If your organization is increasing your usage of @MicrosoftTeams and you want to monitor for suspicious activity then read this blog on collecting Teams data with #AzureSentinel and how to hunt in that data: https://t.co/CdmqejB3Ff
— Pete Bryan (@MSSPete) March 30, 2020
MS link here;
Protecting your Teams with Azure Sentinel
Azure Sentinel now has an integrated connector - https://docs.microsoft.com/en-us/azure/sentinel/connect-office-365 This is the recommended route for collecting these logs and supersedes the collection methods described below. Updated versions of the queries in the blog that work with data collect…