Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

5.4.3. Audit Solutions

💡 First Principle: Audit answers "what did users and admins actually do" by logging and making searchable a huge range of activities across Microsoft 365 — file access, sign-ins, admin configuration changes, mailbox activity — giving investigators an activity trail independent of the content itself.

This is the activity-focused counterpart to eDiscovery's content-focused search: an investigator might use eDiscovery to find a specific leaked document, then use Audit to determine exactly who accessed, downloaded, or forwarded that document and when — combining both answers "what happened" (audit) with "here's the evidence" (eDiscovery).

⚠️ Exam Trap: Audit logs and searches user and admin activity (actions taken); eDiscovery searches and preserves content (documents, emails, messages) — a scenario asking "who accessed this file" is testing Audit, not eDiscovery.

Reflection Question: An investigation needs to know both which specific document was leaked and exactly who downloaded it in the days before the leak. Which Purview capability answers each half of that question?

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder18 professional certifications