6.1.1.10 Ensure that Intune logs are captured and sent to Log Analytics

Information

Ensure that Intune logs are captured and fed into a central log analytics workspace.

Intune includes built-in logs that provide information about your environments. Sending logs to a Log Analytics workspace enables centralized analysis, correlation, and alerting for faster threat detection and response.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Remediate from Azure Portal

- Go to Intune.
- Click Reports.
- Under Azure monitor, click Diagnostic settings.
- Click + Add diagnostic setting.
- Provide a Diagnostic setting name.
- Under Logs > Categories, check the box next to each of the following logs:
- AuditLogs
- OperationalLogs
- DeviceComplianceOrg
- Devices
- Windows365AuditLogs

- Under Destination details, check the box next to Send to Log Analytics workspace.
- Select a Subscription.
- Select a Log Analytics workspace.
- Click Save.

Impact:

A Microsoft Intune plan is required to access Intune: https://www.microsoft.com/en-us/security/business/microsoft-intune-pricing.

The amount of data logged and, thus, the cost incurred can vary significantly depending on the tenant size.

For information on Log Analytics workspace costs, visit: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/cost-logs.

See Also

https://workbench.cisecurity.org/benchmarks/21611

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-2, 800-53|AU-7, 800-53|AU-12, CSCv7|6.2

Plugin: microsoft_azure

Control ID: cefb654abac7bf31946a9e82771a6d18e90940677545a62862094805dae87e6d