Skillplan M365 Checklist
2026-07-20 19:27
M365
Microsoft 365 Security Checklist
de
en
fr
it
System Online
← Back to sections
Mitigation Controls · Section 16 of 17
Audit, Logging & Monitoring
Assessment Progress
0
/ 136 items
0%
Fulfillment so far
0
/ 0 controls
0%
Explain this control
Verify the Unified Audit Log is enabled tenant-wide and returns events for searches.
Not Fulfilled
Fulfilled
Accepted
Extend audit log retention to one year for all users via the Audit retention policy (Audit Premium / E5).
Not Fulfilled
Fulfilled
Accepted
Forward Entra ID sign-in and audit logs to Microsoft Sentinel or an external SIEM with at least 90-day hot retention.
Not Fulfilled
Fulfilled
Accepted
Configure SIEM detection rules for high-severity Entra ID, Exchange, and SharePoint events.
Not Fulfilled
Fulfilled
Accepted
Track sign-in log volume monthly; investigate sudden drops as possible log-tampering indicators.
Not Fulfilled
Fulfilled
Accepted
Maintain a runbook for break-glass account sign-in alerts; treat any sign-in as a paging event.
Not Fulfilled
Fulfilled
Accepted
Validate that Defender XDR alerts reach the SOC ticketing system; test injection quarterly.
Not Fulfilled
Fulfilled
Accepted
Route changes to audit and retention policies through change control with security sign-off.
Not Fulfilled
Fulfilled
Accepted
Save and Continue →