Forum
10

Microsoft 365 audit logs, which feeds are actually useful?

asked by vivida (David) 9 days ago

Azure AD, Exchange, SharePoint, OneDrive, Teams. Turned them all on and immediately regretted it.

2 answers

Sign in to answer.
aklaha 14 points 8 days ago

Azure AD sign-ins first and it is not close. That is where account compromise shows up.

Exchange admin activity second, especially mailbox rule creation. Somebody who gets into a mailbox creates a rule to hide their tracks and it is a small, high signal event.

SharePoint and OneDrive file activity are enormous and only worth it if exfiltration is specifically your concern. Teams is noise unless you are regulated and have to keep it.

cclondon 8 points 8 days ago

Mailbox rules is the one. Every BEC case I have been near had a rule moving anything with "invoice" or "payment" into a folder nobody opens.

Guidelines Newest Search Back to Trunc