This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Identify the core features and objects of Microsoft 365 services (30–35%)
--> Identify the core security features of Microsoft 365 services
--> Use the appropriate tools to review audit logs for user and admin activity
Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.
Introduction
Monitoring user and administrator actions is an essential part of Microsoft 365 security and governance. Organizations must be able to determine:
- Who performed an action.
- What action occurred.
- When the activity occurred.
- Which resource was affected.
- Whether the activity was expected or suspicious.
Microsoft 365 provides several audit and logging tools that help administrators investigate security incidents, track administrative changes, support compliance requirements, and troubleshoot user issues.
For the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals exam, you should understand the purpose of audit logs and know which tools are used to review user and administrator activity.
What Are Audit Logs?
Audit logs are records of activities performed within Microsoft 365 services.
They help organizations:
- Detect suspicious behavior.
- Investigate incidents.
- Meet regulatory requirements.
- Track administrative changes.
- Support forensic investigations.
- Verify user actions.
Audit logs provide visibility into activities occurring across Microsoft 365 environments.
Types of Activities Recorded
Microsoft 365 audit logs can capture actions such as:
User Activities
- Signing in
- Accessing files
- Sharing documents
- Creating Teams messages
- Deleting files
- Downloading content
Administrator Activities
- Resetting passwords
- Creating users
- Assigning licenses
- Modifying policies
- Creating groups
- Changing permissions
Service Activities
- Mailbox operations
- SharePoint changes
- Teams events
- Security configuration changes
Unified Audit Log
The primary audit tool in Microsoft 365 is the Unified Audit Log.
The Unified Audit Log collects events from multiple Microsoft 365 services, including:
- Microsoft Entra ID
- Exchange Online
- SharePoint Online
- OneDrive
- Microsoft Teams
- Microsoft Purview
- Microsoft Defender
- Power Platform services
Instead of reviewing separate logs for every service, administrators can search centrally.
Microsoft Purview Audit
The Unified Audit Log is accessed through Microsoft Purview.
Administrators can:
- Search activities by user.
- Search by date range.
- Filter by workload.
- Filter by activity type.
- Export results.
This centralized approach simplifies investigations.
Common Search Filters
Administrators commonly filter audit logs by:
User
Example:
user1@contoso.com
Activity
Examples:
- File deleted
- Mailbox accessed
- User added
- Password reset
Date and Time
Investigations often focus on a specific period.
Workload
Examples:
- SharePoint
- Exchange
- Teams
- Entra ID
These filters narrow results and improve efficiency.
Microsoft Entra Sign-In Logs
Sign-in logs are separate from the Unified Audit Log and focus specifically on authentication activity.
Sign-in logs record:
- Successful sign-ins
- Failed sign-ins
- IP addresses
- Device information
- Authentication methods used
- Conditional Access results
Sign-in logs are commonly used to troubleshoot access issues and investigate suspicious login attempts.
Audit Logs vs Sign-In Logs
Students frequently confuse these two tools.
Sign-In Logs
Focus on:
- Authentication attempts
- MFA events
- Conditional Access outcomes
- Login locations
Audit Logs
Focus on:
- User actions after authentication
- Administrative changes
- File access
- Configuration modifications
Both are important, but they serve different purposes.
Examples of Audit Events
Exchange Online
Events may include:
- Mailbox access
- Email deletions
- Mailbox permission changes
SharePoint Online
Events may include:
- File creation
- File downloads
- File sharing
Microsoft Teams
Events may include:
- Team creation
- Channel creation
- Membership changes
Microsoft Entra ID
Events may include:
- User creation
- Group modifications
- Role assignments
Reviewing Administrator Activity
Audit logs help determine:
- Which administrator made a change.
- When the change occurred.
- Which object was affected.
Examples include:
- Password resets.
- License assignments.
- Group membership changes.
- Conditional Access policy modifications.
This provides accountability and supports change tracking.
Reviewing User Activity
Audit logs can help answer questions such as:
- Did a user delete a file?
- Was a document downloaded?
- Was information shared externally?
- When did the action occur?
This information is valuable during investigations and compliance reviews.
Audit Logs and Microsoft 365 Copilot
Microsoft 365 Copilot relies on Microsoft 365 data sources.
Audit capabilities help organizations monitor:
- User access to content.
- Sharing activities.
- Administrative changes affecting Copilot environments.
- Compliance investigations involving AI-related workflows.
Copilot itself uses the same Microsoft 365 security and compliance framework.
Microsoft Defender XDR and Advanced Investigations
Microsoft Defender XDR can correlate events across:
- Identities
- Devices
- Applications
This provides a broader security perspective when investigating incidents.
While audit logs show individual events, Defender XDR helps connect related activities.
Retention of Audit Logs
Audit logs are retained for a specific period depending on:
- Subscription level.
- Licensing.
- Service configuration.
Organizations with advanced compliance licensing may receive extended retention periods.
For AB-900, understand that retention periods can vary by license type.
Exporting Audit Results
Administrators can export audit results for:
- Incident response.
- Compliance reporting.
- External investigations.
- Long-term analysis.
Exported data can be reviewed using spreadsheets or SIEM solutions.
Best Practices
Review Logs Regularly
Continuous monitoring helps detect issues early.
Use Filters
Filtering speeds investigations.
Protect Administrator Accounts
Administrative actions should always be auditable.
Enable MFA
Secure accounts that have access to audit data.
Maintain Least Privilege
Limit who can access sensitive logs.
Retain Logs Appropriately
Ensure audit records meet organizational requirements.
Important Exam Tips
Remember these AB-900 concepts:
- The Unified Audit Log is the primary Microsoft 365 audit tool.
- Microsoft Purview provides access to audit searches.
- Audit logs track actions performed after authentication.
- Sign-in logs focus on authentication events.
- Audit logs support investigations and compliance.
- Administrator changes are recorded.
- User activities can be searched and reviewed.
- Microsoft 365 Copilot relies on the same audit and compliance framework.
- Exporting logs supports reporting and analysis.
- Retention periods vary by license.
Practice Exam Questions
Question 1
Which Microsoft 365 feature provides centralized auditing across multiple services?
A. Microsoft Planner
B. Windows Event Viewer
C. Unified Audit Log
D. Microsoft Lists
Correct Answer: C
Explanation: The Unified Audit Log aggregates events from multiple Microsoft 365 services into a single searchable location.
Question 2
Which portal is commonly used to access audit searches?
A. Exchange admin center
B. Teams admin center
C. Microsoft Purview
D. SharePoint admin center
Correct Answer: C
Explanation: Microsoft Purview provides access to auditing and compliance features, including audit searches.
Question 3
Which activity would typically appear in an audit log?
A. Administrator resets a user’s password.
B. Monitor brightness changes.
C. Printer toner replacement.
D. CPU temperature fluctuations.
Correct Answer: A
Explanation: Administrative actions such as password resets are recorded in audit logs.
Question 4
Which log type focuses primarily on authentication events?
A. Microsoft Entra sign-in logs
B. SharePoint recycle bin logs
C. Unified Audit Log
D. Exchange message trace logs
Correct Answer: A
Explanation: Sign-in logs capture authentication attempts, MFA information, and Conditional Access outcomes.
Question 5
Which Microsoft 365 service records file downloads and sharing activities?
A. SharePoint Online audit events
B. Windows Registry
C. BIOS settings
D. Active Directory Sites and Services
Correct Answer: A
Explanation: SharePoint audit events track document-related activities.
Question 6
An administrator wants to determine who changed a Conditional Access policy. Which tool should be used?
A. Windows Device Manager
B. Unified Audit Log
C. Outlook rules wizard
D. Microsoft Paint
Correct Answer: B
Explanation: Administrative changes are captured within Microsoft 365 audit records.
Question 7
What is a major difference between audit logs and sign-in logs?
A. Audit logs only store Exchange events.
B. Sign-in logs are used exclusively for Teams.
C. Audit logs track actions after authentication, while sign-in logs track authentication attempts.
D. Sign-in logs cannot be searched.
Correct Answer: C
Explanation: Sign-in logs focus on access attempts, while audit logs record actions performed after access is granted.
Question 8
Which filter can help narrow audit search results?
A. User name
B. Date range
C. Activity type
D. All of the above
Correct Answer: D
Explanation: Audit searches support multiple filters to improve investigation efficiency.
Question 9
Why are audit logs important for compliance investigations?
A. They increase internet bandwidth.
B. They provide records of user and administrator actions.
C. They automatically block attacks.
D. They create Conditional Access policies.
Correct Answer: B
Explanation: Audit records provide evidence of activities that occurred within Microsoft 365.
Question 10
Which statement about Microsoft 365 Copilot and auditing is correct?
A. Copilot bypasses audit logging.
B. Copilot disables Microsoft Purview.
C. Copilot uses a separate audit system unrelated to Microsoft 365.
D. Copilot operates within the existing Microsoft 365 compliance and auditing framework.
Correct Answer: D
Explanation: Microsoft 365 Copilot relies on the same security, compliance, and audit infrastructure used throughout Microsoft 365.
Go to the AB-900 Exam Prep Hub main page
