Microsoft Defender for Office Dashboard - mattnovitsch/M365 GitHub Wiki

Summary

This dashboard will provide you with information on your Defender for Office environment, provides you with details on Malware, Phish, Spam, URL Clicks, Submissions and more. This information is pulled directly from the Microsoft Security API for your tenant. The pages include(these are examples I could get from my lab so I couldn't get all the tabs filled:

  • Overview
  • Email Malware Detection
  • File Malware Detection
  • Phish Detections
  • Spam Detections
  • URL Clicks
  • Top Users/Senders
  • Submissions

Prerequisites

  • PowerBI Desktop x64 or Power BI Report Server
  • Power BI Pro License (if you want to publish for others in your organization to see)
  • MDO Dashboard

Permissions

  • You will need at least Security Reader to view this data.
  • You can also get access via URBAC roles in Defender XDR, please work with your Defender Administrator.

Steps

  1. Open MDO Dashboard. Note: This will take a few minutes as its building the local database to generate the dashboards.
  2. During the first time logging in, the system will ask you about your credentials for the API calls. You will need to login with Entra account under Organizational Account. It should ask you twice for this report. image

References

I got this dashboard from here and updated it with somethings I think needed to be changed, like the maps for example: MDODetectionDetailsv2.3.1(legacy)