M365EXO-047: Purview Audit (Premium) logging enabled (MS.EXO.17.2)
- Platform
- Entra ID / M365
- Category
- Advanced Threat Protection
- Severity
- Medium
- Zero Trust pillar
- Visibility & Analytics (weight 1)
- Golden fixtures
- 1
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
SCuBA MS.EXO.17.2 requires that Microsoft Purview Audit (Premium) logging be enabled. Premium auditing adds high-value event types (such as MailItemsAccessed) and longer default retention that Standard does not include, materially improving visibility during an investigation. Premium auditing requires E5/G5 or equivalent add-on licensing.
Recommended value
Premium audit event types (e.g., MailItemsAccessed) and audit retention features enabled, subject to E5/G5 or add-on licensing
Remediation
Enable Microsoft Purview Audit (Premium) features so additional event types such as MailItemsAccessed are captured. Confirm the tenant carries the required E5/G5 licensing or compliance add-on; where not licensed, this control cannot be met and should be tracked as not assessed rather than passed. Validate that high-value audit events are being recorded after enabling.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| not-implemented | Not Assessed |
Framework mappings
- NIST SP 800-53
- AU-2, AU-3, AU-12
- MITRE ATT&CK
- T1114