Auditing
15 TopicsLanguage defaults audit for everything M365
We are struggling to find where and how the wrong language is being used for various parts of the M365 platform. We have Swedish set as default, but still English is used for a number of places which often are only realized as a consequence by a user. For example, in Viva Engage language is set to Swedish, and for the SharePoint as well. But: When a new user logs on VE is in English While the SharePoint web part is in Swedish, the link text have for some time ended with "- Home" (English) instead of as it was when we started 2+ years ago " - Startsida" (Swedish) Then when creating a VE group Event (Teams-meeting) default language is also English Tracking down what and where is making the wrong language being used is hard. I would be very grateful if pointed to a resource that give an as complete as possible overview of everything in M365 that we need to look over for making sure that the correct language is default everywhere it should be.70Views0likes4CommentsInterface Views in Microsoft 365 Admin Center
1. Simplified View Purpose: Designed for small businesses or organizations with limited IT resources. Features: Streamlined dashboard with essential tasks like user management, license assignment, and password resets. Minimal configuration options to reduce complexity. Quick access to support and basic service health info. Use Case: Ideal for admins who need to perform routine tasks without diving into advanced settings. 2. Dashboard View (Advanced View) Purpose: Tailored for medium to large enterprises with complex IT environments. Features: Full access to all admin centers (Exchange, SharePoint, Teams, etc.). Advanced analytics, reporting, and configuration tools. Role-based access control and security management. Customizable widgets and navigation for personalized workflows. Use Case: Suitable for IT teams managing multiple services, users, and compliance requirements. Customization Needs Are there specific tasks we perform frequently that can be automated in the dashboard?290Views0likes2CommentsObtain Deleted Stats (SharePoint) by Retention Policy
I've scoured: https://learn.microsoft.com/en-us/purview/retention-cmdlets and the Unified Audit Log (https://www.meetingroom365.com/blog/search-unifiedauditlog-powershell/, https://theitbros.com/query-microsoft-365-audit-logs-using-powershell/#penci-Search_the_SharePoint_Online_Audit_Log) to see if I can come up with a method to obtain some statistics regarding how many files and space (storage) has been freed up with the use of retention policies being enabled. I'm drawing a blank. In an ideal world, I'd like know how many files have been deleted by the system (the system enforcing a 5 Year from last modified Date and Delete Policy) for the last year or 6 month intervals. If possible the corresponding volume of storage space recovered from these deletions. Any ideas?165Views0likes2CommentsWhere do I manage old audit activity alerts?
I have an audit activity alert that, I assume, was created in Office 365 before it became Microsoft 365. My problem is trying to find where to manage this alert. Does anyone recognize this alert and know where I go to manage it? I have spent time looking through the Compliance port at Alerts and alert policies, but there is nothing there to manage.Solved1.2KViews0likes4CommentsCannot create Information Barrier Policy
Hi, I have created two segments within Information Barriers in Microsoft Purview. I have then tried to create a Policy that blocks one segment from the other using both the UI and PowerShell, but I get the same error every time. "Could not run the command New-InformationBarrierPolicy. Cause of the problem: The parameter(s) ModerationAllowed of the cmdlet New-ExoInformationBarrierPolicy is not allowed for the app 00000007-0000-0ff1-ce00-000000000000" Am I missing something? Is anyone else seeing this, or is it just me? Right now, I can create many policies at all.Solved1.7KViews0likes4CommentsAudit Log, what is TokenIssuedAtTime?
I used audit log to search user delete MS Teams files, by using Recycled File and Recycled Folder, I got the log file. Why the TokenIssuedAtTime and the CreationTime are so much different? Below is one of the log record {"AppAccessContext":{"AADSessionId":"8f382a1d-b233-425c-92f4-3cf9ed395c9e","CorrelationId":"ae68fba0-40db-2000-ce07-a7bde7727c3f","TokenIssuedAtTime":"2023-12-23T00:47:57","UniqueTokenId":"U4m5SFCmckOiN_QLrysqAQ"},"CreationTime":"2023-12-26T04:24:52","Id":"7a3dc23c-2699-485b-0a87-08dc05ca9b40","Operation":"FolderRecycled","OrganizationId":"7cf9c29c-c6af-4790-b98b-4eff7637f9be","RecordType":6,"UserKey":"i:0h.f|membership|email address removed for privacy reasons","UserType":0,"Version":1,"Workload":"SharePoint","ClientIP":"2001:d08:e2:58d:61cb:e4bc:c451:aef9","UserId":"email address removed for privacy reasons","AuthenticationType":"FormsCookieAuth","BrowserName":"","BrowserVersion":"","CorrelationId":"ae68fba0-40db-2000-ce07-a7bde7727c3f","EventSource":"SharePoint","IsManagedDevice":false,"ItemType":"Folder","ListId":"33880cd7-1db1-450f-9cd0-5c437c0ccaee","ListItemUniqueId":"184cd92b-40cf-4fa1-82aa-ad5fa61a2a05","Platform":"WinDesktop","Site":"f1bb631d-8ff4-4411-b49f-066e20be905c","UserAgent":"Microsoft SkyDriveSync 23.246.1127.0002 ship; Windows NT 10.0 (19045)","WebId":"aa607282-8b47-47d1-938b-c0cde8e2d87d","DeviceDisplayName":"2a01:111:2055:202:4701:ee31:fe3f:156","CrossScopeSyncDelete":false,"HighPriorityMediaProcessing":false,"SharingType":"","SourceFileExtension":"","SiteUrl":"https://mysharepoint.sharepoint.com/sites/mysite/","SourceRelativeUrl":"Shared Documents/test/MyFolder","SourceFileName":"Quotation","ObjectId":"https://mysharepoint.sharepoint.com/sites/mysite/Shared Documents/test/MyFolder/Test1"}857Views0likes0CommentsAudit Log start-date into past not possible. How getting group members added date 2 years ago?
I cant take start date into past. In Classic Search it is greyed out. In New Search I can go into year 2021 but it said if I take it... "Start/end date shoulbe in valid format and the start date is earlier than end date." How is it possible to make audit-log in the past ?? My Groups are created on early 2021 but I cant make an Audit for this year.Solved664Views0likes1CommentDevice Consent to Terms of Use
Can anyone confirm whether in order for users to consent to the terms of use on any device, those devices will need to be registered in Intune as per this https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/terms-of-use document? Below is mentioned in the document: "Per-device terms of use The Require users to consent on every device setting enables you to require end users to accept your terms of use policy on every device they're accessing from. The end user will be required to register their device in Azure AD. When the device is registered, the device ID is used to enforce the terms of use policy on each device. Supported platforms and software. iOS Android Windows 10 Other Native app Yes Yes Yes Microsoft Edge Yes Yes Yes Internet Explorer Yes Yes Yes Chrome (with extension) Yes Yes Yes Per-device terms of use has the following constraints: A device can only be joined to one tenant. A user must have permissions to join their device. The Intune Enrollment app isn't supported. Ensure that it's excluded from any Conditional Access policy requiring Terms of Use policy. Azure AD B2B users aren't supported. If the user's device isn't joined, they'll receive a message that they need to join their device. Their experience will be dependent on the platform and software."857Views0likes0CommentsAudit Log changes
Like many users, we had IP ranges in Nigeria trying to crack user passwords, and this was showing up in the Audit Logs as "UserLoginFailed" now this seems to have disappeared completely. I tried from the OWA on my account until it locked me out, and nothing showed up in the audit at all. I tried to search the community for this, but nothing came back,.. has anyone had this experience?2.7KViews0likes7CommentsUserLoggedIn events not found in Azure Audit log for about a week
When I search for UserLoggedIn events in my Office 365 Tenant, I'm unable to find any audit records for the last 7 days. Whereas all our users have been logging in and out. I've tested one of our test tenants as well and found it missing as well. Anyone facing this?4.4KViews0likes2Comments