Compliance
Audit logs
Microsoft 365 audit logs
Microsoft 365 audit logs are the record of user and administrator activity captured automatically across Microsoft 365 workloads, including Exchange Online, SharePoint, OneDrive, Teams, Entra ID, and Power Platform.
Why Audit logs matters in a Microsoft estate
Audit logs matters because customers, resellers, and procurement teams need evidence that controls are defined, operated, and reviewable. A useful glossary definition should help a reader connect the term to audit preparation, policy work, or repeatable assurance activity.
How Audit logs shows up in practice
They are surfaced through the unified audit log in the Microsoft Purview compliance portal, and via the Office 365 Management Activity API for programmatic access and SIEM ingestion. Each logged event captures who performed an action, what the action was (such as a file being accessed, shared, or deleted, a mailbox rule being created, an admin role being assigned, or a user signing in from a new location), when it happened, and relevant metadata like the client IP address, application, and affected object. This collectively makes the audit log the primary source of truth when reconstructing what happened during a security incident, insider risk investigation, or compliance review. Licensing materially affects what an organisation can actually rely on here. Standard audit, included broadly across Microsoft 365 plans, retains most events for 180 days.
Microsoft Purview Audit (Premium), available with E5 or as an add-on, extends retention to one year by default (and up to ten years with the add-on), adds a longer list of higher-value event types including mailbox access by non-owners and mail item access events, and provides higher-bandwidth access to the Management Activity API. All of this matters directly for investigations, since an incident discovered weeks or months after it occurred can be effectively unrecoverable in standard audit if the retention window has already lapsed. A recurring operational failure mode is assuming audit logging is both complete and permanent by default. Some event types require explicit enablement: mailbox auditing, for instance, is on by default in current tenants but has not always been, and some diagnostic-level events still require configuration.
Unified audit log search itself must be turned on for a tenant, and administrators sometimes discover only during an actual investigation that the specific event type or time window they need was never being captured or has already aged out. For compliance frameworks like ISO/IEC 27001, SOC 2, and Cyber Essentials Plus, audit logs are frequently the primary evidence an assessor asks to see for access control, change management, and incident response controls. This makes retention period, log completeness, and export or SIEM integration for long-term storage a genuine control decision, rather than an incidental technical setting, particularly for organisations whose regulatory or contractual retention requirements exceed what standard Microsoft 365 licensing provides out of the box.