What's changed: Created SC-200 Chapter 4 (Domain 2: Defender XDR incident investigation/remediation (coverage of Defender for Office 365/Purview/Defender for Cloud workload protections/Defender for Cloud Apps/Entra ID Protection/Defender for Identity/Sentinel); complex attacks (multistage/multi-domain/lateral movement)/attack story (incident graph)/embedded Microsoft Security Copilot (agentic AI)/case management; Defender for Endpoint response (device timeline/live response/investigation package collection/evidence-entity investigation/automatic attack disruption); M365 investigation (Purview Audit/Purview eDiscovery Content search/Microsoft Graph activity logs)).
4.4Investigating Microsoft 365 activities
Understand investigating threats from Microsoft 365 activities using Microsoft Purview Audit, Content search in Microsoft Purview eDiscovery, and Microsoft Graph activity logs.
Attackers operate inside M365 (mail, SharePoint, OneDrive, Teams). Analysts trace who accessed/did what via Purview and Graph logs.
4.4.1Purview Audit and eDiscovery
Microsoft Purview Audit provides activity audit logs of M365/Entra users/admins (who did what, when)—mail-item access, file sharing, role changes—core to breach investigation (Premium adds long retention and high-value events). Content search in Microsoft Purview eDiscovery searches across the content itself (mail/documents) to identify affected data (e.g., exfiltrated secrets). Use Audit for "records of actions," eDiscovery for "searching the content."
4.4.2Microsoft Graph activity logs
Microsoft Graph activity logs record Graph API calls against the tenant (which app/user accessed which resource via API). Use them to investigate OAuth-app abuse or suspicious API-based data access. These logs can be ingested into Sentinel and combined with analytics rules and hunting.
Cues: "who did what, when (activity audit records)" = Purview Audit. "search content (mail/docs) to identify affected data" = eDiscovery Content search. "records of Graph API calls (OAuth-app abuse/API access)" = Microsoft Graph activity logs.
Watch the mix-ups: (1) Purview Audit (records of actions) vs eDiscovery Content search (searching the content). (2) Graph activity logs (API calls) differ from sign-in logs (authentication events). (3) High-value events and long retention may require Audit (Premium).
4.4.3Section summary
- Purview Audit = M365/Entra activity audit records (who did what, when); Premium adds long retention/high-value events
- eDiscovery Content search = search the content of mail/docs to identify affected data
- Microsoft Graph activity logs = records of Graph API calls (investigate OAuth abuse/API access)
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. For breach investigation, you want activity audit records of "who accessed mail items and shared which files, when." Which is best?
Q2. You want to identify potentially exfiltrated sensitive documents by searching the content of mail and SharePoint. Which is best?
Q3. You want to investigate which resources a suspicious OAuth app accessed via the Graph API. Which is best?
Q4. Which correctly distinguishes Purview Audit from eDiscovery Content search?
Q5. Which correctly distinguishes Microsoft Graph activity logs from sign-in logs?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

