1
00:00:00,000 --> 00:00:02,820
Most teams use Microsoft 365 every day,

2
00:00:02,820 --> 00:00:04,220
but when something goes wrong,

3
00:00:04,220 --> 00:00:05,900
they can't answer a basic question.

4
00:00:05,900 --> 00:00:07,040
Who opened that file?

5
00:00:07,040 --> 00:00:08,440
Who shared it outside the company?

6
00:00:08,440 --> 00:00:09,620
Who deleted it, changed it,

7
00:00:09,620 --> 00:00:11,560
or changed the rule that was meant to protect it?

8
00:00:11,560 --> 00:00:13,360
I'm Mirko Peters from M365.

9
00:00:13,360 --> 00:00:15,320
FM and this knowledge nugget puts Microsoft

10
00:00:15,320 --> 00:00:16,820
Perview Audit into plain English.

11
00:00:16,820 --> 00:00:18,500
By the end, you'll see what it records,

12
00:00:18,500 --> 00:00:20,180
why compliance teams depend on it,

13
00:00:20,180 --> 00:00:22,200
and where it fits in the wider Perview platform.

14
00:00:22,200 --> 00:00:24,600
Think of Microsoft 365 like an office building.

15
00:00:24,600 --> 00:00:26,700
You've got rooms for email, files, meetings,

16
00:00:26,700 --> 00:00:28,020
chat and administration.

17
00:00:28,020 --> 00:00:29,680
Perview Audit is the security camera

18
00:00:29,680 --> 00:00:31,520
logbook running behind the scenes.

19
00:00:31,520 --> 00:00:33,460
It records who entered what they did

20
00:00:33,460 --> 00:00:35,000
when it happened, where it happened,

21
00:00:35,000 --> 00:00:36,600
and sometimes how they got there.

22
00:00:36,600 --> 00:00:38,080
But here's the key distinction.

23
00:00:38,080 --> 00:00:40,520
It records actions, not the full contents

24
00:00:40,520 --> 00:00:42,200
of every file or message.

25
00:00:42,200 --> 00:00:44,040
That difference matters a lot.

26
00:00:44,040 --> 00:00:45,600
The problem audit solves.

27
00:00:45,600 --> 00:00:47,440
Before cloud services work together,

28
00:00:47,440 --> 00:00:49,360
every system kept its own log.

29
00:00:49,360 --> 00:00:52,240
Email had one set of records, file storage had another,

30
00:00:52,240 --> 00:00:53,760
and meeting tools, devices,

31
00:00:53,760 --> 00:00:55,320
sign-ins and admin portals,

32
00:00:55,320 --> 00:00:56,960
each kept their own history somewhere else.

33
00:00:56,960 --> 00:00:58,160
So when an incident happened,

34
00:00:58,160 --> 00:01:00,400
someone had to pull records from several places

35
00:01:00,400 --> 00:01:02,240
and try to build a timeline by hand.

36
00:01:02,240 --> 00:01:04,280
That takes time, and during an investigation,

37
00:01:04,280 --> 00:01:05,520
time is everything.

38
00:01:05,520 --> 00:01:07,400
Imagine a finance employee shares a file

39
00:01:07,400 --> 00:01:09,360
from one drive with an external address.

40
00:01:09,360 --> 00:01:12,160
A few minutes later, someone changes a mailbox rule.

41
00:01:12,160 --> 00:01:14,600
Then an administrator edits a data protection policy

42
00:01:14,600 --> 00:01:15,440
in Perview.

43
00:01:15,440 --> 00:01:16,680
Maybe none of those actions connect,

44
00:01:16,680 --> 00:01:18,720
or maybe there are three parts of the same problem.

45
00:01:18,720 --> 00:01:21,600
Without a shared activity record, your team has to guess.

46
00:01:21,600 --> 00:01:23,400
That's where Microsoft Perview Audit comes in.

47
00:01:23,400 --> 00:01:26,960
It brings activity from connected Microsoft 365 services

48
00:01:26,960 --> 00:01:29,040
into one searchable audit log.

49
00:01:29,040 --> 00:01:30,440
Instead of opening separate portals

50
00:01:30,440 --> 00:01:31,840
and comparing separate timestamps,

51
00:01:31,840 --> 00:01:34,640
you can start with one question and search from one place.

52
00:01:34,640 --> 00:01:36,280
You might need to know who shared a file

53
00:01:36,280 --> 00:01:39,120
outside the company, or when a mailbox rule changed,

54
00:01:39,120 --> 00:01:41,640
especially if messages suddenly started forwarding

55
00:01:41,640 --> 00:01:43,200
somewhere they shouldn't.

56
00:01:43,200 --> 00:01:45,200
Maybe you need to confirm whether an administrator

57
00:01:45,200 --> 00:01:48,200
changed a sensitivity label, a retention setting,

58
00:01:48,200 --> 00:01:50,600
or a data loss prevention policy.

59
00:01:50,600 --> 00:01:52,400
Or perhaps an employee is leaving,

60
00:01:52,400 --> 00:01:54,800
and HR or security needs to understand

61
00:01:54,800 --> 00:01:57,480
which files that person accessed before their last day.

62
00:01:57,480 --> 00:01:59,600
These questions aren't about blame by default.

63
00:01:59,600 --> 00:02:01,960
Sometimes a person clicks the wrong sharing option,

64
00:02:01,960 --> 00:02:04,720
sometimes an admin changes a setting during normal work,

65
00:02:04,720 --> 00:02:07,760
and sometimes a security alert turns out to be harmless.

66
00:02:07,760 --> 00:02:10,680
Still, you need facts before you can decide what happened.

67
00:02:10,680 --> 00:02:12,760
The unified audit log gives you those facts

68
00:02:12,760 --> 00:02:14,200
as activity records.

69
00:02:14,200 --> 00:02:16,680
An activity record includes the person who took the action,

70
00:02:16,680 --> 00:02:18,880
the time, the Microsoft service involved,

71
00:02:18,880 --> 00:02:22,240
and the item involved like a file mailbox, site, or policy.

72
00:02:22,240 --> 00:02:23,240
Depending on the activity,

73
00:02:23,240 --> 00:02:25,280
it can also include details like an IP address

74
00:02:25,280 --> 00:02:26,720
and other context around the event.

75
00:02:26,720 --> 00:02:29,360
That means you can move from, we think something changed

76
00:02:29,360 --> 00:02:32,040
to this account changed, this setting at this time

77
00:02:32,040 --> 00:02:33,320
from this location.

78
00:02:33,320 --> 00:02:34,920
That's a very different conversation.

79
00:02:34,920 --> 00:02:36,840
Now notice what an audit record does not promise.

80
00:02:36,840 --> 00:02:38,800
It doesn't automatically give you the full contents

81
00:02:38,800 --> 00:02:40,480
of an email, chat, or document.

82
00:02:40,480 --> 00:02:42,880
It tells you that an action happened around that item.

83
00:02:42,880 --> 00:02:44,800
Think of the logbook at a building entrance.

84
00:02:44,800 --> 00:02:47,120
It shows someone entered a room at 10.14,

85
00:02:47,120 --> 00:02:50,360
but it doesn't tell you every word spoken inside the room.

86
00:02:50,360 --> 00:02:53,080
Per view audit also keeps a trail for more than everyday users.

87
00:02:53,080 --> 00:02:55,120
It records actions by administrators

88
00:02:55,120 --> 00:02:57,960
and it records activity around per view settings themselves.

89
00:02:57,960 --> 00:03:00,120
So if someone changes a protection policy,

90
00:03:00,120 --> 00:03:02,080
your investigation can include that change,

91
00:03:02,080 --> 00:03:03,920
not just the activity that followed it.

92
00:03:03,920 --> 00:03:05,760
Compliance depends on this kind of evidence

93
00:03:05,760 --> 00:03:08,280
and auditor, legal team, security team,

94
00:03:08,280 --> 00:03:10,480
or manager can't work from a hunch.

95
00:03:10,480 --> 00:03:12,360
They need to show what happened, when it happened,

96
00:03:12,360 --> 00:03:14,200
and what the organization did next.

97
00:03:14,200 --> 00:03:16,160
Once you see the problem audit solves,

98
00:03:16,160 --> 00:03:17,920
the logbook starts to make much more sense.

99
00:03:17,920 --> 00:03:21,040
Blas, how purview audit works behind the scenes.

100
00:03:21,040 --> 00:03:23,360
Per view audit is a central record of activity

101
00:03:23,360 --> 00:03:26,600
from all the connected Microsoft Cloud services you already use.

102
00:03:26,600 --> 00:03:30,200
It doesn't replace Exchange Online SharePoint OneDrive or Teams,

103
00:03:30,200 --> 00:03:32,440
those still run your email files and chats.

104
00:03:32,440 --> 00:03:34,680
Instead, audits it's behind those services

105
00:03:34,680 --> 00:03:37,760
and records selected actions that those services report.

106
00:03:37,760 --> 00:03:39,440
Let's break down the main building blocks.

107
00:03:39,440 --> 00:03:42,440
Exchange Online can record activity around email and calendars.

108
00:03:42,440 --> 00:03:45,240
That might include mailbox actions, mail flow activity,

109
00:03:45,240 --> 00:03:47,520
or changes that affect how messages are handled.

110
00:03:47,520 --> 00:03:50,320
SharePoint and OneDrive can record actions around files

111
00:03:50,320 --> 00:03:52,640
when someone opens a file, edits it, moves it,

112
00:03:52,640 --> 00:03:54,440
deletes it, syncs it, or shares it.

113
00:03:54,440 --> 00:03:56,200
Those are different actions and they can create

114
00:03:56,200 --> 00:03:57,200
different records.

115
00:03:57,200 --> 00:03:59,400
Teams adds collaboration activity.

116
00:03:59,400 --> 00:04:01,280
Your team might create a workspace,

117
00:04:01,280 --> 00:04:03,400
change membership, work around a meeting,

118
00:04:03,400 --> 00:04:05,680
or interact with files linked from a channel.

119
00:04:05,680 --> 00:04:08,360
The exact events depend on the service and your licensing,

120
00:04:08,360 --> 00:04:09,960
but the point stays the same.

121
00:04:09,960 --> 00:04:11,480
Actions can leave a record.

122
00:04:11,480 --> 00:04:13,760
Enter ID, Microsoft's identity service,

123
00:04:13,760 --> 00:04:16,640
adds, sign in an identity context where it's available.

124
00:04:16,640 --> 00:04:18,400
That helps you connect an action to the account

125
00:04:18,400 --> 00:04:21,520
that's signed in rather than looking at a file event on its own.

126
00:04:21,520 --> 00:04:22,760
Then there is PerView itself.

127
00:04:22,760 --> 00:04:25,240
A policy doesn't protect anybody if someone can quietly

128
00:04:25,240 --> 00:04:26,760
change it without a record.

129
00:04:26,760 --> 00:04:29,360
Audit can track activity around policy changes,

130
00:04:29,360 --> 00:04:32,480
sensitivity labels, data loss prevention rules, retention

131
00:04:32,480 --> 00:04:34,960
settings, and other admin work in PerView.

132
00:04:34,960 --> 00:04:37,000
That link matters because an investigation often

133
00:04:37,000 --> 00:04:39,520
starts with a file or email then turns into a question

134
00:04:39,520 --> 00:04:40,880
about the controls around it.

135
00:04:40,880 --> 00:04:43,480
Imagine a confidential spreadsheet stored in OneDrive.

136
00:04:43,480 --> 00:04:45,040
On Monday morning, an employee shares it

137
00:04:45,040 --> 00:04:46,240
with an external address.

138
00:04:46,240 --> 00:04:49,160
Later that day, the same employee opens the file again.

139
00:04:49,160 --> 00:04:50,680
A manager notices the sharing alert

140
00:04:50,680 --> 00:04:53,440
and asks whether the spreadsheet left the company by mistake.

141
00:04:53,440 --> 00:04:55,480
You wouldn't search for everything in the tenant.

142
00:04:55,480 --> 00:04:57,360
You would start with a narrow question,

143
00:04:57,360 --> 00:04:59,440
which account shared this specific file,

144
00:04:59,440 --> 00:05:00,280
and when.

145
00:05:00,280 --> 00:05:01,760
The audit search can then help you build

146
00:05:01,760 --> 00:05:03,280
a timeline around that question.

147
00:05:03,280 --> 00:05:05,560
You might find the sharing event, the file location,

148
00:05:05,560 --> 00:05:07,920
the account involved, and other nearby actions

149
00:05:07,920 --> 00:05:09,440
that give the event context.

150
00:05:09,440 --> 00:05:11,760
Perhaps the account signed in shortly before the share,

151
00:05:11,760 --> 00:05:13,680
perhaps the file moved from a team site

152
00:05:13,680 --> 00:05:15,840
into a personal OneDrive folder first.

153
00:05:15,840 --> 00:05:17,960
Or perhaps the employee removed the external link

154
00:05:17,960 --> 00:05:19,800
shortly after realizing the mistake.

155
00:05:19,800 --> 00:05:21,080
Those records are breadcrumbs.

156
00:05:21,080 --> 00:05:22,520
They help you follow the path.

157
00:05:22,520 --> 00:05:24,160
They do not decide intent for you.

158
00:05:24,160 --> 00:05:26,080
A person sharing a file externally

159
00:05:26,080 --> 00:05:28,040
could be doing normal work with a supplier.

160
00:05:28,040 --> 00:05:29,280
It could also be an error.

161
00:05:29,280 --> 00:05:32,080
In a more serious case, it might need a deeper investigation.

162
00:05:32,080 --> 00:05:33,720
Audit gives you the activity trail

163
00:05:33,720 --> 00:05:36,000
and your people apply judgment to the facts.

164
00:05:36,000 --> 00:05:38,160
The search screen gives you ways to narrow that trail.

165
00:05:38,160 --> 00:05:39,320
You can set a date range.

166
00:05:39,320 --> 00:05:40,560
You can search for a person.

167
00:05:40,560 --> 00:05:42,440
You can choose an activity such as a file share

168
00:05:42,440 --> 00:05:43,760
or a policy update.

169
00:05:43,760 --> 00:05:46,200
You can filter by service, file, mailbox, sharepoint site,

170
00:05:46,200 --> 00:05:47,480
object, or a keyword.

171
00:05:47,480 --> 00:05:49,480
When that fits the question, you are trying to answer.

172
00:05:49,480 --> 00:05:50,440
Start small.

173
00:05:50,440 --> 00:05:52,560
A search for every event from every user

174
00:05:52,560 --> 00:05:55,920
across a long period can leave you with far too much noise.

175
00:05:55,920 --> 00:05:58,120
A search for one person, one file, and one day

176
00:05:58,120 --> 00:05:59,360
gives you a place to begin.

177
00:05:59,360 --> 00:06:01,480
Give the search a clear name as well.

178
00:06:01,480 --> 00:06:03,840
Finance File External Share 14 May

179
00:06:03,840 --> 00:06:06,160
tells the next investigator what you looked for.

180
00:06:06,160 --> 00:06:08,480
Search seven tells them almost nothing.

181
00:06:08,480 --> 00:06:11,920
If the case returns weeks later, a clear name, a defined scope,

182
00:06:11,920 --> 00:06:14,480
and a recorded reason make it easier to repeat the work

183
00:06:14,480 --> 00:06:16,040
and compare the results.

184
00:06:16,040 --> 00:06:17,960
When the search returns useful records,

185
00:06:17,960 --> 00:06:19,040
you can export them.

186
00:06:19,040 --> 00:06:21,640
That export may go to security for incident work, HR,

187
00:06:21,640 --> 00:06:23,880
for an internal review, legal for a case,

188
00:06:23,880 --> 00:06:25,680
or an outside reviewer who needs evidence

189
00:06:25,680 --> 00:06:28,640
without direct access to your Microsoft 365 tenant.

190
00:06:28,640 --> 00:06:31,880
Keep track of what you exported, who received it, and why.

191
00:06:31,880 --> 00:06:33,480
Audit data can be sensitive because it

192
00:06:33,480 --> 00:06:35,600
describes real actions by real people,

193
00:06:35,600 --> 00:06:38,800
but a long list of audit events still leaves one question open.

194
00:06:38,800 --> 00:06:41,520
You may know that someone opened, shared, or changed something.

195
00:06:41,520 --> 00:06:44,120
How do you find the actual document, email, chat, or compliance

196
00:06:44,120 --> 00:06:45,880
case that belongs with that activity?

197
00:06:45,880 --> 00:06:47,240
Audit finds the actions.

198
00:06:47,240 --> 00:06:49,440
The other purview tools answer different parts

199
00:06:49,440 --> 00:06:52,120
of the investigation.

200
00:06:52,120 --> 00:06:54,080
Where audit fits in the purview building.

201
00:06:54,080 --> 00:06:56,440
Microsoft purview has several tools that sound close enough

202
00:06:56,440 --> 00:06:57,840
to confuse almost anyone.

203
00:06:57,840 --> 00:07:01,800
Audit, compliance manager, e-discovery, content search,

204
00:07:01,800 --> 00:07:04,440
insider risk management, and communication compliance

205
00:07:04,440 --> 00:07:07,000
all deal with data, risk, or investigations.

206
00:07:07,000 --> 00:07:08,200
But they don't do the same job.

207
00:07:08,200 --> 00:07:10,240
Start with audit and compliance manager.

208
00:07:10,240 --> 00:07:12,440
Audit answers what happened.

209
00:07:12,440 --> 00:07:14,760
You search it when you need the history of an action.

210
00:07:14,760 --> 00:07:17,640
A person shared a file, an admin changed a policy,

211
00:07:17,640 --> 00:07:19,160
a mailbox setting changed.

212
00:07:19,160 --> 00:07:20,600
You want the record of that event.

213
00:07:20,600 --> 00:07:23,040
Compliance manager answers a different question.

214
00:07:23,040 --> 00:07:25,160
What controls does our organization need?

215
00:07:25,160 --> 00:07:26,800
And how far along are we?

216
00:07:26,800 --> 00:07:31,280
Think about a company working toward a rule set such as HIPAA, ISO 27001,

217
00:07:31,280 --> 00:07:32,680
or another industry requirement.

218
00:07:32,680 --> 00:07:34,800
Compliance manager helps the team track the controls,

219
00:07:34,800 --> 00:07:37,040
the work still left to do, and the evidence connected

220
00:07:37,040 --> 00:07:37,960
to those controls.

221
00:07:37,960 --> 00:07:39,840
So audit gives you the event history.

222
00:07:39,840 --> 00:07:42,560
Compliance manager gives you the wider compliance work list.

223
00:07:42,560 --> 00:07:45,320
One can support the other, but neither replaces the other.

224
00:07:45,320 --> 00:07:46,800
Then there is e-discovery.

225
00:07:46,800 --> 00:07:49,040
Audit can tell you that somebody opened, shared,

226
00:07:49,040 --> 00:07:50,800
downloaded, or deleted something.

227
00:07:50,800 --> 00:07:53,160
It gives you the timeline and the event details.

228
00:07:53,160 --> 00:07:55,560
E-discovery helps when you need the actual content.

229
00:07:55,560 --> 00:07:58,200
Maybe legal needs to find emails connected to a case.

230
00:07:58,200 --> 00:08:00,400
Maybe HR needs to review team's chats.

231
00:08:00,400 --> 00:08:02,840
Maybe an investigation needs to preserve documents

232
00:08:02,840 --> 00:08:04,960
so they are not removed while the case continues.

233
00:08:04,960 --> 00:08:06,080
That's e-discovery work.

234
00:08:06,080 --> 00:08:09,320
It can find content, place it on hold, bring it into a case,

235
00:08:09,320 --> 00:08:12,000
support review, and export it when the people handling the case

236
00:08:12,000 --> 00:08:12,680
need it.

237
00:08:12,680 --> 00:08:15,120
A simple way to remember the difference is this.

238
00:08:15,120 --> 00:08:17,200
Audit tells you that a person opened a document

239
00:08:17,200 --> 00:08:18,200
at a certain time.

240
00:08:18,200 --> 00:08:20,160
E-discovery helps you find the document itself

241
00:08:20,160 --> 00:08:22,200
and manage it as evidence.

242
00:08:22,200 --> 00:08:23,880
Content search sits close to e-discovery,

243
00:08:23,880 --> 00:08:25,280
but it has a narrower job.

244
00:08:25,280 --> 00:08:27,920
Suppose audit shows that an employee shared a file

245
00:08:27,920 --> 00:08:29,840
or that a message left a mailbox.

246
00:08:29,840 --> 00:08:31,440
You now know an action took place.

247
00:08:31,440 --> 00:08:33,640
Content search helps you locate the actual file

248
00:08:33,640 --> 00:08:36,360
or message by searching the places where that content lives.

249
00:08:36,360 --> 00:08:38,520
You might search a mailbox, a SharePoint site,

250
00:08:38,520 --> 00:08:41,400
or one drive account, or a Microsoft 365 group.

251
00:08:41,400 --> 00:08:43,200
So audit can point you toward the item.

252
00:08:43,200 --> 00:08:45,480
Content search helps you find the item.

253
00:08:45,480 --> 00:08:47,840
For a larger legal HR or regulatory matter,

254
00:08:47,840 --> 00:08:50,080
that search may become part of an e-discovery case

255
00:08:50,080 --> 00:08:52,280
where access, review, preservation, and exports

256
00:08:52,280 --> 00:08:53,680
need tighter control.

257
00:08:53,680 --> 00:08:56,120
Inside a risk management works differently again.

258
00:08:56,120 --> 00:08:58,000
Audit gives you raw activity evidence.

259
00:08:58,000 --> 00:08:59,960
It can show a download, a share, a sign-in,

260
00:08:59,960 --> 00:09:01,400
or another recorded event.

261
00:09:01,400 --> 00:09:03,760
By itself, each event may be normal.

262
00:09:03,760 --> 00:09:05,720
Inside a risk management looks for patterns

263
00:09:05,720 --> 00:09:07,440
that might point to risky behavior.

264
00:09:07,440 --> 00:09:09,520
For example, one download may mean nothing.

265
00:09:09,520 --> 00:09:11,640
A pattern of downloading sensitive files,

266
00:09:11,640 --> 00:09:13,320
moving them to a personal location,

267
00:09:13,320 --> 00:09:14,960
and then sharing them outside the company

268
00:09:14,960 --> 00:09:16,360
deserves a closer look.

269
00:09:16,360 --> 00:09:18,320
Inside a risk management brings signals together

270
00:09:18,320 --> 00:09:19,800
and can raise an alert for reviewers.

271
00:09:19,800 --> 00:09:21,520
It doesn't declare somebody guilty.

272
00:09:21,520 --> 00:09:24,320
It helps the right people notice behavior that needs context,

273
00:09:24,320 --> 00:09:27,320
and audit can help them examine the actions behind that alert.

274
00:09:27,320 --> 00:09:29,880
Communication compliance has an even more focused role.

275
00:09:29,880 --> 00:09:32,320
Audit can record communication-related actions.

276
00:09:32,320 --> 00:09:34,920
It may help show that an activity happened around a mailbox,

277
00:09:34,920 --> 00:09:36,880
chat, or collaboration service.

278
00:09:36,880 --> 00:09:39,080
Communication compliance helps approve reviewers

279
00:09:39,080 --> 00:09:41,760
examine actual messages that were flagged by a policy.

280
00:09:41,760 --> 00:09:43,520
That might involve inappropriate language,

281
00:09:43,520 --> 00:09:45,440
sensitive information, a conflict of interest,

282
00:09:45,440 --> 00:09:46,720
or another defined concern.

283
00:09:46,720 --> 00:09:48,960
Because reviewers can see real conversations,

284
00:09:48,960 --> 00:09:50,600
this process needs strict controls.

285
00:09:50,600 --> 00:09:52,960
Not every admin should see every audit record,

286
00:09:52,960 --> 00:09:55,200
and not every investigator should read every message

287
00:09:55,200 --> 00:09:57,760
or enter every case, give people only the access

288
00:09:57,760 --> 00:09:58,960
they need for their job.

289
00:09:58,960 --> 00:10:01,120
An audit reader can search activity records,

290
00:10:01,120 --> 00:10:02,720
and e-discovery case can limit access

291
00:10:02,720 --> 00:10:04,320
to the people handling that case.

292
00:10:04,320 --> 00:10:06,560
Communication compliance can restrict message review

293
00:10:06,560 --> 00:10:07,800
to trained reviewers.

294
00:10:07,800 --> 00:10:10,880
This protects privacy, reduces unnecessary exposure,

295
00:10:10,880 --> 00:10:13,320
and makes the process fairer for everyone involved.

296
00:10:13,320 --> 00:10:15,120
A typical investigation can move from question

297
00:10:15,120 --> 00:10:17,880
to evidence in a clear order, and alert arrives,

298
00:10:17,880 --> 00:10:19,600
or somebody asks a question.

299
00:10:19,600 --> 00:10:21,480
Audit helps build the activity timeline,

300
00:10:21,480 --> 00:10:23,440
content search, or e-discovery helps locate

301
00:10:23,440 --> 00:10:24,760
and manage the content.

302
00:10:24,760 --> 00:10:26,400
Then the right team reviews the evidence

303
00:10:26,400 --> 00:10:27,840
and decides what responses needed.

304
00:10:27,840 --> 00:10:31,080
Different tools, different jobs, one connected process.

305
00:10:31,080 --> 00:10:33,440
The next decision changes how far back you can search

306
00:10:33,440 --> 00:10:35,600
and how much detail you can retrieve.

307
00:10:35,600 --> 00:10:38,320
Audit standard or audit premium.

308
00:10:38,320 --> 00:10:40,840
Audit standard and audit premium simply explained.

309
00:10:40,840 --> 00:10:42,120
So which version do you need?

310
00:10:42,120 --> 00:10:43,120
Let's break it down.

311
00:10:43,120 --> 00:10:45,400
The choice really comes down to whether you need

312
00:10:45,400 --> 00:10:48,120
a basic activity history or a deeper record

313
00:10:48,120 --> 00:10:50,160
for longer, more detailed investigations.

314
00:10:50,160 --> 00:10:52,200
Audit standard is where most organizations start.

315
00:10:52,200 --> 00:10:54,480
It comes with many Microsoft 365 plans

316
00:10:54,480 --> 00:10:56,560
and gives you the everyday records most teams need

317
00:10:56,560 --> 00:10:58,880
when they're trying to answer a focused question.

318
00:10:58,880 --> 00:11:01,280
You can search for sign-ins, file actions,

319
00:11:01,280 --> 00:11:03,400
sharing activity, and admin changes

320
00:11:03,400 --> 00:11:05,120
across the services you use.

321
00:11:05,120 --> 00:11:07,120
When a manager asks whether a project document

322
00:11:07,120 --> 00:11:09,000
was shared outside the company yesterday,

323
00:11:09,000 --> 00:11:11,040
that's a normal audit standard question.

324
00:11:11,040 --> 00:11:13,240
You know the likely user, the file, and the time period.

325
00:11:13,240 --> 00:11:15,880
So you run a focused search, check the activity record,

326
00:11:15,880 --> 00:11:17,720
and decide whether more work is needed.

327
00:11:17,720 --> 00:11:20,120
For many organizations that covers a lot of ground.

328
00:11:20,120 --> 00:11:22,480
By default, audit standard keeps many audit records

329
00:11:22,480 --> 00:11:24,240
for up to 180 days.

330
00:11:24,240 --> 00:11:26,840
Six months is enough when your team spots problems quickly,

331
00:11:26,840 --> 00:11:28,600
investigates them within a reasonable time

332
00:11:28,600 --> 00:11:31,400
and doesn't have a rule that requires a much longer history.

333
00:11:31,400 --> 00:11:33,280
But some questions arrive much later.

334
00:11:33,280 --> 00:11:36,160
A legal team may begin reviewing a matter that started last year.

335
00:11:36,160 --> 00:11:37,960
A security team may discover that an account

336
00:11:37,960 --> 00:11:40,680
has been misused for months or a regulated business

337
00:11:40,680 --> 00:11:43,200
may need to keep records for years because a rule requires it.

338
00:11:43,200 --> 00:11:44,920
That's where audit premium comes in.

339
00:11:44,920 --> 00:11:50,080
To get audit premium, you need Microsoft 365 E5, E5 compliance,

340
00:11:50,080 --> 00:11:53,200
or a suitable add-on depending on your licensing setup.

341
00:11:53,200 --> 00:11:55,200
It includes the standard capabilities,

342
00:11:55,200 --> 00:11:57,600
then adds a longer lookback period and more detail

343
00:11:57,600 --> 00:11:59,120
for certain investigations.

344
00:11:59,120 --> 00:12:02,120
Premium keeps eligible audit records for one year by default.

345
00:12:02,120 --> 00:12:04,520
It also allows custom audit retention policies,

346
00:12:04,520 --> 00:12:07,600
which can keep selected records for up to 10 years

347
00:12:07,600 --> 00:12:09,240
when the right licensing is in place.

348
00:12:09,240 --> 00:12:10,960
You don't have to treat every user

349
00:12:10,960 --> 00:12:12,720
and every activity the same way.

350
00:12:12,720 --> 00:12:14,520
A finance team may need longer records

351
00:12:14,520 --> 00:12:15,800
than a general project team.

352
00:12:15,800 --> 00:12:17,800
Prove-ledged administrators may need longer records

353
00:12:17,800 --> 00:12:18,840
than ordinary users.

354
00:12:18,840 --> 00:12:21,480
A mailbox access event may matter more to your organization

355
00:12:21,480 --> 00:12:23,120
than a routine file edit.

356
00:12:23,120 --> 00:12:26,400
Premium lets you shape retention around those real needs

357
00:12:26,400 --> 00:12:29,120
rather than applying one broad rule to everything.

358
00:12:29,120 --> 00:12:32,000
It also provides more event detail, intelligent insights,

359
00:12:32,000 --> 00:12:34,160
and higher bandwidth API access.

360
00:12:34,160 --> 00:12:36,000
In plain English, you get richer information

361
00:12:36,000 --> 00:12:37,480
for more complex investigations

362
00:12:37,480 --> 00:12:39,720
and larger organizations can move audit data

363
00:12:39,720 --> 00:12:42,000
into their own security tools more efficiently.

364
00:12:42,000 --> 00:12:43,400
Picture two situations.

365
00:12:43,400 --> 00:12:45,560
In the first, someone asked whether a file was shared

366
00:12:45,560 --> 00:12:47,000
externally this morning.

367
00:12:47,000 --> 00:12:49,160
Audit standard may give you everything you need.

368
00:12:49,160 --> 00:12:51,160
In the second, an organization needs to rebuild

369
00:12:51,160 --> 00:12:53,480
a long-running security or legal case.

370
00:12:53,480 --> 00:12:55,400
It may need a year or more of activity,

371
00:12:55,400 --> 00:12:56,880
deeper mailbox records,

372
00:12:56,880 --> 00:12:58,920
and a way to send large volumes of audit data

373
00:12:58,920 --> 00:13:00,080
to a security platform.

374
00:13:00,080 --> 00:13:02,280
That's the type of work audit premium is built for,

375
00:13:02,280 --> 00:13:04,600
but don't fall into one common licensing trap.

376
00:13:04,600 --> 00:13:06,600
Longer retention only keeps records from the point

377
00:13:06,600 --> 00:13:09,160
where the service began recording them under the right setup.

378
00:13:09,160 --> 00:13:11,240
It cannot go back in time and create events

379
00:13:11,240 --> 00:13:12,280
that were never kept.

380
00:13:12,280 --> 00:13:14,360
So if you decide in June that you need five years

381
00:13:14,360 --> 00:13:16,920
of audit history, you can't recover four missing years

382
00:13:16,920 --> 00:13:17,760
from the past.

383
00:13:17,760 --> 00:13:20,400
Your retention plan needs to exist before the incident.

384
00:13:20,400 --> 00:13:21,840
Start with your business needs.

385
00:13:21,840 --> 00:13:23,880
Ask which users create the most risk

386
00:13:23,880 --> 00:13:25,440
if their accounts are misused.

387
00:13:25,440 --> 00:13:27,960
Ask which workloads hold sensitive information.

388
00:13:27,960 --> 00:13:29,240
Then check the rules that apply

389
00:13:29,240 --> 00:13:31,880
to your industry, contracts, and internal policies.

390
00:13:31,880 --> 00:13:34,120
Keep records longer where there is a clear reason.

391
00:13:34,120 --> 00:13:35,840
Even the best audit record fails

392
00:13:35,840 --> 00:13:38,440
if nobody can search it safely, understand it,

393
00:13:38,440 --> 00:13:40,120
or act on what they find.

394
00:13:40,120 --> 00:13:42,160
Starts more, then build a process

395
00:13:42,160 --> 00:13:45,080
your people can follow when the pressure is on.

396
00:13:45,080 --> 00:13:47,960
A simple audit plan for your organization.

397
00:13:47,960 --> 00:13:50,800
A useful audit plan starts before anyone reports a problem.

398
00:13:50,800 --> 00:13:52,600
First, make sure audit is enabled,

399
00:13:52,600 --> 00:13:55,040
then confirm that records are actually arriving.

400
00:13:55,040 --> 00:13:56,280
Don't assume a setting exists

401
00:13:56,280 --> 00:13:58,280
because someone turned it on years ago.

402
00:13:58,280 --> 00:14:01,320
Run a simple search and check that recent activity appears.

403
00:14:01,320 --> 00:14:04,160
That small check can save a difficult conversation later.

404
00:14:04,160 --> 00:14:05,880
Next, separate the jobs.

405
00:14:05,880 --> 00:14:08,600
An audit reader searches records and reviews the results.

406
00:14:08,600 --> 00:14:11,520
An audit manager handles the settings, retention policies,

407
00:14:11,520 --> 00:14:13,400
and the wider care of the audit service.

408
00:14:13,400 --> 00:14:15,800
Those roles don't need to sit with the same person.

409
00:14:15,800 --> 00:14:18,520
In fact, separating them often gives you better control.

410
00:14:18,520 --> 00:14:19,960
The person who searches a record

411
00:14:19,960 --> 00:14:21,640
doesn't always need the power to change

412
00:14:21,640 --> 00:14:23,800
how long that record stays in the system.

413
00:14:23,800 --> 00:14:26,080
Sensitive cases need another boundary.

414
00:14:26,080 --> 00:14:27,920
E-discovery case access should stay separate

415
00:14:27,920 --> 00:14:29,240
from general audit access.

416
00:14:29,240 --> 00:14:31,720
A person may need to confirm that a file was shared

417
00:14:31,720 --> 00:14:33,680
without needing permission to open a legal case

418
00:14:33,680 --> 00:14:35,160
or review private documents.

419
00:14:35,160 --> 00:14:38,240
Give people the access their work requires and no more.

420
00:14:38,240 --> 00:14:40,960
Then write down the questions your organization needs to answer.

421
00:14:40,960 --> 00:14:41,840
Keep the list practical.

422
00:14:41,840 --> 00:14:44,040
Can we see who shared or accessed a file?

423
00:14:44,040 --> 00:14:46,200
Can we investigate mailbox and sign in activity

424
00:14:46,200 --> 00:14:47,720
when an account looks unusual?

425
00:14:47,720 --> 00:14:49,360
Can we confirm who changed a policy?

426
00:14:49,360 --> 00:14:51,040
Can we trace a data loss prevention event

427
00:14:51,040 --> 00:14:52,520
back to the action that triggered it?

428
00:14:52,520 --> 00:14:54,400
These questions give your team a starting point

429
00:14:54,400 --> 00:14:56,880
when they build searches, choose retention periods

430
00:14:56,880 --> 00:14:58,200
and write incident plans.

431
00:14:58,200 --> 00:15:00,240
Without them, audit can turn into a large tool

432
00:15:00,240 --> 00:15:01,960
that nobody feels confident using.

433
00:15:01,960 --> 00:15:03,840
Retention needs the same clear thinking.

434
00:15:03,840 --> 00:15:06,120
Don't keep everything forever just because you can.

435
00:15:06,120 --> 00:15:08,560
More records can also mean more sensitive data

436
00:15:08,560 --> 00:15:10,760
for your organization to protect and manage.

437
00:15:10,760 --> 00:15:13,160
Look at your legal duties, contracts, industry rules

438
00:15:13,160 --> 00:15:14,480
and internal policies.

439
00:15:14,480 --> 00:15:17,600
Then decide what you need to keep for how long and why.

440
00:15:17,600 --> 00:15:20,480
Start with the areas where a missing record would hurt most.

441
00:15:20,480 --> 00:15:22,640
Finance may handle payment details and forecasts.

442
00:15:22,640 --> 00:15:24,760
HR may handle employee information.

443
00:15:24,760 --> 00:15:27,400
Administrators can change settings that affect the whole company.

444
00:15:27,400 --> 00:15:30,760
Those teams and workloads give you a focused place to begin.

445
00:15:30,760 --> 00:15:32,280
You can expand later when you understand

446
00:15:32,280 --> 00:15:33,320
what your organization needs.

447
00:15:33,320 --> 00:15:35,480
Now test the process before it becomes urgent.

448
00:15:35,480 --> 00:15:37,360
Set up a safe practice investigation.

449
00:15:37,360 --> 00:15:38,840
Have someone share a test file.

450
00:15:38,840 --> 00:15:40,280
Change a test mailbox rule.

451
00:15:40,280 --> 00:15:42,480
Download a test document from a controlled location.

452
00:15:42,480 --> 00:15:43,800
Edit a test policy.

453
00:15:43,800 --> 00:15:45,840
Then ask your team to find the action in audit.

454
00:15:45,840 --> 00:15:47,400
This isn't about catching anyone out.

455
00:15:47,400 --> 00:15:50,080
It's about finding gaps while there is no real incident.

456
00:15:50,080 --> 00:15:51,520
Maybe the search is too broad.

457
00:15:51,520 --> 00:15:52,840
Maybe the wrong people have access.

458
00:15:52,840 --> 00:15:54,680
Maybe the team can find the event,

459
00:15:54,680 --> 00:15:56,280
but doesn't know what to do next.

460
00:15:56,280 --> 00:15:58,960
And boom, you found something useful before it costs you.

461
00:15:58,960 --> 00:16:00,240
For every real investigation,

462
00:16:00,240 --> 00:16:01,920
keep a simple record of the work.

463
00:16:01,920 --> 00:16:03,000
Write the search name.

464
00:16:03,000 --> 00:16:04,720
Record the scope, the reason for the search

465
00:16:04,720 --> 00:16:06,040
and the person responsible.

466
00:16:06,040 --> 00:16:08,480
If you export results, note what was exported,

467
00:16:08,480 --> 00:16:10,400
who received it and where it is stored.

468
00:16:10,400 --> 00:16:13,200
That record helps the next person understand the case.

469
00:16:13,200 --> 00:16:14,840
It also helps your organization show

470
00:16:14,840 --> 00:16:17,200
that it handled sensitive information carefully.

471
00:16:17,200 --> 00:16:18,640
Audit rarely works alone.

472
00:16:18,640 --> 00:16:21,640
A security alert in Defender may lead your team to an audit search,

473
00:16:21,640 --> 00:16:24,360
and inside a risk case may need audit events to add context.

474
00:16:24,360 --> 00:16:26,440
Any discovery case may need the content connected

475
00:16:26,440 --> 00:16:28,280
to an action you found in audit.

476
00:16:28,280 --> 00:16:30,120
Build those handoffs into your process early.

477
00:16:30,120 --> 00:16:31,640
Decide who owns the first review

478
00:16:31,640 --> 00:16:33,440
when a case moves to another team

479
00:16:33,440 --> 00:16:35,160
and who can approve the next step.

480
00:16:35,160 --> 00:16:37,520
The common mistake is waiting until something goes wrong.

481
00:16:37,520 --> 00:16:39,240
At that point, people are under pressure.

482
00:16:39,240 --> 00:16:40,440
Names and dates aren't clear,

483
00:16:40,440 --> 00:16:42,400
and everyone wants answers immediately.

484
00:16:42,400 --> 00:16:44,160
A tested process changes that.

485
00:16:44,160 --> 00:16:45,680
Your team can begin with a known search,

486
00:16:45,680 --> 00:16:48,400
a known owner and a timeline that is already there.

487
00:16:48,400 --> 00:16:50,280
Perview audit can't decide whether an action

488
00:16:50,280 --> 00:16:52,320
was harmless, accidental or deliberate.

489
00:16:52,320 --> 00:16:53,880
Your people still need to make that call.

490
00:16:53,880 --> 00:16:56,160
It gives them a record to work from.

491
00:16:56,160 --> 00:16:58,360
Perview audit takes all the scattered activity

492
00:16:58,360 --> 00:17:01,880
across Microsoft 365 and turns it into a searchable log,

493
00:17:01,880 --> 00:17:04,080
so you can see who did what and when.

494
00:17:04,080 --> 00:17:05,880
First, check if audit is enabled,

495
00:17:05,880 --> 00:17:08,560
then run a focused search for a file, a user,

496
00:17:08,560 --> 00:17:10,240
or a policy action you already know.

497
00:17:10,240 --> 00:17:11,600
You're not looking for a crisis.

498
00:17:11,600 --> 00:17:13,520
You're just confirming the record exists.

499
00:17:13,520 --> 00:17:16,360
Next, figure out where audit fits with eDiscovery,

500
00:17:16,360 --> 00:17:18,640
compliance manager and insider risk.

501
00:17:18,640 --> 00:17:19,840
When a question comes in,

502
00:17:19,840 --> 00:17:21,560
every team should know exactly where to start

503
00:17:21,560 --> 00:17:22,720
and where to go next.

504
00:17:22,720 --> 00:17:24,840
I'm Mirko Peters from M365 FM.

505
00:17:24,840 --> 00:17:26,680
Subscribe on your favorite podcast platform

506
00:17:26,680 --> 00:17:27,720
and share this knowledge nugget

507
00:17:27,720 --> 00:17:31,040
with someone building their Microsoft 365 Compliance Foundation.

