Auditing, Logging & Alerting
9 checks · 2 sub-categories
The Notifiable Data Breaches scheme requires you to assess whether a breach is likely to cause serious harm — which means knowing what an intruder accessed. Without the unified audit log switched on and adequate retention, that question has no answer, and the safe legal assumption becomes 'everything'.
Log collection and retention
Unified (Purview) audit log enabled
The tenant-wide switch that makes forensic investigation possible at all.
- Privacy Act / NDB — breach assessment
- CIS 5.2
- ACSC ISM — event logging
Mailbox auditing enabled by default
Captures owner, delegate and admin mailbox actions including message reads.
- CIS 5.3
Audit log retention period
Default retention is often shorter than the time it takes to notice a breach. We report your actual retention window against your licensing.
- ACSC ISM — event log retention
Sign-in log retention and export
Whether sign-in and audit data is exported anywhere durable, or lives only inside the retention window Microsoft gives you.
Alerting
Alert on risky sign-in activity
Impossible-travel and anonymous-IP sign-ins should notify a human within minutes.
- CIS 5.4
Alert on mail forwarding rule creation
One of the highest-signal breach indicators available in Microsoft 365.
- CIS 5.8
Alert on role and group membership changes
Privilege escalation shows up here first.
- CIS 5.7
Alert on password reset and MFA method changes
Attackers register their own MFA method to keep access after the password is changed back.
- CIS 5.6
Alert recipients verified
We check the alerts actually go to a monitored mailbox — not to an unused address or the departed IT manager.
Want to know where you actually stand?
Every one of these checks is run as part of a single point-in-time audit, delivered as a plain-English, risk-prioritised report.