365 defender audit log

Sksks0909 1 Reputation point
2022-08-11T06:54:46.447+00:00

I was wondering if there is any audit log for 365 defender admin activities.

Eg reviewing who previewed which email from threat explorer, who shared quarantined email with whom.

Cheers

Exchange | Exchange Server | Management
Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
{count} votes

2 answers

Sort by: Most helpful
  1. Limitless Technology 39,931 Reputation points
    2022-08-11T15:39:52.147+00:00

    Hi,

    You should be able to access the Defender logs via the Defender Portal:

    https://security.microsoft.com/

    I hope this answers your question.

    ---------------------------------------------------------------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept as answer--

    0 comments No comments

  2. Aholic Liang-MSFT 13,886 Reputation points Microsoft External Staff
    2022-08-16T09:55:42.367+00:00

    Hi @Sksks0909 ,
    As far as I know, you could view who accessed this mailbox by getting the audit logs or mailbox audit logs. However , you can't log which messages are previewed unless the user makes specific modifications to this message.

    who shared quarantined email with whom.

    I want to know if admin has assigned a quarantine policy to prevent users from managing their own quarantined phishing messages?
    Quarantine policies - Office 365 | Microsoft Learn

    231449-2022-8-16-4.png

    If not, I would suggest you could use Get-MessageTrace cmdlet to search message data for the last 10 days . Or use message trace in EAC to query mail flow within your organization.
    Message trace in the modern EAC in Exchange Online | Microsoft Learn


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.