Available for ☑️
Plan: Enterprise
Role: Owner
SIEM (Security Information and Event Management) platforms collect and analyze security events to help organizations monitor activity and investigate incidents. When integrated with Tresorit, your SIEM platform receives selected security events from your Tresorit subscription.
The following event groups can be forwarded:
- Authentication: e.g. logins, logouts, passwords, two-factor authentication (2FA), single sign-on (SSO), and device events
- User activity: e.g. sign-ins and sign-outs
- Admin activity: e.g. policies, access control, SSO, and email domain changes
- Domain user management: e.g. user invitations, suspensions, deletions, and device revocations
Before you begin
- Currently, Tresorit supports log forwarding to Microsoft Sentinel. If you use a different provider, you can submit a request through our Roadmap.
- Before enabling SIEM integration, you must sign a Data Processing Agreement (DPA) with Tresorit.