Skip to main content

Overview

Ocean can operate in two permission modes: Read-Only for threat monitoring and reporting, or Read/Write for active threat protection. This guide explains how to upgrade from read-only to read/write mode, enabling Ocean to automatically remediate detected threats by moving or quarantining malicious emails.
A Microsoft 365 Global Admin account is required to grant the additional permissions.

What Changes with Read/Write Mode

Read-Only Mode

  • Ocean analyzes and reports on threats
  • No emails are moved, deleted, or quarantined
  • Full visibility into threat landscape
  • Your team manually handles remediation

Read/Write Mode

  • Automatic threat remediation based on configured policies
  • Malicious emails can be quarantined or moved to trash/spam
  • Users can be notified of threats
  • Quarantined emails can be released by administrators

Remediation Actions

With read/write permissions, Ocean can perform the following actions based on your configured policies:
ActionDescription
QuarantineRemoves the email from the user’s mailbox and stores it securely for admin review
Move to TrashMoves the email to the user’s Deleted Items folder
Move to SpamMoves the email to the user’s Junk Email folder
Do NothingLogs the threat but takes no action (useful for monitoring)
Remediation actions are configurable per threat type (malicious, spam) and can be customized to match your organization’s security policies.

Upgrade Steps

1

Access Integration Settings

Navigate to Integrations in the Ocean portal. Locate your Microsoft 365 integration and click Edit.
2

Select Read & Write Permissions

In the integration wizard, change the permission level from Read to Read & Write.
Select Read & Write permissions
3

Save Changes

Click Save to initiate the permission upgrade. You will be redirected to Microsoft 365 to authorize the additional permissions.
4

Authorize Additional Permissions

  1. Log in to Microsoft 365 with a Global Admin account
  2. Review the additional permissions being requested
  3. Click Accept to grant the permissions
Microsoft consent for additional permissions
5

Upgrade Complete

Once authorized, your integration is upgraded to Read/Write mode. Ocean will now actively protect your organization based on your configured remediation policies.

Additional Permissions Required

When upgrading to Read/Write mode, Ocean requests the following additional Microsoft Graph API permissions:

Mail Management

Scope: Mail.ReadWriteWhat it does: Enables the app to create, read, update, and delete mail in all mailboxes without a signed-in user.Why it’s needed: Allows Ocean to move or delete malicious emails from user mailboxes as part of automated remediation.
Scope: MailboxSettings.ReadWriteWhat it does: Enables the app to create, read, update, and delete all user’s mailbox settings.Why it’s needed: Allows Ocean to manage mailbox rules and settings as part of threat remediation workflows.

Mailbox Folder Management

Scope: MailboxFolder.ReadWrite.AllWhat it does: Enables the app to create, read, update, and delete mail folders in all mailboxes.Why it’s needed: Allows Ocean to create quarantine folders and manage email organization during remediation.
Scope: MailboxItem.ImportExport.AllWhat it does: Enables the app to import and export items in all mailboxes.Why it’s needed: Allows Ocean to restore quarantined emails back to user mailboxes when released by administrators.
Scope: User-Mail.ReadWrite.AllWhat it does: Enables the app to read, update, create and delete all user mail.Why it’s needed: Provides comprehensive access for threat remediation actions across all protected mailboxes.

External User Management

Scopes: ExternalUserProfile.ReadWrite.All, PendingExternalUserProfile.ReadWrite.AllWhat it does: Enables the app to read and write external user profile information.Why it’s needed: Allows Ocean to manage external sender information as part of threat intelligence and remediation.

Complete API Permissions Summary

Below is the complete list of Microsoft Graph API permissions for Read/Write mode (includes all read-only permissions plus the additional write permissions):

Read Permissions (base permissions)

User.Read.All
User.ReadBasic.All
AuditLog.Read.All
Contacts.Read
Mail.Read
Mail.ReadBasic.All
Organization.Read.All
OrgContact.Read.All
Group.Read.All
Directory.Read.All
GroupMember.Read.All
MailboxSettings.Read
ThreatHunting.Read.All

Additional Write Permissions

Mail.ReadWrite
Mail.Send
MailboxFolder.ReadWrite.All
MailboxItem.ImportExport.All
MailboxSettings.ReadWrite
User-Mail.ReadWrite.All
ExternalUserProfile.ReadWrite.All
PendingExternalUserProfile.ReadWrite.All

Configuring Remediation Policies

After upgrading to Read/Write mode, you can configure remediation policies in the Ocean portal:
  1. Navigate to SettingsPolicies
  2. Configure actions for each threat category:
    • Malicious emails: Recommended action is Quarantine
    • Spam emails: Recommended action is Move to Trash
  3. Save your policy configuration
We recommend starting with Quarantine for malicious emails, which allows administrators to review and release emails if needed.

Frequently Asked Questions

No, the upgrade only affects how Ocean handles new threats going forward. Existing emails in user mailboxes are not modified during the upgrade process.
Once upgraded and configured, Ocean remediates threats in near real-time as they are detected. Most malicious emails are quarantined within seconds of detection.
Quarantined emails can only be released by administrators through the Ocean portal. Users cannot access quarantined emails directly, ensuring malicious content remains isolated.
Email delivery continues normally even if Ocean services are temporarily unavailable. However, automatic remediation will be paused until services are restored. Threats detected during the outage will be remediated once connectivity is restored.
Ocean is designed to complement existing email security infrastructure. It operates as an additional layer of protection and does not interfere with other security tools like Microsoft Defender or third-party email gateways.

Need Help?

If you encounter any issues during the upgrade process or need assistance configuring remediation policies, contact your Ocean account executive for support.