Instiq
Chapter 4 · Responding to security incidents·v1.0.0·Updated 8/6/2026·~12 min

What's changed: Created SC-200 Chapter 4 (Domain 2: Defender XDR incident investigation/remediation (coverage of Defender for Office 365/Purview/Defender for Cloud workload protections/Defender for Cloud Apps/Entra ID Protection/Defender for Identity/Sentinel); complex attacks (multistage/multi-domain/lateral movement)/attack story (incident graph)/embedded Microsoft Security Copilot (agentic AI)/case management; Defender for Endpoint response (device timeline/live response/investigation package collection/evidence-entity investigation/automatic attack disruption); M365 investigation (Purview Audit/Purview eDiscovery Content search/Microsoft Graph activity logs)).

4.4Investigating Microsoft 365 activities

Key points

Understand investigating threats from Microsoft 365 activities using Microsoft Purview Audit, Content search in Microsoft Purview eDiscovery, and Microsoft Graph activity logs.

Attackers operate inside M365 (mail, SharePoint, OneDrive, Teams). Analysts trace who accessed/did what via Purview and Graph logs.

4.4.1Purview Audit and eDiscovery

Microsoft Purview Audit provides activity audit logs of M365/Entra users/admins (who did what, when)—mail-item access, file sharing, role changes—core to breach investigation (Premium adds long retention and high-value events). Content search in Microsoft Purview eDiscovery searches across the content itself (mail/documents) to identify affected data (e.g., exfiltrated secrets). Use Audit for "records of actions," eDiscovery for "searching the content."

4.4.2Microsoft Graph activity logs

Microsoft Graph activity logs record Graph API calls against the tenant (which app/user accessed which resource via API). Use them to investigate OAuth-app abuse or suspicious API-based data access. These logs can be ingested into Sentinel and combined with analytics rules and hunting.

Exam point

Cues: "who did what, when (activity audit records)" = Purview Audit. "search content (mail/docs) to identify affected data" = eDiscovery Content search. "records of Graph API calls (OAuth-app abuse/API access)" = Microsoft Graph activity logs.

Warning

Watch the mix-ups: (1) Purview Audit (records of actions) vs eDiscovery Content search (searching the content). (2) Graph activity logs (API calls) differ from sign-in logs (authentication events). (3) High-value events and long retention may require Audit (Premium).

Diagram of Purview Audit (activity records: who did what when; Premium for long/high-value), eDiscovery Content search (search the content), and Microsoft Graph activity logs (API calls), combined with Sentinel.
Trace records and content

4.4.3Section summary

  • Purview Audit = M365/Entra activity audit records (who did what, when); Premium adds long retention/high-value events
  • eDiscovery Content search = search the content of mail/docs to identify affected data
  • Microsoft Graph activity logs = records of Graph API calls (investigate OAuth abuse/API access)

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. For breach investigation, you want activity audit records of "who accessed mail items and shared which files, when." Which is best?

Q2. You want to identify potentially exfiltrated sensitive documents by searching the content of mail and SharePoint. Which is best?

Q3. You want to investigate which resources a suspicious OAuth app accessed via the Graph API. Which is best?

Q4. Which correctly distinguishes Purview Audit from eDiscovery Content search?

Q5. Which correctly distinguishes Microsoft Graph activity logs from sign-in logs?

Check your understandingPractice questions for Chapter 4: Responding to security incidents

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.