Transcription
[ Music ]
JEAN-FRANCOIS BILODEAU: Picture this, a sensitive file leaves your organization, nobody realizes it until a week later, and now you're piecing together what happened with incomplete evidence and a ticking clock. In security operation, those moments are exactly when you need fast answers: what data was exposed, who touched it, and what to do next. Let me introduce you to a session where we'll learn how to tackle these real-world scenarios using Microsoft Purview and connected investigation tools. Hello, and welcome, we're glad you've joined us. I am Jean-Francois Bilodeau, a Microsoft Technical Trainer.
In this session, let's explore Learning Path 3, Mitigate Threat Using Microsoft Purview. Together, we'll walk through how security operation analysts can support compliance and investigation workflows, starting with data loss prevention alerts, moving into insider risk management, and then using eDiscovery and Auditing to investigate, validate, and export the evidence you need. So, let's get started with this session.
Here, we set the stage for the bigger mission: defending against cyberthreats using Microsoft Security Operations platform. The goal isn't just to detect threats; it's to investigate them efficiently, connect security signals together, compliance, evidence, and take action with confidence when data or users are at risk. Let's take a look at what we'll cover. We'll begin with Microsoft Purview Compliance Solution, then move into investigating and remediating compromised entities identified by Microsoft Purview data loss prevention policies. From there, we'll explore how to investigate and remediate insider risk threats identified by Microsoft Purview policies. Next, we'll shift into investigation techniques using Microsoft Purview eDiscovery Content Search. And then, we'll finish with investigation using Microsoft Purview Audit, first Audit Standard, then we'll move into Audit Premium.
Here, we transition into Microsoft Purview Compliance Solutions capabilities, designed to help organizations protect sensitive information, meet regulatory obligations, and investigate issues when something goes wrong. For security operation analysts, like us, the key is understanding how these tools complement security detection with compliance-grade evidence and control. To access these compliance capabilities, you'll work with the Microsoft Purview portal at purview.microsoft.com. From this centralized portal, you can navigate into areas like data loss prevention, insider risk management, eDiscovery, and Audit, each one supporting a different part of the investigation and response life cycle.
Let's clarify how security operation analysts often partner with compliance and eDiscovery administrators. One major area is eDiscovery, especially "Content Search," which supports finding and exporting relevant electronic information that may be needed as evidence in legal or in internal cases. Another key area is auditing. Microsoft Purview auditing solutions provides an integrated way to capture and review user and administrator activity, helping organizations respond to security events, support forensic investigations, and run internal investigations. We also have information protection where data loss prevention, DLP, helps organizations prevent users from inappropriately sharing sensitive information such as financial data, proprietary data, credit card numbers, health records, or Social Security numbers. And finally, insider risk management correlates a variety of signals to identify potential malicious or inadvertent insider risk, like intellectual property theft, data leakage, or security violations so teams can detect and contain issues before they grow.
Now, we shift into the first investigation module, using Microsoft Purview DLP policies to identify compromised entities and then remediate the situation. The key theme is turning a DLP signal, like sensitive data exposure, into a clear investigation path and actionable next steps. After completing this module, you should be able to do three things: first, describe the key data loss prevention component in Microsoft Purview; second, investigate DLP alerts directly in the Microsoft Purview compliance center; and finally, investigate DLP alerts in Microsoft Defender for Cloud Apps, which is especially useful when you're looking at cloud app activities and file-related controls. With a DLP policy, you can identify sensitive information and prevent the accidental sharing of that information. You can also monitor and protect sensitive content directly into desktop versions of Excel, PowerPoint, and Word, so protection isn't limited to the web. Another important benefit is agitation without disruption. DLP can help users learn how to stay compliant while keeping their workflow moving. And from the investigation site, you can view DLP alerts and reports that show content matching your organization's DLP policy, giving you evidence you can act on. To understand how those alerts are generated, it helps to know the core components involved: sensitive information type, sensitivity labels, and the data loss prevention policy itself, and finally, in Cloud Apps scenarios, a Defender for Cloud Apps file policy.
Here, we look at investigating DLP alerts directly into Microsoft Purview. When an alert is triggered, you can review what content matched the policy, which location it occurred in, which user was involved, and what actions were taken, so it can quickly determine whether this was an accident, a risky pattern, or a potential compromise that needs escalation. Next, let's take a look at investigating DLP alerts inside Microsoft Defender XDR. A practical approach is to create and apply an alert filter where the category is set to "data loss prevention." This helps you quickly pivot from the broader incident queue into the subset of alerts tied to a sensitive data exposure. And it's worth remembering that Defender for Cloud Apps and Cloud Apps alerts are consolidated into Microsoft Defender XDR. So, this becomes a central place to triage and correlate Cloud Apps related DLP activities alongside other security signals.
Now, we move from accidental data exposure into a different category of risk, insider risk. Here, the objective is to investigate and remediate threats identified by Microsoft Purview insider risk policy, whether the behavior is malicious, negligent, or simply high risk in context. After completing this module, you'll be able to explain how insider risk management in Microsoft Purview helps prevent, detect, and contain internal risks in an organization. You'll also be able to describe the built-in predefined policy templates, list the prerequisites that must be met before you can create insider risk policies, and explain the kind of action you can take when you're working an insider risk management case. Insider risk management is designed to help you address the type of risk and violations that can come from within the organization. That can include intentional misuse, like data theft, or unintentional actions, like accidental leaks or policy violations. The value here is correlation. Instead of looking at one isolated incident, insider risk management brings signals together to highlight patterns that deserve investigation.
Here, we walk through the workflow used by Microsoft 365 to identify and resolve internal risk activities and compliance issues with insider risk management. The workflow focuses on moving from signals to indicator into policy detection, then into triage and investigation, and finally, into taking appropriate action to resolve the risk while aligning to privacy and compliance expectations. Managing insider risk policies starts with choosing the right policy template. Common templates include departing employees data theft, data leaks, and currently preview security policy violations, health record misuse, and risky browser usage. Once you select a template, you can configure policy settings such as privacy indicators, the timeframe the policy should evaluate, and the intelligent detection used to identify risky behavior with the right balance of visibility and privacy.
Now, let's turn to eDiscovery, specifically how to search for content using Microsoft Purview. This capability is critical when an investigation requires you to find, preserve, and potentially export content across Microsoft 365 services in a way that supports compliant and legal defensibility. In this module, the learning objectives are straightforward. You'll learn how to assign the role and permission required to access Microsoft Purview eDiscovery, how to create and manage keys used to run eDiscovery searches, how to define search scope and build queries using conditions, keywords, and Copilot-generated prompts, and finally, how to run searches and validate results using statistics or random samples.
Let's define what eDiscovery is and how it compares to Content Search. eDiscovery is a tool in the Microsoft Purview portal that lets you search for content, place hold, and export content. Access is limited to users who have assigned the right role, typically eDiscovery managers or eDiscovery administrators, and licensing impacts which feature you can use, with Core eDiscovery included in E3 and E5. You'll use eDiscovery for internal investigations like HR cases, or suspected data misuse, as well as legal and regulatory requests, data subject rights requests, and incident responses or breach reviews. The big idea is that eDiscovery helps security and compliance teams find, preserve, and export content during investigations, legal inquiries, or incident responses. It's also important to use eDiscovery as more than a simple search feature. While Content Search can retrieve data quickly, it doesn't provide the same auditability and access control that eDiscovery provides. eDiscovery, on the other hand, is designed for secure, auditable searches tied to a formal case with role-based permission.
On to the licensing side. Core eDiscovery is available in E5, and advanced eDiscovery, often referred to as "Premium," adds capabilities like custodian holds, legal hold notifications, and built-in review sets. Even if you're not using the premium tier, understanding the difference helps you assess what your environment can support. A helpful way to internalize this is to think through a real-world investigation, like a phishing attack or an insider leak, where you create a case, run a search, and export results for review.
Before you can use eDiscovery access, you have to explicitly assign it to ensure the investigation remains secure and auditable. The required roles are typically eDiscovery managers who can create and manage cases, search and export, and eDiscovery administrators who have all the manager permissions plus the ability to manage role assignments and control settings. To assign these roles, you go to the Microsoft Purview portal, then you navigate to "Settings," "Roles and Scope," and "Role Groups," and add users to the appropriate role group. To confirm access, you can navigate into eDiscovery in the portal. If the user has the correct role and license, the "Create Case" page should appear. A key operational point is that access is scoped intentionally. Even if someone has an eDiscovery tool, they may only see their case they're a member of, which supports least privileged access and keeps unrelated investigations separated. This also helps with common troubleshooting during hands-on work. If someone can't see anything, it's usually because they're missing either the role assignment or the case membership.
In Microsoft Purview eDiscovery, every search is created within a case. The case acts as a secure, auditable workspace for managing the investigation. That requirement matters because it enforces access control, keeps a consistent investigation structure, and ensures every action—searching, accessing, exporting—is logged in the context of the case. Only members of a case can access it, even if they're on an eDiscovery role, and when somebody else creates the case, they're automatically added as a member. To create a search, you go to the eDiscovery open cases, and then select "Create Search." You provide the case name and the search name, and in a single step, Purview creates both the case and the search. This case structure is what makes eDiscovery legally defensible. It provides a container where investigation diligence and data integrity can be demonstrated if the results ever need to stand up to scrutiny.
Now, let's walk through conducting a search. The purpose is to locate content across Microsoft 365 services that's relevant to a security incident, a regulatory request, or an internal investigation. You start by defining the criteria in your search, set the filter using keywords or conditions such as date, sender, or content type, then you select your data source—user, group, site, or even broader tenant-wide sources—depending on whether you want to narrow the scope or cast a wider net. Next, you build a query logic. You can use the condition builder if you prefer a guided experience, write KQL for more advanced filtering, or where possible, try Copilot or "Search by File" in Purview to generate or accelerate the search logic. After you've run the search, you review settings, using statistics, how many items match, or a sample to validate relevance before you explore. From there, you refine and rerun as needed. A practical best practice is to avoid scoping too broadly at the start, because that creates review overload. Instead, start small, validate, and then expand only when the evidence tells you to.
Once you have the right results, the next step is exporting them along with metadata. For investigation documentation, legal review, or external handoff, you start an export by selecting a completed search from the search step and choosing what to export, such as index items, partially indexed items, or both, then you configure options for workloads like OneDrive, SharePoint, Exchange, Teams. For example, whether to include version history, include threaded messages, or cloud attachments. You can choose the output format you want to use, PST or MSG, along with a folder structure and friendly naming. As the export runs, you track status and details in the process manager. When it's ready, you go to the "Export" tab, review the export overview, and download the package along with reports. This step matters for a chain of custody. Export packages can include original format and metadata, and they're typically delivered as secure packages with manifest and logs. Hashes and export identifiers help demonstrate integrity, showing the data hasn't been modified, while secure, time-limited download links help protect the export during transfer.
Now, we move into Microsoft Purview Audit, which is all about understanding activities across Microsoft 365: who did what, when, and where. Audit data becomes critical evidence for incident response, compliance, verification, and deeper investigation where you need a reliable activity trail. In this module, you'll learn how to identify the difference between Microsoft Purview Audit Standard and Audit Premium, configure Microsoft Purview Audit for optimal log management, and perform audits to assess compliant and security measures. You'll also learn how to analyze irregular access patterns using advanced tools available in Audit Premium and PowerShell, and how strategic data management supports regulatory compliance.
Microsoft Purview Audit helps organizations understand how Microsoft 365 is being used by capturing user and admin activity. That visibility supports security investigation, compliance requirements, and operational transparency. Audit Standard is enabled by default, providing 180-day log retention that can be accessed through the portal, PowerShell, and API, and supports exporting results in CSV. Audit Premium extends those capabilities with custom retention policies, a default one-year retention for core services, intelligence insights into activity patterns, and higher API bandwidth for advanced integrations. Together, these options give organizations flexibility for day-to-day needs as well as longer-term investigation and regulatory requirements.
To put that in context, Audit Standard is ideal for general visibility, tracking basic activities like sign-in, file modification, or sharing events. Audit Premium, on the other hand, is where you get forensic depth for longer-term or higher-risk investigations, including scenarios where you need to know whether a sensitive message was actually accessed. It's also important to remember that Premium capabilities depend on licensing, such as Microsoft 365 E5, or E5 Compliance, or an equivalent add-on. So, you only see these features if your environment is entitled to them.
Now, let's take a look at configuration and management. If auditing isn't already enabled, you can turn it on through the Purview portal or by running the "Set-AdminAuditLogConfig" cmdlet in PowerShell. You also need to verify licensing. Audit Standard is included in Microsoft 365 E3 and E5, as well as F1 and F3, and in Office 365 E1, E3, and E5. Audit Premium requires Microsoft 365 E5, E5 Compliance, or relevant add-on. Finally, roles determine who can work with audit logs. An audit reader can search and export logs, while an audit manager can search and explore but also manage audit settings. Even if someone is a global admin, they still need the right role assignment in Purview to access logs. A good investigation habit is to confirm Audit is enabled early, because if logging wasn't on, then there may be no way to have an activity trail to follow.
Audit Standard provides the tools needed to search, manage, and analyze activity across Microsoft 365, helping organizations respond to incidents and meet compliance requirements. You can search audit logs using the Microsoft Purview portal or "Search-UnifiedAuditLog" cmdlet. As you search, you filter by activity type, user, file or site, date range, workload, and you can export results or access logs through an API for automation. As results come in, you can monitor job progress, drill into detailed results, and filter by action, user, IP address, record type, or item detail. One practical limitation to keep in mind is export scale and standard. Exports are limited, so this tier is best for focused queries rather than large-scale analysis. Conceptually, audit logs help you tell the story of an incident, and what you find depends on what you asked. So, it's important to choose filters that align to the activity you expect to see.
Audit Premium, on the other hand, provides deeper visibility into user activity, which helps you investigate sensitive access, detect suspicious behavior, and respond to incidents. A classic example is investigating email access using the mail send access activity. This can show which messages were accessed, by whom, and from where within an activity. Bind access logs individual emails used, while sync access logs bulk downloads, such as when a mailbox is synchronized to Outlook. There are also practical considerations, like throttling. Logging pauses after 1,000 binding events per day per mailbox, and duplicate entries are filtered automatically to reduce noise. You can analyze these events in the Purview portal or use PowerShell when you need advanced filtering, and exporting to CSV helps to review access type and throttling details into the raw audit log. This is where audit becomes truly forensic, helping answer a question like whether a departing employee viewed a sensitive message, not just whether something was downloaded.
Exporting audit logs to CSV supports deeper analysis and helps meet compliance requirements. The process starts by running a search in the Microsoft Purview portal, and then selecting "Export" to download up to 50,000 audit records as a CSV file. For analysis, you can open the CSV in Excel using Data, then from Text/CSV, and use Power Query Editor to transform the audit data columns from JSON into readable columns. From there, you expand the properties you care about, such as IP address, access type, item detail, so you can focus on what's relevant. This is especially useful when you need to correlate events across services or identify anomalies such as unusual access during non-business hours.
Audit retention is a major part of meeting regulatory and investigation requirements. With Audit Premium, you get custom retention policies that control how long audit data is kept. By default, Premium provides a one-year retention for Exchange, SharePoint, OneDrive, and Microsoft Entra ID. That default policy can't be changed, but custom policies get overwritten for specific needs. With custom retention policies, you can create up to 50 policies scoped to specific users, record types, or activities, and retain data from seven days all the way up to 10 years, although a 10-year retention requires an add-on license. One important operational detail is that retention is determined at the time data is logged. So, changes apply only to new data going forward. From a risk perspective, longer retention increases resilience from slow-developing incidents and helps in regulated industries where investigations or audits may look back years.
Let's recap what we've covered in this module. We examined the difference between Microsoft Purview Audit Standard and Microsoft Purview Audit Premium, how to search for audited activities using Microsoft Purview Audit, and how to implement audit log searching in practice. We also discussed how audit log searches can help investigate common support issues and how Audit Premium builds on the capabilities of Audit Standard to enable deeper investigation. Finally, we covered how to create audit log prevention policies, and how auditing supports forensic investigation of compromised user accounts.
Now, let's see Microsoft Purview in action in a short demo. Let's learn how to start an audit in Purview. We're currently in Microsoft Defender, but let's access Purview from here. From the Defender bar, let's move down to "More Resources." This gives us access to links to additional portals, including the Microsoft Purview portal. Let's open it. Now, when we open it, it will tell us that the old compliance portal is retired. Let's manually switch to the new portal. And here we are in the Microsoft Purview portal. The only thing we're going to do over here is explore how to start an audit and basic search. Let's go into "Solutions," "Audit." There's our button, "Start recording user and admin activity." We'll start that. It will take a moment or two to start the audit, and from that point forward, after we've captured enough information, we can start querying and create cases as necessary.
Let's wrap up with a quick Learning Path recap. We've covered how Microsoft Purview provides compliance solutions to mitigate threats. We discussed "Content Search" as a key feature within Microsoft Purview eDiscovery, and also looked at Microsoft Purview Audit Solution, including both Audit Standard and Audit Premium. You saw that Audit Standard is enabled by default and provides the ability to log and search for audited activities, and that Audit Premium builds on that foundation by providing advanced auditing functionality for deeper investigations and longer-term requirements. And this completes our session. There are many ways to continue your learning journey. We encourage you to watch other videos in Discourse or search out your next favorite topic on Microsoft Learn at aka.ms/learn.