![]() ![]() For any other object type, it's a hard delete. The Audit log always records a "Delete " event when an object in the tenant is removed from an active state by either a soft or hard deletion.Ī delete event for applications, users, and Microsoft 365 Groups is a soft delete. For more information on how to find deleted items by using Microsoft Graph, see List deleted items - Microsoft Graph v1.0. You can also use Microsoft Graph to audit changes and build a custom solution to monitor differences over time. ![]() Export these logs to a security information and event management tool such as Microsoft Sentinel. The Azure AD Audit log contains information on all delete operations performed in your tenant. If you haven't already done so, read Recoverability best practices for foundational knowledge. This article addresses recovering from soft and hard deletions in your Azure Active Directory (Azure AD) tenant. ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |