When a security incident involves Microsoft 365, you need to know what an account actually did: which files it downloaded, which mailbox rules it created, whether it shared content externally or accessed a Teams chat. Microsoft Purview Audit provides that record through the unified audit log, which captures user and administrator activities across Exchange Online, SharePoint Online, OneDrive, Microsoft Teams, Microsoft Entra ID, Power BI, Microsoft 365 Copilot interactions and many other services.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 5 more sections, 4 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.