Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDREasy

A Microsoft 365 administrator is configuring Microsoft Defender for Endpoint for a new organization. The organization has a strict policy that all security events from endpoints must be retained for at least 180 days for forensic analysis and compliance purposes. The default retention period is insufficient. Which setting must the administrator modify to meet this requirement?

  1. AConfigure a Microsoft Sentinel data connector to ingest Defender for Endpoint logs into a Log Analytics workspace with a custom retention policy.
  2. BTurn on 'Advanced features' and configure 'Custom detection rules'.
  3. CImplement a Microsoft Purview eDiscovery hold on all endpoint data.
  4. DNavigate to 'Settings' > 'Endpoints' > 'Data retention' and adjust the 'Security events retention period'.
Show answer & explanation

Correct answer: D. Navigate to 'Settings' > 'Endpoints' > 'Data retention' and adjust the 'Security events retention period'.

The data retention period for Microsoft Defender for Endpoint security events is directly configurable within the Defender for Endpoint settings. This allows the administrator to extend the retention beyond the default to meet compliance requirements. Options A, C, and D describe different functionalities or external integrations that do not directly manage the core retention period for Defender for Endpoint's security events.

Why the other options are wrong

  • A. While this can achieve longer retention, it involves external services (Sentinel, Log Analytics) rather than directly modifying the retention within Defender for Endpoint itself, which is the most direct and native solution for this requirement.
  • B. This option relates to creating custom alerts and enabling advanced capabilities, not data retention.
  • C. eDiscovery holds are for compliance and legal purposes on specific content, not for the general retention of raw security events in Defender for Endpoint.

Defender for Endpoint Data Retention

Microsoft Defender for Endpoint allows administrators to configure the retention period for security events collected from endpoints, ensuring compliance and forensic readiness.

  • Default retention is 30 days.
  • Can be extended up to 180 days (or more with specific licenses/integrations).
  • Configured in Defender for Endpoint settings.

Memory trick: Remember, the 'Endpoint's Data' has a 'Retention' 'Setting' that controls its 'Time'.

More Implement and manage Microsoft Defender XDR questions