M365AUDIT-003: Audit log search capability
- Platform
- Entra ID / M365
- Category
- Unified Audit & Logging
- Severity
- Medium
- Zero Trust pillar
- Visibility & Analytics (weight 1)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
The ability to effectively search and analyze audit log data is critical for security investigations, compliance audits, and incident response activities. Without verified search capability and trained personnel, audit log data that exists cannot be leveraged during time-sensitive security incidents. Organizations must ensure that audit log search tools are accessible, functional, and that response procedures include audit log analysis.
Recommended value
Audit log search accessible to security team; search queries tested and documented for common investigation scenarios; SIEM integration operational
Remediation
Verify that members of the security operations and incident response teams have the appropriate role assignments (Audit Logs or View-Only Audit Logs role) to search the unified audit log. Create and document standard search queries for common investigation scenarios such as mailbox compromise, unauthorized file access, and administrative privilege escalation. Test the audit log search functionality regularly and validate that SIEM integration is ingesting and indexing audit events correctly for automated detection and correlation.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| throttled | Not Assessed |
Framework mappings
- NIST SP 800-53
- AU-6