LOG-01: Enable Unified Audit Logging
Frequently asked questions about implementing and managing the LOG-01 security control in Microsoft 365 and Entra ID.
QWhat is LOG-01 (Enable Unified Audit Logging)?▼
LOG-01 is a security control that without audit logs, you cannot detect compromises, investigate incidents, or meet compliance requirements. logs are your forensic evidence and early warning system. It requires that unified audit log is enabled in microsoft purview and sign-in logs are enabled in entra id, default retention (90 days for e3, 1 year for e5) is active.
QWhy is Enable Unified Audit Logging important for Microsoft 365 security?▼
Without audit logs, you cannot detect compromises, investigate incidents, or meet compliance requirements. Logs are your forensic evidence and early warning system.
QHow do I implement LOG-01 in my tenant?▼
LOG-01 requires manual implementation. Requires Microsoft Purview admin access - cannot be evaluated via Graph API
QWhat license do I need for LOG-01?▼
This control can be implemented with any Microsoft 365 subscription, including free Azure AD.
QWhich security baseline includes LOG-01?▼
LOG-01 is included in the TrueConfig Recommended Secure baseline (Level 1). This is the foundation level suitable for most organizations.
5
Questions
1
Related Controls
—
Categorized
Related Resources
Still have questions?
Our security experts are here to help. Start a free trial and get personalized guidance for your Microsoft 365 environment.
Start Free Trial