{"id":23199,"date":"2023-10-30T08:37:17","date_gmt":"2023-10-30T16:37:17","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2023\/10\/30\/news-16929\/"},"modified":"2023-10-30T08:37:17","modified_gmt":"2023-10-30T16:37:17","slug":"news-16929","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2023\/10\/30\/news-16929\/","title":{"rendered":"Expanding audit logging and retention within Microsoft Purview for increased security visibility"},"content":{"rendered":"<p><strong>Credit to Author: Rudra Mitra| Date: Wed, 18 Oct 2023 16:00:00 +0000<\/strong><\/p>\n<p>Since our announcement in July 2023, we have made significant efforts to enhance the access to Microsoft Purview&#8217;s audit logging.<sup>1<\/sup> This ongoing work expands accessibility and flexibility to cloud security logs, which began rolling out to customers around the world in September 2023. Our decision to update the scope of log data accessible from Microsoft&#8217;s cloud infrastructure resulted from a close collaboration with both commercial and government customers, as well as ongoing engagement with the Cybersecurity and Infrastructure Security Agency (CISA). It is important to emphasize that log data, while an invaluable resource, is not a preventive measure against cyberattacks. Rather, it plays a pivotal role in incident response by helping uncover auditable insights into the methods by which various entities, such as user identities, applications, and devices, interact with a customer&#8217;s cloud-based services. In addition to that vital work, we have several other updates coming to <a href=\"https:\/\/www.microsoft.com\/security\/business\/risk-management\/microsoft-purview-audit\">Microsoft Purview Audit<\/a> in the coming weeks.<\/p>\n<div class=\"wp-block-msxcm-cta-block\" data-moray data-bi-an=\"CTA Block\">\n<div class=\"card d-block mx-ng mx-md-0\">\n<div class=\"row no-gutters material-color-dark bg-green\">\n<div class=\"d-flex col-md\">\n<div class=\"card-body align-self-center p-4 p-md-5\">\n<h2>Microsoft Purview Audit<\/h2>\n<div class=\"mb-3\">\n<p>Discover new capabilities that will transform how you secure your organization&#039;s data across clouds, devices, and platforms.<\/p>\n<\/p><\/div>\n<div class=\"link-group\"> \t\t\t\t\t\t\t<a href=\"https:\/\/www.microsoft.com\/security\/business\/risk-management\/microsoft-purview-audit\" class=\"btn btn-primary bg-body text-body\" > \t\t\t\t\t\t\t\t<span>Learn more<\/span> \t\t\t\t\t\t\t\t<span class=\"glyph-append glyph-append-chevron-right glyph-append-xsmall\"><\/span> \t\t\t\t\t\t\t<\/a> \t\t\t\t\t\t<\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"col-md-4\"> \t\t\t\t\t<img loading=\"lazy\" width=\"800\" height=\"800\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2023\/05\/Win17_CDOC_1477.jpg\" class=\"card-img img-object-cover\" alt=\"Microsoft Cyber Defense Operations Center.\" decoding=\"async\" srcset=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2023\/05\/Win17_CDOC_1477.jpg 800w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2023\/05\/Win17_CDOC_1477-300x300.jpg 300w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2023\/05\/Win17_CDOC_1477-150x150.jpg 150w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2023\/05\/Win17_CDOC_1477-768x768.jpg 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/>\t\t\t\t<\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<h2 class=\"wp-block-heading\">New default retention period for activity logs<\/h2>\n<p>Starting in October 2023, we began rolling out changes to extend <strong>default retention<\/strong> <strong>to 180 days<\/strong> from 90 for audit logs generated by Audit (Standard) customers. Audit (Premium) license holders will continue with a default of one year, and the option to extend up to 10 years. Our public roadmaps detail when retention changes will reach your organization, starting with <a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-365\/roadmap?filters=&amp;searchterms=171160\">worldwide enterprise customers<\/a> and quickly followed by our <a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-365\/roadmap?filters=&amp;searchterms=171161\">government customers<\/a> in accordance with our standard service rollout process. This update helps all organizations minimize risk by increasing access to historical audit log activity data that is critical when investigating the impact from a security breach incident or accommodating a litigation event.<\/p>\n<h2 class=\"wp-block-heading\">New logs for increased security<\/h2>\n<p>Every day, Microsoft Purview Audit Logs record and retain the thousands of user and admin activities that take place in <a href=\"https:\/\/www.microsoft.com\/microsoft-365\">Microsoft 365<\/a> applications. Authorized administrators can search and access the logs from the <a href=\"https:\/\/compliance.microsoft.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Purview compliance portal<\/a> to determine the scope of a compromise and enhance their investigations. Audit (Standard) license holders will be able to access an additional 30 audit logs, shown in the table below over the next several months. To learn more about when the logs will be available in your tenant, please visit the <a href=\"https:\/\/aka.ms\/AuditEvents\/Roadmap\" target=\"_blank\" rel=\"noreferrer noopener\">Public roadmap<\/a>.<\/p>\n<figure class=\"wp-block-table table\">\n<table>\n<tbody>\n<tr>\n<td><strong><a href=\"https:\/\/aka.ms\/NewAuditLogs\/Exchange\" target=\"_blank\" rel=\"noreferrer noopener\">Exchange<\/a><\/strong><br \/>Send, MailItemsAccessed,<br \/>SearchQueryInitiatedExchange<\/p>\n<p><strong><a href=\"https:\/\/aka.ms\/NewAuditLogs\/SharePoint\" target=\"_blank\" rel=\"noreferrer noopener\">SharePoint Online<\/a><\/strong><br \/>SearchQueryInitiatedSharePoint<br \/><strong><br \/><a href=\"https:\/\/aka.ms\/NewAuditLogs\/Stream\" target=\"_blank\" rel=\"noreferrer noopener\">Stream<\/a><\/strong><br \/>StreamInvokeGetTranscript, streamInvokeChannelView,<br \/>StreamInvokeGetTextTrack, StreamInvokeGetVideo,<br \/>StreamInvokeGroupView<\/td>\n<td><strong><a href=\"https:\/\/aka.ms\/NewAuditLogs\/Teams\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Teams<\/a><\/strong><br \/>MeetingParticipantDetail, MessageSent,<br \/>MessagesListed, MeetingDetail,<br \/>MessageUpdated, ChatRetrieved<br \/>MessageRead, MessageHostedContentRead,<br \/>SubscribedToMessages, MessageHostedContentsListed,<br \/>ChatCreated, ChatUpdated<br \/>MessageCreatedNotification, MessageDeletedNotification,<br \/>MessageUpdatedNotification<br \/><strong><br \/><a href=\"https:\/\/aka.ms\/NewAuditLogs\/VivaEngage\">Microsoft Viva Engage<\/a><\/strong><br \/>ThreadViewed, ThredAccessFailure,<br \/>MessageUpdated, FileAccessFailure,<br \/>MessageCreation, GroupAccessFailure<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p><a href=\"https:\/\/aka.ms\/CISA\/AuditBlog\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft has worked closely with CISA<\/a> to identify these critical logs and include them in our Microsoft Purview Audit (Standard) license. Audit (Premium) license holders will continue to get longer default retention, broader access to export data, higher bandwidth API access, and logs enriched by Microsoft&#8217;s AI-powered intelligent insights.<\/p>\n<h2 class=\"wp-block-heading\">Additional enhancements recently released and coming soon<\/h2>\n<p>In addition to the retention extension and newly available logs, we also have a number of new enhancements in Purview Audit recently released or coming soon, that will help improve your experience:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-365\/roadmap?filters=&amp;searchterms=117587\"><strong>Audit Search Graph API<\/strong><\/a>:<strong> <\/strong>Programmatically access new async Audit Search experience for improved reliability and search completeness, through Microsoft Graph API.&nbsp;<\/li>\n<li><a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-365\/roadmap?filters=&amp;searchterms=98145\"><strong>Granular scoping with role-based access controls<\/strong><\/a>: Delegate role-based permissions to users or analysts in a granular way and access role-based information with Audit search results.<strong>&nbsp;<\/strong>&nbsp;<\/li>\n<li><a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-365\/roadmap?filters=&amp;searchterms=124912\"><strong>Audit Custom Activities Search<\/strong><\/a><strong>: <\/strong>Admins can use the custom search bar to search for several audit log events directly.&nbsp;<\/li>\n<li><a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-365\/roadmap?filters=&amp;searchterms=115501\"><strong>Customized retention policies (short)<\/strong><\/a>:<strong> <\/strong>Customers with the 10-Year Audit Log Retention add-on for Microsoft Purview Audit (Premium) can create additional customized retention policies (7 days, 30 days, three years, five years, and seven years retention).<strong> <\/strong>And customers with the Audit (Premium) SKU will have additional short-term retention policies available (7 days and 30 days).<\/li>\n<li><a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-365\/roadmap?filters=&amp;searchterms=144251\"><strong>Customized retention policies (long)<\/strong><\/a>:<strong> <\/strong>New long-term retention policies for the 10-Year Audit Log Retention add-on for Microsoft Purview Audit (Premium) (three years, five years, and seven years).<\/li>\n<\/ul>\n<p>We are pleased to share today\u2019s cloud logging update as a continuation of the thoughtful conversations we\u2019ve had with our security experts, customers, and influential authorities like CISA. Please visit the <a href=\"https:\/\/aka.ms\/AuditEvents\/Roadmap\">Public roadmap<\/a> to get the latest information on updates coming to Microsoft Purview Audit.\u00a0<\/p>\n<h2 class=\"wp-block-heading\">Learn more<\/h2>\n<p>Learn more about&nbsp;<a href=\"https:\/\/www.microsoft.com\/security\/business\/risk-management\/microsoft-purview-audit\">Microsoft Purview Audit<\/a> or sign up now for a <a href=\"https:\/\/go.microsoft.com\/fwlink\/p\/?LinkID=2225056&amp;clcid=0x409&amp;culture=en-us&amp;country=us\" target=\"_blank\" rel=\"noreferrer noopener\">free trial<\/a>.<\/p>\n<p>To learn more about Microsoft Security solutions, visit our\u202f<a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\" target=\"_blank\" rel=\"noreferrer noopener\">website.<\/a>\u202fBookmark the\u202f<a href=\"https:\/\/www.microsoft.com\/security\/blog\/\" target=\"_blank\" rel=\"noreferrer noopener\">Security blog<\/a>\u202fto keep up with our expert coverage on security matters. Also, follow us on LinkedIn (<a href=\"https:\/\/www.linkedin.com\/showcase\/microsoft-security\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Security<\/a>) and X, formerly known as Twitter, (<a href=\"https:\/\/twitter.com\/@MSFTSecurity\" target=\"_blank\" rel=\"noreferrer noopener\">@MSFTSecurity<\/a>)\u202ffor the latest news and updates on cybersecurity.&nbsp;<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<p><sup>1<\/sup><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2023\/07\/19\/expanding-cloud-logging-to-give-customers-deeper-security-visibility\/\">Expanding cloud logging to give customers deeper security visibility<\/a>, Vasu Jakkal. July 19, 2023.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2023\/10\/18\/expanding-audit-logging-and-retention-within-microsoft-purview-for-increased-security-visibility\/\">Expanding audit logging and retention within Microsoft Purview for increased security visibility<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\">Microsoft Security Blog<\/a>.<\/p>\n<p><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2023\/10\/18\/expanding-audit-logging-and-retention-within-microsoft-purview-for-increased-security-visibility\/\" target=\"bwo\" >https:\/\/blogs.technet.microsoft.com\/mmpc\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Rudra Mitra| Date: Wed, 18 Oct 2023 16:00:00 +0000<\/strong><\/p>\n<p>Since our announcement in July 2023, we have made significant efforts to enhance the access of Microsoft Purview&#8217;s audit logging. This ongoing work expands accessibility and flexibility to cloud security logs. Read about the additional updates coming to Microsoft Purview Audit in the coming weeks. <\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2023\/10\/18\/expanding-audit-logging-and-retention-within-microsoft-purview-for-increased-security-visibility\/\">Expanding audit logging and retention within Microsoft Purview for increased security visibility<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\">Microsoft Security Blog<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10759,10378],"tags":[],"class_list":["post-23199","post","type-post","status-publish","format-standard","hentry","category-microsoft","category-security"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/23199","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=23199"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/23199\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=23199"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=23199"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=23199"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}