Target
- Cloud Protection Administrators
Purpose
- This document explains the items that administrators should consider in advance when a threat is detected in Cloud Protection.
Notes
- The content of this article is based on the product details as of July 2025 and may change without notice thereafter.
Types of Detectable Threats
Cloud Protection can monitor the following threats that may occur on Microsoft 365 in real-time and automatically respond when a threat is detected.
- Exchange Online
・Files containing malware (viruses, trojans, ransomware, etc.) attached to items on Exchange Online (※)
・Malicious URLs on Exchange Online items
・Leakage of Microsoft 365 accounts to third parties (account compromise)
・Malicious inbox rules
※ Microsoft Office 365 user mailbox items such as emails, attachments, calendar events, notes, contacts, groups, etc. - SharePoint
・Files containing malware (viruses, trojans, ransomware, etc.) or malicious URLs uploaded to created sites - OneDrive
・Files containing malware (viruses, trojans, ransomware, etc.) or malicious URLs uploaded - Teams
・Files containing malware (viruses, trojans, ransomware, etc.) or malicious URLs uploaded
※ The files that can detect malicious URLs in SharePoint / OneDrive / Teams are as follows.
- Microsoft Excel / Microsoft Word / Microsoft PowerPoint / PDF / OpenDocumentPresentation / OpenDocumentSpreadsheet / OpenDocumentText
- Only hyperlinked URLs in PDF files are targeted.
Response to Threats
When a threat is detected, the following responses are possible.
Exchange Online
1. Malware files attached to Exchange Online items+
2. Malicious URLs on Exchange Online items+
3. Malicious inbox rules+
4. Compromised accounts+
5. Notification+
SharePoint
1. Malware files uploaded to SharePoint sites+
2. Notification+
OneDrive
1. Malware files uploaded to OneDrive+
2. Notification+
Teams
1. Malware files uploaded to Teams sites+
2. Notification+
Considerations for Policy Settings
In Cloud Protection, you can configure policy settings and start operations using the following three methods.
- Set notifications only without taking any action
- Protect only some users
- Start detection/quarantine for all users
※ Please refer to the following for how to create a policy
Create a New Policy
▼ Set notifications only without taking any action+
▼ Connect only some users+
▼ Start applying to all users+
Reference
Response when a threat is detected
How to check details of detected threats
Checking the dashboard