Presentation is loading. Please wait.

Presentation is loading. Please wait.

Decoding audit events in Microsoft Office 365

Similar presentations


Presentation on theme: "Decoding audit events in Microsoft Office 365"— Presentation transcript:

1 Decoding audit events in Microsoft Office 365
7/1/2018 6:31 PM THR2095 Decoding audit events in Microsoft Office 365 Alan Byrne & Tony Redmond Office 365 MVPs © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

2 7/1/2018 6:31 PM The Past Auditing was enabled, configured and viewed on a workload by workload basis: Exchange Online Admin/Mailbox Auditing SharePoint Online Auditing Azure AD Auditing © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

3 One Office 365 auditing log to rule them all
7/1/2018 6:31 PM Unified Audit Log One Office 365 auditing log to rule them all © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

4 What is audited? Workload Admin Activity Recorded
7/1/2018 6:31 PM What is audited? Workload Admin Activity Recorded User Activity Recorded Azure AD Yes Exchange Online Yes (Exchange Admin Audit Logging) Yes (Mailbox Audit Logging) SharePoint Online Skype for Business No Sway PowerBI for Office 365 Microsoft Teams Yammer Security & Compliance Center (eDiscovery actions) N/A Flow Coming © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

5 Audit Event Lag Times Office 365 Workload 30 Mins 24 Hours
7/1/2018 6:31 PM Audit Event Lag Times Office 365 Workload 30 Mins 24 Hours SharePoint Online and OneDrive for Business X Exchange Online Azure Active Directory (user login events) Azure Active Directory (admin events) Sway PowerBI Yammer Security & Compliance Center Teams Flow Coming © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

6 You need to turn auditing on!
7/1/2018 6:31 PM You need to turn auditing on! BEFORE you need to investigate something © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

7 Accessing the Audit Logs
7/1/2018 6:31 PM Accessing the Audit Logs PowerShell (Search-UnifiedAuditLog) Audit Log Search in Security & Compliance Centre 3rd Party tools (Using the Management Activity API) Dashboards (Coming soon to Security & Compliance Centre) © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

8 Accessing the Audit Logs
7/1/2018 6:31 PM Accessing the Audit Logs © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

9 7/1/2018 6:31 PM An Audit Event © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

10 A look at individual audit events
7/1/2018 6:31 PM A look at individual audit events © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

11 7/1/2018 6:31 PM File Accessed © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

12 Mailbox Delegate Permission Changes
7/1/2018 6:31 PM Mailbox Delegate Permission Changes © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

13 Sharing Anonymous Links
7/1/2018 6:31 PM Sharing Anonymous Links © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

14 It’s not always obvious
7/1/2018 6:31 PM It’s not always obvious © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

15 7/1/2018 6:31 PM Limitations © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

16 Audit data is only retained for 90 days
Audit events are normalized, but relevant workload specific properties are hard to identify Analyzing thousands of log lines of raw data is not for everyone

17 7/1/2018 6:31 PM Alternatives? © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

18 Quadrotech Radar Reporting
7/1/2018 6:31 PM Quadrotech Radar Reporting © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

19 Please evaluate this session
Tech Ready 15 7/1/2018 Please evaluate this session From your Please expand notes window at bottom of slide and read. Then Delete this text box. PC or tablet: visit MyIgnite Phone: download and use the Microsoft Ignite mobile app Your input is important! © 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

20 7/1/2018 6:31 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.


Download ppt "Decoding audit events in Microsoft Office 365"

Similar presentations


Ads by Google