Microsoft 365 Certified: Administrator ExpertDeploy and manage a Microsoft 365 tenantEasy
A Microsoft 365 administrator is managing a new tenant for a startup company. The company wants to ensure that all administrative actions performed by global administrators are logged and available for review for compliance purposes. Which Microsoft 365 service should the administrator configure to meet this requirement?
- AMicrosoft 365 Unified Audit Log
- BMicrosoft 365 Defender
- CMicrosoft Purview Compliance Manager
- DAzure Monitor
Show answer & explanationAnswer & explanation
Correct answer: A. Microsoft 365 Unified Audit Log
The Microsoft 365 Unified Audit Log records user and administrator activities across various Microsoft 365 services, including actions performed by global administrators. It is the primary tool for auditing and compliance in Microsoft 365.
Why the other options are wrong
- B. Microsoft 365 Defender provides threat protection, not a comprehensive audit trail of administrative actions.
- C. Compliance Manager helps manage compliance posture, but relies on other services like the audit log for data.
- D. Azure Monitor collects telemetry from Azure resources, but not specifically the detailed administrative actions within Microsoft 365 services.
Microsoft 365 Unified Audit Log
A centralized logging service in Microsoft 365 that records user and administrator activities across various services for security, compliance, and forensic investigations.
- Captures actions from Exchange, SharePoint, Teams, Azure AD, etc.
- Searchable via the Microsoft Purview compliance portal.
- Essential for compliance, security, and troubleshooting.
Memory trick: The Audit Log is like a universal diary for all M365 activities.