MS.EXO.17.2v1 - Microsoft Purview Audit (Premium) logging SHALL be enabled.

Information

Standard logging may not include relevant details necessary for visibility into user actions during an incident. Enabling Microsoft Purview Audit (Premium) captures additional event types not included with Standard. Furthermore, it is required for government agencies by OMB M-21-31 (referred to therein by its former name, Unified Audit Logs w/Advanced Features).

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

See the following implementation steps for enabling [Microsoft Purview (Premium)](https://github.com/cisagov/ScubaGear/tree/v1.5.0/PowerShell/ScubaGear/baselines/defender.md#msdefender62v1-instructions) for additional guidance.

See Also

https://github.com/cisagov/ScubaGear/tree/v1.5.0/

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

References: 800-53|AC-2, 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|CM-5, 800-53|IA-2

Plugin: microsoft_azure

Control ID: 169aa01966019c57e13e696f870ed4f8daa536fd5548715d603064a5b0ad3784