← Microsoft 365 audit scope

Auditing, Logging & Alerting

9 checks · 2 sub-categories

The Notifiable Data Breaches scheme requires you to assess whether a breach is likely to cause serious harm — which means knowing what an intruder accessed. Without the unified audit log switched on and adequate retention, that question has no answer, and the safe legal assumption becomes 'everything'.

Log collection and retention

  • Unified (Purview) audit log enabled

    The tenant-wide switch that makes forensic investigation possible at all.

    • Privacy Act / NDB — breach assessment
    • CIS 5.2
    • ACSC ISM — event logging
  • Mailbox auditing enabled by default

    Captures owner, delegate and admin mailbox actions including message reads.

    • CIS 5.3
  • Audit log retention period

    Default retention is often shorter than the time it takes to notice a breach. We report your actual retention window against your licensing.

    • ACSC ISM — event log retention
  • Sign-in log retention and export

    Whether sign-in and audit data is exported anywhere durable, or lives only inside the retention window Microsoft gives you.

Alerting

  • Alert on risky sign-in activity

    Impossible-travel and anonymous-IP sign-ins should notify a human within minutes.

    • CIS 5.4
  • Alert on mail forwarding rule creation

    One of the highest-signal breach indicators available in Microsoft 365.

    • CIS 5.8
  • Alert on role and group membership changes

    Privilege escalation shows up here first.

    • CIS 5.7
  • Alert on password reset and MFA method changes

    Attackers register their own MFA method to keep access after the password is changed back.

    • CIS 5.6
  • Alert recipients verified

    We check the alerts actually go to a monitored mailbox — not to an unused address or the departed IT manager.

Want to know where you actually stand?

Every one of these checks is run as part of a single point-in-time audit, delivered as a plain-English, risk-prioritised report.