Smooth Google migration

Migrate from Google Drive to M365 the right way

Learn more
No items found.

Master Hacks: Migrate like a pro

Check out our video series to help you turn migration projects into masterpieces!

Watch now

Table of contents

TL;DR: A walkthrough of searching Purview's audit log: the role you need, how to filter, and what Standard vs Premium actually gets you. Short version, 180 days unless you pay for more.

Microsoft Purview Audit brings together the auditing and unified audit log capabilities of Microsoft Purview with its wider data governance, compliance, and risk management solutions.

Audit gives you visibility into thousands of user and admin actions across Microsoft 365 services, so you can investigate security events, support forensic and internal investigations, and meet compliance obligations, all from a single audit log.

With Microsoft Purview, you get a data management and security solution built for how organizations work today: distributed teams, growing security threats, and depending on licensing, configuration, and supported workloads, AI and Copilot activity that may also need to be visible and accountable.

How to audit with Microsoft 365 

Auditing in Microsoft 365 is part of Microsoft Purview. Thousands of actions and operations across Microsoft 365 services are recorded in your organization's unified audit log. IT admins, risk teams, and compliance and legal staff can search these logs using the audit log search tool

Good to know

  • Microsoft Purview Audit (Standard) is enabled by default, so activities start being captured as soon as your organization subscribes.
  • Audit records are retained and searchable for 180 days by default with Audit (Standard). If you do not need historical context, focus on the current 180-day default retention period.
  • To search the audit log in the Microsoft Purview portal, admins and investigators need the Audit Logs or View-Only Audit Logs role, assigned by default through the Audit Manager or Audit Reader role groups in the Purview portal itself.
  • Once permissions are in place, you can search for specific activities, filtering by user, activity type, date range, or a combination of criteria.

Example: Searching the audit log to recover a lost file 

Heather is an IT team member and compliance auditor at Contoso.

Peter, an employee at the same company, has submitted a support ticket about a lost Excel file he needs for a priority project. He accessed the file within the last two weeks but hasn't been able to find it for the last few days.

Using a two-week date range, combined with filters for file type and user, Heather searches the audit log in the Microsoft Purview portal. If the relevant audit events are available for the workload and still within the retention period, the search can help identify whether the file was moved to the recycle bin or deleted.  

Besides the Purview portal, audit records can also be retrieved using the Search-UnifiedAuditLog cmdlet in Exchange Online PowerShell, the Office 365 Management Activity API, the newer Audit Search Graph API, or exported directly as a CSV file.

Why auditing Microsoft 365 is important to do regularly 

The amount of data organizations generate keeps growing, and with distributed work and asynchronous collaboration now the norm, keeping track of who did what, and when, matters more than it used to.

Regular auditing gives organizations proactive insight into potential threats, visibility into how software is actually being used across teams, and a way to confirm that user permissions still match what people actually need.

What is Microsoft Purview Audit in Microsoft 365? 

Microsoft Purview Audit provides auditing and reporting capabilities for your organization. The Microsoft Purview portal is where you manage data protection and compliance needs and audit user and admin activity. Access to Purview and related security and compliance experiences depends on the roles and role groups assigned to each user. Audit includes several audit-specific capabilities, including:

  • Audit log search in the Microsoft Purview portal
  • Filtering by activities, users, workloads, and date ranges
  • CSV export for investigation and reporting
  • Search-UnifiedAuditLog access through Exchange Online PowerShell
  • Programmatic access through the Office 365 Management Activity API and Audit Search Graph API
  • Audit retention policies and additional Audit (Premium) events, depending on licensing

Depending on whether your organization has Audit (Standard) or Audit (Premium), specific capabilities and retention periods will vary. 

Two types of licenses

To meet different organizational needs, Microsoft Purview offers two auditing solutions: Audit (Standard) and Audit (Premium).

Capability Audit (Standard) Audit (Premium)
Enabled by default Yes Yes
Thousands of searchable audit events Yes Yes
Search via Purview portal, Graph API, cmdlet, or CSV export Yes Yes
Default retention 180 days 1 year for selected workloads such as Microsoft Entra ID, Exchange, SharePoint, and OneDrive for users with the appropriate Audit (Premium) license; 180 days for other services
Custom audit log retention policies No Yes, up to 10 years with the required add-on license
Intelligent insights (e.g. sensitivity label on accessed mail items) No Yes
Bandwidth for Office 365 Management Activity API Baseline Higher-bandwidth access

Audit (Standard)

Audit (Standard) is enabled by default with Microsoft Purview and lets you search thousands of events using the audit search tool in the Purview portal. Audit records are retained for 180 days and can be exported as a CSV or searched using the Search-UnifiedAuditLog cmdlet in Exchange Online PowerShell or the Office 365 Management Activity API.

Audit (Premium)

Audit (Premium) builds on Audit (Standard) with more retention and customizability. For users with the appropriate Audit (Premium) license, audit logs for selected workloads such as Exchange, SharePoint, OneDrive, and Microsoft Entra ID are automatically retained for one year by default.

IT admins can also modify audit log retention policies, extending retention up to one year for other services, or up to 10 years with the dedicated 10-year retention add-on license.

Audit (Premium) provides higher-bandwidth access to audit logs for large enterprises. It also generates high-value "intelligent insights" events for critical scenarios, helping with forensic and compliance investigations by surfacing details such as user search history and mailbox access behavior.

Get started with Microsoft Purview Audit

Microsoft Purview Audit is worth exploring even for small and medium organizations relying on Microsoft 365 and SharePoint. Here's how to get started with Audit (Standard):

  1. Verify that your organization has a subscription that supports Audit (Standard) and, if applicable, one that supports Audit (Premium).
  2. Assign audit search permissions in the Microsoft Purview portal. Go to Settings > Roles and Scopes > Role groups. Add the relevant users to the Audit Reader role group for read-only audit search, or to the Audit Manager role group when they also need to export audit search results.

Use the Microsoft Purview portal for audit search permissions. Exchange admin center audit roles are only needed when someone must enable or disable auditing or use audit-related PowerShell cmdlets.

Once permissions are in place, people in your organization can use the audit log search tool in the Microsoft Purview portal to search for audited activities.

  • Go to https://purview.microsoft.com and sign in with an account that has the appropriate audit permissions.
  • In the left navigation pane, select Audit under Solutions.
  • On the Audit page, configure your search using the available filters on the Search tab, such as date range, activities, users, or workloads.
The Audit search page in the Microsoft Purview portal.

For more information about the auditing solutions in Microsoft Purview and how to get started, check out the official Microsoft documentation to create greater visibility into your organization.