5.4.3. Audit Solutions
💡 First Principle: Audit answers "what did users and admins actually do" by logging and making searchable a huge range of activities across Microsoft 365 — file access, sign-ins, admin configuration changes, mailbox activity — giving investigators an activity trail independent of the content itself.
This is the activity-focused counterpart to eDiscovery's content-focused search: an investigator might use eDiscovery to find a specific leaked document, then use Audit to determine exactly who accessed, downloaded, or forwarded that document and when — combining both answers "what happened" (audit) with "here's the evidence" (eDiscovery).
⚠️ Exam Trap: Audit logs and searches user and admin activity (actions taken); eDiscovery searches and preserves content (documents, emails, messages) — a scenario asking "who accessed this file" is testing Audit, not eDiscovery.
Reflection Question: An investigation needs to know both which specific document was leaked and exactly who downloaded it in the days before the leak. Which Purview capability answers each half of that question?