Skillplan M365 Checklist
2026-07-20 19:27
M365
Checklist Sécurité Microsoft 365
de
en
fr
it
Système En ligne
← Retour aux sections
Mesures de mitigation · Section 16 sur 17
Audit, Logging & Monitoring
Progression de l'évaluation
0
/ 136 éléments
0%
Conformité jusqu'à présent
0
/ 0 contrôles
0%
Expliquer ce contrôle
Verify the Unified Audit Log is enabled tenant-wide and returns events for searches.
Non remplie
Remplie
Accepté
Extend audit log retention to one year for all users via the Audit retention policy (Audit Premium / E5).
Non remplie
Remplie
Accepté
Forward Entra ID sign-in and audit logs to Microsoft Sentinel or an external SIEM with at least 90-day hot retention.
Non remplie
Remplie
Accepté
Configure SIEM detection rules for high-severity Entra ID, Exchange, and SharePoint events.
Non remplie
Remplie
Accepté
Track sign-in log volume monthly; investigate sudden drops as possible log-tampering indicators.
Non remplie
Remplie
Accepté
Maintain a runbook for break-glass account sign-in alerts; treat any sign-in as a paging event.
Non remplie
Remplie
Accepté
Validate that Defender XDR alerts reach the SOC ticketing system; test injection quarterly.
Non remplie
Remplie
Accepté
Route changes to audit and retention policies through change control with security sign-off.
Non remplie
Remplie
Accepté
Enregistrer et continuer →