Skip to content

Commit cbf52c9

Browse files
committed
updated auditing feature
1 parent f97c5d8 commit cbf52c9

File tree

2 files changed

+13
-21
lines changed

2 files changed

+13
-21
lines changed

defender-xdr/auditing.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ ms.custom:
1717
- cx-ti
1818
- cx-dex
1919
search.appverid: met150
20-
ms.date: 10/30/2024
20+
ms.date: 01/14/2025
2121
---
2222

2323
# Auditing
@@ -28,7 +28,7 @@ ms.date: 10/30/2024
2828

2929
As a tenant administrator, you can use Microsoft Purview to search the audit logs for the times Microsoft Defender Experts signed into your tenant and the actions they did there to perform their investigations. You can also search the audit logs for the changes done by your tenant administrators to the Defender Experts settings.
3030

31-
[Audit (Standard)](/microsoft-365/compliance/audit-solutions-overview) is turned on by default for all Microsoft Defender Experts for XDR customers when paid licenses are assigned to the tenant. If you have a trial license, work with your service delivery manager to turn on Audit if it isn't yet.
31+
Auditing is automatically turned on in the Microsoft Defender portal. Features that are audited are logged in the audit log automatically. Auditing can also collect audit logs from GCC environments.
3232

3333
> [!NOTE]
3434
> Make sure you have the right [permissions](/microsoft-365/compliance/audit-log-search#before-you-search-the-audit-log) to search for audit logs.

defender-xdr/microsoft-xdr-auditing.md

Lines changed: 11 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -11,19 +11,17 @@ ms.collection:
1111
- m365-security
1212
- tier3
1313
ms.topic: overview
14-
ms.date: 08/14/2024
14+
ms.date: 01/14/2025
1515
search.appverid: met150
16+
appliesto:
17+
- Microsoft Defender for Endpoint Plan 2
18+
- Microsoft Defender XDR
1619
---
1720

1821
# Search the audit log for events in Microsoft Defender XDR
1922

2023
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/microsoft-defender.md)]
2124

22-
**Applies to:**
23-
24-
- [Microsoft Defender for Endpoint Plan 2](/defender-endpoint/microsoft-defender-endpoint)
25-
- [Microsoft Defender XDR](microsoft-365-defender.md)
26-
2725
The audit log can help you investigate specific activities across Microsoft 365 services. In the Microsoft Defender portal, Microsoft Defender XDR and Microsoft Defender for Endpoint activities are audited. Some of the activities audited are:
2826

2927
- Changes to data retention settings
@@ -43,26 +41,20 @@ To access the audit log, you need to have the **View-Only Audit Logs** or **Audi
4341
> [!NOTE]
4442
> Global administrators in Office 365 and Microsoft 365 are automatically added as members of the Organization Management role group in Exchange Online.
4543
46-
## Turn on auditing in Microsoft Defender XDR
47-
48-
Microsoft Defender XDR uses the [Microsoft Purview auditing solution](/purview/audit-solutions-overview), before you can look at the audit data in the Microsoft Defender XDR portal:
44+
## Turn on auditing
4945

50-
- You should confirm that auditing is turned on in the Microsoft Purview compliance portal. For more information, see [Turn auditing on or off](/purview/audit-log-enable-disable).
46+
Auditing is automatically turned on for Microsoft Defender XDR. Features that are audited are logged in the audit log automatically. Auditing can also collect audit logs from GCC environments.
5147

52-
- Follow the steps below to enable the unified audit log in the Microsoft Defender XDR portal:
53-
1. Log in to [Microsoft Defender XDR](https://security.microsoft.com/homepage) using an account with the Security administrator or Global administrator role assigned.
54-
2. In the navigation pane, select **Settings** \> **Endpoints** \> **Advanced features**.
55-
3. Scroll own to **Unified audit log** and toggle the setting to **On**.
56-
57-
:::image type="content" source="/defender/media/defender/unified-audit-log.png" alt-text="Screenshot of the unified audit log toggle in Microsoft Defender XDR advanced settings" lightbox="/defender/media/defender/unified-audit-log.png":::
58-
4. Select **Save preferences**.
48+
Microsoft Defender XDR uses the [Microsoft Purview auditing solution](/purview/audit-solutions-overview). Before you can look at the audit data in the Microsoft Defender portal, you need to turn on auditing in the Microsoft Purview compliance portal. For more information, see [Turn auditing on or off](/purview/audit-log-enable-disable).
5949

6050
> [!IMPORTANT]
6151
> Global Administrator is a highly privileged role that should be limited to scenarios when you can't use an existing role. Microsoft recommends that you use roles with the fewest permissions. Using lower permissioned accounts helps improve security for your organization.
6252
6353
## Using the audit search in Microsoft Defender XDR
6454

65-
1. To retrieve audit logs for Microsoft Defender XDR activities, navigate to the [Microsoft Defender XDR Audit page](https://security.microsoft.com/auditlogsearch) or go to the [Purview compliance portal](https://compliance.microsoft.com) and select **Audit**.
55+
Follow these steps to search the audit log:
56+
57+
1. To get audit logs for Microsoft Defender XDR activities, navigate to the [Microsoft Defender XDR Audit page](https://security.microsoft.com/auditlogsearch) or go to the [Purview compliance portal](https://compliance.microsoft.com) and select **Audit**.
6658

6759
:::image type="content" source="/defender/media/defender/unified-audit-log-xdr.png" alt-text="Screenshot of the unified audit log page in Microsoft Defender XDR " lightbox="/defender/media/defender/unified-audit-log-xdr.png":::
6860

@@ -108,7 +100,7 @@ Search-UnifiedAuditLog -StartDate 2023/03/12 -EndDate 2023/03/20 -RecordType <ID
108100
>[!NOTE]
109101
> See the API column in Audit activities included for the record type values.
110102
111-
## Additional resources
103+
## See also
112104

113105
- [Search the audit log in the compliance center](/purview/audit-new-search)
114106
- [Use a PowerShell script to search the audit log](/purview/audit-log-search-script)

0 commit comments

Comments
 (0)