More Info:

A log profile controls how the activity log is exported and retained. Since the average time to detect a breach is 210 days, the activity log should be retained for 365 days or more in order to have time to respond to any incidents.

Risk Level

Low

Address

Security, Operational Maturity

Compliance Standards

HIPAA, ISO27001

Triage and Remediation

Remediation

To remediate the misconfiguration “Ensure activity log retention is set for 365 days or greater” in Azure using Azure console, follow the below steps:

  1. Login to the Azure portal (https://portal.azure.com/).
  2. Click on the “Azure Active Directory” icon from the left-hand side menu.
  3. Select the “Activity log” option from the left-hand side menu.
  4. Click on the “Export settings” option from the top menu.
  5. In the “Export settings” page, select the “Retention (days)” option.
  6. Enter “365” or greater in the “Retention (days)” field.
  7. Click on the “Save” button to save the changes.

Once the retention period is set to 365 days or greater, all the activity logs will be retained for the specified period, and the misconfiguration will be remediated.

Additional Reading: