 email collector.
The following Microsoft Graph API permissions are required:
Mailbox access (read-write)
Read and write mail in all mailboxes
Read contacts in all mailboxes
Read all user mailbox settings
User information, groups, and directory data (read-only)
Read directory data
Read all groups
Read all users' full profiles