Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDREasy

A Microsoft 365 administrator is investigating a potential insider threat. They need to review the activities of a specific user across various Microsoft 365 services, including email, SharePoint, and Teams, to identify any suspicious actions related to data exfiltration. Which feature in Microsoft 365 Defender provides a unified view of a user's activities across these services?

  1. AMicrosoft Defender XDR unified activity timeline
  2. BAdvanced Hunting
  3. CMicrosoft Purview eDiscovery
  4. DUnified audit log
Show answer & explanation

Correct answer: A. Microsoft Defender XDR unified activity timeline

The Microsoft Defender XDR unified activity timeline provides a consolidated, chronological view of a user's activities across various Microsoft 365 services (email, SharePoint, Teams, Defender for Endpoint, etc.) within the context of an incident or user investigation. This unified timeline is specifically designed to help administrators track user actions and identify suspicious behavior related to threats like data exfiltration. While Advanced Hunting and the Unified Audit Log contain the data, the 'unified activity timeline' is the feature that presents this data in a user-centric, chronological view for easy investigation in the Defender portal. eDiscovery is for compliance, not real-time threat investigation.

Why the other options are wrong

  • B. Advanced Hunting allows for querying raw data, but it requires crafting complex KQL queries and doesn't inherently provide a pre-built, unified user-centric timeline view for quick investigation.
  • C. Microsoft Purview eDiscovery is used for legal hold and content search for compliance and litigation purposes, not for real-time threat investigation of user activities.
  • D. The Unified Audit Log is the underlying data source for activities across Microsoft 365 services, but the 'unified activity timeline' is the feature within the Defender portal that *presents* this data in a user-friendly, chronological view for an investigation.

Defender XDR Unified Activity Timeline

The Microsoft Defender XDR unified activity timeline provides a consolidated, chronological view of a user's activities across various Microsoft 365 services, streamlining investigations into user-centric threats.

  • Consolidates activities from email, SharePoint, Teams, devices, etc.
  • Presents data in a chronological order.
  • Accessible within the Microsoft 365 Defender portal.
  • Aids in insider threat and user compromise investigations.

Memory trick: Remember, for a 'Unified View' of a 'User's Activities', check the 'Unified Activity Timeline'.

More Implement and manage Microsoft Defender XDR questions