Overview
- This explains the items that administrators of Cloud Protection should consider in advance in preparation for responding when a threat is discovered.
Notes
- The content of this article is based on the product specifications as of August 2026 and may be subject to change without notice.
Types of Threats That Can Be Detected
Cloud Protection monitors the following threats that may occur on Microsoft 365 in real time and can automatically take action when a threat is detected.
-
Exchange Online
・Files containing malware (viruses, Trojan horses, ransomware, etc.) attached to items (※) on Exchange Online
・Malicious URLs on Exchange Online items
・Leakage of Microsoft 365 accounts to third parties (account compromise)
・Malicious inbox rules
※ Microsoft Office 365 user mailbox items such as emails, attachments, and groups -
SharePoint
・Files containing malware (viruses, Trojan horses, ransomware, etc.) or malicious URLs uploaded to created sites -
OneDrive
・Uploaded files containing malware (viruses, Trojan horses, ransomware, etc.) or malicious URLs -
Teams
・Uploaded files containing malware (viruses, Trojan horses, ransomware, etc.) or malicious URLs
※ The file types on SharePoint / OneDrive / Teams for which malicious URLs can be detected are as follows.
- Microsoft Excel / Microsoft Word / Microsoft PowerPoint / PDF / OpenDocumentPresentation / OpenDocumentSpreadsheet / OpenDocumentText
- For PDF files, only hyperlinked URLs are Target.
Responding to Threats
When a threat is detected, the following responses are available.
Exchange Online
1. Malware Files Attached to Exchange Online Items+
2. Malicious URLs on Exchange Online Items+
3. Malicious Inbox Rules+
4. Compromised Accounts+
5. Notifications+
SharePoint
1. Malware Files Uploaded to SharePoint Sites+
2. Notifications+
OneDrive
1. Malware Files Uploaded to OneDrive+
2. Notifications+
Teams
1. Malware Files Uploaded to Teams Sites+
2. Notifications+
Points to Consider for Policy Configuration
Cloud Protection allows you to configure policy settings using the following three methods and start operations.
- Take no action and only configure notifications
- Protect only some users
- Start detection / quarantine for all users
※ Please refer to the following for how to create a policy
Creating a New Policy
▼ Take no action and only configure notifications+
▼ Connect only some users+
▼ Start applying to all users+
Reference
Response When a Threat Is Detected
How to Check Details of Detected Threats
Checking the Dashboard
Translation Disclaimer
This article has been automatically translated from the original Japanese version for your convenience.
While we strive to ensure accuracy, we cannot guarantee its reliability or completeness.
In the event of any discrepancies or questions regarding the content, the official Japanese version shall prevail.