M365EXO-048: Audit log retention meets minimum (MS.EXO.17.3)
- Platform
- Entra ID / M365
- Category
- Advanced Threat Protection
- Severity
- Medium
- Zero Trust pillar
- Visibility & Analytics (weight 1)
- Golden fixtures
- 1
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
SCuBA MS.EXO.17.3 requires that audit logs be retained for at least the minimum duration dictated by OMB M-21-31 (Appendix C), which calls for at least twelve months in active storage. Default retention may be shorter than required, and logs unavailable when needed prevent investigation of older incidents. An explicit audit log retention policy enforces the required duration.
Recommended value
An audit log retention policy retaining unified audit logs for at least 12 months in active storage (per OMB M-21-31 Appendix C)
Remediation
Create an audit log retention policy that retains unified audit logs for at least twelve months in active storage as required by OMB M-21-31 Appendix C, with additional cold storage retention as applicable. Confirm the tenant licensing supports custom audit retention (E5/G5 or add-on); where not licensed, track this as not assessed rather than passed. Validate the policy scope covers the relevant Exchange and unified audit log record types.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| not-implemented | Not Assessed |
Framework mappings
- CISA SCuBA
- MS.DEFENDER.6.3v1
- NIST SP 800-53
- AU-11
- MITRE ATT&CK
- T1070