Is anyone monitoring user permissions/access to SharePoint / Office365 sites and files?


We currently have a use case to examine the permissions/access associated with a users Office365 or SharePoint account. There are a ton of different O365 audit logs that are related to access and sharing groups. I would like to be able to figure out some correlations but have been having some difficulty due to the confusing nature of the logs. Wondering if anyone has faced this problem and is working through it or has solved it.

Here's the smart way to get your usecases - get someone to DO the activities you want to detect, and have them tell you EXACTLY WHEN they did them, and ON WHOM.

Then you can find the appropriate records easily. Once you see those records, then you can check closely related records (by time or other field similarities) and see if you want them as well.

You're going to want the RecordType, Operation, Target, UserID, UserKey, UserSharedWIth, UserType, Workload to start with. Once you've identified the records that document the actions that you are looking for, then you can see if there are other fields available that are relevant to those exact actions.

If you know when and what the action was that you are hunting, then just filtering by date/time, Workload, and RecordType should be enough to locate the appropriate records.

Failing that, if you have to go from theory to details, then the key to figuring out your usecases is going to be drilldown, probably. Start with the recordtype, probably concentrating on 4 but later check 8, 6, 14, and then maybe 1 and 18.

From here - https://support.office.com/en-us/article/Detailed-properties-in-the-Office-365-audit-log-ce004100-9e...

