Aug. 6, 2026

Microsoft Purview Audit - Simply Explained

Microsoft Purview Audit - Simply Explained
Microsoft Purview Audit - Simply Explained
M365 FM Podcast
Microsoft Purview Audit - Simply Explained

Every day, employees open files, share documents, send emails, modify Microsoft Teams settings, update compliance policies, and perform countless actions across Microsoft 365. When a security incident, compliance investigation, or legal request occurs, organizations need clear answers about what happened, who performed the action, and when it took place. In this Microsoft Knowledge Nuggets episode, Mirko Peters explains Microsoft Purview Audit in plain English, showing how the Unified Audit Log helps organizations investigate user activity, administrative changes, and compliance events across Microsoft 365. Whether you're an IT administrator, compliance officer, security analyst, Microsoft consultant, or governance specialist, this episode provides a practical understanding of one of Microsoft's most important compliance services.

UNDERSTANDING THE MICROSOFT PURVIEW UNIFIED AUDIT LOG
Microsoft Purview Audit collects activity records from Microsoft 365 services into a centralized, searchable audit platform. Instead of searching separate logs across Exchange Online, SharePoint Online, OneDrive, Microsoft Teams, Microsoft Entra ID, and Microsoft Purview, investigators can analyze user actions from a single interface. Audit records capture events such as file access, document sharing, mailbox activity, sign-ins, administrative changes, sensitivity label modifications, retention policy updates, and Data Loss Prevention (DLP) policy changes. Rather than storing the actual contents of documents or emails, the Unified Audit Log records the activities surrounding those items, creating a reliable timeline for investigations and compliance reporting.

BUILDING INCIDENT TIMELINES ACROSS MICROSOFT 365
One of the greatest strengths of Microsoft Purview Audit is its ability to reconstruct events across multiple Microsoft services. Security teams can trace how files were accessed, determine when content was shared externally, investigate mailbox rule modifications, review administrator activity, and correlate user actions with identity events recorded by Microsoft Entra ID. By filtering searches based on users, workloads, dates, activities, locations, and affected objects, investigators can quickly narrow large volumes of audit data into meaningful timelines. This centralized visibility dramatically reduces investigation time while improving incident response, internal reviews, and regulatory reporting.

HOW PURVIEW AUDIT FITS WITH OTHER MICROSOFT PURVIEW SOLUTIONS
Microsoft Purview Audit forms the investigative foundation for many other Microsoft Purview capabilities. While Audit records what happened, Content Search locates the associated emails, documents, and files. Microsoft Purview eDiscovery preserves, reviews, and exports that content for legal and regulatory investigations. Compliance Manager measures organizational compliance against industry standards, while Insider Risk Management analyzes behavioral patterns that may indicate risky activity. Communication Compliance focuses on reviewing communications that violate organizational policies. Together, these solutions create a complete Microsoft Purview compliance ecosystem where audit records provide the factual timeline that supports broader governance, legal, HR, and cybersecurity investigations.

AUDIT STANDARD VS AUDIT PREMIUM
Organizations can choose between Microsoft Purview Audit Standard and Audit Premium depending on their investigation and retention requirements. Audit Standard provides the core Unified Audit Log with activity retention suitable for most day-to-day investigations across Microsoft 365. Audit Premium extends these capabilities with longer retention periods, custom audit retention policies, richer event details, higher-volume API access, and enhanced investigation capabilities designed for highly regulated industries, enterprise security operations, legal investigations, and long-running compliance cases. Selecting the appropriate licensing strategy ensures organizations retain critical evidence for the period required by regulatory obligations, contractual commitments, and internal governance policies.

BUILDING A STRONG MICROSOFT 365 AUDIT STRATEGY
Successful auditing extends beyond simply enabling the Unified Audit Log. Organizations should regularly verify that audit events are being collected, assign dedicated Audit Reader and Audit Manager roles, establish clear investigation procedures, define retention requirements, and document repeatable search processes for common security and compliance scenarios. Testing audit searches before incidents occur allows security teams to validate workflows, improve response times, and ensure investigators know how to correlate Audit with Microsoft Defender, Insider Risk Management, eDiscovery, Compliance Manager, and other Microsoft Purview services. By building these processes early, organizations create a strong governance foundation that improves security visibility, regulatory compliance, and operational resilience across the Microsoft 365 environment.

Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support.

πŸš€ Want to be part of m365.fm?

Then stop just listening… and start showing up.

πŸ‘‰ Connect with me on LinkedIn and let’s make something happen:

  • πŸŽ™οΈ Be a podcast guest and share your story
  • 🎧 Host your own episode (yes, seriously)
  • πŸ’‘ Pitch topics the community actually wants to hear
  • 🌍 Build your personal brand in the Microsoft 365 space

This isn’t just a podcast — it’s a platform for people who take action.

πŸ”₯ Most people wait. The best ones don’t.

πŸ‘‰ Connect with me on LinkedIn and send me a message:
"I want in"

Let’s build something awesome πŸ‘Š

1
00:00:00,000 --> 00:00:02,820
Most teams use Microsoft 365 every day,

2
00:00:02,820 --> 00:00:04,220
but when something goes wrong,

3
00:00:04,220 --> 00:00:05,900
they can't answer a basic question.

4
00:00:05,900 --> 00:00:07,040
Who opened that file?

5
00:00:07,040 --> 00:00:08,440
Who shared it outside the company?

6
00:00:08,440 --> 00:00:09,620
Who deleted it, changed it,

7
00:00:09,620 --> 00:00:11,560
or changed the rule that was meant to protect it?

8
00:00:11,560 --> 00:00:13,360
I'm Mirko Peters from M365.

9
00:00:13,360 --> 00:00:15,320
FM and this knowledge nugget puts Microsoft

10
00:00:15,320 --> 00:00:16,820
Perview Audit into plain English.

11
00:00:16,820 --> 00:00:18,500
By the end, you'll see what it records,

12
00:00:18,500 --> 00:00:20,180
why compliance teams depend on it,

13
00:00:20,180 --> 00:00:22,200
and where it fits in the wider Perview platform.

14
00:00:22,200 --> 00:00:24,600
Think of Microsoft 365 like an office building.

15
00:00:24,600 --> 00:00:26,700
You've got rooms for email, files, meetings,

16
00:00:26,700 --> 00:00:28,020
chat and administration.

17
00:00:28,020 --> 00:00:29,680
Perview Audit is the security camera

18
00:00:29,680 --> 00:00:31,520
logbook running behind the scenes.

19
00:00:31,520 --> 00:00:33,460
It records who entered what they did

20
00:00:33,460 --> 00:00:35,000
when it happened, where it happened,

21
00:00:35,000 --> 00:00:36,600
and sometimes how they got there.

22
00:00:36,600 --> 00:00:38,080
But here's the key distinction.

23
00:00:38,080 --> 00:00:40,520
It records actions, not the full contents

24
00:00:40,520 --> 00:00:42,200
of every file or message.

25
00:00:42,200 --> 00:00:44,040
That difference matters a lot.

26
00:00:44,040 --> 00:00:45,600
The problem audit solves.

27
00:00:45,600 --> 00:00:47,440
Before cloud services work together,

28
00:00:47,440 --> 00:00:49,360
every system kept its own log.

29
00:00:49,360 --> 00:00:52,240
Email had one set of records, file storage had another,

30
00:00:52,240 --> 00:00:53,760
and meeting tools, devices,

31
00:00:53,760 --> 00:00:55,320
sign-ins and admin portals,

32
00:00:55,320 --> 00:00:56,960
each kept their own history somewhere else.

33
00:00:56,960 --> 00:00:58,160
So when an incident happened,

34
00:00:58,160 --> 00:01:00,400
someone had to pull records from several places

35
00:01:00,400 --> 00:01:02,240
and try to build a timeline by hand.

36
00:01:02,240 --> 00:01:04,280
That takes time, and during an investigation,

37
00:01:04,280 --> 00:01:05,520
time is everything.

38
00:01:05,520 --> 00:01:07,400
Imagine a finance employee shares a file

39
00:01:07,400 --> 00:01:09,360
from one drive with an external address.

40
00:01:09,360 --> 00:01:12,160
A few minutes later, someone changes a mailbox rule.

41
00:01:12,160 --> 00:01:14,600
Then an administrator edits a data protection policy

42
00:01:14,600 --> 00:01:15,440
in Perview.

43
00:01:15,440 --> 00:01:16,680
Maybe none of those actions connect,

44
00:01:16,680 --> 00:01:18,720
or maybe there are three parts of the same problem.

45
00:01:18,720 --> 00:01:21,600
Without a shared activity record, your team has to guess.

46
00:01:21,600 --> 00:01:23,400
That's where Microsoft Perview Audit comes in.

47
00:01:23,400 --> 00:01:26,960
It brings activity from connected Microsoft 365 services

48
00:01:26,960 --> 00:01:29,040
into one searchable audit log.

49
00:01:29,040 --> 00:01:30,440
Instead of opening separate portals

50
00:01:30,440 --> 00:01:31,840
and comparing separate timestamps,

51
00:01:31,840 --> 00:01:34,640
you can start with one question and search from one place.

52
00:01:34,640 --> 00:01:36,280
You might need to know who shared a file

53
00:01:36,280 --> 00:01:39,120
outside the company, or when a mailbox rule changed,

54
00:01:39,120 --> 00:01:41,640
especially if messages suddenly started forwarding

55
00:01:41,640 --> 00:01:43,200
somewhere they shouldn't.

56
00:01:43,200 --> 00:01:45,200
Maybe you need to confirm whether an administrator

57
00:01:45,200 --> 00:01:48,200
changed a sensitivity label, a retention setting,

58
00:01:48,200 --> 00:01:50,600
or a data loss prevention policy.

59
00:01:50,600 --> 00:01:52,400
Or perhaps an employee is leaving,

60
00:01:52,400 --> 00:01:54,800
and HR or security needs to understand

61
00:01:54,800 --> 00:01:57,480
which files that person accessed before their last day.

62
00:01:57,480 --> 00:01:59,600
These questions aren't about blame by default.

63
00:01:59,600 --> 00:02:01,960
Sometimes a person clicks the wrong sharing option,

64
00:02:01,960 --> 00:02:04,720
sometimes an admin changes a setting during normal work,

65
00:02:04,720 --> 00:02:07,760
and sometimes a security alert turns out to be harmless.

66
00:02:07,760 --> 00:02:10,680
Still, you need facts before you can decide what happened.

67
00:02:10,680 --> 00:02:12,760
The unified audit log gives you those facts

68
00:02:12,760 --> 00:02:14,200
as activity records.

69
00:02:14,200 --> 00:02:16,680
An activity record includes the person who took the action,

70
00:02:16,680 --> 00:02:18,880
the time, the Microsoft service involved,

71
00:02:18,880 --> 00:02:22,240
and the item involved like a file mailbox, site, or policy.

72
00:02:22,240 --> 00:02:23,240
Depending on the activity,

73
00:02:23,240 --> 00:02:25,280
it can also include details like an IP address

74
00:02:25,280 --> 00:02:26,720
and other context around the event.

75
00:02:26,720 --> 00:02:29,360
That means you can move from, we think something changed

76
00:02:29,360 --> 00:02:32,040
to this account changed, this setting at this time

77
00:02:32,040 --> 00:02:33,320
from this location.

78
00:02:33,320 --> 00:02:34,920
That's a very different conversation.

79
00:02:34,920 --> 00:02:36,840
Now notice what an audit record does not promise.

80
00:02:36,840 --> 00:02:38,800
It doesn't automatically give you the full contents

81
00:02:38,800 --> 00:02:40,480
of an email, chat, or document.

82
00:02:40,480 --> 00:02:42,880
It tells you that an action happened around that item.

83
00:02:42,880 --> 00:02:44,800
Think of the logbook at a building entrance.

84
00:02:44,800 --> 00:02:47,120
It shows someone entered a room at 10.14,

85
00:02:47,120 --> 00:02:50,360
but it doesn't tell you every word spoken inside the room.

86
00:02:50,360 --> 00:02:53,080
Per view audit also keeps a trail for more than everyday users.

87
00:02:53,080 --> 00:02:55,120
It records actions by administrators

88
00:02:55,120 --> 00:02:57,960
and it records activity around per view settings themselves.

89
00:02:57,960 --> 00:03:00,120
So if someone changes a protection policy,

90
00:03:00,120 --> 00:03:02,080
your investigation can include that change,

91
00:03:02,080 --> 00:03:03,920
not just the activity that followed it.

92
00:03:03,920 --> 00:03:05,760
Compliance depends on this kind of evidence

93
00:03:05,760 --> 00:03:08,280
and auditor, legal team, security team,

94
00:03:08,280 --> 00:03:10,480
or manager can't work from a hunch.

95
00:03:10,480 --> 00:03:12,360
They need to show what happened, when it happened,

96
00:03:12,360 --> 00:03:14,200
and what the organization did next.

97
00:03:14,200 --> 00:03:16,160
Once you see the problem audit solves,

98
00:03:16,160 --> 00:03:17,920
the logbook starts to make much more sense.

99
00:03:17,920 --> 00:03:21,040
Blas, how purview audit works behind the scenes.

100
00:03:21,040 --> 00:03:23,360
Per view audit is a central record of activity

101
00:03:23,360 --> 00:03:26,600
from all the connected Microsoft Cloud services you already use.

102
00:03:26,600 --> 00:03:30,200
It doesn't replace Exchange Online SharePoint OneDrive or Teams,

103
00:03:30,200 --> 00:03:32,440
those still run your email files and chats.

104
00:03:32,440 --> 00:03:34,680
Instead, audits it's behind those services

105
00:03:34,680 --> 00:03:37,760
and records selected actions that those services report.

106
00:03:37,760 --> 00:03:39,440
Let's break down the main building blocks.

107
00:03:39,440 --> 00:03:42,440
Exchange Online can record activity around email and calendars.

108
00:03:42,440 --> 00:03:45,240
That might include mailbox actions, mail flow activity,

109
00:03:45,240 --> 00:03:47,520
or changes that affect how messages are handled.

110
00:03:47,520 --> 00:03:50,320
SharePoint and OneDrive can record actions around files

111
00:03:50,320 --> 00:03:52,640
when someone opens a file, edits it, moves it,

112
00:03:52,640 --> 00:03:54,440
deletes it, syncs it, or shares it.

113
00:03:54,440 --> 00:03:56,200
Those are different actions and they can create

114
00:03:56,200 --> 00:03:57,200
different records.

115
00:03:57,200 --> 00:03:59,400
Teams adds collaboration activity.

116
00:03:59,400 --> 00:04:01,280
Your team might create a workspace,

117
00:04:01,280 --> 00:04:03,400
change membership, work around a meeting,

118
00:04:03,400 --> 00:04:05,680
or interact with files linked from a channel.

119
00:04:05,680 --> 00:04:08,360
The exact events depend on the service and your licensing,

120
00:04:08,360 --> 00:04:09,960
but the point stays the same.

121
00:04:09,960 --> 00:04:11,480
Actions can leave a record.

122
00:04:11,480 --> 00:04:13,760
Enter ID, Microsoft's identity service,

123
00:04:13,760 --> 00:04:16,640
adds, sign in an identity context where it's available.

124
00:04:16,640 --> 00:04:18,400
That helps you connect an action to the account

125
00:04:18,400 --> 00:04:21,520
that's signed in rather than looking at a file event on its own.

126
00:04:21,520 --> 00:04:22,760
Then there is PerView itself.

127
00:04:22,760 --> 00:04:25,240
A policy doesn't protect anybody if someone can quietly

128
00:04:25,240 --> 00:04:26,760
change it without a record.

129
00:04:26,760 --> 00:04:29,360
Audit can track activity around policy changes,

130
00:04:29,360 --> 00:04:32,480
sensitivity labels, data loss prevention rules, retention

131
00:04:32,480 --> 00:04:34,960
settings, and other admin work in PerView.

132
00:04:34,960 --> 00:04:37,000
That link matters because an investigation often

133
00:04:37,000 --> 00:04:39,520
starts with a file or email then turns into a question

134
00:04:39,520 --> 00:04:40,880
about the controls around it.

135
00:04:40,880 --> 00:04:43,480
Imagine a confidential spreadsheet stored in OneDrive.

136
00:04:43,480 --> 00:04:45,040
On Monday morning, an employee shares it

137
00:04:45,040 --> 00:04:46,240
with an external address.

138
00:04:46,240 --> 00:04:49,160
Later that day, the same employee opens the file again.

139
00:04:49,160 --> 00:04:50,680
A manager notices the sharing alert

140
00:04:50,680 --> 00:04:53,440
and asks whether the spreadsheet left the company by mistake.

141
00:04:53,440 --> 00:04:55,480
You wouldn't search for everything in the tenant.

142
00:04:55,480 --> 00:04:57,360
You would start with a narrow question,

143
00:04:57,360 --> 00:04:59,440
which account shared this specific file,

144
00:04:59,440 --> 00:05:00,280
and when.

145
00:05:00,280 --> 00:05:01,760
The audit search can then help you build

146
00:05:01,760 --> 00:05:03,280
a timeline around that question.

147
00:05:03,280 --> 00:05:05,560
You might find the sharing event, the file location,

148
00:05:05,560 --> 00:05:07,920
the account involved, and other nearby actions

149
00:05:07,920 --> 00:05:09,440
that give the event context.

150
00:05:09,440 --> 00:05:11,760
Perhaps the account signed in shortly before the share,

151
00:05:11,760 --> 00:05:13,680
perhaps the file moved from a team site

152
00:05:13,680 --> 00:05:15,840
into a personal OneDrive folder first.

153
00:05:15,840 --> 00:05:17,960
Or perhaps the employee removed the external link

154
00:05:17,960 --> 00:05:19,800
shortly after realizing the mistake.

155
00:05:19,800 --> 00:05:21,080
Those records are breadcrumbs.

156
00:05:21,080 --> 00:05:22,520
They help you follow the path.

157
00:05:22,520 --> 00:05:24,160
They do not decide intent for you.

158
00:05:24,160 --> 00:05:26,080
A person sharing a file externally

159
00:05:26,080 --> 00:05:28,040
could be doing normal work with a supplier.

160
00:05:28,040 --> 00:05:29,280
It could also be an error.

161
00:05:29,280 --> 00:05:32,080
In a more serious case, it might need a deeper investigation.

162
00:05:32,080 --> 00:05:33,720
Audit gives you the activity trail

163
00:05:33,720 --> 00:05:36,000
and your people apply judgment to the facts.

164
00:05:36,000 --> 00:05:38,160
The search screen gives you ways to narrow that trail.

165
00:05:38,160 --> 00:05:39,320
You can set a date range.

166
00:05:39,320 --> 00:05:40,560
You can search for a person.

167
00:05:40,560 --> 00:05:42,440
You can choose an activity such as a file share

168
00:05:42,440 --> 00:05:43,760
or a policy update.

169
00:05:43,760 --> 00:05:46,200
You can filter by service, file, mailbox, sharepoint site,

170
00:05:46,200 --> 00:05:47,480
object, or a keyword.

171
00:05:47,480 --> 00:05:49,480
When that fits the question, you are trying to answer.

172
00:05:49,480 --> 00:05:50,440
Start small.

173
00:05:50,440 --> 00:05:52,560
A search for every event from every user

174
00:05:52,560 --> 00:05:55,920
across a long period can leave you with far too much noise.

175
00:05:55,920 --> 00:05:58,120
A search for one person, one file, and one day

176
00:05:58,120 --> 00:05:59,360
gives you a place to begin.

177
00:05:59,360 --> 00:06:01,480
Give the search a clear name as well.

178
00:06:01,480 --> 00:06:03,840
Finance File External Share 14 May

179
00:06:03,840 --> 00:06:06,160
tells the next investigator what you looked for.

180
00:06:06,160 --> 00:06:08,480
Search seven tells them almost nothing.

181
00:06:08,480 --> 00:06:11,920
If the case returns weeks later, a clear name, a defined scope,

182
00:06:11,920 --> 00:06:14,480
and a recorded reason make it easier to repeat the work

183
00:06:14,480 --> 00:06:16,040
and compare the results.

184
00:06:16,040 --> 00:06:17,960
When the search returns useful records,

185
00:06:17,960 --> 00:06:19,040
you can export them.

186
00:06:19,040 --> 00:06:21,640
That export may go to security for incident work, HR,

187
00:06:21,640 --> 00:06:23,880
for an internal review, legal for a case,

188
00:06:23,880 --> 00:06:25,680
or an outside reviewer who needs evidence

189
00:06:25,680 --> 00:06:28,640
without direct access to your Microsoft 365 tenant.

190
00:06:28,640 --> 00:06:31,880
Keep track of what you exported, who received it, and why.

191
00:06:31,880 --> 00:06:33,480
Audit data can be sensitive because it

192
00:06:33,480 --> 00:06:35,600
describes real actions by real people,

193
00:06:35,600 --> 00:06:38,800
but a long list of audit events still leaves one question open.

194
00:06:38,800 --> 00:06:41,520
You may know that someone opened, shared, or changed something.

195
00:06:41,520 --> 00:06:44,120
How do you find the actual document, email, chat, or compliance

196
00:06:44,120 --> 00:06:45,880
case that belongs with that activity?

197
00:06:45,880 --> 00:06:47,240
Audit finds the actions.

198
00:06:47,240 --> 00:06:49,440
The other purview tools answer different parts

199
00:06:49,440 --> 00:06:52,120
of the investigation.

200
00:06:52,120 --> 00:06:54,080
Where audit fits in the purview building.

201
00:06:54,080 --> 00:06:56,440
Microsoft purview has several tools that sound close enough

202
00:06:56,440 --> 00:06:57,840
to confuse almost anyone.

203
00:06:57,840 --> 00:07:01,800
Audit, compliance manager, e-discovery, content search,

204
00:07:01,800 --> 00:07:04,440
insider risk management, and communication compliance

205
00:07:04,440 --> 00:07:07,000
all deal with data, risk, or investigations.

206
00:07:07,000 --> 00:07:08,200
But they don't do the same job.

207
00:07:08,200 --> 00:07:10,240
Start with audit and compliance manager.

208
00:07:10,240 --> 00:07:12,440
Audit answers what happened.

209
00:07:12,440 --> 00:07:14,760
You search it when you need the history of an action.

210
00:07:14,760 --> 00:07:17,640
A person shared a file, an admin changed a policy,

211
00:07:17,640 --> 00:07:19,160
a mailbox setting changed.

212
00:07:19,160 --> 00:07:20,600
You want the record of that event.

213
00:07:20,600 --> 00:07:23,040
Compliance manager answers a different question.

214
00:07:23,040 --> 00:07:25,160
What controls does our organization need?

215
00:07:25,160 --> 00:07:26,800
And how far along are we?

216
00:07:26,800 --> 00:07:31,280
Think about a company working toward a rule set such as HIPAA, ISO 27001,

217
00:07:31,280 --> 00:07:32,680
or another industry requirement.

218
00:07:32,680 --> 00:07:34,800
Compliance manager helps the team track the controls,

219
00:07:34,800 --> 00:07:37,040
the work still left to do, and the evidence connected

220
00:07:37,040 --> 00:07:37,960
to those controls.

221
00:07:37,960 --> 00:07:39,840
So audit gives you the event history.

222
00:07:39,840 --> 00:07:42,560
Compliance manager gives you the wider compliance work list.

223
00:07:42,560 --> 00:07:45,320
One can support the other, but neither replaces the other.

224
00:07:45,320 --> 00:07:46,800
Then there is e-discovery.

225
00:07:46,800 --> 00:07:49,040
Audit can tell you that somebody opened, shared,

226
00:07:49,040 --> 00:07:50,800
downloaded, or deleted something.

227
00:07:50,800 --> 00:07:53,160
It gives you the timeline and the event details.

228
00:07:53,160 --> 00:07:55,560
E-discovery helps when you need the actual content.

229
00:07:55,560 --> 00:07:58,200
Maybe legal needs to find emails connected to a case.

230
00:07:58,200 --> 00:08:00,400
Maybe HR needs to review team's chats.

231
00:08:00,400 --> 00:08:02,840
Maybe an investigation needs to preserve documents

232
00:08:02,840 --> 00:08:04,960
so they are not removed while the case continues.

233
00:08:04,960 --> 00:08:06,080
That's e-discovery work.

234
00:08:06,080 --> 00:08:09,320
It can find content, place it on hold, bring it into a case,

235
00:08:09,320 --> 00:08:12,000
support review, and export it when the people handling the case

236
00:08:12,000 --> 00:08:12,680
need it.

237
00:08:12,680 --> 00:08:15,120
A simple way to remember the difference is this.

238
00:08:15,120 --> 00:08:17,200
Audit tells you that a person opened a document

239
00:08:17,200 --> 00:08:18,200
at a certain time.

240
00:08:18,200 --> 00:08:20,160
E-discovery helps you find the document itself

241
00:08:20,160 --> 00:08:22,200
and manage it as evidence.

242
00:08:22,200 --> 00:08:23,880
Content search sits close to e-discovery,

243
00:08:23,880 --> 00:08:25,280
but it has a narrower job.

244
00:08:25,280 --> 00:08:27,920
Suppose audit shows that an employee shared a file

245
00:08:27,920 --> 00:08:29,840
or that a message left a mailbox.

246
00:08:29,840 --> 00:08:31,440
You now know an action took place.

247
00:08:31,440 --> 00:08:33,640
Content search helps you locate the actual file

248
00:08:33,640 --> 00:08:36,360
or message by searching the places where that content lives.

249
00:08:36,360 --> 00:08:38,520
You might search a mailbox, a SharePoint site,

250
00:08:38,520 --> 00:08:41,400
or one drive account, or a Microsoft 365 group.

251
00:08:41,400 --> 00:08:43,200
So audit can point you toward the item.

252
00:08:43,200 --> 00:08:45,480
Content search helps you find the item.

253
00:08:45,480 --> 00:08:47,840
For a larger legal HR or regulatory matter,

254
00:08:47,840 --> 00:08:50,080
that search may become part of an e-discovery case

255
00:08:50,080 --> 00:08:52,280
where access, review, preservation, and exports

256
00:08:52,280 --> 00:08:53,680
need tighter control.

257
00:08:53,680 --> 00:08:56,120
Inside a risk management works differently again.

258
00:08:56,120 --> 00:08:58,000
Audit gives you raw activity evidence.

259
00:08:58,000 --> 00:08:59,960
It can show a download, a share, a sign-in,

260
00:08:59,960 --> 00:09:01,400
or another recorded event.

261
00:09:01,400 --> 00:09:03,760
By itself, each event may be normal.

262
00:09:03,760 --> 00:09:05,720
Inside a risk management looks for patterns

263
00:09:05,720 --> 00:09:07,440
that might point to risky behavior.

264
00:09:07,440 --> 00:09:09,520
For example, one download may mean nothing.

265
00:09:09,520 --> 00:09:11,640
A pattern of downloading sensitive files,

266
00:09:11,640 --> 00:09:13,320
moving them to a personal location,

267
00:09:13,320 --> 00:09:14,960
and then sharing them outside the company

268
00:09:14,960 --> 00:09:16,360
deserves a closer look.

269
00:09:16,360 --> 00:09:18,320
Inside a risk management brings signals together

270
00:09:18,320 --> 00:09:19,800
and can raise an alert for reviewers.

271
00:09:19,800 --> 00:09:21,520
It doesn't declare somebody guilty.

272
00:09:21,520 --> 00:09:24,320
It helps the right people notice behavior that needs context,

273
00:09:24,320 --> 00:09:27,320
and audit can help them examine the actions behind that alert.

274
00:09:27,320 --> 00:09:29,880
Communication compliance has an even more focused role.

275
00:09:29,880 --> 00:09:32,320
Audit can record communication-related actions.

276
00:09:32,320 --> 00:09:34,920
It may help show that an activity happened around a mailbox,

277
00:09:34,920 --> 00:09:36,880
chat, or collaboration service.

278
00:09:36,880 --> 00:09:39,080
Communication compliance helps approve reviewers

279
00:09:39,080 --> 00:09:41,760
examine actual messages that were flagged by a policy.

280
00:09:41,760 --> 00:09:43,520
That might involve inappropriate language,

281
00:09:43,520 --> 00:09:45,440
sensitive information, a conflict of interest,

282
00:09:45,440 --> 00:09:46,720
or another defined concern.

283
00:09:46,720 --> 00:09:48,960
Because reviewers can see real conversations,

284
00:09:48,960 --> 00:09:50,600
this process needs strict controls.

285
00:09:50,600 --> 00:09:52,960
Not every admin should see every audit record,

286
00:09:52,960 --> 00:09:55,200
and not every investigator should read every message

287
00:09:55,200 --> 00:09:57,760
or enter every case, give people only the access

288
00:09:57,760 --> 00:09:58,960
they need for their job.

289
00:09:58,960 --> 00:10:01,120
An audit reader can search activity records,

290
00:10:01,120 --> 00:10:02,720
and e-discovery case can limit access

291
00:10:02,720 --> 00:10:04,320
to the people handling that case.

292
00:10:04,320 --> 00:10:06,560
Communication compliance can restrict message review

293
00:10:06,560 --> 00:10:07,800
to trained reviewers.

294
00:10:07,800 --> 00:10:10,880
This protects privacy, reduces unnecessary exposure,

295
00:10:10,880 --> 00:10:13,320
and makes the process fairer for everyone involved.

296
00:10:13,320 --> 00:10:15,120
A typical investigation can move from question

297
00:10:15,120 --> 00:10:17,880
to evidence in a clear order, and alert arrives,

298
00:10:17,880 --> 00:10:19,600
or somebody asks a question.

299
00:10:19,600 --> 00:10:21,480
Audit helps build the activity timeline,

300
00:10:21,480 --> 00:10:23,440
content search, or e-discovery helps locate

301
00:10:23,440 --> 00:10:24,760
and manage the content.

302
00:10:24,760 --> 00:10:26,400
Then the right team reviews the evidence

303
00:10:26,400 --> 00:10:27,840
and decides what responses needed.

304
00:10:27,840 --> 00:10:31,080
Different tools, different jobs, one connected process.

305
00:10:31,080 --> 00:10:33,440
The next decision changes how far back you can search

306
00:10:33,440 --> 00:10:35,600
and how much detail you can retrieve.

307
00:10:35,600 --> 00:10:38,320
Audit standard or audit premium.

308
00:10:38,320 --> 00:10:40,840
Audit standard and audit premium simply explained.

309
00:10:40,840 --> 00:10:42,120
So which version do you need?

310
00:10:42,120 --> 00:10:43,120
Let's break it down.

311
00:10:43,120 --> 00:10:45,400
The choice really comes down to whether you need

312
00:10:45,400 --> 00:10:48,120
a basic activity history or a deeper record

313
00:10:48,120 --> 00:10:50,160
for longer, more detailed investigations.

314
00:10:50,160 --> 00:10:52,200
Audit standard is where most organizations start.

315
00:10:52,200 --> 00:10:54,480
It comes with many Microsoft 365 plans

316
00:10:54,480 --> 00:10:56,560
and gives you the everyday records most teams need

317
00:10:56,560 --> 00:10:58,880
when they're trying to answer a focused question.

318
00:10:58,880 --> 00:11:01,280
You can search for sign-ins, file actions,

319
00:11:01,280 --> 00:11:03,400
sharing activity, and admin changes

320
00:11:03,400 --> 00:11:05,120
across the services you use.

321
00:11:05,120 --> 00:11:07,120
When a manager asks whether a project document

322
00:11:07,120 --> 00:11:09,000
was shared outside the company yesterday,

323
00:11:09,000 --> 00:11:11,040
that's a normal audit standard question.

324
00:11:11,040 --> 00:11:13,240
You know the likely user, the file, and the time period.

325
00:11:13,240 --> 00:11:15,880
So you run a focused search, check the activity record,

326
00:11:15,880 --> 00:11:17,720
and decide whether more work is needed.

327
00:11:17,720 --> 00:11:20,120
For many organizations that covers a lot of ground.

328
00:11:20,120 --> 00:11:22,480
By default, audit standard keeps many audit records

329
00:11:22,480 --> 00:11:24,240
for up to 180 days.

330
00:11:24,240 --> 00:11:26,840
Six months is enough when your team spots problems quickly,

331
00:11:26,840 --> 00:11:28,600
investigates them within a reasonable time

332
00:11:28,600 --> 00:11:31,400
and doesn't have a rule that requires a much longer history.

333
00:11:31,400 --> 00:11:33,280
But some questions arrive much later.

334
00:11:33,280 --> 00:11:36,160
A legal team may begin reviewing a matter that started last year.

335
00:11:36,160 --> 00:11:37,960
A security team may discover that an account

336
00:11:37,960 --> 00:11:40,680
has been misused for months or a regulated business

337
00:11:40,680 --> 00:11:43,200
may need to keep records for years because a rule requires it.

338
00:11:43,200 --> 00:11:44,920
That's where audit premium comes in.

339
00:11:44,920 --> 00:11:50,080
To get audit premium, you need Microsoft 365 E5, E5 compliance,

340
00:11:50,080 --> 00:11:53,200
or a suitable add-on depending on your licensing setup.

341
00:11:53,200 --> 00:11:55,200
It includes the standard capabilities,

342
00:11:55,200 --> 00:11:57,600
then adds a longer lookback period and more detail

343
00:11:57,600 --> 00:11:59,120
for certain investigations.

344
00:11:59,120 --> 00:12:02,120
Premium keeps eligible audit records for one year by default.

345
00:12:02,120 --> 00:12:04,520
It also allows custom audit retention policies,

346
00:12:04,520 --> 00:12:07,600
which can keep selected records for up to 10 years

347
00:12:07,600 --> 00:12:09,240
when the right licensing is in place.

348
00:12:09,240 --> 00:12:10,960
You don't have to treat every user

349
00:12:10,960 --> 00:12:12,720
and every activity the same way.

350
00:12:12,720 --> 00:12:14,520
A finance team may need longer records

351
00:12:14,520 --> 00:12:15,800
than a general project team.

352
00:12:15,800 --> 00:12:17,800
Prove-ledged administrators may need longer records

353
00:12:17,800 --> 00:12:18,840
than ordinary users.

354
00:12:18,840 --> 00:12:21,480
A mailbox access event may matter more to your organization

355
00:12:21,480 --> 00:12:23,120
than a routine file edit.

356
00:12:23,120 --> 00:12:26,400
Premium lets you shape retention around those real needs

357
00:12:26,400 --> 00:12:29,120
rather than applying one broad rule to everything.

358
00:12:29,120 --> 00:12:32,000
It also provides more event detail, intelligent insights,

359
00:12:32,000 --> 00:12:34,160
and higher bandwidth API access.

360
00:12:34,160 --> 00:12:36,000
In plain English, you get richer information

361
00:12:36,000 --> 00:12:37,480
for more complex investigations

362
00:12:37,480 --> 00:12:39,720
and larger organizations can move audit data

363
00:12:39,720 --> 00:12:42,000
into their own security tools more efficiently.

364
00:12:42,000 --> 00:12:43,400
Picture two situations.

365
00:12:43,400 --> 00:12:45,560
In the first, someone asked whether a file was shared

366
00:12:45,560 --> 00:12:47,000
externally this morning.

367
00:12:47,000 --> 00:12:49,160
Audit standard may give you everything you need.

368
00:12:49,160 --> 00:12:51,160
In the second, an organization needs to rebuild

369
00:12:51,160 --> 00:12:53,480
a long-running security or legal case.

370
00:12:53,480 --> 00:12:55,400
It may need a year or more of activity,

371
00:12:55,400 --> 00:12:56,880
deeper mailbox records,

372
00:12:56,880 --> 00:12:58,920
and a way to send large volumes of audit data

373
00:12:58,920 --> 00:13:00,080
to a security platform.

374
00:13:00,080 --> 00:13:02,280
That's the type of work audit premium is built for,

375
00:13:02,280 --> 00:13:04,600
but don't fall into one common licensing trap.

376
00:13:04,600 --> 00:13:06,600
Longer retention only keeps records from the point

377
00:13:06,600 --> 00:13:09,160
where the service began recording them under the right setup.

378
00:13:09,160 --> 00:13:11,240
It cannot go back in time and create events

379
00:13:11,240 --> 00:13:12,280
that were never kept.

380
00:13:12,280 --> 00:13:14,360
So if you decide in June that you need five years

381
00:13:14,360 --> 00:13:16,920
of audit history, you can't recover four missing years

382
00:13:16,920 --> 00:13:17,760
from the past.

383
00:13:17,760 --> 00:13:20,400
Your retention plan needs to exist before the incident.

384
00:13:20,400 --> 00:13:21,840
Start with your business needs.

385
00:13:21,840 --> 00:13:23,880
Ask which users create the most risk

386
00:13:23,880 --> 00:13:25,440
if their accounts are misused.

387
00:13:25,440 --> 00:13:27,960
Ask which workloads hold sensitive information.

388
00:13:27,960 --> 00:13:29,240
Then check the rules that apply

389
00:13:29,240 --> 00:13:31,880
to your industry, contracts, and internal policies.

390
00:13:31,880 --> 00:13:34,120
Keep records longer where there is a clear reason.

391
00:13:34,120 --> 00:13:35,840
Even the best audit record fails

392
00:13:35,840 --> 00:13:38,440
if nobody can search it safely, understand it,

393
00:13:38,440 --> 00:13:40,120
or act on what they find.

394
00:13:40,120 --> 00:13:42,160
Starts more, then build a process

395
00:13:42,160 --> 00:13:45,080
your people can follow when the pressure is on.

396
00:13:45,080 --> 00:13:47,960
A simple audit plan for your organization.

397
00:13:47,960 --> 00:13:50,800
A useful audit plan starts before anyone reports a problem.

398
00:13:50,800 --> 00:13:52,600
First, make sure audit is enabled,

399
00:13:52,600 --> 00:13:55,040
then confirm that records are actually arriving.

400
00:13:55,040 --> 00:13:56,280
Don't assume a setting exists

401
00:13:56,280 --> 00:13:58,280
because someone turned it on years ago.

402
00:13:58,280 --> 00:14:01,320
Run a simple search and check that recent activity appears.

403
00:14:01,320 --> 00:14:04,160
That small check can save a difficult conversation later.

404
00:14:04,160 --> 00:14:05,880
Next, separate the jobs.

405
00:14:05,880 --> 00:14:08,600
An audit reader searches records and reviews the results.

406
00:14:08,600 --> 00:14:11,520
An audit manager handles the settings, retention policies,

407
00:14:11,520 --> 00:14:13,400
and the wider care of the audit service.

408
00:14:13,400 --> 00:14:15,800
Those roles don't need to sit with the same person.

409
00:14:15,800 --> 00:14:18,520
In fact, separating them often gives you better control.

410
00:14:18,520 --> 00:14:19,960
The person who searches a record

411
00:14:19,960 --> 00:14:21,640
doesn't always need the power to change

412
00:14:21,640 --> 00:14:23,800
how long that record stays in the system.

413
00:14:23,800 --> 00:14:26,080
Sensitive cases need another boundary.

414
00:14:26,080 --> 00:14:27,920
E-discovery case access should stay separate

415
00:14:27,920 --> 00:14:29,240
from general audit access.

416
00:14:29,240 --> 00:14:31,720
A person may need to confirm that a file was shared

417
00:14:31,720 --> 00:14:33,680
without needing permission to open a legal case

418
00:14:33,680 --> 00:14:35,160
or review private documents.

419
00:14:35,160 --> 00:14:38,240
Give people the access their work requires and no more.

420
00:14:38,240 --> 00:14:40,960
Then write down the questions your organization needs to answer.

421
00:14:40,960 --> 00:14:41,840
Keep the list practical.

422
00:14:41,840 --> 00:14:44,040
Can we see who shared or accessed a file?

423
00:14:44,040 --> 00:14:46,200
Can we investigate mailbox and sign in activity

424
00:14:46,200 --> 00:14:47,720
when an account looks unusual?

425
00:14:47,720 --> 00:14:49,360
Can we confirm who changed a policy?

426
00:14:49,360 --> 00:14:51,040
Can we trace a data loss prevention event

427
00:14:51,040 --> 00:14:52,520
back to the action that triggered it?

428
00:14:52,520 --> 00:14:54,400
These questions give your team a starting point

429
00:14:54,400 --> 00:14:56,880
when they build searches, choose retention periods

430
00:14:56,880 --> 00:14:58,200
and write incident plans.

431
00:14:58,200 --> 00:15:00,240
Without them, audit can turn into a large tool

432
00:15:00,240 --> 00:15:01,960
that nobody feels confident using.

433
00:15:01,960 --> 00:15:03,840
Retention needs the same clear thinking.

434
00:15:03,840 --> 00:15:06,120
Don't keep everything forever just because you can.

435
00:15:06,120 --> 00:15:08,560
More records can also mean more sensitive data

436
00:15:08,560 --> 00:15:10,760
for your organization to protect and manage.

437
00:15:10,760 --> 00:15:13,160
Look at your legal duties, contracts, industry rules

438
00:15:13,160 --> 00:15:14,480
and internal policies.

439
00:15:14,480 --> 00:15:17,600
Then decide what you need to keep for how long and why.

440
00:15:17,600 --> 00:15:20,480
Start with the areas where a missing record would hurt most.

441
00:15:20,480 --> 00:15:22,640
Finance may handle payment details and forecasts.

442
00:15:22,640 --> 00:15:24,760
HR may handle employee information.

443
00:15:24,760 --> 00:15:27,400
Administrators can change settings that affect the whole company.

444
00:15:27,400 --> 00:15:30,760
Those teams and workloads give you a focused place to begin.

445
00:15:30,760 --> 00:15:32,280
You can expand later when you understand

446
00:15:32,280 --> 00:15:33,320
what your organization needs.

447
00:15:33,320 --> 00:15:35,480
Now test the process before it becomes urgent.

448
00:15:35,480 --> 00:15:37,360
Set up a safe practice investigation.

449
00:15:37,360 --> 00:15:38,840
Have someone share a test file.

450
00:15:38,840 --> 00:15:40,280
Change a test mailbox rule.

451
00:15:40,280 --> 00:15:42,480
Download a test document from a controlled location.

452
00:15:42,480 --> 00:15:43,800
Edit a test policy.

453
00:15:43,800 --> 00:15:45,840
Then ask your team to find the action in audit.

454
00:15:45,840 --> 00:15:47,400
This isn't about catching anyone out.

455
00:15:47,400 --> 00:15:50,080
It's about finding gaps while there is no real incident.

456
00:15:50,080 --> 00:15:51,520
Maybe the search is too broad.

457
00:15:51,520 --> 00:15:52,840
Maybe the wrong people have access.

458
00:15:52,840 --> 00:15:54,680
Maybe the team can find the event,

459
00:15:54,680 --> 00:15:56,280
but doesn't know what to do next.

460
00:15:56,280 --> 00:15:58,960
And boom, you found something useful before it costs you.

461
00:15:58,960 --> 00:16:00,240
For every real investigation,

462
00:16:00,240 --> 00:16:01,920
keep a simple record of the work.

463
00:16:01,920 --> 00:16:03,000
Write the search name.

464
00:16:03,000 --> 00:16:04,720
Record the scope, the reason for the search

465
00:16:04,720 --> 00:16:06,040
and the person responsible.

466
00:16:06,040 --> 00:16:08,480
If you export results, note what was exported,

467
00:16:08,480 --> 00:16:10,400
who received it and where it is stored.

468
00:16:10,400 --> 00:16:13,200
That record helps the next person understand the case.

469
00:16:13,200 --> 00:16:14,840
It also helps your organization show

470
00:16:14,840 --> 00:16:17,200
that it handled sensitive information carefully.

471
00:16:17,200 --> 00:16:18,640
Audit rarely works alone.

472
00:16:18,640 --> 00:16:21,640
A security alert in Defender may lead your team to an audit search,

473
00:16:21,640 --> 00:16:24,360
and inside a risk case may need audit events to add context.

474
00:16:24,360 --> 00:16:26,440
Any discovery case may need the content connected

475
00:16:26,440 --> 00:16:28,280
to an action you found in audit.

476
00:16:28,280 --> 00:16:30,120
Build those handoffs into your process early.

477
00:16:30,120 --> 00:16:31,640
Decide who owns the first review

478
00:16:31,640 --> 00:16:33,440
when a case moves to another team

479
00:16:33,440 --> 00:16:35,160
and who can approve the next step.

480
00:16:35,160 --> 00:16:37,520
The common mistake is waiting until something goes wrong.

481
00:16:37,520 --> 00:16:39,240
At that point, people are under pressure.

482
00:16:39,240 --> 00:16:40,440
Names and dates aren't clear,

483
00:16:40,440 --> 00:16:42,400
and everyone wants answers immediately.

484
00:16:42,400 --> 00:16:44,160
A tested process changes that.

485
00:16:44,160 --> 00:16:45,680
Your team can begin with a known search,

486
00:16:45,680 --> 00:16:48,400
a known owner and a timeline that is already there.

487
00:16:48,400 --> 00:16:50,280
Perview audit can't decide whether an action

488
00:16:50,280 --> 00:16:52,320
was harmless, accidental or deliberate.

489
00:16:52,320 --> 00:16:53,880
Your people still need to make that call.

490
00:16:53,880 --> 00:16:56,160
It gives them a record to work from.

491
00:16:56,160 --> 00:16:58,360
Perview audit takes all the scattered activity

492
00:16:58,360 --> 00:17:01,880
across Microsoft 365 and turns it into a searchable log,

493
00:17:01,880 --> 00:17:04,080
so you can see who did what and when.

494
00:17:04,080 --> 00:17:05,880
First, check if audit is enabled,

495
00:17:05,880 --> 00:17:08,560
then run a focused search for a file, a user,

496
00:17:08,560 --> 00:17:10,240
or a policy action you already know.

497
00:17:10,240 --> 00:17:11,600
You're not looking for a crisis.

498
00:17:11,600 --> 00:17:13,520
You're just confirming the record exists.

499
00:17:13,520 --> 00:17:16,360
Next, figure out where audit fits with eDiscovery,

500
00:17:16,360 --> 00:17:18,640
compliance manager and insider risk.

501
00:17:18,640 --> 00:17:19,840
When a question comes in,

502
00:17:19,840 --> 00:17:21,560
every team should know exactly where to start

503
00:17:21,560 --> 00:17:22,720
and where to go next.

504
00:17:22,720 --> 00:17:24,840
I'm Mirko Peters from M365 FM.

505
00:17:24,840 --> 00:17:26,680
Subscribe on your favorite podcast platform

506
00:17:26,680 --> 00:17:27,720
and share this knowledge nugget

507
00:17:27,720 --> 00:17:31,040
with someone building their Microsoft 365 Compliance Foundation.