Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
09Mitigate threats using Microsoft Purview4 modules · 42 units · DLP alerts, insider risk, Audit, eDiscovery, Defender XDR, and investigation workflows0/42 units complete
Learning path 09 · Mitigate threats using Microsoft Purview

4 modules · 42 units · DLP alerts, insider risk, Audit, eDiscovery, Defender XDR, and investigation workflows

0%

Study focus

Data risk response

Investigate DLP and insider-risk alerts, correlate evidence, remediate activity, and manage cases.

Evidence discovery

Search, validate, retain, and export evidence with Microsoft Purview Audit and eDiscovery.

4 modules · 42 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

03

Module 3

Search and investigate with Microsoft Purview Audit

Focus: Standard and Premium capabilities, audit configuration, searches, Copilot events, exports, PowerShell, and retention.
0/10
01 / 10Introduction

Purview Audit records user and administrator activities across Microsoft 365 for investigations, troubleshooting, security analysis, and regulatory evidence.

Official lessonAudit investigation objectives
02 / 10Microsoft Purview Audit overview
CapabilityStandardPremium
Search, CSV export, PowerShell, APIYesYes
Default retentionTypically 180 daysOne year for key workloads; otherwise standard defaults
Custom retention policiesNoYes; longer retention with licensing
High-value intelligent insights / higher API bandwidthNoYes

Retention and licensed features can change; verify the tenant's current entitlement before planning an investigation.

Official lessonStandard versus Premium
03 / 10Configure and manage Microsoft Purview Audit

Assign the least-privilege Audit role groups, verify auditing status, understand workload coverage and schema, and use portal, PowerShell, API, or Graph access as appropriate. Protect exported results as sensitive investigation data.

Official lessonPermissions and audit management
04 / 10Conduct searches with Audit (Standard)
  1. Define UTC time range, users, workloads, and activities.
  2. Name and run the search.
  3. Inspect operation, record type, actor, target, IP, and workload-specific fields.
  4. Refine filters or use Search-UnifiedAuditLog for scripted retrieval.
  5. Save or export results with investigation notes.

Broad searches can return incomplete-looking samples or require pagination; scope deliberately and preserve query parameters.

Official lessonPortal and PowerShell searches
05 / 10Audit Microsoft Copilot for Microsoft 365 interactions

Copilot and supported AI application interactions appear in the unified audit log with operations and record types such as Copilot interaction events. Relevant fields can include app, user, thread or session context, and accessed resources.

Audit records provide activity metadata, not necessarily full prompt and response content; interpret them alongside licensing, workload, and privacy requirements.

Official lessonCopilot audit events
06 / 10Investigate activities with Audit (Premium)

Premium supports longer retention and high-value events for forensic investigations, including granular mail access and search activity. Build a timeline, identify affected items and actors, correlate IP and session context, and distinguish normal application access from suspicious patterns.

Official lessonHigh-value forensic events
07 / 10Export audit log data

Export results to CSV for offline analysis or use PowerShell and APIs for repeatable, paginated collection. Preserve the search criteria, export time, timezone, row count, hashes where required, and access controls to support evidence integrity.

Official lessonExport and preserve audit evidence
08 / 10Configure audit retention with Audit (Premium)

Retention policies can scope audit records by user, record type, activity, duration, and priority. Higher-priority policies win when scopes overlap. Policies affect new records after creation; they do not retroactively extend existing expiration.

Align retention with investigation needs, legal obligations, licensing, data minimization, and storage or API strategy.

Official lessonRetention policies and priority
09 / 10Module assessment

Review Standard and Premium differences, roles, search filters, PowerShell, Copilot events, high-value records, CSV and API exports, retention scope, priority, and non-retroactive behavior.

Official assessmentPurview Audit knowledge check
10 / 10Summary

Purview Audit supports defensible investigations when access is governed, searches are reproducible, exports preserve context, and retention is planned before an incident occurs.

Official lessonModule summary
End of learning pathMitigate threats using Microsoft Purview