Audit
Comprehensive audit logging across Microsoft 365 for investigation and compliance.
Microsoft Purview Audit provides comprehensive logging of user and admin activity across Microsoft 365 — search, retention, and access to audit records for security investigations, forensics, and compliance. Audit Premium adds longer retention and high-value events for deeper investigation. Faltrox operates it as managed audit and forensic readiness.
Overview
What Audit is
When something goes wrong — a breach, an insider incident, a compliance question — you need a reliable record of who did what and when. Microsoft Purview Audit provides that: comprehensive logging of user and administrator activity across Microsoft 365, searchable for investigation and retained for compliance.
It records a wide range of activities across Exchange, SharePoint, Teams, Entra ID, and more, with search to investigate specific events, and retention policies to keep records as long as needed. Audit Premium adds longer default retention, high-value crucial events (like mail access), and higher bandwidth for investigations — key for forensic depth after an incident. Faltrox operates it as managed audit and forensic readiness, ensuring the records are there and searchable when needed.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
User & Admin Activity
Logs user and administrator activity across Microsoft 365 workloads.
Investigation
Search audit records to investigate specific security and compliance events.
Retention
Retains audit records as long as compliance and investigation require.
Forensics
Provides the record needed for forensic investigation after an incident.
High-Value Events
Audit Premium adds crucial events like mail access for deeper investigation.
Compliance
Supports compliance requirements for audit logging and retention.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Log
User and admin activity across Microsoft 365 workloads is logged comprehensively.
- 02
Retain
Retention policies keep audit records as long as compliance and investigation require.
- 03
Search
Analysts search audit records to investigate specific events and reconstruct activity.
- 04
Investigate
Audit Premium high-value events add the depth needed for forensic investigation.
- 05
Operate
Faltrox ensures the records are captured, retained, and searchable as managed audit readiness.
Capabilities
Key capabilities
Comprehensive Logging
Logs user and admin activity across Exchange, SharePoint, Teams, Entra ID, and more.
Audit Search
Search audit records to investigate specific events across the estate.
Retention Policies
Retains audit records as long as compliance and investigation require.
High-Value Events
Audit Premium adds crucial events like mail access for deeper investigation.
Longer Retention
Audit Premium extends default retention for forensic and compliance needs.
Investigation Bandwidth
Higher bandwidth for investigations during an incident.
Forensic Readiness
Provides the record needed for forensic investigation after an incident.
Purview Integration
Part of the unified Microsoft Purview compliance platform.
Works with
Part of the platform
Microsoft products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Microsoft Audit for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01Why is audit logging important?
Because when a breach, insider incident, or compliance question arises, you need a reliable record of who did what and when. Purview Audit provides comprehensive, searchable logging across Microsoft 365 — the forensic and compliance record that makes investigation possible.
02What does Audit Premium add over Standard?
Longer default retention, high-value "crucial events" (like mail-item access, which is key to understanding what an attacker read), and higher bandwidth for investigations — the depth needed for serious forensic investigation after an incident.
03What activity does it log?
A wide range of user and administrator activity across Microsoft 365 workloads — Exchange, SharePoint, Teams, Entra ID, and more — so you have visibility into the actions that matter for security and compliance investigations.
04How does it support forensics after an incident?
It provides the record needed to reconstruct what happened — which accounts did what, what was accessed, when — and Audit Premium’s crucial events (like mail access) are often decisive in understanding the scope of a compromise. Faltrox ensures those records are retained and searchable.
05How does Faltrox operate it?
We ensure the right audit logging and retention are in place, and use the records for investigation and forensics as part of the SOC and incident-response services we run — delivering managed audit and forensic readiness.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us