Exchange Online Unified Audit Log Ingestion Disabled via Set-AdminAuditLogConfig

Detects when an administrator explicitly disables Unified Audit Log (UAL) ingestion for Exchange Online using the Set-AdminAuditLogConfig cmdlet. This action effectively stops the generation of audit records for Exchange administration and user activity, a critical defense evasion tactic used to conceal malicious operations.