In this chapter, we reviewed the possibilities for capturing and monitoring audit logs for Microsoft 365 apps and services.
We configured retention by starting data collection as an administrator with at least the Audit Logs role. We then had to enable audit log activity tracking for SharePoint sites and Exchange mailboxes separately.
We learned most of our auditing is enabled by default, and that E3 licenses give us 90 days' logging, and E5 licenses give us 365 days' worth.
We looked at the unified audit log and found that we have lots of flexibility in searching for, and filtering to, specific content across our tenant and that we can create alert policies for specific activities that appear.
We learned that Azure AD also has sign-in activity and audit logs available.
In the next and final chapter before the mock exams and assessment, we'll learn about...