DefenderATP Audit logs

%3CLINGO-SUB%20id%3D%22lingo-sub-1431509%22%20slang%3D%22en-US%22%3EDefenderATP%20Audit%20logs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1431509%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhere%20i%20can%20see%20all%20the%20modification%20by%20the%20administrator%20in%20the%20securitycenter.microsoft.com%20(Defender%20ATP)%20%3F%3C%2FP%3E%3CP%3ESome%20one%20have%20changed%20some%20configurations%20and%20i%20don%C2%B4t%20know%20wo%20did%20it%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1431509%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAdmin%20center%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAdvanced%20Security%20Management%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ECompliance%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Occasional Contributor

Hi all,

 

Where i can see all the modification by the administrator in the securitycenter.microsoft.com (Defender ATP) ? Someone changed some settings and I don't know who did

2 Replies
Bumping for visibility as also interested in how others handle this. I have previously seen that you can do something like this for device actions by using Azure Log Analytics and Azure Logic App workflow.

@Ru bump