SecureMyEmail logoSecureMyEmail

Microsoft 365 security guide

Switch on audit logs and alerts in Microsoft 365

A practical guide for Australian businesses. Verify unified audit logging, assign least-privilege audit roles, configure alert notifications and test that suspicious activity is detected and investigated.

Microsoft 365 audit logs and security alerts monitoring

Recommended method: turn on Microsoft 365 unified audit logging and configure alert notifications

Audit logging records activities performed by users and administrators across Exchange Online, SharePoint, OneDrive, Microsoft Entra ID and Microsoft Teams. It helps establish who performed an action, what they changed and when it happened. Microsoft enables auditing automatically for many enterprise tenants, but small-business licences may require manual activation, so every organisation should verify it.

Before you begin

You will need:

  • A separate Microsoft 365 administrator account.
  • Suitable permissions, such as Audit Manager, Security Administrator or the relevant audit roles.
  • A monitored security email address.
  • At least two people responsible for responding to critical alerts.
  • An incident-response procedure for handling suspicious activity.

Avoid using a Global Administrator account for routine monitoring. Assign the minimum privileges required.

1

Verify that audit logging is enabled

  • Sign in to the Microsoft Purview portal.
  • Select Solutions.
  • Select Audit.
  • If Audit is not displayed, select View all solutions, then select Audit under the Core section.
  • Review the Audit page.
  • If a banner states that auditing is not enabled, select Start recording user and admin activity.
  • Allow up to 60 minutes for auditing to become active. Some events may take several hours before they are searchable.
  • If no activation banner appears and audit searches are available, auditing is normally already enabled.

Microsoft confirms that auditing is enabled by default for many Microsoft 365 organisations, but small-business licences may require manual activation.

2

Verify auditing with PowerShell — optional

  • Open PowerShell as an administrator.
  • Install the Exchange Online module if it is not already available:
    Install-Module ExchangeOnlineManagement
  • Connect to Exchange Online:
    Connect-ExchangeOnline
  • Check the auditing status:
    Get-AdminAuditLogConfig |
        Format-List UnifiedAuditLogIngestionEnabled
  • Confirm the result is: UnifiedAuditLogIngestionEnabled : True
  • If it is False, enable auditing:
    Set-AdminAuditLogConfig -UnifiedAuditLogIngestionEnabled $true
  • Wait at least 60 minutes, then run the status command again.
  • Disconnect when finished:
    Disconnect-ExchangeOnline

Run the verification command through Exchange Online PowerShell. Microsoft warns that running the equivalent command through Security and Compliance PowerShell can incorrectly display False.

3

Assign audit permissions

Use least-privilege roles rather than making monitoring personnel Global Administrators.

  • In the Purview portal, select Settings.
  • Open Roles and scopes.
  • Select Role groups.
  • Locate one of the following: Audit Reader (can search and export audit records) or Audit Manager (can search, export and manage audit settings).
  • Open the appropriate role group.
  • Select Edit.
  • Add the authorised security or compliance personnel.
  • Review the changes carefully.
  • Save the role assignment.
4

Test the audit search

  • In the Purview portal, go to Solutions > Audit.
  • Select New search.
  • Enter a suitable date and time range.
  • Under Activities, select one or more activities, such as Added member to role, Changed user licence, Updated user, Changed mailbox settings, Shared file, folder or site, Deleted file, Added mailbox permission or Created inbox rule.
  • To search a particular person, enter the user or administrator under Users.
  • Enter a descriptive search name.
  • Select Search.
  • Wait for the search to finish.
  • Open the results and confirm they identify the activity performed, the date and time, the user or administrator responsible, the affected service or object, the originating IP address where recorded, and whether the activity succeeded.
  • Export the results if they are required as incident evidence.
5

Review existing Microsoft 365 alert policies

  • Sign in to the Microsoft Defender portal.
  • Go to Email & collaboration > Policies & rules.
  • Select Alert policy.
  • Review the default Microsoft alert policies.
  • Confirm important policies are enabled.
  • Open each important policy and review alert severity, triggering activity, user or activity scope, notification recipients, and alert frequency or threshold.

Microsoft provides default policies covering activities such as administrator-role assignments, malware, phishing, unusual file deletion and external sharing. Availability varies by licence.

6

Configure alert notification recipients

  • For each important alert policy, open the policy.
  • Select Edit where editing is supported.
  • Find the Email notifications or Recipients setting.
  • Enable email notifications.
  • Add a monitored address, such as security@yourdomain.com.au.
  • Add an external managed IT or cybersecurity address if authorised.
  • Avoid sending alerts only to the user who may become compromised.
  • Confirm the selected severity and threshold.
  • Save the policy.
  • Repeat for other important policies.

Recipients must actively monitor the mailbox. Configuring notifications without assigning responsibility does not provide effective incident detection.

7

Prioritise important alerts

At minimum, review or configure alerts for:

  • Global Administrator or other privileged-role changes
  • Suspicious or risky sign-ins
  • Impossible or unusual travel
  • Multifactor authentication changes
  • Password resets or changes affecting administrators
  • User accounts created or deleted
  • Mailbox forwarding to external addresses
  • Suspicious inbox rules
  • Mailbox delegation or permission changes
  • Unusual email sending patterns
  • User-reported phishing or malware
  • Malware and phishing campaigns
  • Mass file deletion
  • Unusual file downloads
  • Anonymous or external sharing
  • Data-loss prevention policy matches
  • Changes to security or compliance policies
  • Audit logging being disabled
  • App registrations or service principals receiving powerful permissions
  • OAuth consent granted to applications

Some of these alerts require Microsoft Defender for Office 365, Microsoft Entra ID P1/P2, Microsoft Purview or other premium licensing.

8

Create a custom alert policy — where supported

  • Open the Microsoft Defender portal.
  • Go to Email & collaboration > Policies & rules > Alert policy.
  • Select New alert policy.
  • Enter a descriptive name, such as High-volume file deletion.
  • Add a plain-language description explaining what the policy detects.
  • Select a category, such as Threat management, Information governance, Data loss prevention or Permissions.
  • Set the severity to Low, Medium or High, according to the business risk.
  • Select the activity that will trigger the alert.
  • Define the users, workloads or thresholds to monitor.
  • Add the designated notification recipients.
  • Review the settings.
  • Create or save the policy.

Do not select an extremely low threshold without testing it first. This can create excessive alerts from normal business activity.

9

Review Defender incidents and alerts

  • In the Microsoft Defender portal, go to Incidents & alerts > Alerts.
  • Filter the list by severity, status, service source, assigned person and date.
  • Open each high-severity alert.
  • Review the affected user, device, mailbox and activity.
  • Assign the alert to an authorised responder.
  • Set its status to In progress.
  • Record investigation notes.
  • Apply appropriate containment and remediation.
  • Close the alert only after confirming the threat has been addressed.
  • Document the incident in your ticketing or incident-management system.
10

Check audit-log retention

Audit logs are useful only while the required evidence is still retained.

  • Microsoft Purview Audit Standard generally retains qualifying audit records for 180 days. Longer retention and custom retention policies require eligible Audit Premium, Microsoft 365 E5 or related add-on licensing.
  • For eligible tenants, open the Purview portal.
  • Go to Solutions > Audit.
  • Open the Policies or Audit retention policies section.
  • Select Create audit retention policy.
  • Enter a unique policy name and description.
  • Select the applicable users, record types and activities.
  • Choose the required retention period.
  • Assign the appropriate priority.
  • Review the licensing requirements.
  • Save the policy.

Be careful: a custom policy can override the default policy and may unintentionally result in a shorter retention period.

11

Perform a controlled test

  • Choose a low-risk test account and record the test window.
  • Perform a harmless administrative action, such as changing the description of a test Microsoft 365 group.
  • Wait for the event to enter the audit system.
  • Run an audit search for that action.
  • Confirm that the record shows who made the change and when.
  • Where an alert rule applies, confirm that an alert was generated, the correct recipients were notified, the message was not quarantined or sent to junk mail, and the alert can be assigned and investigated.
  • Reverse the test change if required.
  • Record the results and any adjustments made.

Ongoing recommendations

  • Investigate critical and high-severity alerts immediately.
  • Review open alerts and risky sign-ins daily.
  • Review administrator activity, forwarding rules and OAuth consent weekly.
  • Review notification recipients and security roles quarterly.
  • Keep at least two emergency-access accounts securely protected.
  • Export incident evidence before its retention period expires.
  • Consider a SIEM or managed security-monitoring service if continuous monitoring, correlation or longer retention is required.
  • Include audit and alert checks in every Microsoft 365 security review.

Important warnings

  • Audit logs do not stop an attack. They provide evidence and support investigation, but alerts require a prompt human response.
  • Events are not always immediate. Some records take hours to become searchable.
  • Enabling auditing is not retrospective. Activity that occurred before auditing was enabled may not be recoverable.
  • Licensing affects visibility. Not all audit events, alert policies, retention periods or investigation functions are available under every Microsoft 365 plan.
  • Alerts may contain sensitive information. Restrict access to authorised personnel.
  • Too many alerts create alert fatigue. Prioritise high-risk activity and tune thresholds carefully.
  • Do not disable default policies without investigation. Doing so may remove important detection coverage.
  • Be cautious with automated remediation. Automatically suspending users or blocking activity can interrupt legitimate operations.
  • Protect the notification mailbox. Apply MFA and ensure more than one authorised person can access it.
  • Audit data has limited retention. Export important evidence promptly and ensure retention satisfies legal, contractual and cyber-insurance requirements.
  • Role changes carry risk. Incorrect permissions may expose sensitive logs or give staff excessive administrative access.

Microsoft 365 disclaimer

These instructions provide general security guidance and may not exactly match every Microsoft 365 subscription, licence or portal interface. Microsoft changes its administration portals and feature availability regularly. Alerting, retention and investigation capabilities depend on the licences assigned to the tenant and individual users.

Before making changes, document the existing configuration, confirm emergency administrator access, verify licensing and test new policies with controlled accounts where practical. Organisations with regulatory, contractual or cyber-insurance obligations should have the configuration reviewed by a qualified Microsoft 365 security professional.

Incorrectly configured permissions, alert thresholds, retention policies or automated response actions may expose sensitive information, generate excessive alerts, interrupt users or result in important events being missed. Netlogyx/Securemyemail accepts no responsibility for service interruption, missed alerts, loss of audit evidence or other consequences arising from changes made without an appropriate technical assessment, backup plan and testing.