purview-audit
Installation
SKILL.md
Microsoft Purview Audit
Microsoft Purview Audit records user and admin activity across Microsoft 365 services and makes it searchable for security investigations, forensics, and compliance. It's the first thing the IR team reaches for and the first thing leadership wishes they had configured better.
When to use
Investigating incidents, supporting eDiscovery/compliance, and meeting regulatory logging requirements for Microsoft 365 services.
Do not use this skill for sign-in/identity logs (use Entra ID sign-in logs / Defender XDR) or for Azure resource activity (use Azure Activity Log via Sentinel).