Understanding Office 365 Unified Audit Logging

Understanding Office 365 Unified Audit Logging

Sponsored by

? 2016 Monterey Technology Group Inc.

Thanks to

Made possible by

? 2016 Monterey Technology Group Inc.

Preview of key points

Which applications?

What administrative actions you can audit What user level actions you can audit

What other events are captured such as suspicious logons How to enable auditing How to access the audit logs

Which applications

Azure AD SharePoint Online and OneDrive for Business Exchange Online Sway eDiscovery activities Power BI Yammer

Azure AD

Azure AD

User maintenance

Groups maintenance

Admin authority delegation

Other

Integrated application maintenance Domains Partners Federation Policies Sync

Exchange Online

Administrator

Every administrative action exchange is ultimately executed as a PowerShell command

That's what's audited

Mailbox

Copy Create SoftDelete Move MoveToDeletedItems HardDelete SendAs SendOnBehalf Update MailboxLogin

SharePoint Online and OneDrive for Business

For better or worse OneDrive for Business is essentially SharePoint document libraries

So audit log is same for both

Track every option to files

Access/download, check in/out, copy, delete, modify rename, restore, upload

Sharing links Synch

SharePoint

Site admins SharePoint groups

................
................

In order to avoid copyright disputes, this page is only a partial summary.

Google Online Preview   Download