LOG-02: Export Logs to Long-Term Storage
Frequently asked questions about implementing and managing the LOG-02 security control in Microsoft 365 and Entra ID.
QWhat is LOG-02 (Export Logs to Long-Term Storage)?▼
LOG-02 is a security control that default entra log retention is 30-90 days. apt attacks often go undetected for months. long-term retention enables forensic investigation of compromises that happened weeks or months ago. It requires that audit logs are exported to log analytics workspace or external siem and retention is configured for at least 1 year, sign-in logs and audit logs are both included.
QWhy is Export Logs to Long-Term Storage important for Microsoft 365 security?▼
Default Entra log retention is 30-90 days. APT attacks often go undetected for months. Long-term retention enables forensic investigation of compromises that happened weeks or months ago.
QHow do I implement LOG-02 in my tenant?▼
LOG-02 requires manual implementation. Requires Azure Monitor or external SIEM configuration
QWhat license do I need for LOG-02?▼
This control requires Azure AD Premium P1 (included in Microsoft 365 E3) or higher.
QWhich security baseline includes LOG-02?▼
LOG-02 is included in the Enhanced Security baseline (Level 2). This level adds stricter controls for security-conscious organizations.
5
Questions
1
Related Controls
—
Categorized
Related Resources
Still have questions?
Our security experts are here to help. Start a free trial and get personalized guidance for your Microsoft 365 environment.
Start Free Trial