Track permission changes from Unified Audit Log for security monitoring and compliance.
Related topics
permission audit
audit log
access changes
security monitoring
change tracking
About this tool
The Permission Change Audit tool tracks permission modifications from the Microsoft 365 Unified Audit Log. Monitor who granted or revoked access, when changes occurred, and what permissions were affected.
Essential for security monitoring and incident investigation. Identify unauthorized permission changes and track the chain of access modifications.
Export audit data for compliance documentation and forensic analysis.
Key features
Permission grant tracking
Access revocation history
User activity timeline
Sharing link creation
Role assignment changes
Forensic investigation support
Date range filtering
Export for analysis
Use cases
.
.
.
Graph scopes
undefined (application).
Tool identity
Slug: permission-audit.
Category: audit.
Plan tier: pro.
Editions: cloud, desktop.
SKUs: security, suite.
Documented scenarios: 3.
Declared features: 8.
Graph permissions requested: 1.
Licensing & access
Requires a paid edition (security). The Suite bundle includes this tool alongside every other capability in the catalogue.
Limitations & out-of-scope
Permission Change Audit: Detective control only: findings are reported, never auto-remediated. Severity rankings use the documented heuristic and may diverge from Microsoft Secure Score. Detection coverage stops at the Graph permission surface declared above — workloads behind tenant-licensed add-ons (Defender XDR, Purview eDiscovery Premium) require the matching license to enumerate.