Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Purview complianceMedium

A company is implementing Microsoft Purview to manage compliance. They need to ensure that all audit logs related to administrative activities across Exchange Online, SharePoint Online, and Azure Active Directory are retained for a minimum of one year for forensic investigations. Which type of retention policy should be configured?

  1. AA retention policy specifically for audit logs in the Microsoft 365 compliance center.
  2. BA data loss prevention (DLP) policy to prevent audit log deletion.
  3. CAn eDiscovery hold on all administrative accounts.
  4. DA standard retention policy for all user mailboxes and sites.
Show answer & explanation

Correct answer: A. A retention policy specifically for audit logs in the Microsoft 365 compliance center.

Microsoft Purview allows for the configuration of specific retention policies for audit logs, separate from content retention, to ensure that administrative activities are preserved for a defined period for compliance and forensic purposes.

Why the other options are wrong

  • B. DLP is for preventing sensitive data exfiltration, not for retaining audit logs.
  • C. eDiscovery holds are for specific legal cases on user content, not for general audit log retention.
  • D. This would apply to user content, not specifically the administrative audit logs themselves.

Audit Log Retention Policies

Microsoft Purview allows administrators to configure retention policies specifically for unified audit logs, ensuring that records of user and administrative activities are preserved for compliance and investigative purposes.

  • Separate from content retention policies.
  • Retains records of activities across M365 services.
  • Crucial for forensic investigations and compliance audits.

Memory trick: Audit logs: Keep the record, know the story!

More Implement and manage Microsoft Purview compliance questions