MCSB LT-4: Logging and Threat Detection
7 Senserva Microsoft 365 security checks provide evidence for Microsoft Cloud Security Benchmark control LT-4 (Logging and Threat Detection). Each is checked against your tenant, ranked by Severity, with validated remediation.
What MCSB LT-4 covers
The Microsoft Cloud Security Benchmark is Microsoft's own security baseline for Azure and Microsoft 365, organized into control domains. LT-4 sits in the Logging and Threat Detection domain. Senserva evidences it with the 7 checks below, so you can see, per tenant, whether the control is actually met rather than assumed.
Ask your own AI about this control
Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.
The 7 checks that evidence MCSB LT-4
Click any row for why it matters and how to fix it, with a link to the full check page.
| Senserva check | Severity | What it verifies |
|---|---|---|
| Internet Facing VM Protected By Nsg | High | Internet-facing VM is protected by a Network Security Group (NSG) |
| Purview Audit Log No Records Returned | High | The Microsoft Graph audit log probe returned zero records for the past 24 hours. |
| Purview Audit Log Unavailable | High | The Microsoft Graph audit log query API is not available to this tenant. |
| Network Flow Logs Configured | Medium | TODO: Network flow logs configuration check. Not yet implemented |
| Non Internet Facing VM Protected By Nsg | Medium | Non-internet-facing VM is protected by a Network Security Group (NSG) |
| Nsg Flow Logs Enabled | Medium | NSG flow logs are enabled for network traffic monitoring and forensics |
| Purview Audit Permission Check Skipped | Medium | Purview audit log checks were skipped because the scanning credential lacks the AuditLogsQuery.Read.All permission or required directory role. |
Also evidences
The same checks provide evidence for these frameworks, so one fix counts across your obligations:
Evidence this control in your own Microsoft 365
This page maps Microsoft Cloud Security Benchmark control LT-4 (Logging and Threat Detection) to the checks that prove it. Siemserva by Senserva runs those checks, and 650+ others, against your own tenant: it shows exactly where this control is met or failing, ranks the gaps by Severity, and produces the audit-ready evidence and validated fixes to close them.
Built for the people who own this outcome: security and IT teams closing gaps, auditors and compliance teams gathering evidence, and MSPs and MSSPs running it across every client tenant.
Every MCSB control and the checks that evidence it: the control reference. The full benchmark crosswalk: MCSB for Microsoft 365.
