Microsoft has announced changes to their unified auditing and logging capability that will change what event types are logged by default and available to be logged such that event types previously only available to E5/G5 or add-on licensing for Purview (Premium) will now be logged under E3/G3 or Purview (standard) starting September 2023 as noted here. This enhancement is meant to test and validate the specific event types that changed and propose baseline and assessment changes under those changes.
Motivation and context
Auditing and logging M365 events is an important part of securing M365 services, detecting potential security events, and responding to incidents. Accurately understanding which audit events are logged at different licensing levels, both by default and which are available but disabled, is important to recommend audit policy changes and determine if advanced auditing is still needed as part of minimum standards.
Implementation notes
This exploration should include the following:
Review of updated Microsoft documentation and consulting with Microsoft on new audit policies and event inclusion in Purview Standard
Review of existing baseline audit policies and determination of impact
Hands-on prototyping and testing of new audit logging to validate new settings in commercial, gcc, and gcchigh regions
Set of recommendations for baseline and ScubaGear code updates IAW audit best practices and federal memos and regulations.
Acceptance criteria
How do we know when this work is done?
[ ] List of both default and non-default event types available at Purview Standard and Premium levels created
[ ] Baseline policies have been reviewed and recommendations for audit related updates logged in a pull request
[ ] New code changes to support baseline policy updates successfully logged as issues for prioritization and development
💡 Summary
Microsoft has announced changes to their unified auditing and logging capability that will change what event types are logged by default and available to be logged such that event types previously only available to E5/G5 or add-on licensing for Purview (Premium) will now be logged under E3/G3 or Purview (standard) starting September 2023 as noted here. This enhancement is meant to test and validate the specific event types that changed and propose baseline and assessment changes under those changes.
Motivation and context
Auditing and logging M365 events is an important part of securing M365 services, detecting potential security events, and responding to incidents. Accurately understanding which audit events are logged at different licensing levels, both by default and which are available but disabled, is important to recommend audit policy changes and determine if advanced auditing is still needed as part of minimum standards.
Implementation notes
This exploration should include the following:
Acceptance criteria
How do we know when this work is done?