M365EXO-048: Audit log retention meets minimum (MS.EXO.17.3)

Platform
Entra ID / M365
Category
Advanced Threat Protection
Severity
Medium
Zero Trust pillar
Visibility & Analytics (weight 1)
Golden fixtures
1
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

SCuBA MS.EXO.17.3 requires that audit logs be retained for at least the minimum duration dictated by OMB M-21-31 (Appendix C), which calls for at least twelve months in active storage. Default retention may be shorter than required, and logs unavailable when needed prevent investigation of older incidents. An explicit audit log retention policy enforces the required duration.

Recommended value

An audit log retention policy retaining unified audit logs for at least 12 months in active storage (per OMB M-21-31 Appendix C)

Remediation

Create an audit log retention policy that retains unified audit logs for at least twelve months in active storage as required by OMB M-21-31 Appendix C, with additional cold storage retention as applicable. Confirm the tenant licensing supports custom audit retention (E5/G5 or add-on); where not licensed, track this as not assessed rather than passed. Validate the policy scope covers the relevant Exchange and unified audit log record types.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for M365EXO-048
ScenarioExpected verdict
not-implementedNot Assessed

Framework mappings

CISA SCuBA
MS.DEFENDER.6.3v1
NIST SP 800-53
AU-11
MITRE ATT&CK
T1070