M365 Auditing Changes and Enhancements, Part 1 #1084
Labels
baseline-document
Issues relating to the text in the baseline documents themselves
enhancement
This issue or pull request will add new or improve existing functionality
epic
A high-level objective issue encompassing multiple issues instead of a specific unit of work
Milestone
💡 Summary
The M365 unified audit log capability tracks actions taken across many of the M365 services. The log types supported depend on services in use, tenant licensing, and licenses applied to individual users. This epic is built around reviewing existing auditing policies and to determine what updates are feasible and recommended based on both recent service updates and additional audit guidance.
Motivation and context
Auditing is a critical component for monitoring SaaS usage patterns, potential misuse, and detecting threats. Based on the expanded availability of several log types previously only available to Purview Premium and the publication of the Microsoft Expanded Cloud Logs Implementation Playbook, SCuBA baselines should be reviewed and updated to keep pace with these service updates and latest guidance.
Implementation notes
Implementing auditing policy and assessment check enhancements will include:
Acceptance criteria
The following issues are completed
The text was updated successfully, but these errors were encountered: