Another common scenario is to alert an operations team whenever specific activity occurs. An example would include any one of the following:

  • Notifying a user who shared a document externally
  • Blocking unauthorized administrators
  • Blocking a potentially compromised account that is performing a suspicious activity

To do that, administrators can leverage Activity Alerts, which allows them to create rules based on conditions comprised of the following:

  • Activities to be performed by one or more users
  • Users who are under investigation

Whenever a user does anything that trips an alert, an email will be sent to the recipient configured in the alert, notifying them about the flagged activity. From here, the administrator can open the audit ...

Get Microsoft 365 Certified Fundamentals MS-900 Exam Guide now with O’Reilly online learning.

O’Reilly members experience live online training, plus books, videos, and digital content from 200+ publishers.