M365EXO-046: Purview Audit (Standard) logging enabled (MS.EXO.17.1)

Platform
Entra ID / M365
Category
Advanced Threat Protection
Severity
High
Zero Trust pillar
Visibility & Analytics (weight 2)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

SCuBA MS.EXO.17.1 requires that Microsoft Purview Audit (Standard) logging, the unified audit log, be enabled. The unified audit log captures user and admin activity across Microsoft 365 and is foundational for incident response and threat detection. If unified audit log ingestion is disabled, activity evidence is not collected and investigations are severely hampered.

Recommended value

Unified audit log ingestion enabled (UnifiedAuditLogIngestionEnabled = True)

Remediation

Verify that unified audit log ingestion is enabled (UnifiedAuditLogIngestionEnabled = True) so user and admin activity is captured in the Microsoft 365 audit log. If disabled, enable it via the audit log configuration. Confirm logging is active by querying for recent events after enabling.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for M365EXO-046
ScenarioExpected verdict
cleanPASS
known-badFAIL
throttledNot Assessed

Framework mappings

CISA SCuBA
MS.DEFENDER.6.1v1
NIST SP 800-53
AU-2, AU-3, AU-12
MITRE ATT&CK
T1562.008