Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

M365 Auditing Changes and Enhancements, Part 1 #1084

Closed
3 tasks
schrolla opened this issue May 2, 2024 · 0 comments
Closed
3 tasks

M365 Auditing Changes and Enhancements, Part 1 #1084

schrolla opened this issue May 2, 2024 · 0 comments
Assignees
Labels
baseline-document Issues relating to the text in the baseline documents themselves enhancement This issue or pull request will add new or improve existing functionality epic A high-level objective issue encompassing multiple issues instead of a specific unit of work
Milestone

Comments

@schrolla
Copy link
Collaborator

schrolla commented May 2, 2024

💡 Summary

The M365 unified audit log capability tracks actions taken across many of the M365 services. The log types supported depend on services in use, tenant licensing, and licenses applied to individual users. This epic is built around reviewing existing auditing policies and to determine what updates are feasible and recommended based on both recent service updates and additional audit guidance.

Motivation and context

Auditing is a critical component for monitoring SaaS usage patterns, potential misuse, and detecting threats. Based on the expanded availability of several log types previously only available to Purview Premium and the publication of the Microsoft Expanded Cloud Logs Implementation Playbook, SCuBA baselines should be reviewed and updated to keep pace with these service updates and latest guidance.

Implementation notes

Implementing auditing policy and assessment check enhancements will include:

  • Hands-on prototyping to determine the effects of service and policy changes on tenants
  • Validating the set of implementation instructions needed to configure new audit settings
  • Determining specific set of log types to be configured, if not enabled by default
  • Identifying baseline changes to align policy with current best practice guidance and service updates

Acceptance criteria

The following issues are completed

@schrolla schrolla added epic A high-level objective issue encompassing multiple issues instead of a specific unit of work enhancement This issue or pull request will add new or improve existing functionality baseline-document Issues relating to the text in the baseline documents themselves labels May 2, 2024
@schrolla schrolla added this to the Halibut milestone May 2, 2024
@schrolla schrolla self-assigned this May 20, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
baseline-document Issues relating to the text in the baseline documents themselves enhancement This issue or pull request will add new or improve existing functionality epic A high-level objective issue encompassing multiple issues instead of a specific unit of work
Projects
None yet
Development

No branches or pull requests

1 participant