How to Get Real-Time Microsoft 365 Alerts Without E5

Table of Contents

Microsoft locks its most useful alerting features behind E5 licensing, but that doesn’t mean you’re stuck flying blind on Business Premium or E3. The native alert policies available on lower tiers cover more ground than most admins realize.

This guide walks through what’s actually available without E5, how to configure it, and where the gaps show up for MSPs managing multiple tenants.

What alerts you can get without an E5 license

You can configure basic real-time alerts in Microsoft 365 without an E5 license by using standard alert policies in the Microsoft Defender portal or Microsoft Purview compliance center. Alert policies trigger when specific activities occur in a tenant, such as an admin role being granted, a user being restricted from sending mail, or someone reporting a phishing message. The limitation is that advanced capabilities like threshold-based alerting and AI-driven anomaly detection require E5 or an add-on like Defender for Office 365 Plan 2.

On Business Premium or E3, you can monitor for discrete events. You won’t get alerts that fire when a pattern emerges over time, like a user downloading an unusual number of files in a short window.

Alerts available on Business Premium and E3

Business Premium and E3 licenses include access to single-event alert policies across several categories. A single-event policy fires when a defined activity happens once, rather than when it crosses a threshold or deviates from a baseline.

  • Threat management: Malware detected in email, user-reported phishing, potential malware uploaded to SharePoint
  • Mail flow: Messages delayed, external forwarding rule created, sending limits exceeded
  • Permissions: Exchange admin role granted, service principal created, app consent granted
  • Information governance: eDiscovery search started, retention policy removed, DLP rule matched

For many organizations, single-event alerts cover the most critical security scenarios. The gap shows up when you want to detect behavioral anomalies or set numeric thresholds.

Alerts gated behind E5 and Defender for Office 365 Plan 2

Some alerting capabilities are only available with E5 licensing or the Defender for Office 365 Plan 2 add-on. If you’re evaluating what you’re missing on lower tiers, here’s the short list:

  • Unusual activity detection: Alerts based on behavioral anomalies, like a user suddenly accessing files they’ve never touched before
  • Threshold-based alerting: Policies that trigger after an activity occurs a specific number of times within a defined window
  • Advanced threat investigation: Automated investigation and response workflows tied to alerts
  • Safe Attachments and Safe Links alerting: Notifications when Defender blocks malicious content in real time

Clients on Business Premium or E3 can still monitor individual events. They miss the pattern-based detection that makes E5 alerting more proactive.

What real-time means on non-E5 licensing

“Real-time” on lower license tiers typically means minutes to hours, not seconds. Microsoft processes audit log data and evaluates alert conditions on a schedule that varies by workload and license tier. E5 tenants generally see faster alert delivery because they have access to more advanced processing pipelines.

For time-sensitive threats like account compromise, a 30-minute gap between suspicious activity and the alert can be the difference between catching an attacker mid-session and cleaning up after they’ve already exfiltrated data.

How Microsoft 365 alert policies work on lower license tiers

Alert policies follow a straightforward logic. An activity occurs in a workload like Exchange, SharePoint, or Entra ID. The system checks whether that activity matches a defined condition. If it does, an alert is generated and a notification is sent.

The flow looks like this:

  1. Activity occurs in a workload
  2. Condition matched against the alert policy definition
  3. Alert generated and logged in the Microsoft Defender portal
  4. Email notification sent to the configured recipients

Each policy has a severity level of informational, low, medium, or high. The level affects how the alert is categorized and whether it triggers a notification. You define the activity type, the conditions, and who receives the email. On lower license tiers, you’re limited to single-event conditions rather than thresholds or anomaly detection.

Default Microsoft 365 alert policies available without E5

Microsoft ships a set of pre-configured alert policies that are active by default across all license tiers. You don’t have to create anything to start receiving notifications for common security and compliance scenarios.

You can view and manage default policies in the Microsoft Defender portal under Policies & rules > Alert policies, or in the Microsoft Purview compliance center at compliance.microsoft.com.

Threat management alerts

Default threat management alerts cover the most common email and file-based threats:

  • Malware campaign detected
  • User reported a message as phishing
  • Potential malware uploaded to SharePoint or OneDrive
  • Email sending patterns consistent with spam

Mail flow alerts

Mail flow alerts notify you when something disrupts normal email delivery:

  • Messages have been delayed
  • Mail queue is growing
  • External forwarding rule created
  • User restricted from sending email

External forwarding rules are worth watching closely. Attackers often create forwarding rules to exfiltrate data without triggering obvious alarms.

Permissions alerts

Permissions alerts fire when someone gains elevated access or grants consent to an application:

  • Exchange admin role granted
  • Service principal created
  • Application consent granted by user or admin
  • Delegated mailbox access added

Information governance alerts

Information governance alerts cover compliance-related activities:

  • eDiscovery search started or exported
  • Retention policy removed
  • DLP policy rule matched
  • Sensitivity label downgraded

Default policies provide a baseline. However, they fire on single events and send notifications to a static list of recipients, which creates operational challenges when you’re managing more than a handful of tenants.

How to set up real-time Microsoft 365 alerts without E5

Creating a custom alert policy takes about five minutes per tenant. The process is the same whether you’re on Business Premium, E3, or E5. The difference is which activities and conditions are available to you.

Step 1: Open the Microsoft Purview compliance portal

Navigate to compliance.microsoft.com and go to Policies > Alert policies. You can also access alert policies through the Microsoft Defender portal at security.microsoft.com under Policies & rules.

Step 2: Create a new alert policy

Click New alert policy and give it a clear name. If you’re managing multiple tenants, a naming convention helps keep things organized. Something like “Contoso – External Forwarding Created” tells you the client and the alert type at a glance.

Step 3: Choose the activity and conditions to monitor

Select the activity you want to track from the available list. On lower license tiers, you’re limited to single-event triggers. You can add conditions to narrow the scope, like “user is a member of a specific group” or “activity occurred in a specific site.”

The activity list is long, but the most commonly monitored events include:

  • External forwarding rule created
  • Admin role granted
  • Mailbox permission changed
  • File shared externally
  • DLP policy matched

Step 4: Set recipients and notification rules

Enter the email addresses that will receive notifications when the alert fires. This is a static list. There’s no native way to route alerts dynamically based on the tenant, the severity, or the type of activity.

You can also set the severity level here. Higher severity alerts are more prominent in the Defender portal, but the notification behavior is the same regardless of severity.

Step 5: Review and activate the policy

Review your settings and turn the policy on. Once activated, alerts will appear in the Microsoft Defender portal under Incidents & alerts > Alerts when the policy triggers.

How to view triggered alerts in Microsoft 365

Triggered alerts surface in the Microsoft Defender portal at security.microsoft.com. Navigate to Incidents & alerts > Alerts to see a filterable list of all alerts across workloads.

You can sort by severity, status, or time. Clicking an alert opens an investigation pane with details about the activity, the user involved, and related events. From there, you can mark the alert as resolved, assign it to a team member, or suppress future alerts of the same type.

The investigation pane is useful, but it requires you to be logged into the portal. Alert notification emails include basic information but lack the context you’d want for quick triage.

Limitations of native Microsoft 365 alert policies

Native alerting works reasonably well for single-tenant environments with dedicated security staff. For MSPs managing dozens or hundreds of client tenants, the limitations add up quickly.

Delayed delivery on lower license tiers

Alerts on Business Premium and E3 may take 30 minutes to several hours to fire. That delay reduces the value of alerting for time-sensitive threats like credential compromise or data exfiltration. By the time you see the alert, the damage may already be done.

Static recipient lists with no routing

You can only send notifications to a fixed list of email addresses. There’s no native integration with PSA tools like ConnectWise or Autotask. Alerts don’t automatically create tickets or route to the right queue. Someone has to read the email, decide what to do, and manually create a ticket if one is warranted.

Missing context in alert emails

Notification emails include the basics: what happened, when, and which user was involved. They don’t include the detail you’d want for quick triage, like recent activity from the same user or related alerts in the same tenant. Technicians typically have to log into the portal, find the alert, and investigate manually before they can act.

No delegation to L1 and L2 technicians

Microsoft’s role-based access doesn’t support granular delegation for alert triage. Junior technicians either have full access to the security portal or none. That creates bottlenecks for senior staff, who end up handling first-response triage instead of focusing on escalations and complex investigations.

No multi-tenant view for MSPs

Each client tenant requires a separate login. There’s no single dashboard to view alerts across all managed environments. Portal-hopping is the default workflow, which means you’re logging in and out of tenants all day just to check for alerts.

How to get real-time alerts across multiple tenants without E5

Third-party platforms solve the operational gaps that native alerting leaves open. For MSPs, the value is in aggregation, routing, and delegation, not just faster alerts.

Third-party alerting built on the Microsoft Graph

Tools like Augmentt pull data from client tenants via the Microsoft Graph API. That approach enables faster alert aggregation and enrichment without requiring E5 licensing on every tenant. You get near-real-time visibility across environments from a single dashboard, rather than logging into each tenant individually.

Routing alerts to a PSA instead of a static email list

With the right platform, alerts can create tickets automatically in ConnectWise, Autotask, or other PSA tools. The ticket includes context: what happened, which user, which tenant. The technician can act without logging into another portal or copying details from an email.

Delegating alert triage to junior technicians safely

Platforms built for MSPs support role-based access with guardrails. L1 and L2 technicians can triage alerts and execute templated remediation workflows without full admin access to the client tenant. Senior time goes to escalations, not first-response triage.

Tip: If your team spends more time logging into portals than resolving alerts, the workflow is the problem, not the alert volume. Multi-tenant platforms like Augmentt consolidate alerting, remediation, and reporting into one view.

Get real-time M365 alerting without the E5 upsell

Native Microsoft 365 alert policies work for basic monitoring, but they weren’t built for MSPs managing multiple tenants on Business Premium or E3. Augmentt delivers real-time alerting, multi-tenant visibility, and PSA routing without requiring E5 across your client base.

See how Augmentt works →

Frequently asked questions about Microsoft 365 alerts without E5

Is Microsoft 365 Business Premium enough for real-time alerting?
Business Premium supports native alert policies, but delivery may be delayed compared to E5. Advanced anomaly detection and threshold-based alerting require E5 or a third-party tool.

How long does it take for a native Microsoft 365 alert to fire?
Delivery time varies by license tier and alert type. Lower tiers may experience delays of 30 minutes to several hours. E5 offers faster processing, though Microsoft doesn’t publish specific SLAs for alert delivery.

Can I send Microsoft 365 alert notifications to ConnectWise or Autotask?
Not natively. Microsoft sends alerts via email only. PSA integration requires a third-party platform that supports webhook or API routing.

Do I need Microsoft Sentinel to get real-time M365 alerts?
No. Sentinel adds SIEM-level correlation and automation but is not required for basic alerting. Native policies and third-party tools work independently of Sentinel.

Can MSPs manage Microsoft 365 alerts across multiple client tenants without E5?
Not with native Microsoft tools. Multi-tenant alert management requires a third-party platform built for MSP operations.

Cover Photo by Terrillo Walls on Unsplash

Author
Gavin Garbutt
Co-Founder & Chairman of Augmentt

FAQ

Using our GDAP tool & Magic Link, setting up is easy! You can integrate with your CSP partner portal in minutes
Augmentt uses a combination of Microsoft Secure Score best practices as well as industry standards such as NIST & CIS. You can use the out of box templates to get started right away and even build your own custom templates to match your client requirements.
Out of box, Augmentt comes pre-configured to not be noisy. Very few Microsoft alerts are critical in nature so you will be receiving tickets for account breaches and not minor user log related events. That said, everything is customizable and you can turn alerts on & off to match your clients’ needs.
No. You can choose to schedule alerts to any stakeholder you want and at the frequency you want or manually download reports when you need them.
Regardless of how MFA is managed across your tenants, we have you covered. Augmentt supports Conditional Access Policies, Security Defaults, Entra ID per user (Legacy) MFA as well as 3rd party MFA services like DUO.
No. You can use Augmentt to monitor and manage all clients regardless of their licensing. For environments with no premium licensing you can still provide alerts and monitoring for account breaches and configure security best practices. For environments with premium licensing, you can leverage Microsoft’s premium alerts and premium security configurations such as Conditional Access Policies.
Augmentt is one of the few vendors SOC 2 Type II, and GDPR compliant.
Site licenses to make sure you can deliver standardized service across all clients very affordably.

SUBSCRIBE for more resources

Related Content

Policy Sprawl Is Killing MSP Efficiency
Policy sprawl is quietly draining your margins, creating security gaps, and eroding client trust. The good news? Standardization is the cure.
Does Microsoft Secure Score Tell the Whole Story?
Do you have a complete understanding of your security? See why MSPs need to understand the role licensing plays in Secure Score results.
Top 10 M365 Security Best Practices for MSPs
Here are the top M365 security best practices to help you enhance protection, ensure compliance, and stay ahead of emerging threats.