What's changed: Created SC-100 Chapter 2 (Domain 2 first-half "Security operations": Defender XDR/Sentinel (SIEM)/XDR+SIEM integration/Defender for Endpoint, Identity, Office 365, Cloud Apps; SOAR/automation rules/playbooks (Logic Apps)/threat hunting (KQL)/UEBA; centralized logging/Microsoft Purview Audit (Standard, Premium)/multicloud monitoring/retention and isolation; MITRE ATT&CK (Enterprise/Mobile/ICS)/detection coverage/incident-response workflows).
2.3Centralized logging/auditing and multi-environment monitoring
Understand centralized logging and auditing including Microsoft Purview Audit, monitoring design supporting hybrid/multicloud, and approaches to log ingestion, retention, and isolation.
Detection, response, investigation, and compliance all rest on "trustworthy logs." Architects design what is recorded, where, for how long, and in a form no one can tamper with.
2.3.1Microsoft Purview Audit
Microsoft Purview Audit centrally records audit logs of user/admin activity across Microsoft 365/Entra. Audit (Standard) provides baseline logging; Audit (Premium) provides longer retention (extended by default) and high-value events crucial to breach investigation (e.g., access to mail items = MailItemsAccessed). Architects design the right Purview Audit tier and retention for "after an incident, trace how far back and what happened."
2.3.2Hybrid/multicloud monitoring
Monitoring extends beyond Microsoft. Microsoft Sentinel data connectors ingest AWS (CloudTrail/GuardDuty), GCP, and on-prem logs for org-wide correlation. Infrastructure configuration risk is evaluated across clouds by Microsoft Defender for Cloud, while threats are detected by Defender XDR/Sentinel. Architects organize design decisions for "log retention (cost vs investigation needs)," "tamper-resistant storage isolated from production," and "retention required by regulation."
Cues: "M365/Entra activity audit, high-value events for investigations, long retention" = Purview Audit (Premium). "Collect and correlate AWS/GCP/on-prem too" = Sentinel connectors. "Evaluate cloud configuration posture across clouds" = Defender for Cloud.
Watch the mix-ups: (1) Purview Audit (activity audit logs) and Sentinel (SIEM correlation/detection) are complementary—different roles. (2) Design logs for tamper-resistance, isolation, and retention—not just collection. (3) Balance compliance retention requirements with investigative practicality (cost).
2.3.3Section summary
- Purview Audit = M365/Entra activity audit; Premium adds long retention + high-value investigation events
- Multicloud monitoring = Sentinel connectors aggregate AWS/GCP/on-prem; Defender for Cloud evaluates configuration posture
- Design logs for tamper-resistance, isolation from production, and regulatory retention
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. To trace high-value events like mail-item access (MailItemsAccessed) over a long period for breach investigation, which is best?
Q2. To correlate AWS CloudTrail and on-prem firewall logs together with Microsoft 365 signals, which is best?
Q3. To evaluate cloud infrastructure configuration risk (posture) including AWS/GCP, which is best?
Q4. Which is the most important consideration in centralized logging design?
Q5. Which correctly states the relationship between Purview Audit and Microsoft Sentinel?

