Tools Used
- Microsoft Learn Sandbox
- Microsoft Purview Portal
- Microsoft 365 Compliance Center
Steps Taken
- Signed into Microsoft Purview portal as MOD Administrator.
- Navigated to Audit → Audit Search.
- Enabled auditing and verified service activation.
- Configured audit log retention and searched for recent user activity.
- Filtered results by activity type, user, and workload.
- Exported audit logs for external review and compliance documentation.
- Reviewed audit insights and alert policies in Compliance Center.
Outcome
Audit settings successfully configured and validated. Microsoft 365 now tracks user and admin activity across services, supporting forensic investigation and regulatory compliance.
Certification Alignment
SC-401 Domain 2.2 – Implement Audit and Investigation Capabilities
Sandbox Link
Lab 11 – Configure Audit Settings