New Crucial Audit Events Added to Office 365



Microsoft has added three new "crucial" Office 365 audit events designed to help investigators know what happened inside mailboxes and sites if a tenant is penetrated and accounts are compromised. You need Office 365 E5 licenses (or the Microsoft 365 equivalents) to see the new events. Like most things to do with audit events, PowerShell is the best way to extract information from the new events.

0 Replies