Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

5.2.4. Querying Microsoft Purview Audit in Defender XDR

💡 First Principle: Some of the most sensitive audit-relevant activity — mailbox access, eDiscovery searches, admin actions across Microsoft 365 — is captured by Microsoft Purview Audit rather than Sentinel's own data connectors, and being able to query that audit trail directly from within Defender XDR closes a gap that would otherwise require switching tools mid-investigation.

Querying Microsoft Purview Audit in Defender XDR lets an analyst pull Microsoft 365 audit log activity into the same investigation surface used for broader security incidents, without needing separate access to the Purview compliance portal — useful when an incident under investigation in Defender XDR needs corroborating evidence from Microsoft 365 activity logs (a mailbox rule change, a sensitive file download) that live in Purview's audit system specifically.

⚠️ Exam Trap: Purview Audit and Sentinel's own log tables are separate data stores with separate query surfaces — a scenario emphasizing "audit trail of a specific mailbox permission change" is a Purview Audit question even in an otherwise Sentinel-and-Defender-XDR-focused investigation.

Reflection Question: Why does the ability to query Purview Audit directly from Defender XDR reduce investigation friction compared to needing to separately open the Purview compliance portal mid-incident?

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder18 professional certifications