Microsoft 365 FundamentalsDescribe security, compliance, privacy, and trust in Microsoft 365Medium
A Microsoft 365 administrator is investigating a potential data breach where sensitive company documents might have been exfiltrated from SharePoint Online. The administrator needs to review user activities, file access, and sharing events related to the suspicious activity. Which Microsoft 365 compliance feature should the administrator use first to gather this information?
- ACommunication Compliance
- BAudit log search
- CRetention policies
- DData Loss Prevention (DLP) policies
Show answer & explanationAnswer & explanation
Correct answer: B. Audit log search
The audit log search in the Microsoft Purview compliance portal allows administrators to search for user and admin activities across various Microsoft 365 services, including file access, sharing, and deletion events, which is essential for investigating potential data breaches.
Why the other options are wrong
- A. Communication Compliance monitors internal and external communications for policy violations, not general file activity for breach investigations.
- C. Retention policies govern how long data is kept, not for investigating specific user activities.
- D. DLP policies prevent data exfiltration, but don't provide a historical log of all activities for investigation.
Audit Log Search
A feature in the Microsoft Purview compliance portal that allows administrators to search for user and admin activities across Microsoft 365 services, providing detailed records for investigations.
- Records activities across Exchange, SharePoint, Teams, Azure AD, etc.
- Crucial for security investigations and compliance audits.
- Provides granular search capabilities based on activity, user, date, and more.
Memory trick: Investigate with the AUDIT Log, finding every digital step.