Controls / MCSB / LT-4

MCSB LT-4: Logging and Threat Detection

7 Senserva Microsoft 365 security checks provide evidence for Microsoft Cloud Security Benchmark control LT-4 (Logging and Threat Detection). Each is checked against your tenant, ranked by Severity, with validated remediation.

7 checksLogging and Threat DetectionTop Severity: High

What MCSB LT-4 covers

The Microsoft Cloud Security Benchmark is Microsoft's own security baseline for Azure and Microsoft 365, organized into control domains. LT-4 sits in the Logging and Threat Detection domain. Senserva evidences it with the 7 checks below, so you can see, per tenant, whether the control is actually met rather than assumed.

Ask your own AI about this control

Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.

The 7 checks that evidence MCSB LT-4

Click any row for why it matters and how to fix it, with a link to the full check page.

Senserva checkSeverityWhat it verifies
Internet Facing VM Protected By NsgHighInternet-facing VM is protected by a Network Security Group (NSG)
Purview Audit Log No Records ReturnedHighThe Microsoft Graph audit log probe returned zero records for the past 24 hours.
Purview Audit Log UnavailableHighThe Microsoft Graph audit log query API is not available to this tenant.
Network Flow Logs ConfiguredMediumTODO: Network flow logs configuration check. Not yet implemented
Non Internet Facing VM Protected By NsgMediumNon-internet-facing VM is protected by a Network Security Group (NSG)
Nsg Flow Logs EnabledMediumNSG flow logs are enabled for network traffic monitoring and forensics
Purview Audit Permission Check SkippedMediumPurview audit log checks were skipped because the scanning credential lacks the AuditLogsQuery.Read.All permission or required directory role.

Also evidences

The same checks provide evidence for these frameworks, so one fix counts across your obligations:

Every MCSB control and the checks that evidence it: the control reference. The full benchmark crosswalk: MCSB for Microsoft 365.

Reference: the compliance frameworks crosswalk, the check reference, and the audit guide.
Data notice: control mappings describe which Siemserva checks provide evidence for a control and are informational only, without warranty. They do not constitute compliance advice or certification; confirm requirements with your assessor. All use is subject to the Senserva EULA.