From the course: Microsoft Information Security Administrator Associate (SC-401) Cert Prep by Microsoft Press
Unlock this course with a free trial
Join today to access over 25,500 courses taught by industry experts.
Assign Microsoft Purview Audit (Premium) user licenses - Microsoft 365 Tutorial
From the course: Microsoft Information Security Administrator Associate (SC-401) Cert Prep by Microsoft Press
Assign Microsoft Purview Audit (Premium) user licenses
To use Purview Audit premium features, each relevant account must have the correct license. You need to make sure that any user that you want to enable premium audit for has an E5 or an E5 compliance user. Without one of these licenses, a user will be limited to the standard audit retention, which is about 90 days, and will not generate the advanced audit events. In other words, only licensed users get the benefit of one-year retention for audit logs. After confirming the license, you can also ensure that the auditing service is turned on for that user, but by default, when you apply an E5 license, that should be done. Let's have a look at how that works. But just before we do, remember that changes to licenses can take up to 24 hours to apply across the system. So once active, any new audited activities by that user will be kept for one year by default, instead of just 90 or 180 days. But if the user isn't licensed, their audit data will roll off after the short of a standard period.…
Contents
-
-
-
-
-
-
-
-
-
-
(Locked)
Learning objectives1m 16s
-
(Locked)
Assign Microsoft Purview Audit (Premium) user licenses2m 12s
-
(Locked)
Investigate activities by using Microsoft Purview Audit1m 51s
-
(Locked)
Configure audit retention policies3m 50s
-
(Locked)
Analyze Purview activities by using activity explorer3m 38s
-
(Locked)
Respond to data loss prevention alerts in the Microsoft Purview portal4m 29s
-
(Locked)
Investigate insider risk activities by using the Microsoft Purview portal5m 54s
-
(Locked)
Respond to Purview alerts in Microsoft Defender XDR3m 31s
-
(Locked)
Respond to Defender for Cloud Apps file policy alerts3m
-
(Locked)
Perform searches by using Content search3m 23s
-
(Locked)
-
-