I don’t know how many times I’ve discussed this topic before, but due to recent events, I'm bringing it up again: One of our customers experienced an Azure compromise - attackers gained unauthorized access to an account. The customer is a "cloud-only" organization that uses SharePoint and OneDrive for all document storage.
When we spoke with the customer's IT support technician, the first thing he said was:
"UAL (the Unified Audit Log) isn’t enabled. Why on earth can’t Microsoft just activate this proactively for all customers?"
He really struck a nerve with that statement. My team and I have preached time and again that everything else should be dropped immediately to run the following command:
Get-AdminAuditLogConfig
If the output says "AdminAuditLogEnabled : False", then it's overdue to enable UAL!
The Unified Audit Log tracks, among many other things, access to SharePoint and OneDrive. No UAL, no evidence.
George E. 🇺🇸♥🇺🇦🇵🇸🏳️🌈🏳️⚧️
in reply to Stephan Berger • • •