MS.EXO.17.1v1 - Microsoft Purview Audit (Standard) logging SHALL be enabled.

Information

Responding to incidents without detailed information about activities that took place slows response actions. Enabling Microsoft Purview Audit (Standard) helps ensure agencies have visibility into user actions. Furthermore, Microsoft Purview Audit (Standard) is required for government agencies by OMB M-21-31 (referred to therein by its former name, Unified Audit Logs).

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

See the following implementation steps for enabling [Microsoft Purview (Standard)](https://github.com/cisagov/ScubaGear/tree/v1.5.0/PowerShell/ScubaGear/baselines/defender.md#msdefender61v1-instructions) for additional guidance.

See Also

https://github.com/cisagov/ScubaGear/tree/v1.5.0/

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

References: 800-53|AC-2, 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|CM-5, 800-53|IA-2

Plugin: microsoft_azure

Control ID: 9804a05e2fa746e3ab8fe56bcaa5ce89b28e7bdfaaffd7e30d259d131ec13399