Skip to content

Commit 989f806

Browse files
Merge pull request #34152 from MicrosoftDocs/NEW-investigate-threats-using-audit-in-microsoft-365-defender-microsoft-purview-premium
New investigate threats using audit in microsoft 365 defender microsoft purview premium
2 parents 8d72708 + e5d728f commit 989f806

23 files changed

+851
-0
lines changed
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.investigate-threats-using-audit-in-microsoft-365-defender-microsoft-purview-premium.introduction
3+
title: Introduction
4+
metadata:
5+
title: Introduction
6+
description: "Introduction."
7+
ms.date: 3/22/2023
8+
author: wwlpublish
9+
ms.author: kelawson
10+
ms.topic: interactive-tutorial
11+
ms.prod: learning-m365
12+
durationInMinutes: 1
13+
content: |
14+
[!include[](includes/1-introduction.md)]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,28 @@
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.investigate-threats-using-audit-in-microsoft-365-defender-microsoft-purview-premium.explore-microsoft-purview-audit-premium
3+
title: Explore Microsoft Purview Audit (Premium)
4+
metadata:
5+
title: Explore Microsoft Purview Audit (Premium)
6+
description: "Explore Microsoft Purview Audit (Premium)."
7+
ms.date: 3/22/2023
8+
author: wwlpublish
9+
ms.author: kelawson
10+
ms.topic: interactive-tutorial
11+
ms.prod: learning-m365
12+
durationInMinutes: 10
13+
content: |
14+
[!include[](includes/2-explore-microsoft-purview-audit-premium.md)]
15+
quiz:
16+
title: "Check your knowledge"
17+
questions:
18+
- content: "Fabrikam has implemented Microsoft Purview Audit (Premium). It now wants to create appropriate 10-year audit log retention policies for the managers of its security and compliance teams. What must Fabrikam do to enable this functionality?"
19+
choices:
20+
- content: "Configure the 10 year audit log setting in the Microsoft Purview compliance portal"
21+
isCorrect: false
22+
explanation: "Incorrect. There's no such setting in the Microsoft Purview compliance portal."
23+
- content: "Purchase per-user add-on licenses for each manager"
24+
isCorrect: true
25+
explanation: "Correct. In addition to the one-year retention capabilities of Audit (Premium), Microsoft 365 can optionally retain audit logs for 10 years. The 10-year retention of audit logs helps support long running investigations and respond to regulatory, legal, and internal obligations. Retaining audit logs for 10 years requires an extra per-user add-on license. After this license is assigned to a user and an appropriate 10-year audit log retention policy is set for that user, audit logs covered by that policy will start to be retained for the 10-year period."
26+
- content: "Nothing extra is needed since audit logs are retained by default for 10 years when Audit (Premium) is licensed"
27+
isCorrect: false
28+
explanation: "Incorrect. Audit logs are retained by default for one year in Audit (Premium)."
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.investigate-threats-using-audit-in-microsoft-365-defender-microsoft-purview-premium.implement-microsoft-purview-audit-premium
3+
title: Implement Microsoft Purview Audit (Premium)
4+
metadata:
5+
title: Implement Microsoft Purview Audit (Premium)
6+
description: "Implement Microsoft Purview Audit (Premium)."
7+
ms.date: 3/22/2023
8+
author: wwlpublish
9+
ms.author: kelawson
10+
ms.topic: interactive-tutorial
11+
ms.prod: learning-m365
12+
durationInMinutes: 3
13+
content: |
14+
[!include[](includes/3-implement-microsoft-purview-audit-premium.md)]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,28 @@
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.investigate-threats-using-audit-in-microsoft-365-defender-microsoft-purview-premium.manage-audit-log-retention-policies
3+
title: Manage audit log retention policies
4+
metadata:
5+
title: Manage audit log retention policies
6+
description: "Manage audit log retention policies."
7+
ms.date: 3/22/2023
8+
author: wwlpublish
9+
ms.author: kelawson
10+
ms.topic: interactive-tutorial
11+
ms.prod: learning-m365
12+
durationInMinutes: 10
13+
content: |
14+
[!include[](includes/4-manage-audit-log-retention-policies.md)]
15+
quiz:
16+
title: "Check your knowledge"
17+
questions:
18+
- content: "Contoso has implemented Microsoft Purview Audit (Premium). How long does Contoso's default audit log retention policy retain Exchange Online audit records?"
19+
choices:
20+
- content: "90 days"
21+
isCorrect: false
22+
explanation: "Incorrect. If an organization has non-E5 users or guest users, their corresponding audit records are retained for 90 days. However, this value isn't the retention period for the default audit log retention policy."
23+
- content: "One year"
24+
isCorrect: true
25+
explanation: "Correct. Microsoft Purview Audit (Premium) provides a default audit log retention policy for all organizations. This policy retains all Exchange Online, SharePoint Online, OneDrive for Business, and Azure Active Directory audit records for one year."
26+
- content: "Ten years"
27+
isCorrect: false
28+
explanation: "Incorrect. An organization can create a custom audit log retention policy that retains Exchange Online audit records for 10 years. However, this value isn't the retention period for the default audit log retention policy."
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.investigate-threats-using-audit-in-microsoft-365-defender-microsoft-purview-premium.investigate-compromised-email-accounts
3+
title: Investigate compromised email accounts using Purview Audit (Premium)
4+
metadata:
5+
title: Investigate compromised email accounts using Purview Audit (Premium)
6+
description: "Investigate compromised email accounts using Purview Audit (Premium)."
7+
ms.date: 3/22/2023
8+
author: wwlpublish
9+
ms.author: kelawson
10+
ms.topic: interactive-tutorial
11+
ms.prod: learning-m365
12+
durationInMinutes: 15
13+
content: |
14+
[!include[](includes/5-investigate-compromised-email-accounts.md)]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,50 @@
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.investigate-threats-using-audit-in-microsoft-365-defender-microsoft-purview-premium.knowledge-check
3+
title: Knowledge check
4+
metadata:
5+
title: Knowledge check
6+
description: "Knowledge check."
7+
ms.date: 3/22/2023
8+
author: wwlpublish
9+
ms.author: kelawson
10+
ms.topic: interactive-tutorial
11+
ms.prod: learning-m365
12+
durationInMinutes: 6
13+
content: |
14+
[!include[](includes/6-knowledge-check.md)]
15+
quiz:
16+
title: "Check your knowledge"
17+
questions:
18+
- content: "To help organizations investigate compromised email accounts, Microsoft 365 audits access to mail data by mail protocols and clients. What mailbox-auditing action does Microsoft 365 use in Audit (Premium) to provide this functionality?"
19+
choices:
20+
- content: "MailItemsAccessed"
21+
isCorrect: true
22+
explanation: "Correct. To help organizations investigate compromised email accounts, Microsoft 365 audits access to mail data by mail protocols and clients. It does so by using the MailItemsAccessed mailbox-auditing action. This audited action can help investigators better understand email data breaches and identify the scope of compromises to specific mail items that may have been compromised."
23+
- content: "AuditExchangeMail"
24+
isCorrect: false
25+
explanation: "Incorrect. This item isn't a valid mailbox-auditing action."
26+
- content: "ExchangeMailActivity"
27+
isCorrect: false
28+
explanation: "Incorrect. This item isn't a valid mailbox-auditing action."
29+
- content: "Audit (Premium) helps organizations conduct forensic and compliance investigations by providing access to important events. Which of the following prerequisites must be completed so that audit logs will be generated when users perform these events?"
30+
choices:
31+
- content: "An extra add-on license must be purchased per user"
32+
isCorrect: false
33+
explanation: "Incorrect. Retaining audit logs for 10 years requires an extra per-user add-on license. However, such a license isn't required so that audit logs will be generated when users perform audited events."
34+
- content: "Users must be assigned an Audit (Premium) license"
35+
isCorrect: true
36+
explanation: "Correct. Users must be assigned an Audit (Premium) license so that audit logs will be generated when users perform these important, audited events."
37+
- content: "The MailItemsAccessed action must be enabled"
38+
isCorrect: false
39+
explanation: "Incorrect. This action doesn't require enabling."
40+
- content: "Tailspin Toys has implemented Microsoft Purview Audit (Premium). It set up Audit (Premium) for its users. It's now enabling Audit (Premium) events to be logged. Which of the following items is an Audit (Premium) event that Tailspin Toys must enable?"
41+
choices:
42+
- content: "ExchangeQueryInitiated"
43+
isCorrect: false
44+
explanation: "Incorrect. This item isn't an Audit (Premium) event that must be enabled."
45+
- content: "SearchQueryInitiatedSharePoint"
46+
isCorrect: true
47+
explanation: "Correct. You must enable the following Audit (Premium) events to be logged so that users can perform searches in Exchange Online and SharePoint Online: SearchQueryInitiatedExchange andSearchQueryInitiatedSharePoint."
48+
- content: "InitiateOneDriveQuery"
49+
isCorrect: false
50+
explanation: "Incorrect. This item isn't an Audit (Premium) event that must be enabled."
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.investigate-threats-using-audit-in-microsoft-365-defender-microsoft-purview-premium.summary
3+
title: Summary
4+
metadata:
5+
title: Summary
6+
description: "Summary."
7+
ms.date: 3/22/2023
8+
author: wwlpublish
9+
ms.author: kelawson
10+
ms.topic: interactive-tutorial
11+
ms.prod: learning-m365
12+
durationInMinutes: 1
13+
content: |
14+
[!include[](includes/7-summary.md)]
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
## Introduction to threat investigation with Microsoft Purview Audit (Premium)
2+
3+
You're a Security Operations Analyst working at a company that is implementing Microsoft Purview and Microsoft 365 Defender solutions. You have already implemented Microsoft Purview Audit (Standard) and used it to search the Unified Audit Log (UAL). Now you need to understand how to setup and implement Microsoft Purview Audit (Premium). Your manager has asked you to create audit log retention policies and to conduct forensic investigations.
4+
5+
This module explores the key functionality in Microsoft Purview Audit (Premium). Audit (Premium) builds on the capabilities of Audit (Standard). It does so by providing audit log retention policies, longer retention of audit records, high-value crucial events, and higher bandwidth access to the Office 365 Management Activity API.
6+
7+
The module begins by examining the setup requirements for Audit (Premium). Setup is basically a matter of maintaining proper organization subscriptions and user licensing. You'll then review the primary differences between Audit (Standard) and Audit (Premium). One of the key features of Audit (Premium) is that it can help organizations conduct forensic and compliance investigations by providing access to important events, such as:
8+
9+
- when mail items were accessed.
10+
- when mail items were replied to and forwarded.
11+
- when and what a user searched for in Exchange Online and SharePoint Online.
12+
13+
These events can help organizations investigate possible breaches and determine the scope of compromise.
14+
15+
The module then examines how to implement Audit (Premium). You'll review the following steps that make up this workflow:
16+
17+
1. Set up Audit (Premium) for users.
18+
1. Enable logging of crucial events.
19+
1. Create audit log retention policies.
20+
1. Perform forensic investigations.
21+
22+
The module then focuses on the final two activities in this workflow - setting up audit log retention policies and performing investigations of compromised accounts.
23+
24+
After completing this module, you'll be able to:
25+
26+
- Describe the differences between Audit (Standard) and Audit (Premium).
27+
- Set up and implement Microsoft Purview Audit (Premium).
28+
- Create audit log retention policies.
29+
- Perform forensic investigations of compromised user accounts.

0 commit comments

Comments
 (0)