M365 Audit Logs Zero Trust: The Microsoft 365 Audit Logs You’re Ignoring

M365 Audit Logs Zero Trust: The Microsoft 365 Audit Logs You’re Ignoring

(00:00:00) Zero Trust and Log Analysis
(00:00:21) The Importance of Continuous Monitoring
(00:00:37) Identity Verification: The First Line of Defense
(00:01:26) Risky Sign-Ins: The Early Warning Sign
(00:02:42) Combining Logs for Comprehensive Visibility
(00:05:44) The Power of Lateral Movement Detection
(00:07:51) Data Staging: The Next Stage of Attack
(00:12:53) The Critical Role of Retention Policies
(00:17:44) Copilot Interactions: A New Frontier in Detection
(00:24:00) Case Study: A Quiet Data Exfiltration

In this episode of M365.fm, Mirko Peters shows why Zero Trust without audit evidence is policy theater — and how to use Microsoft 365 audit logs to catch the quiet exfiltration and lateral movement your dashboards miss.

WHAT YOU WILL LEARN
  • Why a 12,000‑file SharePoint download in 20 minutes can pass every “green” Zero Trust check
  • How to fuse Entra ID sign‑in risk, Unified Audit Log events, Purview policy changes, and Copilot interactions into one coherent attack timeline
  • The difference between risky sign‑ins, risk detections, and workload identity anomalies — and why the retention gap matters
  • How to spot the three‑stream pattern that precedes most real data staging: risk, privilege change, and data surge
  • How to turn audit traces into KQL hunting queries, alerts, dashboards, and automation in Sentinel or Microsoft 365 Defender
  • Practical techniques for building per‑user baselines so you can see the difference between sync and staging
THE CORE INSIGHT

Zero Trust is not what you configure; it’s what actually happens — and you only see that in logs. Conditional Access can “succeed” while an attacker quietly replays tokens, stages data, and widens sharing scopes.
The real story starts when movement begins: inbox rules, mailbox forwarding, new sync relationships, sudden file surges, and “anyone” links — all stitched together by audit evidence.
This episode argues that if you’re not joining Entra risk, Unified Audit Log events, Purview changes, and Copilot logs, you don’t have Zero Trust — you have a policy slide deck.

WHY M365 AUDIT LOGS ARE YOUR REAL ZERO TRUST ENGINE
  • Entra ID sign‑in & risk provide the prologue: risky sign‑ins, risk detections, and anomalous tokens before any data moves
  • The Unified Audit Log traces lateral movement across Exchange, SharePoint, OneDrive, and Teams in one place
  • Purview audit and policy logs show when retention, labels, or DLP are quietly weakened before exfiltration
  • Copilot interaction logs reveal how attackers or insiders might weaponize AI to discover sensitive documents faster
  • Combined, these logs let you reconstruct “who did what, from where, with which privileges, to which data” — and build detections from that reality
PRACTICAL DETECTION PATTERNS YOU’LL HEAR
  • Repeated medium‑risk sign‑ins from new ASNs/IPs followed by SharePoint download bursts
  • Mailbox rule creation or forwarding changes paired with sudden OneDrive/SharePoint activity
  • New sync clients plus hundreds of unique files touched in a short time window
  • SharingLinkCreated events widening scope to “Anyone” or “Organization” right before or after file surges
WHO THIS EPISODE IS FOR

This episode is essential for Microsoft 365 security engineers, incident responders, SOC analysts, and cloud architects responsible for Zero Trust and data protection in M365.
If your tenant looks healthy in portals but you can’t explain how you’d spot a “clean” exfiltration case, this conversation will give you concrete queries, pivots, and patterns to fix that.

ABOUT THE HOST

Mirko Peters is a Microsoft 365 consultant and digital workplace architect focused on building attack‑aware, evidence‑driven security programs on the Microsoft cloud.
Through M365.fm, Mirko shares practical investigations, KQL approaches, and governance patterns that help security teams turn Microsoft 365 audit logs into the backbone of real Zero Trust

Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support.

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(857)

Microsoft Purview Insider Risk Management - Simply Explained

Microsoft Purview Insider Risk Management - Simply Explained

Welcome to another episode of Knowledge Nuggets with Mirko Peters. Today we're exploring Microsoft Purview Insider Risk Management, Microsoft's intelligent solution for identifying risky user behavior...

24 Juli 0s

Microsoft Purview Information Protection - Simply Explained

Microsoft Purview Information Protection - Simply Explained

Welcome to another episode of Knowledge Nuggets with Mirko Peters. Today we're exploring Microsoft Purview Information Protection, the foundation of Microsoft's data classification and protection stra...

24 Juli 0s

Microsoft Purview Data Loss Prevention (DLP) - Simply Explained

Microsoft Purview Data Loss Prevention (DLP) - Simply Explained

Welcome to another episode of Knowledge Nuggets with Mirko Peters. Today we're exploring Microsoft Purview Data Loss Prevention (DLP), one of the most important security capabilities in Microsoft 365 ...

24 Juli 0s

Microsoft Entra Private Access - Simply Explained

Microsoft Entra Private Access - Simply Explained

Welcome to another episode of Knowledge Nuggets with Mirko Peters. Today we're exploring Microsoft Entra Internet Access, Microsoft's modern cloud-native approach to secure internet connectivity that ...

24 Juli 0s

Microsoft Graph Delta Queries - Simply Explained

Microsoft Graph Delta Queries - Simply Explained

Welcome to another episode of Knowledge Nuggets with Mirko Peters. Today we're exploring Microsoft Graph Delta Queries, one of the most powerful features for building efficient synchronization solutio...

24 Juli 0s

Responsible AI Is Good Business — Featuring Wiebke Apitzsch

Responsible AI Is Good Business — Featuring Wiebke Apitzsch

Artificial intelligence is transforming every industry, but successful AI adoption requires far more than deploying the latest models or building autonomous agents. In this episode of M365.fm, Mirko P...

24 Juli 0s

Microsoft Graph Webhooks - Simply Explained

Microsoft Graph Webhooks - Simply Explained

Welcome to another episode of Knowledge Nuggets with Mirko Peters. Today we're exploring Microsoft Graph Webhooks, one of the core building blocks for creating modern, event-driven Microsoft 365 appli...

24 Juli 0s

Microsoft Graph Change Notifications - Simply Explained

Microsoft Graph Change Notifications - Simply Explained

Welcome to another episode of Knowledge Nuggets with Mirko Peters. Today we're exploring Microsoft Graph Change Notifications, one of the most important capabilities for building modern, event-driven ...

24 Juli 0s

Populärt inom Politik & nyheter

svenska-fall
p3-krim
aftonbladet-daily
aftonbladet-krim
rss-krimstad
flashback-forever
rss-sanning-konsekvens
tv4-nyheterna-story
rss-krimreportrarna
motiv
rss-frandfors-horna
mannen-utan-spar
rss-vad-fan-hande
de-fyras-gang
rss-flodet
spar
politiken
rss-aftonbladet-krim
olyckan-inifran
grans