{"id":2143,"date":"2018-06-18T14:03:13","date_gmt":"2018-06-18T12:03:13","guid":{"rendered":"https:\/\/msb365.abstergo.ch\/?p=2143"},"modified":"2023-06-23T13:20:42","modified_gmt":"2023-06-23T11:20:42","slug":"enabling-audit-logs-in-office-365-security-and-compliance","status":"publish","type":"post","link":"https:\/\/www.msb365.blog\/?p=2143","title":{"rendered":"Enabling Audit Logs in Office 365 Security and Compliance"},"content":{"rendered":"<p>After an organization has deployed Office 365, the companies\u2019 administrator roles will be changed. Each company needs an administrator, who is responsible to track, what the company users are doing with E-Mails, Documents, SharePoint etc. for the various security and compliance reason of the organization.<\/p>\n<p>In the Office 365 admin center Microsoft has given us a feature, to be able to enable the audit logging for these tasks. Like always in this kind of topics, we can find this by Security & Compliance center.<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"alignnone size-full wp-image-2144\" src=\"https:\/\/msb365.abstergo.ch\/wp-content\/uploads\/2018\/06\/1-1.png\" alt=\"\" width=\"425\" height=\"569\" srcset=\"https:\/\/msb365.abstergo.ch\/wp-content\/uploads\/2018\/06\/1-1.png 425w, https:\/\/msb365.abstergo.ch\/wp-content\/uploads\/2018\/06\/1-1-224x300.png 224w\" sizes=\"(max-width: 425px) 100vw, 425px\" \/><\/p>\n<p>\u00a0<\/p>\n<p>If we browse in the Office 365 admin center to the security & compliance center, your browser will open a new TAB or windows with the security & compliance portal. Here you can find in the right menu the Widget <strong>Search for activity<\/strong>.<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-2145\" src=\"https:\/\/msb365.abstergo.ch\/wp-content\/uploads\/2018\/06\/2-2.png\" alt=\"\" width=\"1287\" height=\"315\" srcset=\"https:\/\/msb365.abstergo.ch\/wp-content\/uploads\/2018\/06\/2-2.png 1287w, https:\/\/msb365.abstergo.ch\/wp-content\/uploads\/2018\/06\/2-2-300x73.png 300w, https:\/\/msb365.abstergo.ch\/wp-content\/uploads\/2018\/06\/2-2-768x188.png 768w, https:\/\/msb365.abstergo.ch\/wp-content\/uploads\/2018\/06\/2-2-1024x251.png 1024w, https:\/\/msb365.abstergo.ch\/wp-content\/uploads\/2018\/06\/2-2-600x147.png 600w, https:\/\/msb365.abstergo.ch\/wp-content\/uploads\/2018\/06\/2-2-780x191.png 780w\" sizes=\"(max-width: 1287px) 100vw, 1287px\" \/><\/p>\n<p>\u00a0<\/p>\n<p>Note: if you cannot find it, go to the left corner on top and click on <strong>Customize<\/strong>:<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-2146\" src=\"https:\/\/msb365.abstergo.ch\/wp-content\/uploads\/2018\/06\/3-1.png\" alt=\"\" width=\"366\" height=\"157\" srcset=\"https:\/\/msb365.abstergo.ch\/wp-content\/uploads\/2018\/06\/3-1.png 366w, https:\/\/msb365.abstergo.ch\/wp-content\/uploads\/2018\/06\/3-1-300x129.png 300w\" sizes=\"(max-width: 366px) 100vw, 366px\" \/><\/p>\n<p>After that on <strong>Add<\/strong>\u00a0<strong>widget<\/strong> and take the right one to your home screen. Save it and continue with the next steps.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2147\" src=\"https:\/\/msb365.abstergo.ch\/wp-content\/uploads\/2018\/06\/4-1.png\" alt=\"\" width=\"684\" height=\"157\" srcset=\"https:\/\/msb365.abstergo.ch\/wp-content\/uploads\/2018\/06\/4-1.png 684w, https:\/\/msb365.abstergo.ch\/wp-content\/uploads\/2018\/06\/4-1-300x69.png 300w, https:\/\/msb365.abstergo.ch\/wp-content\/uploads\/2018\/06\/4-1-600x138.png 600w\" sizes=\"(max-width: 684px) 100vw, 684px\" \/><\/p>\n<p>\u00a0<\/p>\n<p>After we have started the recording, the security & compliance center will open a <strong>Start recording user and admin activities<\/strong> box. Now we continue with pushing <strong>Turn on<\/strong>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2148\" src=\"https:\/\/msb365.abstergo.ch\/wp-content\/uploads\/2018\/06\/5-1.png\" alt=\"\" width=\"789\" height=\"326\" srcset=\"https:\/\/msb365.abstergo.ch\/wp-content\/uploads\/2018\/06\/5-1.png 789w, https:\/\/msb365.abstergo.ch\/wp-content\/uploads\/2018\/06\/5-1-300x124.png 300w, https:\/\/msb365.abstergo.ch\/wp-content\/uploads\/2018\/06\/5-1-768x317.png 768w, https:\/\/msb365.abstergo.ch\/wp-content\/uploads\/2018\/06\/5-1-600x248.png 600w, https:\/\/msb365.abstergo.ch\/wp-content\/uploads\/2018\/06\/5-1-780x322.png 780w\" sizes=\"(max-width: 789px) 100vw, 789px\" \/><\/p>\n<p>\u00a0<\/p>\n<p>At this moment, we need to keep in our minds, that after starting this feature, we need to wait around 24 hours until it is fully provisioned. Knowing this I highly recommend, to start with the audit reporting\/audit processing after the feature is provisioned. To know the exact moment when the feature is active we can see it on our Security and Compliance Dashboard:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2149\" src=\"https:\/\/msb365.abstergo.ch\/wp-content\/uploads\/2018\/06\/6.png\" alt=\"\" width=\"294\" height=\"172\" \/><\/p>\n<p>\u00a0<\/p>\n<p>After some time we can browse in our Security and Compliance center to Search & investigation and then to Audit log search<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2150\" src=\"https:\/\/msb365.abstergo.ch\/wp-content\/uploads\/2018\/06\/7.png\" alt=\"\" width=\"298\" height=\"118\" \/><\/p>\n<p>\u00a0<\/p>\n<p>If you follow up this step too early, you will receive the following information:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2151\" src=\"https:\/\/msb365.abstergo.ch\/wp-content\/uploads\/2018\/06\/8.png\" alt=\"\" width=\"287\" height=\"54\" \/><\/p>\n<p>\u00a0<\/p>\n<p>After the successful provisioning, we will get the results and we are able to start to report our audits.<\/p>\n<p>\u00a0<\/p>\n<p>To get more information about the audit log search and the searching results, I can recommend you the link <a href=\"https:\/\/support.office.com\/en-us\/article\/Search-the-audit-log-in-the-Office-365-Security-Compliance-Center-0d4d0f35-390b-4518-800e-0c7ec95e946c?ui=en-US&rs=en-US&ad=US#auditlogevents\" target=\"_blank\" rel=\"noopener\">HERE<\/a> to follow up the Microsoft article on the official Microsoft page.<\/p>\n<p>\u00a0<\/p>\n<p>\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>After an organization has deployed Office 365, the companies\u2019 administrator roles will be changed. Each company needs an administrator, who is responsible to track, what the company users are doing with E-Mails, Documents, SharePoint etc. for the various security and compliance reason of the organization. In the Office 365 admin center Microsoft has given us [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2152,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_crdt_document":"","om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[1923],"tags":[],"class_list":["post-2143","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-365"],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/www.msb365.blog\/index.php?rest_route=\/wp\/v2\/posts\/2143","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.msb365.blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.msb365.blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.msb365.blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.msb365.blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2143"}],"version-history":[{"count":6,"href":"https:\/\/www.msb365.blog\/index.php?rest_route=\/wp\/v2\/posts\/2143\/revisions"}],"predecessor-version":[{"id":5227,"href":"https:\/\/www.msb365.blog\/index.php?rest_route=\/wp\/v2\/posts\/2143\/revisions\/5227"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.msb365.blog\/index.php?rest_route=\/wp\/v2\/media\/2152"}],"wp:attachment":[{"href":"https:\/\/www.msb365.blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2143"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.msb365.blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2143"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.msb365.blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2143"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}