▲
10
Microsoft 365 audit logs, which feeds are actually useful?
Azure AD, Exchange, SharePoint, OneDrive, Teams. Turned them all on and immediately regretted it.
Azure AD, Exchange, SharePoint, OneDrive, Teams. Turned them all on and immediately regretted it.
Azure AD sign-ins first and it is not close. That is where account compromise shows up.
Exchange admin activity second, especially mailbox rule creation. Somebody who gets into a mailbox creates a rule to hide their tracks and it is a small, high signal event.
SharePoint and OneDrive file activity are enormous and only worth it if exfiltration is specifically your concern. Teams is noise unless you are regulated and have to keep it.