Track permission changes from Unified Audit Log for security monitoring and compliance.
Related topics
permission audit
audit log
access changes
security monitoring
change tracking
About this tool
The Permission Change Audit tool tracks permission modifications from the Microsoft 365 Unified Audit Log. Monitor who granted or revoked access, when changes occurred, and what permissions were affected.
Essential for security monitoring and incident investigation. Identify unauthorized permission changes and track the chain of access modifications.
Export audit data for compliance documentation and forensic analysis.
Key features
Permission grant tracking
Access revocation history
User activity timeline
Sharing link creation
Role assignment changes
Forensic investigation support
Date range filtering
Export for analysis
Use cases
Incident investigation. Track permission changes during security incident
Audit trail. Document permission changes for compliance
Change monitoring. Monitor who is modifying access permissions
Graph scopes
AuditLog.Read.All (application).
Tool identity
Slug: permission-audit.
Category: audit.
Plan tier: pro.
Editions: cloud, desktop.
SKUs: security, suite.
Documented scenarios: 3.
Declared features: 8.
Graph permissions requested: 1.
Licensing & access
Requires a paid edition (security). The Suite bundle includes this tool alongside every other capability in the catalogue.
Limitations & out-of-scope
The only scope requested is AuditLog.Read.All — a single-permission tool by design — so the entire output is bounded by what the Unified Audit Log actually recorded and how long the tenant's license retains it; an event that predates the retention window, or was never logged, cannot be reconstructed. It surfaces the change history; reversing an unwanted permission grant is still a manual step.