Granting Least Privilege Audit Log Search Access

Answer Correct answer: B — Assign the View-Only Audit Logs role in the Exchange admin center to User1.

You have a Microsoft 365 subscription linked to a Microsoft Entra tenant that contains a user named User1. You need to grant User1 permission to search Microsoft 365 audit logs. The solution must use the principle of least privilege. Which role should you assign to User1?

  1. the Reviewer role in the Microsoft Purview compliance portal
  2. the View-Only Audit Logs role in the Exchange admin center Correct Answer
  3. the Compliance Management role in the Exchange admin center
  4. the Security Reader role in the Microsoft Entra admin center

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests the knowledge that despite the existence of Purview roles, the View-Only Audit Logs role in Exchange Online is still a valid and often cited method for granting audit search permissions with minimal impact.

This question addresses the specific role assignment required to search Microsoft 365 audit logs while adhering to the principle of least privilege. The correct answer identifies the Exchange admin center role that provides necessary permissions without granting broader administrative access.

Many learners select the Security Reader role (D) because it sounds appropriate for security tasks, or they choose Reviewer (A), not realizing that Security Reader does not grant audit log search permissions by default.

Community Discussion (4 comments)

Boeroe 👍 3
None of the answers are correct, this is possible by enabling the audit reader or manager role within Purview: https://learn.microsoft.com/en-us/purview/audit-get-started#step-2-assign-permissions-to-search-the-audit-log
thetootall 👍 2 Selected: B
Access to enable or disable auditing and access to audit cmdlets currently requires permissions from the Exchange admin center. Use the existing Audit Logs and View-Only Audit Logs roles in the Exchange admin center to grant access to audit cmdlets. Use the existing Audit Logs role in the Exchange admin center to grant access to enable or disable auditing. https://learn.microsoft.com/en-us/purview/audit-get-started#step-2-assign-permissions-to-search-the-audit-log
JimboJones99 👍 1 Selected: B
https://learn.microsoft.com/en-us/purview/audit-get-started#step-2-assign-permissions-to-search-the-audit-log
Domza 👍 4 Selected: B
Correct~ Note: To search the audit log, administrators and members of investigation teams must be assigned the View-Only Audit Logs or Audit Logs role in Exchange Online with love~

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The View-Only Audit Logs role in the Exchange admin center allows users to view and search audit logs without granting them the ability to enable/disable auditing or perform other administrative tasks. This aligns perfectly with the principle of least privilege for the specific task of searching logs.

Why the Other Options Are Wrong

The Security Reader role (D) allows viewing security alerts but does not inherently include permission to search audit logs. The Compliance Management role (C) grants broader permissions related to compliance management, which exceeds the scope of just searching logs. The Reviewer role (A) in Purview is typically associated with content review workflows rather than audit log investigation.

Community Comment Notes

Community members frequently reference official Microsoft documentation which confirms that the View-Only Audit Logs role in Exchange Online is a supported method for this task. Some comments note that while Purview has its own roles, the Exchange-based roles remain relevant for this specific capability in many configurations.

Official Reference

Exam Strategy

Always look for the most granular role that satisfies the requirement. When asked for 'least privilege' regarding audit logs, remember that specific audit roles exist separate from general security or compliance reader roles.

Frequently Asked Questions

Does the Security Reader role allow searching audit logs?

No, the Security Reader role allows viewing security alerts and reports but does not provide permissions to search the audit log.

Why is the Exchange admin center used for audit roles?

Historically, audit logging was managed through Exchange Online. While Purview is now the central hub, the Exchange-based roles remain valid for granting these specific permissions.

Related Analysis

← Back to SC-400 Study Guide