Microsoft 365 and Azure record every sign-in, mailbox rule and role change. When a question arrives months later, the record is gone. Microsoft keeps standard audit logs for 180 days by default, and Azure deletes activity log events after 90.
Tenants
Microsoft's shared responsibility model is clear: whatever the deployment, the customer keeps responsibility for data, endpoints, accounts and access management. The provider keeps the service running. It does not keep your evidence. Three windows decide what survives.
180 days
Microsoft 365 standard audit records generated since October 2023 are kept for 180 days by default. Premium audit extends Exchange, SharePoint, OneDrive and Entra records to one year.
90 days
Azure retains activity log events for 90 days and then deletes them.
7 days
The Office 365 Management Activity API serves content for seven days. A collector that stops for a week loses that week for good.
Collection
Most cloud monitoring asks you to install something in the tenant or forward logs to a service you do not control. Both add a dependency to the thing you are trying to watch.
ARRTECH SIEM collects Microsoft 365 through its audit API, Azure and Microsoft Graph, and Elasticsearch through one agent that acts as an intermediate collector. Nothing is installed in the tenant. Credentials sit in the console vault and are tested against the source before they are saved. If the SIEM server is unreachable, the agent buffers and delivers when it returns.
The SIEM runs on Debian, Ubuntu or Red Hat, on your servers. Your data stays yours.
Evidence
An auditor, an insurer or a court asks two questions of a cloud log: does it still exist, and could anyone have changed it.
ARRTECH SIEM keeps every record for at least two years, compressed at least 20 to 1, with retention set per source. Every write is hashed and signed with the SIEM certificate, each signature records the one before it, and a qualified timestamp authority stamps the chain daily.
Any source exports with its signatures, the certificate and a standalone verifier, so a third party checks the chain without trusting the team that produced it.
Correlation
A stolen cloud credential produces a clean sign-in. What gives it away is the sequence: a Microsoft 365 login from a new place, then a mailbox rule, then a file share on the network. Each source shows one ordinary event.
ARRTECH SIEM puts a cloud sign-in and an on-premises sign-in in the same event class, graded Informational to Critical and tagged to MITRE ATT&CK. Correlation rules run across sources in memory: this in Microsoft 365, then that on the network, within a set window, is one alert. UEBA learns how each account behaves and gives it a risk score on a timeline, and the graph database shows the neighborhood around it.
Cloud feeds fail quietly. An expired credential or a changed API stops the logs and nothing else changes. The SIEM alerts when a source goes silent for a set period, and on its own health changes and errors.
Uploads
SaaS is also where your data goes. A personal cloud drive, a sync client, a browser upload or a prompt pasted into a generative AI service moves a file out of your control over HTTPS, and the tenant log never sees it.
ARRTECH DLP inspects every HTTP, HTTPS and WebSocket request and upload from any application at the kernel level, before the data leaves the machine. It reads prompts and file uploads to generative AI services by content, not by domain, inside archives too. Its Blacklisted Process rule blocks cloud sync clients by name or hash, and every action is attributed to a named user.
Response
Revoking a session or disabling a cloud account is a decision about a person, and it belongs to people. A rule that acts alone acts on a false positive as fast as on a real attack.
An ARRTECH SIEM alert, a monitored Exchange or IMAP mailbox or a REST call opens an ARRTECH SOAR incident. The playbook gathers the artifacts and can stop at an Operator step. A person decides, SOAR runs the choice through its integration nodes, and the history is kept.
Limits
What the suite does not do in the cloud.
Sources
The documented connectors are Microsoft 365, Azure, Microsoft Graph and Elasticsearch. Other providers arrive as logs through their own exports, not through a named connector. Cloud and container management platforms are predefined source categories for grouping and filtering.
Posture
ARRTECH SIEM records what happened in the tenant. It does not audit tenant settings, inventory OAuth grants or find unsanctioned apps. That is the work of a CSPM or SSPM product.
Remediation
ARRTECH SIEM changes nothing inside the tenant. Actions run through ARRTECH SOAR playbooks your team designs, and a playbook can stop for a person’s decision before it acts.
Evaluation
A proof of value connects the agent to one of your tenants beside your existing controls, with the success and stop criteria agreed before it begins. You see what the tenant would have deleted, what the correlation rules caught, and whether the signed export verifies.
Schedule a meetingSources
Products

Collects Microsoft 365, Azure and Elasticsearch logs beside every other source, signs them and keeps them for two years.

Inspects every HTTPS upload and generative AI prompt from any application at kernel level and blocks cloud sync clients by name or hash.

Opens incidents from a monitored Exchange or IMAP mailbox or a REST call and runs playbooks against them.