M365EXO-047: Purview Audit (Premium) logging enabled (MS.EXO.17.2)

Platform
Entra ID / M365
Category
Advanced Threat Protection
Severity
Medium
Zero Trust pillar
Visibility & Analytics (weight 1)
Golden fixtures
1
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

SCuBA MS.EXO.17.2 requires that Microsoft Purview Audit (Premium) logging be enabled. Premium auditing adds high-value event types (such as MailItemsAccessed) and longer default retention that Standard does not include, materially improving visibility during an investigation. Premium auditing requires E5/G5 or equivalent add-on licensing.

Recommended value

Premium audit event types (e.g., MailItemsAccessed) and audit retention features enabled, subject to E5/G5 or add-on licensing

Remediation

Enable Microsoft Purview Audit (Premium) features so additional event types such as MailItemsAccessed are captured. Confirm the tenant carries the required E5/G5 licensing or compliance add-on; where not licensed, this control cannot be met and should be tracked as not assessed rather than passed. Validate that high-value audit events are being recorded after enabling.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for M365EXO-047
ScenarioExpected verdict
not-implementedNot Assessed

Framework mappings

NIST SP 800-53
AU-2, AU-3, AU-12
MITRE ATT&CK
T1114