Explorer and Real-time Detections
Explorer and Real-time Detections help investigate email and collaboration threats, message delivery, URLs, files, malware, phishing, and post-delivery actions.
capabilitiesCurrent
Relationships
Microsoft Defender for Office 365
Source productproductMicrosoft Defender for Office 365 Plan 1
Required licenselicenseEmailEvents
Related tabletableEmailUrlInfo
Related tabletableEmailAttachmentInfo
Related tabletableEmailPostDeliveryEvents
Related tabletableUrlClickEvents
Related tabletableCampaignInfo
Related tabletableMessageEvents
Related tabletableMessageUrlInfo
Related tabletableMessagePostDeliveryEvents
Related tabletableMicrosoft Graph Security API
API accessapi
Source productproductMicrosoft Defender for Office 365 Plan 1
Required licenselicenseEmailEvents
Related tabletableEmailUrlInfo
Related tabletableEmailAttachmentInfo
Related tabletableEmailPostDeliveryEvents
Related tabletableUrlClickEvents
Related tabletableCampaignInfo
Related tabletableMessageEvents
Related tabletableMessageUrlInfo
Related tabletableMessagePostDeliveryEvents
Related tabletableMicrosoft Graph Security API
API accessapi
Configuration Methods
| Method | Support | Reference or Gap |
|---|---|---|
| Portal | Supported | Reference |
| PowerShell | Supported | Reference |
| REST API | Gap | Explorer is primarily a portal investigation experience; use Graph Security and hunting APIs for programmatic investigation. |
| Graph | Supported | Reference |
| ARM | Gap | No ARM resource is recorded for this capability. |
| Bicep | Gap | No Bicep resource is recorded for this capability. |
| Terraform | Gap | Explorer is an investigation surface, not Terraform-managed configuration. |
| GitHub Actions | Supported | Reference |
| Azure DevOps | Supported | Reference |