M365EXO-046: Purview Audit (Standard) logging enabled (MS.EXO.17.1)
- Platform
- Entra ID / M365
- Category
- Advanced Threat Protection
- Severity
- High
- Zero Trust pillar
- Visibility & Analytics (weight 2)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
SCuBA MS.EXO.17.1 requires that Microsoft Purview Audit (Standard) logging, the unified audit log, be enabled. The unified audit log captures user and admin activity across Microsoft 365 and is foundational for incident response and threat detection. If unified audit log ingestion is disabled, activity evidence is not collected and investigations are severely hampered.
Recommended value
Unified audit log ingestion enabled (UnifiedAuditLogIngestionEnabled = True)
Remediation
Verify that unified audit log ingestion is enabled (UnifiedAuditLogIngestionEnabled = True) so user and admin activity is captured in the Microsoft 365 audit log. If disabled, enable it via the audit log configuration. Confirm logging is active by querying for recent events after enabling.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| throttled | Not Assessed |
Framework mappings
- CISA SCuBA
- MS.DEFENDER.6.1v1
- NIST SP 800-53
- AU-2, AU-3, AU-12
- MITRE ATT&CK
- T1562.008