A role in Microsoft Purview, also found in Exchange Online, that allows searching and exporting the unified audit log (Fabric activities included) without permission to alter audit settings. Switching auditing on or off needs the Audit Logs role instead.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains View-Only Audit Logs in context, with comparison tables and the common traps.
Terms in this definition
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- Microsoft Purview
Family of Microsoft products for data governance, security and compliance. Its Data Map stores only metadata, such as lineage, schema and classification, never the data itself.
- Exchange Online
Microsoft 365's hosted service for mail, calendars and contacts. Defender for Office 365 protects these mailboxes.
- Unified audit log
A record of what users and administrators do across numerous Microsoft 365 services, which can be searched with Microsoft Purview Audit. For core services, entries typically become available between one hour and an hour and a half after the activity.
- Audit
Policy effect that lets a request proceed but flags the resource as non-compliant and logs a warning to the activity log. Microsoft suggests beginning there and later moving to something enforcing, like Deny.
- Auditing
Azure SQL capability that sends database audit logs to Log Analytics, Event Hubs or a storage account; that account is allowed to be in a different region.
- Audit logs
Record directory changes in Microsoft Entra, covering users, groups, applications, policies and other objects. Free tenants keep them for 7 days and P1 or P2 tenants for 30, and diagnostic settings can send them elsewhere for longer.