Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft 365 audit searches can return many different kinds of events because the unified audit log collects supported activity across services such as Exchange, SharePoint, OneDrive, Entra ID, and Teams. An unfamiliar entry is not automatically suspicious: first identify its record type, actor, operation, and workload-specific details in AuditData.

Why does my Office 365 audit log show so much data?

The unified audit log records supported user and administrative operations across multiple Microsoft 365 workloads. A single search can therefore mix unrelated event families: a group membership change, an Exchange mailbox-property update, a SharePoint file deletion, a Teams sign-in, or an AIP heartbeat, for example. Microsoft describes it this way: “The audit log is a tool that records events from a range of workloads.” (Microsoft Learn: AIP Unified Audit Log Best Practices.)

Each result’s RecordType identifies its workload or event family. The AuditData property contains event details, but it does not use one universal schema: different workloads put different kinds of information there. Read the fields in the context of the record type and operation rather than treating every result as the same sort of event.

Read an unfamiliar record in context

  1. Establish the time and actor. Check when the event occurred and which user or service account is listed as the actor.
  2. Identify the record type. Use RecordType to determine the workload or event family.
  3. Inspect the operation and payload. Review the activity or operation name and the relevant fields in AuditData.
  4. Compare it with the event catalog. Look up the event in Microsoft’s Audit log activities reference, which includes Exchange admin auditing coverage.

An odd-looking event is a reason to identify what recorded it and what its fields mean—not, by itself, proof of compromise.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Microsoft 365 Personal | 12-Month Subscription | 1 Person | Premium Office Apps: Word, Excel, PowerPoint and more | 1TB Cloud Storage | Windows Laptop or MacBook Instant Download | Activation Required
  • Designed for Your Windows and Apple Devices | Install premium Office apps on your Windows laptop, desktop, MacBook or iMac. Works seamlessly across your devices for home, school, or personal productivity.
  • Includes Word, Excel, PowerPoint & Outlook | Get premium versions of the essential Office apps that help you work, study, create, and stay organized.
  • 1 TB Secure Cloud Storage | Store and access your documents, photos, and files from your Windows, Mac or mobile devices.
  • Premium Tools Across Your Devices | Your subscription lets you work across all of your Windows, Mac, iPhone, iPad, and Android devices with apps that sync instantly through the cloud.
  • Easy Digital Download with Microsoft Account | Product delivered electronically for quick setup. Sign in with your Microsoft account, redeem your code, and download your apps instantly to your Windows, Mac, iPhone, iPad, and Android devices.

How to narrow a large audit search

Start with a defined activity and time range, then narrow by the filters relevant to the investigation. A wide time window across all workloads can return a noisy mixture that is harder to interpret than separate, targeted searches.

  • Filter by activity or operation when you know what action you are investigating.
  • Limit the date range to the period that matters.
  • Use the workload or record type when the investigation concerns one service.
  • Check whether the search is looking for actions by an actor or actions involving a particular mailbox; those are different scopes.

In PowerShell, Search-UnifiedAuditLog returns 100 records by default. Microsoft documents a ResultSize maximum of 5,000 records per request and a maximum of 50,000 records processed for one search when paging. These are search limits, not guarantees that a broad query will provide a complete, easy-to-review history. The investigator also needs the Exchange View-Only Audit Logs or Audit Logs role. See Microsoft’s cmdlet guidance.

For repeatable scripted searches or bulk review, PowerShell is useful; Microsoft also documents exporting records to CSV. Its export guidance says a Search-UnifiedAuditLog command supports one RecordType value, so a search covering several record types may require separate calls and combining the results. For a portal-based investigation, use Microsoft Purview’s audit search. If the need is centralized analytics across sources or large-scale downstream analysis, records can be exported or accessed through Microsoft Sentinel; Sentinel is optional, not required for an ordinary investigation. See Microsoft’s export and viewing guidance.

Why can’t I find mailbox audit events?

An empty mailbox search does not prove that the action did not happen. Check the search scope, mailbox auditing, tenant ingestion, investigator permissions, timing, and the applicable retention window before drawing that conclusion.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Actor search and mailbox search are not the same

A user filter can find activity performed by that user, but it may not return every action involving a particular mailbox. Microsoft notes that delegate actions can be missed when searching for activities performed by a specified user, and that the user filter does not return activities performed in a shared mailbox.

For a mailbox-wide or shared-mailbox investigation, Microsoft documents using the mailbox’s Exchange GUID in the FreeText search of Search-UnifiedAuditLog. Follow its current procedure in Search the audit log to investigate common support issues rather than assuming a user filter covers mailbox scope.

Rank #3
Cryptnox FIDO2 Security Key NFC Smart Card for 2FA MFA Passwordless Login
  • FIDO2 CERTIFIED: FIDO Alliance Certified FIDO2 v2.1 and CTAP Level 1 for 2FA and MFA on Google Microsoft Apple GitHub login.gov AGOV SwissID and any WebAuthn service
  • PASSKEY READY: Works as a hardware passkey for passwordless sign-in where the service enables it and as a U2F and WebAuthn security key everywhere else
  • CERTIFIED SECURITY: NXP JCOP 4.5 secure element rated Common Criteria EAL6+ (augmented)
  • TAP OR INSERT: Dual NFC ISO 14443 and contact ISO 7816 interface in an ID-1 format smart card that is passive and battery-free
  • BUILT TO LAST: Passive smart card made in Switzerland designed by Swiss company Cryptnox and backed by a 2 year manufacturer warranty

Check mailbox auditing and licensing

Microsoft’s troubleshooting guidance identifies license-related visibility behavior for mailbox audit events searched through Purview, Search-UnifiedAuditLog, or the Office 365 Management Activity API. For the scenario covered in that guidance, Microsoft’s workaround is to enable mailbox auditing individually with Exchange Online PowerShell. Verify the tenant’s applicable licensing and use the current Microsoft instructions before changing mailbox settings.

Confirm the mailbox type and search details

Microsoft’s mailbox auditing documentation covers supported mailbox types and notes a cross-geo caveat. For mailbox-specific investigations, use Microsoft’s checklist for searching mailbox activities in specific mailboxes; confirm the mailbox scope and supported configuration rather than treating every mailbox as interchangeable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check that auditing is collecting records

Auditing is on by default for most organizations, but Microsoft lists exceptions among SMB subscriptions, including Business Basic, Business Standard, and Business Premium, as well as some unmanaged trial tenants. Verify that unified audit log ingestion is enabled for the tenant you are investigating, particularly if it is new or a trial.

Rank #4
Microsoft System Builder | Windоws 11 Home | Intended use for new systems | Install on a new PC | Branded by Microsoft
  • STREAMLINED & INTUITIVE UI, DVD FORMAT | Intelligent desktop | Personalize your experience for simpler efficiency | Powerful security built-in and enabled.
  • OEM IS TO BE INSTALLED ON A NEW PC with no prior version of Windows installed and cannot be transferred to another machine.
  • OEM DOES NOT PROVIDE SUPPORT | To acquire product with Microsoft support, obtain the full packaged “Retail” version.
  • PRODUCT SHIPS IN PLAIN ENVELOPE | Activation key is located under scratch-off area on label.
  • GENUINE WINDOWS SOFTWARE IS BRANDED BY MIRCOSOFT ONLY.

If ingestion is switched off, Microsoft says Purview searches return no results, and the Office 365 Management Activity API and Microsoft Sentinel cannot access the organization’s auditing data. See Turn auditing on or off for the current check. Also confirm that the investigator has the required audit role; an account without the necessary role can produce an incomplete troubleshooting picture.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Allow for event delay and retention limits

New events may take time to appear

Microsoft says an Exchange cmdlet’s corresponding audit entry might take up to 30 minutes to appear in results. If the action was recent, allow for that documented delay before deciding the record is absent. It is not a promise that every event in every workload appears on the same schedule; consult the relevant activity reference.

Retention depends on when the record was generated and on licensing

Audit Standard retention changed from 90 to 180 days for records generated on or after October 17, 2023. Records generated before that date retain the earlier 90-day behavior. The 180-day period is not a universal retention promise: policies and license entitlements can change what remains searchable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Audit Premium’s default policy retains specified Exchange Online, SharePoint, OneDrive, and Entra audit records for one year for qualifying E5 or specified add-on users. Other activity and records for non-E5 or guest users are generally retained for 180 days unless a matching custom policy applies. Longer retention, including ten years, has additional licensing conditions. Check the license of the user who generated the activity and the policy that applies to the record in Microsoft’s audit log retention policy guidance and audit search documentation.

How do I search audit logs for a shared mailbox?

Do not rely only on the delegate’s user filter: Microsoft says that filter does not return activities performed in a shared mailbox. Search for the mailbox itself using its Exchange GUID in the FreeText parameter of Search-UnifiedAuditLog, following Microsoft’s shared-mailbox troubleshooting instructions. Confirm the investigator’s role, tenant ingestion status, mailbox auditing and licensing, and the date range if results are missing.

A practical troubleshooting order

  1. Define the event and time range. Decide which action and period you need to investigate.
  2. Narrow the query. Filter by activity, date, user, or workload as appropriate; separate record types when needed for a scripted search.
  3. Check scope. Determine whether you need actions by a user or actions involving a mailbox. For a shared mailbox, use its Exchange GUID as documented by Microsoft.
  4. Verify collection and access. Check unified audit log ingestion and the investigator’s audit role.
  5. Check timing and retention. Allow for the documented Exchange cmdlet delay and confirm the applicable license and retention policy.
  6. Scale up only if necessary. Export or centralize results when the volume or analysis needs justify it.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.