You are correct. Since UEM only uses file shares, you would need to audit the access to those files. The changes to the UEM Configuration Share are probably the most interesting.
I don't have experience with tools, but if you Google a lot of options show up.
Maybe this Microsoft article is interesting, since it describes a way to do it with just Microsoft tooling:
Auditing File Access on File Servers – Premier Field Engineering