MS.DEFENDER.6.1v1 - Microsoft Purview Audit (Standard) logging SHALL be enabled.

Information

Responding to incidents without detailed information about activities that took place slows response actions. Enabling Microsoft Purview Audit (Standard) helps ensure agencies have visibility into user actions. Furthermore, enabling the unified audit log is required for government agencies by OMB M-21-31 (referred to therein by its former name, Unified Audit Logs).

Solution

To enable auditing via the Microsoft Purview compliance portal:

1. Sign in to the Microsoft Purview compliance portal.

2. Under Solutions, select Audit.

3. If auditing is not enabled, a banner is displayed to notify the administrator to start recording user and admin activity.

4. Click the Start recording user and admin activity.

See Also

https://github.com/cisagov/ScubaGear/tree/v1.5.0/

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

References: 800-53|AC-2, 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|CM-5, 800-53|IA-2

Plugin: microsoft_azure

Control ID: 90576a8488eb52691fc8704ccb55e1e22e81475b9e95cb7f2f9839ab7a2bbdff