Query Microsoft Purview Audit in Defender XDR (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage and monitor security posture (20–25%)
   --> Implement activity and event collection in Microsoft Sentinel
      --> Query Microsoft Purview Audit in Defender XDR


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Security investigations often require more than security alerts and endpoint telemetry. Investigators also need to know what users and administrators actually did across Microsoft 365 and Microsoft security services.

For example:

  • Who changed a Microsoft Defender security setting?
  • Who created or modified a custom detection rule?
  • Who isolated a device?
  • Who changed a data-retention setting?
  • Who modified security roles?
  • Who assigned a user to an incident?
  • What actions were performed by an administrator before or during a security incident?

Microsoft Purview Audit provides the auditing infrastructure used to record supported user and administrator activities across Microsoft 365. Microsoft Defender XDR uses this auditing capability, and the audit records can be searched from the Microsoft Defender portal.

For the SC-500 exam, the important skill is understanding how to query the Microsoft Purview unified audit log from Microsoft Defender XDR, what information can be searched, what permissions are required, and how audit-log retention affects an investigation.


1. What Is Microsoft Purview Audit?

Microsoft Purview Audit records supported user and administrator activities throughout the Microsoft 365 environment.

The resulting audit records can be used for:

  • Security investigations
  • Forensic investigations
  • Compliance investigations
  • IT investigations
  • Legal investigations
  • Insider-risk investigations
  • Tracking administrative changes

Microsoft describes Audit (Standard) as a solution for logging and searching audited activities across Microsoft services. It includes thousands of searchable audit events.

A useful conceptual model is:

Users / Administrators
|
v
Audited activities
|
v
Microsoft Purview Unified Audit Log
|
+-----------------------+
| |
v v
Microsoft Defender XDR Microsoft Purview
| |
+-----------+-----------+
|
v
Investigation

The important point is that the audit information is not simply a Defender-specific log.

Microsoft Defender XDR uses Microsoft Purview auditing.


2. Why Query the Audit Log During a Security Investigation?

Security telemetry can tell you that something happened.

The audit log can help answer:

Who performed the action, what action occurred, and when did it occur?

Consider an investigation into a compromised security administrator account.

An investigator might discover that:

  1. The account signed in.
  2. A Defender security configuration was changed.
  3. A device was isolated.
  4. A security role was modified.
  5. A custom detection rule was created.

Security alerts alone might not provide the complete administrative activity trail.

The audit log can provide evidence of supported administrative and user activities.

Microsoft specifically identifies Defender activities such as changes to data-retention settings, changes to advanced features, creation of indicators of compromise, device isolation, security-role changes, custom detection-rule changes, and incident assignments as audited activities.


3. Microsoft Defender XDR and the Unified Audit Log

Microsoft Defender XDR activities are integrated with the Microsoft Purview auditing solution.

This means that an investigator can use the Audit page in the Microsoft Defender portal to search for supported activities.

Microsoft states that the Defender portal audit search is identical to the audit-log search experience available through Microsoft Purview.

Conceptually:

Microsoft Defender XDR
|
| audited activity
v
Microsoft Purview auditing
|
v
Unified Audit Log
|
v
Defender portal → Audit

This is particularly useful because security personnel can investigate Defender activity without having to switch to an entirely separate audit system.


4. What Can You Search For?

The audit search allows investigators to filter activities using several criteria.

Important search criteria include:

  • Date and time range
  • Activities
  • Users

The available activities depend on the services and workloads being audited.

Microsoft Defender XDR audit records can include activities associated with Microsoft Defender XDR and Microsoft Defender for Endpoint.

Examples include:

Activity typeExample investigation question
Data-retention changesWho changed a retention setting?
Advanced-feature changesWho changed a Defender configuration?
Indicator changesWho created an indicator of compromise?
Device isolationWho isolated a device?
Security-role changesWho added, edited, or removed a security role?
Custom detectionsWho created or modified a custom detection rule?
Incident assignmentWho assigned a user to an incident?

These examples illustrate an important distinction:

The audit log records administrative and user actions, not simply security alerts.


5. Accessing Audit Search in Microsoft Defender

The current Microsoft Defender portal provides an Audit page for searching audit records.

The general process is:

  1. Sign in to the Microsoft Defender portal.
  2. Open Audit.
  3. Configure the search criteria.
  4. Select Search.
  5. Review the returned audit records.
  6. Export results if required.

Microsoft documents the Defender portal Audit page as the starting point for audit-log searches.

The same audit-search capability can also be accessed from Microsoft Purview.


6. Search Criteria

A typical audit search begins by narrowing the investigation.

Date and Time

Specify the period in which the activity occurred.

For example:

Start: September 20, 2026 00:00 UTC
End: September 25, 2026 23:59 UTC

Be careful with time zones.

Microsoft’s audit search uses a date/time range, and audit activities are represented using UTC-based timing.

Exam Tip

If an exam question asks you to investigate activity during a specific period, date/time is one of the primary search filters.


Activities

The Activities filter lets you search for specific audited operations.

For example, an investigator could search for a Defender activity involving:

  • Device isolation
  • Security-role changes
  • Custom detection rules
  • Indicators
  • Retention settings

The exact activity names available depend on the workload and audit records being searched.


Users

The Users filter allows an investigator to narrow results to activities performed by particular users.

For example:

“Determine whether the compromised administrator account changed any Defender settings during the incident.”

The investigator can specify that account in the Users filter.

Leaving the Users field empty allows the search to include activities from all users within the search scope.


7. Example Investigation

Suppose a security team discovers that a critical endpoint was isolated unexpectedly.

The team wants to determine:

Who initiated the isolation and when?

A reasonable audit investigation would be:

Audit
|
+-- Date/time
| |
| +-- Incident timeframe
|
+-- Activity
| |
| +-- Device isolation-related activity
|
+-- User
|
+-- Leave blank initially

The investigator reviews the resulting audit records to determine which account performed the action.

If a particular account is identified, a second search can narrow the investigation to that user and the surrounding time period.

This illustrates an important investigation technique:

Start broad enough to discover the activity, then narrow the search as evidence identifies relevant users, activities, or time periods.


8. Audit Records vs. Microsoft Sentinel Logs

This distinction is important for SC-500.

Microsoft Purview Audit is not simply another Microsoft Sentinel table.

The audit log is a Microsoft 365 auditing system.

Microsoft Sentinel can collect and analyze many different data sources, while Microsoft Purview Audit provides auditing of supported Microsoft 365 activities.

Therefore:

Microsoft Purview AuditMicrosoft Sentinel
Focuses on audited user/admin activitiesSecurity information and event management
Unified Microsoft 365 audit logCentralized security data platform
Search through AuditQuery using KQL and Sentinel capabilities
Used heavily for compliance and administrative investigationsUsed for detection, investigation, hunting, and response
Records supported audited activitiesCollects many security and operational data sources

The two systems can complement one another.

For example:

Defender alert
|
v
Sentinel investigation
|
+---- Endpoint telemetry
|
+---- Identity logs
|
+---- Microsoft 365 activity
|
v
Purview Audit
|
v
Administrative action

An investigator may use both security telemetry and audit records to reconstruct an incident.


9. Microsoft Defender XDR Audit vs. Defender Alerts

Another important distinction is:

Alert

An alert generally indicates that a security-related condition or detection occurred.

Audit record

An audit record documents a supported user or administrator activity.

For example:

Alert:

Suspicious activity detected on a device.

Audit record:

Administrator isolated the device.

These are different types of information.

During an investigation, both can be valuable.


10. Required Permissions

Access to the audit log is controlled through permissions.

Microsoft currently documents that users need the Audit Logs or View-Only Audit Logs permissions/roles to search audit records. In the Defender/XDR context, these permissions are associated with Exchange Online role groups such as Compliance Management and Organization Management by default.

Microsoft also emphasizes least privilege.

A Global Administrator can have the necessary access, but Microsoft recommends using lower-privilege roles when they are sufficient.

Exam Tip

If a question asks:

“What permissions are required to search the audit log?”

Think:

Audit Logs or View-Only Audit Logs.

Do not automatically choose Global Administrator simply because that role can perform the task.


11. Audit Logs vs. View-Only Audit Logs

These permissions provide access to audit information.

The principle is:

Give investigators the minimum permissions required to perform their responsibilities.

For an investigator who only needs to search and review audit records, a read-oriented audit role is preferable to granting broad administrative permissions.

This aligns with the principle of least privilege emphasized throughout Microsoft security solutions.


12. Audit Must Be Available

Before investigating audit activity, auditing must be available for the organization.

Microsoft Defender XDR uses Microsoft Purview auditing, and Microsoft states that auditing needs to be turned on in Microsoft Purview before audit data can be viewed in the Defender portal.

This creates an important troubleshooting sequence:

Can't find audit records?
|
+--> Is auditing enabled?
|
+--> Does the user have audit permissions?
|
+--> Is the activity actually audited?
|
+--> Is the activity within the retention period?
|
+--> Are the search filters correct?

A missing audit record does not automatically mean the activity never occurred.

The activity may:

  • Not be audited
  • Fall outside the retention period
  • Require different search criteria
  • Belong to a different workload
  • Have been performed outside the period being searched

13. Audit Retention

Retention is especially important when investigating historical incidents.

The default Audit (Standard) retention period is currently 180 days for audit logs generated on or after October 17, 2023. Older Audit (Standard) records generated before that date followed the previous 90-day default.

Therefore, an investigator should not assume that an audit record from several years ago is automatically available.

Audit retention depends on the organization’s Microsoft Purview audit configuration and licensing.


14. Audit (Premium) and Longer Retention

Microsoft Purview Audit (Premium) provides additional audit capabilities, including configurable audit-log retention policies.

Audit retention policies can retain audit records for:

  • More than the standard retention period
  • Up to one year for appropriately licensed users
  • Up to 10 years when the required licensing and 10-year audit retention add-on are in place

Microsoft currently documents support for audit-log retention policies of up to 10 years.

Important Licensing Concept

Longer retention is not simply a matter of changing a setting.

Microsoft documents licensing requirements for longer retention. For example, retaining audit logs beyond 180 days and up to one year requires appropriate E5-level licensing for the users whose activities generate the audit records; 10-year retention requires an additional 10-year audit-log retention license.

Exam Tip

When a question combines:

  • Long-term audit retention
  • Compliance
  • Microsoft Purview Audit

look for Audit retention policies and the appropriate licensing, rather than assuming Microsoft Sentinel table retention controls the audit records.


15. Audit Retention Policies

Microsoft Purview Audit (Premium) supports audit log retention policies.

Policies can specify how long audit records should be retained.

They can be configured according to criteria such as the audited workload, record type, and other supported conditions.

An organization can have up to 50 audit-log retention policies.

The important exam concept is:

Microsoft Purview Audit retention is managed through Purview audit-retention capabilities, not through Microsoft Sentinel table-retention settings.


16. Searching With PowerShell

The audit log can also be queried programmatically.

Microsoft provides the Search-UnifiedAuditLog PowerShell cmdlet for searching audit events.

This can be useful when:

  • Searches need to be automated
  • Investigators need repeatable queries
  • Results need to be processed programmatically
  • An investigation involves many searches
  • Security teams want to integrate audit searching into operational workflows

The portal and PowerShell access the same underlying audit-log capability.


17. Microsoft Graph Audit Search API

Microsoft also provides the Audit Search Graph API.

This allows applications to programmatically access audit-search data through Microsoft Graph.

This is useful for organizations building:

  • Automated investigations
  • Compliance workflows
  • Security dashboards
  • Custom reporting
  • Integration with security operations tooling

For the SC-500 exam, recognize the relationship:

Audit Search
|
+---- Defender portal
|
+---- Purview portal
|
+---- PowerShell
|
+---- Microsoft Graph Audit Search API

18. Exporting Audit Results

Audit-search results can be exported.

The Microsoft Purview audit search experience supports exporting results to a CSV file.

The exported data includes an AuditData column containing additional event information formatted as JSON.

That JSON can be transformed in tools such as Excel’s Power Query Editor to make individual properties easier to analyze.

This can be useful for:

  • Compliance reports
  • Investigation evidence
  • Sorting and filtering
  • Offline analysis
  • Sharing investigation results with authorized personnel

19. Understanding the AuditData Property

An audit record contains multiple properties describing the event.

When audit results are exported, the AuditData field contains additional event information as JSON.

For example, an exported record can conceptually look like:

CreationTime
UserId
Operation
Workload
RecordType
AuditData

The AuditData field may contain additional properties that provide more context about the operation.

This is particularly useful when the standard columns do not provide all the information required for an investigation.


20. Investigating Microsoft Defender XDR Activities

Microsoft Defender XDR provides a specific collection of audited activities.

Examples include:

Data-retention changes

An investigator can determine whether an administrator changed a security data-retention setting.

Device isolation

An investigator can investigate which user or administrator performed an isolation action.

Security-role changes

An investigator can determine whether security permissions or roles were changed.

Custom detection changes

An investigator can determine who created or modified custom detection rules.

Incident assignments

An investigator can determine who assigned a user to an incident.

These activities can provide important evidence during an investigation into unauthorized administrative behavior.


21. Example: Investigating an Unauthorized Defender Change

Suppose a security team discovers that an organization’s Defender configuration changed unexpectedly.

The investigation could proceed as follows:

Step 1 — Identify the approximate timeframe

Determine when the configuration change was discovered.

Step 2 — Search the Audit page

Open the Audit page in Microsoft Defender.

Step 3 — Filter by activity

Select the relevant Defender activity.

Step 4 — Review users

Identify which account performed the activity.

Step 5 — Correlate with other telemetry

Compare the audit event with:

  • Sign-in activity
  • Device activity
  • Security alerts
  • Incident timelines
  • Other administrative changes

Step 6 — Export if required

Export the results for additional investigation or reporting.

This provides a more complete picture than examining a security alert alone.


22. Audit Log Search Is Not the Same as KQL

A common SC-500 exam trap is assuming that every Microsoft security data source is queried with KQL.

Microsoft Purview Audit provides its own search experience.

The standard Audit search uses filters such as:

  • Date/time
  • Activities
  • Users

It can also be accessed programmatically through PowerShell and Microsoft Graph.

By contrast, Microsoft Sentinel uses KQL extensively for querying data stored in its Log Analytics environment.

Therefore:

TaskPrimary mechanism
Search Microsoft Purview audit activitiesAudit search
Search Defender audit activityDefender Audit
Programmatically search unified audit logSearch-UnifiedAuditLog / Graph API
Query Sentinel log tablesKQL
Build Sentinel analytics rulesKQL-based queries

23. Common Troubleshooting Scenario

Suppose an administrator says:

“I know a user changed a Defender setting yesterday, but I cannot find the event.”

Work through the following checklist.

1. Check permissions

Does the investigator have:

  • Audit Logs
  • View-Only Audit Logs

or equivalent access?

2. Check auditing

Is Microsoft Purview auditing enabled?

3. Check the date/time

Is the correct UTC range being searched?

4. Check the activity

Is the specific operation actually audited?

5. Check the user

Was the correct account selected?

6. Check retention

Is the event still within the organization’s audit-log retention period?

7. Check the workload

Could the activity have been generated by another Microsoft workload?

This systematic approach is more reliable than simply expanding the search indefinitely.


24. Audit Data and Incident Reconstruction

One of the most valuable uses of audit information is reconstructing a timeline.

For example:

09:12 User signs in
|
09:17 Defender configuration changed
|
09:19 Indicator created
|
09:23 Device isolated
|
09:31 Incident assigned
|
09:45 SOC begins investigation

The audit log can provide evidence for supported administrative actions within this timeline.

Other security data sources can then provide additional context.

This is particularly useful for determining:

  • What happened?
  • When did it happen?
  • Who performed the action?
  • Which security controls were changed?
  • What happened immediately before or after the change?

25. Best Practices

Use least privilege

Do not give investigators Global Administrator privileges merely because that role can search audit logs.

Use the appropriate Audit Logs or View-Only Audit Logs permissions.

Search narrowly before expanding

Start with:

  • Known timeframe
  • Known user
  • Known activity

Then expand the search when necessary.

Correlate audit records with security telemetry

Audit records provide administrative context. Combine them with Defender, Microsoft Entra, endpoint, and Sentinel data for a more complete investigation.

Understand retention before an incident occurs

Organizations should establish audit retention policies before they need historical evidence.

Consider licensing requirements

Longer audit retention may require specific Microsoft licensing and the appropriate retention policy configuration.

Export important results

Export relevant audit results when investigation or compliance procedures require a durable copy for analysis or reporting.


26. Common Exam Mistakes

Mistake 1: Confusing Purview Audit with Sentinel data retention

Purview audit records are governed by Microsoft Purview audit retention, not Microsoft Sentinel table-retention settings.

Mistake 2: Assuming Defender audit data is separate from Purview

Microsoft Defender XDR uses Microsoft Purview auditing.

Mistake 3: Choosing Global Administrator unnecessarily

Audit Logs or View-Only Audit Logs permissions are the more relevant concept for audit searches.

Mistake 4: Assuming every Defender action is audited

Only supported activities generate audit records.

Mistake 5: Forgetting retention

If an event is older than the organization’s applicable audit retention period, it may no longer be available.

Mistake 6: Confusing alerts with audit records

An alert identifies a security condition; an audit record documents a supported user or administrator action.

Mistake 7: Assuming audit search requires KQL

The Microsoft Purview/Defender Audit search experience is not the same as querying Sentinel tables with KQL.


27. SC-500 Exam-Focused Summary

ConceptWhat to remember
Microsoft Purview AuditRecords supported user/admin activities
Unified Audit LogCentral audit repository for supported Microsoft 365 activities
Defender XDR auditingUses Microsoft Purview auditing
Defender Audit pageUsed to search audit activity
Main search filtersDate/time, activities, users
Audit Logs roleProvides audit-log access
View-Only Audit LogsRead-oriented audit access
Global AdministratorShould not be selected unnecessarily
Audit (Standard)Default retention is currently 180 days for newer audit records
Audit (Premium)Provides enhanced audit capabilities and retention policies
Long-term retentionRequires appropriate licensing/configuration
Maximum documented retentionUp to 10 years with required licensing
PowerShellSearch-UnifiedAuditLog
Microsoft GraphAudit Search Graph API
ExportCSV
AuditDataJSON containing additional event properties
Sentinel KQLDifferent from Purview Audit search
Retention settingsPurview audit retention, not Sentinel table retention

28. Key Takeaways

The most important points for the SC-500 exam are:

  1. Microsoft Defender XDR uses Microsoft Purview auditing.
  2. The Audit page in Microsoft Defender can be used to search supported audit activities.
  3. Searches can be narrowed by date/time, activities, and users.
  4. Defender audit activities include operations such as device isolation, security-role changes, custom detection changes, indicator creation, and data-retention changes.
  5. Audit searches require appropriate Audit Logs or View-Only Audit Logs permissions.
  6. Microsoft recommends least privilege rather than automatically assigning Global Administrator.
  7. Audit retention is controlled by Microsoft Purview audit-retention capabilities.
  8. The current default Audit (Standard) retention period is 180 days for applicable newer audit records.
  9. Audit (Premium) supports retention policies and can provide retention of up to 10 years when the required licensing is in place.
  10. Audit searches can be performed through the portal and programmatically through PowerShell or Microsoft Graph.
  11. Audit results can be exported to CSV, with additional event information available in the AuditData JSON property.
  12. Purview Audit searches are different from KQL queries against Microsoft Sentinel data.
  13. A missing audit event may be caused by permissions, incorrect filters, unsupported activity, or retention expiration.

Practice Exam Questions

Question 1

A security analyst needs to determine who isolated a device in Microsoft Defender XDR yesterday.

Where should the analyst begin the investigation?

A. Microsoft Defender portal Audit

B. Azure Policy

C. Microsoft Sentinel Data Lake

D. Azure Resource Graph

Answer: A

Explanation: Microsoft Defender XDR activities are audited through Microsoft Purview, and the Defender portal provides an Audit page where supported Defender activities can be searched.


Question 2

An investigator needs to search the Microsoft Purview audit log for activity performed by a specific administrator during a particular time period.

Which combination of search criteria is most appropriate?

A. KQL table, workspace, and analytic rule

B. Subscription, resource group, and Azure region

C. Date/time range, activities, and user

D. Device group, vulnerability, and exposure score

Answer: C

Explanation: Audit searches can be filtered using criteria such as the date/time range, activities, and users. These are the core filters an investigator uses to narrow audit activity.


Question 3

A security analyst needs to search Microsoft Defender XDR audit records but should not receive broad administrative privileges.

Which permission is most directly relevant?

A. Contributor

B. View-Only Audit Logs

C. Security Administrator

D. Global Administrator

Answer: B

Explanation: View-Only Audit Logs provides read-oriented access to audit information. The important SC-500 principle is to use the minimum permissions required rather than assigning Global Administrator unnecessarily.


Question 4

An organization needs to determine whether an administrator changed a Microsoft Defender data-retention setting.

Which Microsoft Defender/Purview capability should be used?

A. Microsoft Defender Vulnerability Management

B. Microsoft Sentinel analytics rules

C. Microsoft Purview Audit

D. Azure Resource Locks

Answer: C

Explanation: Changes to data-retention settings are among the types of Microsoft Defender activities that can be audited. The audit record can be searched through the Defender Audit experience.


Question 5

An investigator wants to search the unified audit log programmatically rather than through the Microsoft Defender portal.

Which PowerShell cmdlet is specifically designed for this purpose?

A. Get-MgUser

B. Get-AzActivityLog

C. Get-MgAuditLogDirectoryAudit

D. Search-UnifiedAuditLog

Answer: D

Explanation: Search-UnifiedAuditLog is the Exchange Online PowerShell cmdlet used to search Microsoft Purview unified audit-log events.


Question 6

A security team discovers that an administrative action occurred 14 months ago. The organization has not configured extended audit retention and is using the standard audit-retention period.

What should the investigator consider first?

A. The audit record may no longer be available because it is outside the applicable retention period.

B. Microsoft Sentinel automatically retrieves the missing audit event.

C. Defender XDR automatically converts the event into an alert.

D. The event must be available indefinitely because it is an administrative action.

Answer: A

Explanation: The current default Audit (Standard) retention period for applicable newer audit records is 180 days. Historical availability depends on the organization’s retention configuration and licensing.


Question 7

An organization has a compliance requirement to retain applicable audit records for several years.

Which capability should the organization investigate?

A. Azure resource locks

B. Microsoft Purview audit-log retention policies with appropriate licensing

C. Microsoft Sentinel automation rules

D. Microsoft Defender Vulnerability Management

Answer: B

Explanation: Microsoft Purview Audit (Premium) supports audit-log retention policies, including long-term retention. Longer retention periods require appropriate licensing.


Question 8

A security analyst searches Microsoft Defender XDR Audit and cannot find an expected event.

Which of the following is a valid reason the event might not appear?

A. Microsoft Defender audit records are never retained.

B. Audit records can only be queried with KQL.

C. The activity may not be a supported audited activity.

D. Audit records are stored only in Azure Resource Manager.

Answer: C

Explanation: Not every action performed in a Microsoft service is necessarily an audited activity. Investigators should verify that the activity is supported, as well as checking permissions, time range, user filters, and retention.


Question 9

A security engineer exports Microsoft Purview audit search results to CSV and wants to examine additional event properties contained within each record.

Which exported field contains additional event information formatted as JSON?

A. AuditData

B. ResourceGroup

C. IncidentData

D. SecurityData

Answer: A

Explanation: The exported audit results include an AuditData column containing additional event information in JSON format. The JSON can be transformed for easier analysis.


Question 10

An investigator is trying to determine whether a user changed a Defender security role immediately before a security incident.

Which approach provides the most appropriate combination of evidence?

A. Search Azure Policy compliance results only.

B. Review the Azure Activity Log only.

C. Search Microsoft Purview Audit for the relevant Defender activity and correlate the result with other security telemetry.

D. Query Azure Resource Graph for the user’s mailbox activity.

Answer: C

Explanation: Defender administrative actions are audited through Microsoft Purview. Searching the relevant audit activity can identify the administrative action and user, while correlating it with Defender, identity, endpoint, or Sentinel telemetry can help reconstruct the incident timeline.


Final Exam Reminder

When an SC-500 question asks you to investigate who performed an administrative or user action in Microsoft Defender XDR or Microsoft 365, think:

Microsoft Defender XDR activity
|
v
Microsoft Purview Audit
|
v
Audit search
|
+------+------+
| | |
Time Activity User
|
v
Audit record
|
v
Correlate with
security telemetry

The central concept to remember is:

Microsoft Defender XDR uses Microsoft Purview auditing to record supported user and administrator activities, and those activities can be searched from the Defender portal’s Audit experience.

For the exam, keep the following distinctions especially clear:

Purview Audit → audited activities

Microsoft Sentinel → security data and KQL-based analysis

Defender XDR Audit → Defender activities recorded through Purview auditing

Audit retention → governed by Microsoft Purview audit-retention capabilities

Long-term audit retention → requires the appropriate Purview licensing and retention configuration


Go to the SC-500 Exam Prep Hub main page

Leave a Reply