audit logs
12 TopicsIssue with search mailbox audit log on Exchange Online
Hi Exchange experts I have an issue with searching the audit logs with the mailboxes on Exchange Online. I have a mailbox on Exchange Online.The properties of that mailbox are as follows AuditEnabled: True AuditLogAgeLimit : 90.00:00:00 AuditAdmin : {Update, MoveToDeletedItems, SoftDelete, HardDelete...} AuditDelegate : {Update, MoveToDeletedItems, SoftDelete, HardDelete...} AuditOwner : {Update, MoveToDeletedItems, SoftDelete, HardDelete...} DefaultAuditSet : {Admin, Delegate, Owner} I have conduted the changes on this maibox such as: changed the Send as permission, changed the Send on behafl, delegated another user on this mailbox. A few days later I used the Audit feature fromsecurity.microsoft.com portal to search the log for above activities with this maibox but I could not find any entries log that I did a few days ago. The options that I made when searching for mailbox logs Date time range:selected the time period in which I made the change Activities - friendly names: selected all activities on Exchange maibox activities Activities - operation name: blank Record types: blank Search name: blank User: Selecteduser that has a mailbox I have changed. Also, when I executed the syntax with Exchange PowerShell it doesn't show the change history that I want to see. Search-MailboxAuditLog -Identity po.panda@mydomain -LogonTypes Admin, Delegate -StartDate 7/15/24 -EndDate 7/19/24 -ResultSize 5000Solved809Views0likes8CommentsSize of the Microsoft Purview Audit Log for sizing SIEM / Splunk Storage
Hi there, we plan to export our M365 Audit Logs into a Splunk solution. The license cost is based on the storage needed. my questions: - is there a way to assess the storage used by our Audit logs in Microsoft Purview? - is there a way to calculate the storage needed for a number of users in a give time, e.g. per day/ week for heavy, medium, low M365 usage, I only need rough numbers? - does anybody have experience or numbers of their export to a SIEM system? Any support highly appreciated. Thanks, Franck587Views1like0CommentsRepost: Important Announcement: Deprecation of Search-AdminAuditLog and New-AdminAuditLogSearch cmdl
In case you get your Exchange blog posts from the Exchange Team's EHLO blog, you may have missed this doozy: Important Announcement: Deprecation of Search-AdminAuditLog and New-AdminAuditLogSearch cmdlets - Microsoft Community Hub It has been posted in the Security, Compliance and Identity blog instead.267Views0likes0CommentsAudit Log for Files or Folders that were deleted more than 6 months
Recently we have a few users reached out and inquired if IT can identify folders or files that were deleted more than 6 months ago (These files and folders are gone from the 2nd stage recycle bin). We’ve attempted to use the Audit feature in M365 Defender module (formally known as Security & Compliance) but since these objects was recycled more than 6 months ago, the Audit service is unable to retrieve any information. We've also attempted to reach out MS Support (standard Support since we don't have any premium support plan) and hope they have other tools that can help us identifying when these objects was recycled from the Document library but no luck either. At this point we are unsure what other approach we could take so any suggestions are welcome and much appreciated!Solved3.1KViews0likes1CommentAudit logs - "Denied access request" - What does this mean exactly?
I'm in Purview and looking at the filterable activities under Audit and I run across "Denied access request." Looking at the description in the docs, it says "An access request to a site, folder, or document was denied." I think this description is a bit vague and I was wondering if someone can explain which of my understanding is the right one. I think it either logs: A) A user with insufficientpermissions tries to access resource and is greeted by a "You don't have enough permissions" screen. (User attempt is logged?) B) A user with insufficient permissionstries to access resource and is greeted by a "You don't have enough permissions" screen. The user then clicks on the button on the screen to request access. The owner/admin of the resource sees the request then intentionally denies it. (Owner denying is logged? Or User being denied is logged?)Solved2.5KViews0likes2CommentsAudit logs for access attempts
Just wondering if the audit activities "Accessed file" and "Used secure link" are logged for when a user with insufficient permission to view the file/link attempts access. Or does the logging only happens on successful file access and viewing of the secure link respectively?Solved1.8KViews0likes3CommentsCreate an Audit for all sites associated to a Hub Site
There is a specific Hub Site that we created for documents that we have migrated from a legacy system to be reviewed by staff. There are over 20 sites associated with the Hub Site. We pull Audit Searches of activity for use with a PowerBI that we use to help determine activity and volume of usage. I was hoping that there is an easier way to pull the Audits for all of the sites associated with the Hub Site rather than having to pull an audit log for each and every single site.370Views0likes0CommentsAudit logs for a change made in SP Admin Center didn't show a change from modern auth to legacy auth
I was performing an audit in Microsoft Purview, https://compliance.microsoft.com/auditlogsearch?viewid=Async%20Search I did a New Search (preview) and I selected a person to "monitor" who was granted access to heightened security. I was monitoring to see what they might be doing and or if they were making changes. I did the audit on the account and for the date as "current" as possible. I ran the search, and it didn't show me that they changed from modern authentication to legacy authentication. I noticed it when they told me. The area is here: https://xxxxxxxxx-admin.sharepoint.com/_layouts/15/online/AdminHome.aspx#/accessControl/LegacyAuthentication Is there a way to have the auditing check the admin centers for admin's performing work and changing things? Thank you. Matt728Views0likes0CommentsPull Audit and Compliance Data via Microsoft Graph
We have been using reports and dashboards in Microsoft Compliance Center. The big issue on those is that the data is only available and limited for 30 days. We need to pull audit/compliance data such as those we have inhttps://compliance.microsoft.com/: a.Microsoft Purview --> Reports: Retention Label Usage, Sensitivity Label Usage, Retention Label Changes, Label trends over the past X days, DLP Policy Matches, DLP Incidents, DLP false positives and overrides, plus b. those we have inMicrosoft Purview --> Reports --> Activity Explorer but for more than 30 days, for any date range we wish to pull the data for and have a report. I would like to know if with Microsoft Graph we can pulling this information via Graph, and then feed it into some PowerBi Dashboard. Any help or directions if you ever had such experience, solution is appreciated. Ali1KViews0likes1Comment