nerdexam
Microsoft

SC-401 · Question #206

You have a Microsoft 365 subscription linked to a Microsoft Entra tenant that contains a user named User1. You need to grant User1 permission to search Microsoft 365 audit logs. The solution must…

The correct answer is C. the View-Only Audit Logs role in the Exchange admin center. The View-Only Audit Logs role in the Exchange admin center is the least-privilege role that grants the specific permission needed to search the Microsoft 365 unified audit log.

Manage risks, alerts, and activities

Question

You have a Microsoft 365 subscription linked to a Microsoft Entra tenant that contains a user named User1. You need to grant User1 permission to search Microsoft 365 audit logs. The solution must use the principle of least privilege. Which role should you assign to User?

Options

  • Athe Compliance Management role in the Exchange admin center
  • Bthe Security Reader role in the Microsoft Entra admin center
  • Cthe View-Only Audit Logs role in the Exchange admin center
  • Dthe Reviewer role in the Microsoft Purview portal

How the community answered

(40 responses)
  • A
    10% (4)
  • B
    3% (1)
  • C
    83% (33)
  • D
    5% (2)

Why each option

The View-Only Audit Logs role in the Exchange admin center is the least-privilege role that grants the specific permission needed to search the Microsoft 365 unified audit log.

Athe Compliance Management role in the Exchange admin center

The Compliance Management role grants extensive administrative control over compliance features across Microsoft Purview and far exceeds the least-privilege requirement for simply searching audit logs.

Bthe Security Reader role in the Microsoft Entra admin center

The Security Reader role in Microsoft Entra provides read access to Entra security information but does not grant permission to search the Microsoft 365 unified audit log in the Purview portal.

Cthe View-Only Audit Logs role in the Exchange admin centerCorrect

The View-Only Audit Logs role, assigned through the Exchange admin center compliance role groups, grants read-only access to search and review Microsoft 365 unified audit logs in the Microsoft Purview portal. It satisfies least privilege because it provides only audit log visibility without granting any broader compliance, security, or administrative permissions. No other role with narrower scope accomplishes this task.

Dthe Reviewer role in the Microsoft Purview portal

The Reviewer role in Microsoft Purview is scoped to reviewing content within eDiscovery cases and does not provide general access to search the unified audit log.

Concept tested: Least-privilege role for Microsoft 365 audit log search

Source: https://learn.microsoft.com/en-us/purview/audit-log-search

Topics

#Audit logs#RBAC#Least privilege#Microsoft Purview

Community Discussion

No community discussion yet for this question.

Full SC-401 Practice