Forum Discussion
tyagia2ul
Aug 03, 2023Copper Contributor
How to get audit logs for Ransomware activity Policy under Threat Detection
I need to fetch the logs like who modified the policy is there any powershell command I can run
tyagia2ul
Aug 03, 2023Copper Contributor
Hello Heike,
We have a Threat Detection Policy under Cloud Apps in Microsoft 365 Defender and I need to pull the logs of that policy like when and who modified it last time .
We have a Threat Detection Policy under Cloud Apps in Microsoft 365 Defender and I need to pull the logs of that policy like when and who modified it last time .
HeikeRitter
Microsoft
Aug 03, 2023Got it, thanks for clarifying - let me check with the Defender for Cloud Apps team.
- tyagia2ulAug 04, 2023Copper ContributorHello Heike,
Just wondering if you have had a chance to check this with Cloud Apps team
Thanks
Atul- Greg WiselkaAug 07, 2023
Microsoft
Hello
If you go to activity log, select advanced filter and select "Administrative activity" is True, then you can further narrow down results if you add additional filter "Action type" contains "Policy "