Microsoft sentinel not ingesting M365 connector data

Brandon DeVane 0 Reputation points
2025-05-01T11:58:52.87+00:00

Greetings, we have this situation where the data connector for M365 isn't ingesting logs to sentinel. The connector shows as connected, but no logs are being ingested

From the health data, they give this message: "Tenant does not exist in the O365 Management API." With the recommended action: "Unified auditing is not enabled for the tenant in O365. Enable unified auditing in O365."

The status code for this is: SC20011

I verified that unified auditing IS enabled in our tenant. This happens for all of the connector types, exchange, sharepoint, and teams. Any idea how to correct this issue? The Microsoft Entra ID connector, and the Azure Activity connector are working fine. It just seems to be an issue with M365

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,268 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.