How to generate email alert notification when Global admin or SharePoint administrator access to OneDrive for business file and folder for each user form Microsoft 365 Admin Center.

Kosal Yeang 20 Reputation points
2024-08-03T10:21:14.7733333+00:00

As a Global admin, I can access to OneDrive for Business file and folder of each user in my tenant when I go to Microsoft 365 Admin Center. I just notice that Global Admin user can access to file and folder of each user from this. This makes privacy concern from managment team, also compliance team as well.

User's image

I got question from compliance team, if there is any way that we can generate an email notification to inform user and compliance team when global admin access to OneDrive of each user? or can we disable this feature?

Can anyone tell me how can I full fill compliance team requirement?

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
4,864 questions
SharePoint
SharePoint
A group of Microsoft Products and technologies used for sharing and managing content, knowledge, and applications.
10,674 questions
Microsoft Purview
Microsoft Purview
A Microsoft data governance service that helps manage and govern on-premises, multicloud, and software-as-a-service data. Previously known as Azure Purview.
1,159 questions
OneDrive Management
OneDrive Management
OneDrive: A Microsoft file hosting and synchronization service.Management: The act or process of organizing, handling, directing or controlling something.
1,252 questions
0 comments No comments
{count} votes

Accepted answer
  1. Vasil Michev 1.1L Reputation points MVP
    2024-08-03T15:50:55.1166667+00:00

    Such actions are audited in the Unified audit log, which you can access as detailed here: https://learn.microsoft.com/en-us/purview/audit-search?tabs=microsoft-purview-portal

    In particular, you can search for the SiteCollectionAdminAdded event.

    For email alerting, you can use the good old Activity alerts feature, although Microsoft is trying to deprecate it for a while now. You can still find the relevant bits in the Security portal or use the New-ActivityAlert cmdlet directly.

    Or if you are exporting the Unified audit logs to external system, consider configuring alerting therein.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.