logo

CISA shares guidance for Microsoft expanded logging capabilities

ID: 4ee0ecda-dbc5-5a27-b4ca-de581730b5ff

STIX ID: report--4ee0ecda-dbc5-5a27-b4ca-de581730b5ff

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-01-15

Date Updated: 2026-03-27

Author: Sergiu Gatlan

...
...

CISA published a playbook advising government and enterprise use of Microsoft Purview Audit (Standard) expanded cloud logs to improve forensic investigations and threat hunting after the Storm-0558 Exchange Online breach in 2023, which used a stolen Microsoft account signing key to forge tokens and exfiltrated an estimated 60,000 State Department emails; Microsoft later broadened logging availability following criticism.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.