Microsoft 365 Certified: Administrator ExpertDeploy and manage a Microsoft 365 tenantHard

A Microsoft 365 administrator is implementing a new security policy that requires all administrative actions in the tenant to be logged and auditable for a period of one year. This includes actions performed by global administrators, user administrators, and other privileged roles. Which feature must the administrator enable to ensure this logging occurs across all relevant Microsoft 365 services?

  1. AMicrosoft Defender for Endpoint
  2. BAzure AD PIM audit history
  3. CAzure AD Identity Protection
  4. DMicrosoft 365 Unified Audit Log
Show answer & explanation

Correct answer: D. Microsoft 365 Unified Audit Log

The Microsoft 365 Unified Audit Log consolidates audit records from various Microsoft 365 services (Exchange, SharePoint, Azure AD, Teams, etc.) into a single searchable log, making it the central place to track and audit administrative actions across the tenant.

Why the other options are wrong

  • A. Defender for Endpoint is an endpoint security solution, not for auditing cloud administrative actions.
  • B. PIM audit history specifically tracks activations and assignments of privileged roles, not all administrative actions performed by those roles.
  • C. Identity Protection detects and remediates identity risks, it does not log all administrative actions.

Microsoft 365 Unified Audit Log

A centralized logging service in Microsoft 365 that records user and administrator activities across various services, enabling organizations to search and investigate events for security and compliance.

  • Captures activities from Exchange, SharePoint, OneDrive, Teams, Azure AD, etc.
  • Essential for security investigations and compliance auditing.
  • Retention period can be configured based on licensing.

Memory trick: Unified Audit Log: All admin actions, one book.

More Deploy and manage a Microsoft 365 tenant questions