Common/Get-ExoAuditConfig.ps1

function Get-ExoAuditConfig {
    <#
    .SYNOPSIS
        Reads unified audit ingestion from an identified Exchange Online connection.
    .DESCRIPTION
        Resolves the cmdlet from the connection's own temporary module. Purview
        connections are never authoritative for UnifiedAuditLogIngestionEnabled.
        Ambiguous or unidentified connections fail closed for manual verification.
    .PARAMETER ExpectedTenantId
        Resolved assessment tenant GUID, when available. Rejects a mismatched session.
    .EXAMPLE
        $audit = Get-ExoAuditConfig
    #>

    [CmdletBinding()]
    [OutputType([PSCustomObject])]
    param([string]$ExpectedTenantId)

    $connections = @(Get-ConnectionInformation -ErrorAction Stop | Where-Object {
        $_.State -eq 'Connected' -and $_.IsEopSession -eq $false -and $_.ModuleName
    })
    if ($connections.Count -ne 1) {
        throw 'Exactly one identifiable Exchange Online connection is required to verify audit ingestion.'
    }
    $connection = $connections[0]
    if ($ExpectedTenantId -and $connection.TenantID -ne $ExpectedTenantId) {
        throw 'Exchange Online connection does not match the assessment tenant.'
    }
    $moduleName = Split-Path -Path $connection.ModuleName -Leaf
    $moduleName = $moduleName -replace '\.(psm1|psd1)$', ''
    $commandName = 'Get-' + $connection.ModulePrefix + 'AdminAuditLogConfig'
    $commands = @(Get-Command -Name $commandName -Module $moduleName -ErrorAction Stop)
    if ($commands.Count -ne 1) { throw 'Exchange Online audit command could not be resolved unambiguously.' }
    $config = & $commands[0] -ErrorAction Stop
    if ($config.UnifiedAuditLogIngestionEnabled -isnot [bool]) {
        throw 'Exchange Online returned no authoritative boolean audit-ingestion value.'
    }
    [PSCustomObject]@{
        Enabled = $config.UnifiedAuditLogIngestionEnabled
        Source = "$($connection.ConnectionUri) / $commandName"
        CollectedAt = [datetime]::UtcNow.ToString('o')
        TenantId = $connection.TenantID
    }
}