Describe security, compliance, privacy, and trust in Microsoft 365 →hardMultiple ChoiceObjective-mapped
Microsoft Purview Audit (Standard) for Admin Actions and Alerts
A security team needs to ensure that all Microsoft 365 administrative actions—such as creating user accounts or resetting passwords—are logged and searchable for at least 90 days. They also need to create custom alert rules for suspicious admin activity. Which Microsoft Purview solution should they use?
Quick Answer
Microsoft Purview Audit Standard is the right fit because it delivers both halves of the requirement without additional licensing: 90 days of retained, searchable logging for administrative actions such as user creation and password resets, and the ability to build custom alert policies that fire on suspicious admin activity. The 90-day retention is worth remembering as a specific number, because it is the boundary that separates Audit Standard from Audit Premium — Premium extends retention to a year or longer and adds high-value event types, but this scenario asks for exactly 90 days, which Standard already covers at no extra cost on eligible licenses. Custom alert policies are configured through the same Purview compliance experience and can be scoped to specific activities or users, generating notifications when a defined pattern of admin behaviour occurs. Recognising the 90-day threshold is the fastest way to distinguish Standard-tier from Premium-tier audit questions on this exam.
⚠ Common exam trap
It's easy for candidates to confuse Audit (Premium) as mandatory for any alerting or retention beyond 30 days, but the question's 90-day requirement is exactly met by Audit (Standard), and Premium is only needed for longer retention or specific high-value events.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Purview Audit (Standard)
Microsoft Purview Audit (Standard) logs and retains all administrative actions (e.g., creating users, resetting passwords) for 90 days by default, meeting the retention requirement. It also supports creating custom alert rules for suspicious admin activity via the Microsoft 365 Defender portal, which queries the audit log. This makes it the correct solution for both logging and alerting on admin actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Purview Audit (Standard)
Why this is correct
Correct. Audit (Standard) records admin and user activities with 90-day retention and supports custom alert rules via the Microsoft Purview compliance portal.
- ✗
Microsoft Purview Audit (Premium)
Why it's wrong here
Incorrect. Audit (Premium) provides longer retention and more API access, but is more expensive than needed for just 90-day retention and basic alerts.
- ✗
Microsoft Entra ID sign-in logs
Why it's wrong here
Incorrect. These logs focus on user sign-ins, not admin actions like creating accounts or resetting passwords, and they have a different retention and alerting model.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Incorrect. This solution is for identifying and managing cloud app usage (shadow IT), not for auditing admin actions within Microsoft 365.
Go deeper
Related to this question
Learn chapter
Benefits of Microsoft Cloud
Key term
Audit log
An audit log is a chronological record of security-relevant events and user activities within a system, used for monitoring, compliance, and forensic analysis.
Key term
Alert
An alert is a notification that something unusual or potentially harmful has happened in a computer system or network.
About these practice questions
Courseiva writes every MS-900 question from scratch — 217 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on MS-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security team needs to monitor all administrative activities in Microsoft 365, including creating users, resetting passwords, and modifying policies. They require that logs be retained for at least 90 days and want to create custom alerts for suspicious admin actions (e.g., multiple password resets in a short time). Which Microsoft Purview solution should they use?
hard- ✓ A.Microsoft Purview Audit (Premium)
- B.Microsoft Purview Audit (Standard)
- C.Microsoft Defender for Cloud Apps
- D.Microsoft Entra ID reporting
Why A: Microsoft Purview Audit (Premium) is the correct solution because it provides extended log retention of up to one year (or more with add-ons), which meets the 90-day requirement, and it supports custom alert policies via the Microsoft 365 Defender portal to detect suspicious admin activities like multiple password resets. Standard Audit only retains logs for 90 days but lacks the advanced alerting and investigation capabilities needed for custom alerts on admin actions.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.