What's changed: Created SC-200 Chapter 4 (Domain 2: Defender XDR incident investigation/remediation (coverage of Defender for Office 365/Purview/Defender for Cloud workload protections/Defender for Cloud Apps/Entra ID ID Protection/Defender for Identity/Sentinel); complex attacks (multistage/multi-domain/lateral movement)/attack story (incident graph)/embedded Microsoft Security Copilot (agentic AI)/case management; Defender for Endpoint response (device timeline/live response/investigation package collection/evidence-entity investigation/automatic attack disruption); M365 investigation (Purview Audit/Purview eDiscovery Content search/Microsoft Graph activity logs)).
4.4Investigating Microsoft 365 activities
Understand investigating threats from Microsoft 365 activities using Microsoft Purview Audit, Content search in Microsoft Purview eDiscovery, and Microsoft Graph activity logs.
Attackers operate inside M365 (mail, SharePoint, OneDrive, Teams). Analysts trace who accessed/did what via Purview and Graph logs.
4.4.1Purview Audit and eDiscovery
Microsoft Purview Audit provides activity audit logs of M365/Entra users/admins (who did what, when)—mail-item access, file sharing, role changes—core to breach investigation (Premium adds long retention and high-value events). Content search in Microsoft Purview eDiscovery searches across the content itself (mail/documents) to identify affected data (e.g., exfiltrated secrets). Use Audit for "records of actions," eDiscovery for "searching the content."
4.4.2Microsoft Graph activity logs
Microsoft Graph activity logs record Graph API calls against the tenant (which app/user accessed which resource via API). Use them to investigate OAuth-app abuse or suspicious API-based data access. These logs can be ingested into Sentinel and combined with analytics rules and hunting.
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

