Use the appropriate tools to review audit logs for user and admin activity (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Identify the core features and objects of Microsoft 365 services (30–35%)
   --> Identify the core security features of Microsoft 365 services
      --> Use the appropriate tools to review audit logs for user and admin activity


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Monitoring user and administrator actions is an essential part of Microsoft 365 security and governance. Organizations must be able to determine:

  • Who performed an action.
  • What action occurred.
  • When the activity occurred.
  • Which resource was affected.
  • Whether the activity was expected or suspicious.

Microsoft 365 provides several audit and logging tools that help administrators investigate security incidents, track administrative changes, support compliance requirements, and troubleshoot user issues.

For the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals exam, you should understand the purpose of audit logs and know which tools are used to review user and administrator activity.


What Are Audit Logs?

Audit logs are records of activities performed within Microsoft 365 services.

They help organizations:

  • Detect suspicious behavior.
  • Investigate incidents.
  • Meet regulatory requirements.
  • Track administrative changes.
  • Support forensic investigations.
  • Verify user actions.

Audit logs provide visibility into activities occurring across Microsoft 365 environments.


Types of Activities Recorded

Microsoft 365 audit logs can capture actions such as:

User Activities

  • Signing in
  • Accessing files
  • Sharing documents
  • Creating Teams messages
  • Deleting files
  • Downloading content

Administrator Activities

  • Resetting passwords
  • Creating users
  • Assigning licenses
  • Modifying policies
  • Creating groups
  • Changing permissions

Service Activities

  • Mailbox operations
  • SharePoint changes
  • Teams events
  • Security configuration changes

Unified Audit Log

The primary audit tool in Microsoft 365 is the Unified Audit Log.

The Unified Audit Log collects events from multiple Microsoft 365 services, including:

  • Microsoft Entra ID
  • Exchange Online
  • SharePoint Online
  • OneDrive
  • Microsoft Teams
  • Microsoft Purview
  • Microsoft Defender
  • Power Platform services

Instead of reviewing separate logs for every service, administrators can search centrally.


Microsoft Purview Audit

The Unified Audit Log is accessed through Microsoft Purview.

Administrators can:

  • Search activities by user.
  • Search by date range.
  • Filter by workload.
  • Filter by activity type.
  • Export results.

This centralized approach simplifies investigations.


Common Search Filters

Administrators commonly filter audit logs by:

User

Example:

user1@contoso.com

Activity

Examples:

  • File deleted
  • Mailbox accessed
  • User added
  • Password reset

Date and Time

Investigations often focus on a specific period.

Workload

Examples:

  • SharePoint
  • Exchange
  • Teams
  • Entra ID

These filters narrow results and improve efficiency.


Microsoft Entra Sign-In Logs

Sign-in logs are separate from the Unified Audit Log and focus specifically on authentication activity.

Sign-in logs record:

  • Successful sign-ins
  • Failed sign-ins
  • IP addresses
  • Device information
  • Authentication methods used
  • Conditional Access results

Sign-in logs are commonly used to troubleshoot access issues and investigate suspicious login attempts.


Audit Logs vs Sign-In Logs

Students frequently confuse these two tools.

Sign-In Logs

Focus on:

  • Authentication attempts
  • MFA events
  • Conditional Access outcomes
  • Login locations

Audit Logs

Focus on:

  • User actions after authentication
  • Administrative changes
  • File access
  • Configuration modifications

Both are important, but they serve different purposes.


Examples of Audit Events

Exchange Online

Events may include:

  • Mailbox access
  • Email deletions
  • Mailbox permission changes

SharePoint Online

Events may include:

  • File creation
  • File downloads
  • File sharing

Microsoft Teams

Events may include:

  • Team creation
  • Channel creation
  • Membership changes

Microsoft Entra ID

Events may include:

  • User creation
  • Group modifications
  • Role assignments

Reviewing Administrator Activity

Audit logs help determine:

  • Which administrator made a change.
  • When the change occurred.
  • Which object was affected.

Examples include:

  • Password resets.
  • License assignments.
  • Group membership changes.
  • Conditional Access policy modifications.

This provides accountability and supports change tracking.


Reviewing User Activity

Audit logs can help answer questions such as:

  • Did a user delete a file?
  • Was a document downloaded?
  • Was information shared externally?
  • When did the action occur?

This information is valuable during investigations and compliance reviews.


Audit Logs and Microsoft 365 Copilot

Microsoft 365 Copilot relies on Microsoft 365 data sources.

Audit capabilities help organizations monitor:

  • User access to content.
  • Sharing activities.
  • Administrative changes affecting Copilot environments.
  • Compliance investigations involving AI-related workflows.

Copilot itself uses the same Microsoft 365 security and compliance framework.


Microsoft Defender XDR and Advanced Investigations

Microsoft Defender XDR can correlate events across:

  • Identities
  • Devices
  • Email
  • Applications

This provides a broader security perspective when investigating incidents.

While audit logs show individual events, Defender XDR helps connect related activities.


Retention of Audit Logs

Audit logs are retained for a specific period depending on:

  • Subscription level.
  • Licensing.
  • Service configuration.

Organizations with advanced compliance licensing may receive extended retention periods.

For AB-900, understand that retention periods can vary by license type.


Exporting Audit Results

Administrators can export audit results for:

  • Incident response.
  • Compliance reporting.
  • External investigations.
  • Long-term analysis.

Exported data can be reviewed using spreadsheets or SIEM solutions.


Best Practices

Review Logs Regularly

Continuous monitoring helps detect issues early.

Use Filters

Filtering speeds investigations.

Protect Administrator Accounts

Administrative actions should always be auditable.

Enable MFA

Secure accounts that have access to audit data.

Maintain Least Privilege

Limit who can access sensitive logs.

Retain Logs Appropriately

Ensure audit records meet organizational requirements.


Important Exam Tips

Remember these AB-900 concepts:

  • The Unified Audit Log is the primary Microsoft 365 audit tool.
  • Microsoft Purview provides access to audit searches.
  • Audit logs track actions performed after authentication.
  • Sign-in logs focus on authentication events.
  • Audit logs support investigations and compliance.
  • Administrator changes are recorded.
  • User activities can be searched and reviewed.
  • Microsoft 365 Copilot relies on the same audit and compliance framework.
  • Exporting logs supports reporting and analysis.
  • Retention periods vary by license.

Practice Exam Questions

Question 1

Which Microsoft 365 feature provides centralized auditing across multiple services?

A. Microsoft Planner
B. Windows Event Viewer
C. Unified Audit Log
D. Microsoft Lists

Correct Answer: C

Explanation: The Unified Audit Log aggregates events from multiple Microsoft 365 services into a single searchable location.


Question 2

Which portal is commonly used to access audit searches?

A. Exchange admin center
B. Teams admin center
C. Microsoft Purview
D. SharePoint admin center

Correct Answer: C

Explanation: Microsoft Purview provides access to auditing and compliance features, including audit searches.


Question 3

Which activity would typically appear in an audit log?

A. Administrator resets a user’s password.
B. Monitor brightness changes.
C. Printer toner replacement.
D. CPU temperature fluctuations.

Correct Answer: A

Explanation: Administrative actions such as password resets are recorded in audit logs.


Question 4

Which log type focuses primarily on authentication events?

A. Microsoft Entra sign-in logs
B. SharePoint recycle bin logs
C. Unified Audit Log
D. Exchange message trace logs

Correct Answer: A

Explanation: Sign-in logs capture authentication attempts, MFA information, and Conditional Access outcomes.


Question 5

Which Microsoft 365 service records file downloads and sharing activities?

A. SharePoint Online audit events
B. Windows Registry
C. BIOS settings
D. Active Directory Sites and Services

Correct Answer: A

Explanation: SharePoint audit events track document-related activities.


Question 6

An administrator wants to determine who changed a Conditional Access policy. Which tool should be used?

A. Windows Device Manager
B. Unified Audit Log
C. Outlook rules wizard
D. Microsoft Paint

Correct Answer: B

Explanation: Administrative changes are captured within Microsoft 365 audit records.


Question 7

What is a major difference between audit logs and sign-in logs?

A. Audit logs only store Exchange events.
B. Sign-in logs are used exclusively for Teams.
C. Audit logs track actions after authentication, while sign-in logs track authentication attempts.
D. Sign-in logs cannot be searched.

Correct Answer: C

Explanation: Sign-in logs focus on access attempts, while audit logs record actions performed after access is granted.


Question 8

Which filter can help narrow audit search results?

A. User name
B. Date range
C. Activity type
D. All of the above

Correct Answer: D

Explanation: Audit searches support multiple filters to improve investigation efficiency.


Question 9

Why are audit logs important for compliance investigations?

A. They increase internet bandwidth.
B. They provide records of user and administrator actions.
C. They automatically block attacks.
D. They create Conditional Access policies.

Correct Answer: B

Explanation: Audit records provide evidence of activities that occurred within Microsoft 365.


Question 10

Which statement about Microsoft 365 Copilot and auditing is correct?

A. Copilot bypasses audit logging.
B. Copilot disables Microsoft Purview.
C. Copilot uses a separate audit system unrelated to Microsoft 365.
D. Copilot operates within the existing Microsoft 365 compliance and auditing framework.

Correct Answer: D

Explanation: Microsoft 365 Copilot relies on the same security, compliance, and audit infrastructure used throughout Microsoft 365.


Go to the AB-900 Exam Prep Hub main page

Leave a comment