Granting Least Privilege Audit Log Search Access
You have a Microsoft 365 subscription linked to a Microsoft Entra tenant that contains a user named User1. You need to grant User1 permission to search Microsoft 365 audit logs. The solution must use the principle of least privilege. Which role should you assign to User1?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests the knowledge that despite the existence of Purview roles, the View-Only Audit Logs role in Exchange Online is still a valid and often cited method for granting audit search permissions with minimal impact.
This question addresses the specific role assignment required to search Microsoft 365 audit logs while adhering to the principle of least privilege. The correct answer identifies the Exchange admin center role that provides necessary permissions without granting broader administrative access.
Many learners select the Security Reader role (D) because it sounds appropriate for security tasks, or they choose Reviewer (A), not realizing that Security Reader does not grant audit log search permissions by default.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The View-Only Audit Logs role in the Exchange admin center allows users to view and search audit logs without granting them the ability to enable/disable auditing or perform other administrative tasks. This aligns perfectly with the principle of least privilege for the specific task of searching logs.Why the Other Options Are Wrong
The Security Reader role (D) allows viewing security alerts but does not inherently include permission to search audit logs. The Compliance Management role (C) grants broader permissions related to compliance management, which exceeds the scope of just searching logs. The Reviewer role (A) in Purview is typically associated with content review workflows rather than audit log investigation.Community Comment Notes
Community members frequently reference official Microsoft documentation which confirms that the View-Only Audit Logs role in Exchange Online is a supported method for this task. Some comments note that while Purview has its own roles, the Exchange-based roles remain relevant for this specific capability in many configurations.Official Reference
Exam Strategy
Always look for the most granular role that satisfies the requirement. When asked for 'least privilege' regarding audit logs, remember that specific audit roles exist separate from general security or compliance reader roles.
Frequently Asked Questions
Does the Security Reader role allow searching audit logs?
No, the Security Reader role allows viewing security alerts and reports but does not provide permissions to search the audit log.
Why is the Exchange admin center used for audit roles?
Historically, audit logging was managed through Exchange Online. While Purview is now the central hub, the Exchange-based roles remain valid for granting these specific permissions.