Microsoft 365 Certified: Administrator ExpertDeploy and manage a Microsoft 365 tenantMedium
A global administrator is setting up a new Microsoft 365 tenant. They want to ensure that all administrative actions performed by other administrators are logged and can be reviewed for auditing purposes. Where should the administrator configure settings to enable comprehensive logging of administrative activities across Microsoft 365 services?
- AMicrosoft 365 Defender portal > Audit
- BMicrosoft Purview compliance portal > Audit
- CAzure Active Directory admin center > Audit logs
- DMicrosoft 365 admin center > Reports > Usage
Show answer & explanationAnswer & explanation
Correct answer: B. Microsoft Purview compliance portal > Audit
The Microsoft Purview compliance portal's Audit solution (formerly Compliance Center) provides a unified audit log that captures administrative and user activities across almost all Microsoft 365 services. This is the central location for configuring and searching comprehensive audit logs.
Why the other options are wrong
- A. Microsoft 365 Defender portal focuses on security incidents and alerts, not comprehensive administrative activity logging across all M365 services.
- C. Azure AD audit logs specifically cover Azure AD activities, but not comprehensive M365 service activities like Exchange, SharePoint, Teams in a unified view.
- D. Usage reports provide aggregate data on service usage, not detailed administrative action logs.
Microsoft 365 Unified Audit Log
A centralized logging service within Microsoft 365 that records user and administrator activities across various services like Exchange, SharePoint, Teams, and Azure AD.
- Enabled by default for most organizations.
- Searchable from the Microsoft Purview compliance portal.
- Crucial for security investigations and compliance audits.
Memory trick: Think of the Purview compliance portal as the grand library where all important actions are meticulously recorded.