This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage and monitor security posture (20–25%)
--> Implement activity and event collection in Microsoft Sentinel
--> Query Microsoft Purview Audit in Defender XDR
Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.
Introduction
Security investigations often require more than security alerts and endpoint telemetry. Investigators also need to know what users and administrators actually did across Microsoft 365 and Microsoft security services.
For example:
- Who changed a Microsoft Defender security setting?
- Who created or modified a custom detection rule?
- Who isolated a device?
- Who changed a data-retention setting?
- Who modified security roles?
- Who assigned a user to an incident?
- What actions were performed by an administrator before or during a security incident?
Microsoft Purview Audit provides the auditing infrastructure used to record supported user and administrator activities across Microsoft 365. Microsoft Defender XDR uses this auditing capability, and the audit records can be searched from the Microsoft Defender portal.
For the SC-500 exam, the important skill is understanding how to query the Microsoft Purview unified audit log from Microsoft Defender XDR, what information can be searched, what permissions are required, and how audit-log retention affects an investigation.
1. What Is Microsoft Purview Audit?
Microsoft Purview Audit records supported user and administrator activities throughout the Microsoft 365 environment.
The resulting audit records can be used for:
- Security investigations
- Forensic investigations
- Compliance investigations
- IT investigations
- Legal investigations
- Insider-risk investigations
- Tracking administrative changes
Microsoft describes Audit (Standard) as a solution for logging and searching audited activities across Microsoft services. It includes thousands of searchable audit events.
A useful conceptual model is:
Users / Administrators | vAudited activities | vMicrosoft Purview Unified Audit Log | +-----------------------+ | | v vMicrosoft Defender XDR Microsoft Purview | | +-----------+-----------+ | v Investigation
The important point is that the audit information is not simply a Defender-specific log.
Microsoft Defender XDR uses Microsoft Purview auditing.
2. Why Query the Audit Log During a Security Investigation?
Security telemetry can tell you that something happened.
The audit log can help answer:
Who performed the action, what action occurred, and when did it occur?
Consider an investigation into a compromised security administrator account.
An investigator might discover that:
- The account signed in.
- A Defender security configuration was changed.
- A device was isolated.
- A security role was modified.
- A custom detection rule was created.
Security alerts alone might not provide the complete administrative activity trail.
The audit log can provide evidence of supported administrative and user activities.
Microsoft specifically identifies Defender activities such as changes to data-retention settings, changes to advanced features, creation of indicators of compromise, device isolation, security-role changes, custom detection-rule changes, and incident assignments as audited activities.
3. Microsoft Defender XDR and the Unified Audit Log
Microsoft Defender XDR activities are integrated with the Microsoft Purview auditing solution.
This means that an investigator can use the Audit page in the Microsoft Defender portal to search for supported activities.
Microsoft states that the Defender portal audit search is identical to the audit-log search experience available through Microsoft Purview.
Conceptually:
Microsoft Defender XDR | | audited activity vMicrosoft Purview auditing | vUnified Audit Log | vDefender portal → Audit
This is particularly useful because security personnel can investigate Defender activity without having to switch to an entirely separate audit system.
4. What Can You Search For?
The audit search allows investigators to filter activities using several criteria.
Important search criteria include:
- Date and time range
- Activities
- Users
The available activities depend on the services and workloads being audited.
Microsoft Defender XDR audit records can include activities associated with Microsoft Defender XDR and Microsoft Defender for Endpoint.
Examples include:
| Activity type | Example investigation question |
|---|---|
| Data-retention changes | Who changed a retention setting? |
| Advanced-feature changes | Who changed a Defender configuration? |
| Indicator changes | Who created an indicator of compromise? |
| Device isolation | Who isolated a device? |
| Security-role changes | Who added, edited, or removed a security role? |
| Custom detections | Who created or modified a custom detection rule? |
| Incident assignment | Who assigned a user to an incident? |
These examples illustrate an important distinction:
The audit log records administrative and user actions, not simply security alerts.
5. Accessing Audit Search in Microsoft Defender
The current Microsoft Defender portal provides an Audit page for searching audit records.
The general process is:
- Sign in to the Microsoft Defender portal.
- Open Audit.
- Configure the search criteria.
- Select Search.
- Review the returned audit records.
- Export results if required.
Microsoft documents the Defender portal Audit page as the starting point for audit-log searches.
The same audit-search capability can also be accessed from Microsoft Purview.
6. Search Criteria
A typical audit search begins by narrowing the investigation.
Date and Time
Specify the period in which the activity occurred.
For example:
Start: September 20, 2026 00:00 UTCEnd: September 25, 2026 23:59 UTC
Be careful with time zones.
Microsoft’s audit search uses a date/time range, and audit activities are represented using UTC-based timing.
Exam Tip
If an exam question asks you to investigate activity during a specific period, date/time is one of the primary search filters.
Activities
The Activities filter lets you search for specific audited operations.
For example, an investigator could search for a Defender activity involving:
- Device isolation
- Security-role changes
- Custom detection rules
- Indicators
- Retention settings
The exact activity names available depend on the workload and audit records being searched.
Users
The Users filter allows an investigator to narrow results to activities performed by particular users.
For example:
“Determine whether the compromised administrator account changed any Defender settings during the incident.”
The investigator can specify that account in the Users filter.
Leaving the Users field empty allows the search to include activities from all users within the search scope.
7. Example Investigation
Suppose a security team discovers that a critical endpoint was isolated unexpectedly.
The team wants to determine:
Who initiated the isolation and when?
A reasonable audit investigation would be:
Audit | +-- Date/time | | | +-- Incident timeframe | +-- Activity | | | +-- Device isolation-related activity | +-- User | +-- Leave blank initially
The investigator reviews the resulting audit records to determine which account performed the action.
If a particular account is identified, a second search can narrow the investigation to that user and the surrounding time period.
This illustrates an important investigation technique:
Start broad enough to discover the activity, then narrow the search as evidence identifies relevant users, activities, or time periods.
8. Audit Records vs. Microsoft Sentinel Logs
This distinction is important for SC-500.
Microsoft Purview Audit is not simply another Microsoft Sentinel table.
The audit log is a Microsoft 365 auditing system.
Microsoft Sentinel can collect and analyze many different data sources, while Microsoft Purview Audit provides auditing of supported Microsoft 365 activities.
Therefore:
| Microsoft Purview Audit | Microsoft Sentinel |
|---|---|
| Focuses on audited user/admin activities | Security information and event management |
| Unified Microsoft 365 audit log | Centralized security data platform |
| Search through Audit | Query using KQL and Sentinel capabilities |
| Used heavily for compliance and administrative investigations | Used for detection, investigation, hunting, and response |
| Records supported audited activities | Collects many security and operational data sources |
The two systems can complement one another.
For example:
Defender alert | vSentinel investigation | +---- Endpoint telemetry | +---- Identity logs | +---- Microsoft 365 activity | vPurview Audit | vAdministrative action
An investigator may use both security telemetry and audit records to reconstruct an incident.
9. Microsoft Defender XDR Audit vs. Defender Alerts
Another important distinction is:
Alert
An alert generally indicates that a security-related condition or detection occurred.
Audit record
An audit record documents a supported user or administrator activity.
For example:
Alert:
Suspicious activity detected on a device.
Audit record:
Administrator isolated the device.
These are different types of information.
During an investigation, both can be valuable.
10. Required Permissions
Access to the audit log is controlled through permissions.
Microsoft currently documents that users need the Audit Logs or View-Only Audit Logs permissions/roles to search audit records. In the Defender/XDR context, these permissions are associated with Exchange Online role groups such as Compliance Management and Organization Management by default.
Microsoft also emphasizes least privilege.
A Global Administrator can have the necessary access, but Microsoft recommends using lower-privilege roles when they are sufficient.
Exam Tip
If a question asks:
“What permissions are required to search the audit log?”
Think:
Audit Logs or View-Only Audit Logs.
Do not automatically choose Global Administrator simply because that role can perform the task.
11. Audit Logs vs. View-Only Audit Logs
These permissions provide access to audit information.
The principle is:
Give investigators the minimum permissions required to perform their responsibilities.
For an investigator who only needs to search and review audit records, a read-oriented audit role is preferable to granting broad administrative permissions.
This aligns with the principle of least privilege emphasized throughout Microsoft security solutions.
12. Audit Must Be Available
Before investigating audit activity, auditing must be available for the organization.
Microsoft Defender XDR uses Microsoft Purview auditing, and Microsoft states that auditing needs to be turned on in Microsoft Purview before audit data can be viewed in the Defender portal.
This creates an important troubleshooting sequence:
Can't find audit records? | +--> Is auditing enabled? | +--> Does the user have audit permissions? | +--> Is the activity actually audited? | +--> Is the activity within the retention period? | +--> Are the search filters correct?
A missing audit record does not automatically mean the activity never occurred.
The activity may:
- Not be audited
- Fall outside the retention period
- Require different search criteria
- Belong to a different workload
- Have been performed outside the period being searched
13. Audit Retention
Retention is especially important when investigating historical incidents.
The default Audit (Standard) retention period is currently 180 days for audit logs generated on or after October 17, 2023. Older Audit (Standard) records generated before that date followed the previous 90-day default.
Therefore, an investigator should not assume that an audit record from several years ago is automatically available.
Audit retention depends on the organization’s Microsoft Purview audit configuration and licensing.
14. Audit (Premium) and Longer Retention
Microsoft Purview Audit (Premium) provides additional audit capabilities, including configurable audit-log retention policies.
Audit retention policies can retain audit records for:
- More than the standard retention period
- Up to one year for appropriately licensed users
- Up to 10 years when the required licensing and 10-year audit retention add-on are in place
Microsoft currently documents support for audit-log retention policies of up to 10 years.
Important Licensing Concept
Longer retention is not simply a matter of changing a setting.
Microsoft documents licensing requirements for longer retention. For example, retaining audit logs beyond 180 days and up to one year requires appropriate E5-level licensing for the users whose activities generate the audit records; 10-year retention requires an additional 10-year audit-log retention license.
Exam Tip
When a question combines:
- Long-term audit retention
- Compliance
- Microsoft Purview Audit
look for Audit retention policies and the appropriate licensing, rather than assuming Microsoft Sentinel table retention controls the audit records.
15. Audit Retention Policies
Microsoft Purview Audit (Premium) supports audit log retention policies.
Policies can specify how long audit records should be retained.
They can be configured according to criteria such as the audited workload, record type, and other supported conditions.
An organization can have up to 50 audit-log retention policies.
The important exam concept is:
Microsoft Purview Audit retention is managed through Purview audit-retention capabilities, not through Microsoft Sentinel table-retention settings.
16. Searching With PowerShell
The audit log can also be queried programmatically.
Microsoft provides the Search-UnifiedAuditLog PowerShell cmdlet for searching audit events.
This can be useful when:
- Searches need to be automated
- Investigators need repeatable queries
- Results need to be processed programmatically
- An investigation involves many searches
- Security teams want to integrate audit searching into operational workflows
The portal and PowerShell access the same underlying audit-log capability.
17. Microsoft Graph Audit Search API
Microsoft also provides the Audit Search Graph API.
This allows applications to programmatically access audit-search data through Microsoft Graph.
This is useful for organizations building:
- Automated investigations
- Compliance workflows
- Security dashboards
- Custom reporting
- Integration with security operations tooling
For the SC-500 exam, recognize the relationship:
Audit Search | +---- Defender portal | +---- Purview portal | +---- PowerShell | +---- Microsoft Graph Audit Search API
18. Exporting Audit Results
Audit-search results can be exported.
The Microsoft Purview audit search experience supports exporting results to a CSV file.
The exported data includes an AuditData column containing additional event information formatted as JSON.
That JSON can be transformed in tools such as Excel’s Power Query Editor to make individual properties easier to analyze.
This can be useful for:
- Compliance reports
- Investigation evidence
- Sorting and filtering
- Offline analysis
- Sharing investigation results with authorized personnel
19. Understanding the AuditData Property
An audit record contains multiple properties describing the event.
When audit results are exported, the AuditData field contains additional event information as JSON.
For example, an exported record can conceptually look like:
CreationTimeUserIdOperationWorkloadRecordTypeAuditData
The AuditData field may contain additional properties that provide more context about the operation.
This is particularly useful when the standard columns do not provide all the information required for an investigation.
20. Investigating Microsoft Defender XDR Activities
Microsoft Defender XDR provides a specific collection of audited activities.
Examples include:
Data-retention changes
An investigator can determine whether an administrator changed a security data-retention setting.
Device isolation
An investigator can investigate which user or administrator performed an isolation action.
Security-role changes
An investigator can determine whether security permissions or roles were changed.
Custom detection changes
An investigator can determine who created or modified custom detection rules.
Incident assignments
An investigator can determine who assigned a user to an incident.
These activities can provide important evidence during an investigation into unauthorized administrative behavior.
21. Example: Investigating an Unauthorized Defender Change
Suppose a security team discovers that an organization’s Defender configuration changed unexpectedly.
The investigation could proceed as follows:
Step 1 — Identify the approximate timeframe
Determine when the configuration change was discovered.
Step 2 — Search the Audit page
Open the Audit page in Microsoft Defender.
Step 3 — Filter by activity
Select the relevant Defender activity.
Step 4 — Review users
Identify which account performed the activity.
Step 5 — Correlate with other telemetry
Compare the audit event with:
- Sign-in activity
- Device activity
- Security alerts
- Incident timelines
- Other administrative changes
Step 6 — Export if required
Export the results for additional investigation or reporting.
This provides a more complete picture than examining a security alert alone.
22. Audit Log Search Is Not the Same as KQL
A common SC-500 exam trap is assuming that every Microsoft security data source is queried with KQL.
Microsoft Purview Audit provides its own search experience.
The standard Audit search uses filters such as:
- Date/time
- Activities
- Users
It can also be accessed programmatically through PowerShell and Microsoft Graph.
By contrast, Microsoft Sentinel uses KQL extensively for querying data stored in its Log Analytics environment.
Therefore:
| Task | Primary mechanism |
|---|---|
| Search Microsoft Purview audit activities | Audit search |
| Search Defender audit activity | Defender Audit |
| Programmatically search unified audit log | Search-UnifiedAuditLog / Graph API |
| Query Sentinel log tables | KQL |
| Build Sentinel analytics rules | KQL-based queries |
23. Common Troubleshooting Scenario
Suppose an administrator says:
“I know a user changed a Defender setting yesterday, but I cannot find the event.”
Work through the following checklist.
1. Check permissions
Does the investigator have:
- Audit Logs
- View-Only Audit Logs
or equivalent access?
2. Check auditing
Is Microsoft Purview auditing enabled?
3. Check the date/time
Is the correct UTC range being searched?
4. Check the activity
Is the specific operation actually audited?
5. Check the user
Was the correct account selected?
6. Check retention
Is the event still within the organization’s audit-log retention period?
7. Check the workload
Could the activity have been generated by another Microsoft workload?
This systematic approach is more reliable than simply expanding the search indefinitely.
24. Audit Data and Incident Reconstruction
One of the most valuable uses of audit information is reconstructing a timeline.
For example:
09:12 User signs in |09:17 Defender configuration changed |09:19 Indicator created |09:23 Device isolated |09:31 Incident assigned |09:45 SOC begins investigation
The audit log can provide evidence for supported administrative actions within this timeline.
Other security data sources can then provide additional context.
This is particularly useful for determining:
- What happened?
- When did it happen?
- Who performed the action?
- Which security controls were changed?
- What happened immediately before or after the change?
25. Best Practices
Use least privilege
Do not give investigators Global Administrator privileges merely because that role can search audit logs.
Use the appropriate Audit Logs or View-Only Audit Logs permissions.
Search narrowly before expanding
Start with:
- Known timeframe
- Known user
- Known activity
Then expand the search when necessary.
Correlate audit records with security telemetry
Audit records provide administrative context. Combine them with Defender, Microsoft Entra, endpoint, and Sentinel data for a more complete investigation.
Understand retention before an incident occurs
Organizations should establish audit retention policies before they need historical evidence.
Consider licensing requirements
Longer audit retention may require specific Microsoft licensing and the appropriate retention policy configuration.
Export important results
Export relevant audit results when investigation or compliance procedures require a durable copy for analysis or reporting.
26. Common Exam Mistakes
Mistake 1: Confusing Purview Audit with Sentinel data retention
Purview audit records are governed by Microsoft Purview audit retention, not Microsoft Sentinel table-retention settings.
Mistake 2: Assuming Defender audit data is separate from Purview
Microsoft Defender XDR uses Microsoft Purview auditing.
Mistake 3: Choosing Global Administrator unnecessarily
Audit Logs or View-Only Audit Logs permissions are the more relevant concept for audit searches.
Mistake 4: Assuming every Defender action is audited
Only supported activities generate audit records.
Mistake 5: Forgetting retention
If an event is older than the organization’s applicable audit retention period, it may no longer be available.
Mistake 6: Confusing alerts with audit records
An alert identifies a security condition; an audit record documents a supported user or administrator action.
Mistake 7: Assuming audit search requires KQL
The Microsoft Purview/Defender Audit search experience is not the same as querying Sentinel tables with KQL.
27. SC-500 Exam-Focused Summary
| Concept | What to remember |
|---|---|
| Microsoft Purview Audit | Records supported user/admin activities |
| Unified Audit Log | Central audit repository for supported Microsoft 365 activities |
| Defender XDR auditing | Uses Microsoft Purview auditing |
| Defender Audit page | Used to search audit activity |
| Main search filters | Date/time, activities, users |
| Audit Logs role | Provides audit-log access |
| View-Only Audit Logs | Read-oriented audit access |
| Global Administrator | Should not be selected unnecessarily |
| Audit (Standard) | Default retention is currently 180 days for newer audit records |
| Audit (Premium) | Provides enhanced audit capabilities and retention policies |
| Long-term retention | Requires appropriate licensing/configuration |
| Maximum documented retention | Up to 10 years with required licensing |
| PowerShell | Search-UnifiedAuditLog |
| Microsoft Graph | Audit Search Graph API |
| Export | CSV |
| AuditData | JSON containing additional event properties |
| Sentinel KQL | Different from Purview Audit search |
| Retention settings | Purview audit retention, not Sentinel table retention |
28. Key Takeaways
The most important points for the SC-500 exam are:
- Microsoft Defender XDR uses Microsoft Purview auditing.
- The Audit page in Microsoft Defender can be used to search supported audit activities.
- Searches can be narrowed by date/time, activities, and users.
- Defender audit activities include operations such as device isolation, security-role changes, custom detection changes, indicator creation, and data-retention changes.
- Audit searches require appropriate Audit Logs or View-Only Audit Logs permissions.
- Microsoft recommends least privilege rather than automatically assigning Global Administrator.
- Audit retention is controlled by Microsoft Purview audit-retention capabilities.
- The current default Audit (Standard) retention period is 180 days for applicable newer audit records.
- Audit (Premium) supports retention policies and can provide retention of up to 10 years when the required licensing is in place.
- Audit searches can be performed through the portal and programmatically through PowerShell or Microsoft Graph.
- Audit results can be exported to CSV, with additional event information available in the AuditData JSON property.
- Purview Audit searches are different from KQL queries against Microsoft Sentinel data.
- A missing audit event may be caused by permissions, incorrect filters, unsupported activity, or retention expiration.
Practice Exam Questions
Question 1
A security analyst needs to determine who isolated a device in Microsoft Defender XDR yesterday.
Where should the analyst begin the investigation?
A. Microsoft Defender portal Audit
B. Azure Policy
C. Microsoft Sentinel Data Lake
D. Azure Resource Graph
Answer: A
Explanation: Microsoft Defender XDR activities are audited through Microsoft Purview, and the Defender portal provides an Audit page where supported Defender activities can be searched.
Question 2
An investigator needs to search the Microsoft Purview audit log for activity performed by a specific administrator during a particular time period.
Which combination of search criteria is most appropriate?
A. KQL table, workspace, and analytic rule
B. Subscription, resource group, and Azure region
C. Date/time range, activities, and user
D. Device group, vulnerability, and exposure score
Answer: C
Explanation: Audit searches can be filtered using criteria such as the date/time range, activities, and users. These are the core filters an investigator uses to narrow audit activity.
Question 3
A security analyst needs to search Microsoft Defender XDR audit records but should not receive broad administrative privileges.
Which permission is most directly relevant?
A. Contributor
B. View-Only Audit Logs
C. Security Administrator
D. Global Administrator
Answer: B
Explanation: View-Only Audit Logs provides read-oriented access to audit information. The important SC-500 principle is to use the minimum permissions required rather than assigning Global Administrator unnecessarily.
Question 4
An organization needs to determine whether an administrator changed a Microsoft Defender data-retention setting.
Which Microsoft Defender/Purview capability should be used?
A. Microsoft Defender Vulnerability Management
B. Microsoft Sentinel analytics rules
C. Microsoft Purview Audit
D. Azure Resource Locks
Answer: C
Explanation: Changes to data-retention settings are among the types of Microsoft Defender activities that can be audited. The audit record can be searched through the Defender Audit experience.
Question 5
An investigator wants to search the unified audit log programmatically rather than through the Microsoft Defender portal.
Which PowerShell cmdlet is specifically designed for this purpose?
A. Get-MgUser
B. Get-AzActivityLog
C. Get-MgAuditLogDirectoryAudit
D. Search-UnifiedAuditLog
Answer: D
Explanation: Search-UnifiedAuditLog is the Exchange Online PowerShell cmdlet used to search Microsoft Purview unified audit-log events.
Question 6
A security team discovers that an administrative action occurred 14 months ago. The organization has not configured extended audit retention and is using the standard audit-retention period.
What should the investigator consider first?
A. The audit record may no longer be available because it is outside the applicable retention period.
B. Microsoft Sentinel automatically retrieves the missing audit event.
C. Defender XDR automatically converts the event into an alert.
D. The event must be available indefinitely because it is an administrative action.
Answer: A
Explanation: The current default Audit (Standard) retention period for applicable newer audit records is 180 days. Historical availability depends on the organization’s retention configuration and licensing.
Question 7
An organization has a compliance requirement to retain applicable audit records for several years.
Which capability should the organization investigate?
A. Azure resource locks
B. Microsoft Purview audit-log retention policies with appropriate licensing
C. Microsoft Sentinel automation rules
D. Microsoft Defender Vulnerability Management
Answer: B
Explanation: Microsoft Purview Audit (Premium) supports audit-log retention policies, including long-term retention. Longer retention periods require appropriate licensing.
Question 8
A security analyst searches Microsoft Defender XDR Audit and cannot find an expected event.
Which of the following is a valid reason the event might not appear?
A. Microsoft Defender audit records are never retained.
B. Audit records can only be queried with KQL.
C. The activity may not be a supported audited activity.
D. Audit records are stored only in Azure Resource Manager.
Answer: C
Explanation: Not every action performed in a Microsoft service is necessarily an audited activity. Investigators should verify that the activity is supported, as well as checking permissions, time range, user filters, and retention.
Question 9
A security engineer exports Microsoft Purview audit search results to CSV and wants to examine additional event properties contained within each record.
Which exported field contains additional event information formatted as JSON?
A. AuditData
B. ResourceGroup
C. IncidentData
D. SecurityData
Answer: A
Explanation: The exported audit results include an AuditData column containing additional event information in JSON format. The JSON can be transformed for easier analysis.
Question 10
An investigator is trying to determine whether a user changed a Defender security role immediately before a security incident.
Which approach provides the most appropriate combination of evidence?
A. Search Azure Policy compliance results only.
B. Review the Azure Activity Log only.
C. Search Microsoft Purview Audit for the relevant Defender activity and correlate the result with other security telemetry.
D. Query Azure Resource Graph for the user’s mailbox activity.
Answer: C
Explanation: Defender administrative actions are audited through Microsoft Purview. Searching the relevant audit activity can identify the administrative action and user, while correlating it with Defender, identity, endpoint, or Sentinel telemetry can help reconstruct the incident timeline.
Final Exam Reminder
When an SC-500 question asks you to investigate who performed an administrative or user action in Microsoft Defender XDR or Microsoft 365, think:
Microsoft Defender XDR activity | v Microsoft Purview Audit | v Audit search | +------+------+ | | | Time Activity User | v Audit record | v Correlate with security telemetry
The central concept to remember is:
Microsoft Defender XDR uses Microsoft Purview auditing to record supported user and administrator activities, and those activities can be searched from the Defender portal’s Audit experience.
For the exam, keep the following distinctions especially clear:
Purview Audit → audited activities
Microsoft Sentinel → security data and KQL-based analysis
Defender XDR Audit → Defender activities recorded through Purview auditing
Audit retention → governed by Microsoft Purview audit-retention capabilities
Long-term audit retention → requires the appropriate Purview licensing and retention configuration
Go to the SC-500 Exam Prep Hub main page
