Configuring audit log retention

Audit logging keeps track of all sorts of actions that users are taking in your environment across various apps and services. You might find actions included as significant as adding someone to an owner's group with full permission or as small as modifying a document.

Audit logging is not turned on by default, so an administrator will need to turn it on before your organization can benefit from it. The least permissive way of granting this level of authority is to provide the Audit Logs role in Exchange Online (not Security & Compliance). If someone just needs to view/search the logs, they could be assigned the View-Only Audit Logs role. The following screenshot shows a custom admin role group being created ...

Get Microsoft 365 Mobility and Security - Exam Guide MS-101 now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.