Microsoft 365 FundamentalsDescribe security, compliance, privacy, and trust in Microsoft 365Medium
A Microsoft 365 administrator is investigating unusual activity on a user's account, specifically a login from an unfamiliar location followed by attempts to access sensitive SharePoint sites. The administrator needs to quickly understand the sequence of events and the resources accessed. Which Microsoft 365 feature provides a detailed, searchable record of user and admin activities?
- AMicrosoft Purview eDiscovery
- BMicrosoft Purview Information Protection
- CMicrosoft Purview Audit
- DMicrosoft Defender for Endpoint
Show answer & explanationAnswer & explanation
Correct answer: C. Microsoft Purview Audit
Microsoft Purview Audit (formerly Audit Log Search) provides a unified audit log that records user and administrator activities across various Microsoft 365 services. This allows administrators to investigate security incidents, compliance issues, and general user activity by searching for specific events.
Why the other options are wrong
- A. Microsoft Purview eDiscovery is used for legal discovery to search and export content in response to litigation or investigations.
- B. Microsoft Purview Information Protection helps classify, label, and protect sensitive information.
- D. Microsoft Defender for Endpoint is a post-breach detection, automated investigation, and response solution focusing on endpoint devices, not M365 service activity logs.
Microsoft Purview Audit
A feature in Microsoft 365 that records user and administrator activities across various services, providing a searchable log for security, compliance, and investigative purposes.
- Records actions like file access, mailbox operations, and admin changes.
- Unified audit log provides a single view of activities.
- Essential for forensics, compliance, and incident response.
- Searchable via the Microsoft Purview compliance portal.
Memory trick: Audit logs tell the story of every action.