MicrosoftMicrosoft Purview

    Audit

    Comprehensive audit logging across Microsoft 365 for investigation and compliance.

    Microsoft Purview Audit provides comprehensive logging of user and admin activity across Microsoft 365 — search, retention, and access to audit records for security investigations, forensics, and compliance. Audit Premium adds longer retention and high-value events for deeper investigation. Faltrox operates it as managed audit and forensic readiness.

    Overview

    What Audit is

    When something goes wrong — a breach, an insider incident, a compliance question — you need a reliable record of who did what and when. Microsoft Purview Audit provides that: comprehensive logging of user and administrator activity across Microsoft 365, searchable for investigation and retained for compliance.

    It records a wide range of activities across Exchange, SharePoint, Teams, Entra ID, and more, with search to investigate specific events, and retention policies to keep records as long as needed. Audit Premium adds longer default retention, high-value crucial events (like mail access), and higher bandwidth for investigations — key for forensic depth after an incident. Faltrox operates it as managed audit and forensic readiness, ensuring the records are there and searchable when needed.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    User & Admin Activity

    Logs user and administrator activity across Microsoft 365 workloads.

    02

    Investigation

    Search audit records to investigate specific security and compliance events.

    03

    Retention

    Retains audit records as long as compliance and investigation require.

    04

    Forensics

    Provides the record needed for forensic investigation after an incident.

    05

    High-Value Events

    Audit Premium adds crucial events like mail access for deeper investigation.

    06

    Compliance

    Supports compliance requirements for audit logging and retention.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Log

      User and admin activity across Microsoft 365 workloads is logged comprehensively.

    2. 02

      Retain

      Retention policies keep audit records as long as compliance and investigation require.

    3. 03

      Search

      Analysts search audit records to investigate specific events and reconstruct activity.

    4. 04

      Investigate

      Audit Premium high-value events add the depth needed for forensic investigation.

    5. 05

      Operate

      Faltrox ensures the records are captured, retained, and searchable as managed audit readiness.

    Capabilities

    Key capabilities

    Comprehensive Logging

    Logs user and admin activity across Exchange, SharePoint, Teams, Entra ID, and more.

    Audit Search

    Search audit records to investigate specific events across the estate.

    Retention Policies

    Retains audit records as long as compliance and investigation require.

    High-Value Events

    Audit Premium adds crucial events like mail access for deeper investigation.

    Longer Retention

    Audit Premium extends default retention for forensic and compliance needs.

    Investigation Bandwidth

    Higher bandwidth for investigations during an incident.

    Forensic Readiness

    Provides the record needed for forensic investigation after an incident.

    Purview Integration

    Part of the unified Microsoft Purview compliance platform.

    Works with

    Part of the platform

    Microsoft products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Microsoft Audit for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01Why is audit logging important?

    Because when a breach, insider incident, or compliance question arises, you need a reliable record of who did what and when. Purview Audit provides comprehensive, searchable logging across Microsoft 365 — the forensic and compliance record that makes investigation possible.

    02What does Audit Premium add over Standard?

    Longer default retention, high-value "crucial events" (like mail-item access, which is key to understanding what an attacker read), and higher bandwidth for investigations — the depth needed for serious forensic investigation after an incident.

    03What activity does it log?

    A wide range of user and administrator activity across Microsoft 365 workloads — Exchange, SharePoint, Teams, Entra ID, and more — so you have visibility into the actions that matter for security and compliance investigations.

    04How does it support forensics after an incident?

    It provides the record needed to reconstruct what happened — which accounts did what, what was accessed, when — and Audit Premium’s crucial events (like mail access) are often decisive in understanding the scope of a compromise. Faltrox ensures those records are retained and searchable.

    05How does Faltrox operate it?

    We ensure the right audit logging and retention are in place, and use the records for investigation and forensics as part of the SOC and incident-response services we run — delivering managed audit and forensic readiness.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us