Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Conduct hands-on examination of organization and user level audit settings for Exchange Online mailboxes #1433

Open
3 tasks
tkol2022 opened this issue Nov 18, 2024 · 0 comments
Assignees
Labels
hands-on-prototyping Reviewing an M365 feature by performing hands-on prototyping
Milestone

Comments

@tkol2022
Copy link
Collaborator

💡 Summary

Perform hands-on tests of Exchange Online mailbox audit settings to understand how each configuration behaves in practice and the relationships between settings. There are numerous mailbox audit settings at both the organizational level and the user level and it is unclear how they behave in practice. The output of this investigation will produce test results that will inform new secure configuration policies for Exchange Online #1072.

The scope of this testing covers the following settings:

  • Organization Level Setting: AuditDisabled
  • User Level Setting: AuditEnabled
  • User Level Setting: AuditBypassEnabled

Motivation and context

Without a hands-on test of all permutations of audit settings we won't know what the risks are and how to mitigate them with SCB policies.

Implementation notes

  • Create a spreadsheet with every combination of the three audit settings listed above.
  • Conduct a hands-on test of each combination and take note of how the system behaves in each state.
  • Generate log events for each combination and then examine the logs to see if the expected events produced log entries. Take note in the spreadsheet.
@tkol2022 tkol2022 added the hands-on-prototyping Reviewing an M365 feature by performing hands-on prototyping label Nov 18, 2024
@tkol2022 tkol2022 added this to the Kraken milestone Nov 18, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
hands-on-prototyping Reviewing an M365 feature by performing hands-on prototyping
Projects
None yet
Development

No branches or pull requests

2 participants