Valid MS-700 Dumps shared by ExamDiscuss.com for Helping Passing MS-700 Exam! ExamDiscuss.com now offer the newest MS-700 exam dumps, the ExamDiscuss.com MS-700 exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com MS-700 dumps with Test Engine here:
You have a Microsoft 365 E3 subscription that contains 500 users. All the users have computers that run Windows 10 and are joined to Azure AD. Vou need to generate a report that identifies which documents the users copied from Microsoft Teams to USB devices. What should you do first?
Correct Answer: B
According to the Microsoft documentation1, to generate a report that identifies which documents the users copied from Teams to USB devices, you need to use advanced hunting on Microsoft Defender ATP. Advanced hunting lets you run queries to find threat activity involving USB devices, such as mounting and unmounting of USB drives or copying of files2. To use advanced hunting, you need to have one of the following roles: * Security administrator * Security reader * Security operator * Global administrator The Groups Administrator role does not have access to advanced hunting or Microsoft Defender ATP. Therefore, based on this information, the correct answer is B. Assign the Microsoft 365 E5 compliance add-on to each user. This add-on includes Microsoft Defender ATP and allows you to use advanced hunting features3. Alternatively, you can request one of the roles that have access to advanced hunting, such as Security administrator or Global administrator.