How to storage Defender Logs for over the default 180 Days

So Defender for Endpoint Logging does not comply PCI DSS Logging requirements of Logging “the audit history should be kept for at least one year 

You have to Stream the Logs to Azure Storage to get this up to 1 year

https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/raw-data-export-storage?view=o365-worldwide

https://jeffreyappel.nl/export-microsoft-defender-for-endpoint-security-events-with-the-streaming-api/
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading...