Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Microsoft 365 audit logging gives authorized administrators and investigators a searchable record of supported user and admin actions across Microsoft services. It can help establish who did what and when during a security incident, a service change investigation, or a compliance review. First verify that your organization is collecting audit data; it is enabled by default for most tenants, but some small and midsize business tenants must turn it on manually.
Why activity logging matters—and what it does not prove
Audit records can help IT and security teams investigate actions such as changes to Microsoft 365 settings or activity involving organizational data. They also support compliance reporting and legal investigations. Microsoft describes audit logs as useful for maintaining, troubleshooting, and protecting Microsoft 365 and making data available for incident investigations and compliance reporting in its Microsoft 365 audit log collection overview.
These records are an investigation trail, not complete surveillance. Microsoft defines supported auditable events, and coverage varies by service. An action that is not recorded in the relevant workload cannot be found by searching the audit log. Logging also does not replace alerting, backups, or an incident-response process.
Check whether your organization is collecting audit data
Auditing is enabled by default for most Microsoft 365 organizations. Microsoft identifies Business Basic, Business Standard, and Business Premium SMB tenants as exceptions that need manual enablement; new enterprise and trial tenants can also differ. Do not assume either way—check the tenant setting.
Free tools Windows power users keep installed
One-click scans. No signup required.
- Connect to Exchange Online PowerShell.
- Run
Get-AdminAuditLogConfig | Format-List UnifiedAuditLogIngestionEnabled. - Check the result:
Truemeans unified audit log ingestion is enabled. If it isFalse, confirm the tenant plan and whether auditing has been enabled.
Run this check in Exchange Online PowerShell. Microsoft warns that the same property always reports False when queried from Security & Compliance PowerShell. See Microsoft’s instructions for turning auditing on or off.
Enable auditing only if it is off
If the tenant requires manual activation and you are authorized to make the change, enable auditing through the Microsoft Purview portal or run Set-AdminAuditLogConfig -UnifiedAuditLogIngestionEnabled $true in Exchange Online PowerShell. The administrator making the change needs the Audit Logs role. Microsoft documents both methods in its auditing setup guidance.
Rank #2
Turning unified audit ingestion off has operational consequences: Purview searches return no results, and the Office 365 Management Activity API and Microsoft Sentinel cannot access the organization’s auditing data through this logging path.
Give investigators the right access
Use least privilege rather than granting Global Administrator for routine audit work. Microsoft distinguishes the roles by purpose:
Rank #3
- Audit Reader or View-Only Audit Logs: appropriate for investigators who need to search and export records.
- Audit Logs: required for administrators who need to turn organization auditing on or off.
Assign only the access a person needs. Microsoft’s auditing setup guidance describes role and setup requirements.
Search for an action in Purview or PowerShell
Use Audit search in the Microsoft Purview portal, or use the Exchange Online PowerShell cmdlet Search-UnifiedAuditLog. Narrow a search with the relevant time range and criteria, such as user, operation, record type, or object. Start with the smallest useful scope, then broaden it if the expected record is not found. Microsoft’s audit search guide covers portal searching and available filters.
Rank #4
For scripted searches, Search-UnifiedAuditLog returns a subset of up to 100 records by default. Microsoft documents the ReturnLargeSet session command option for retrieving up to 50,000 results; those results are unsorted. Review the cmdlet reference before building an export or investigation around its output.
Allow for ingestion delay
Audit records do not necessarily appear immediately. Microsoft says records from core workloads such as Exchange, SharePoint, OneDrive, and Teams are typically available after 60–90 minutes. If a recent action is missing, check the time window and filters, allow for ingestion, and consider whether the event is supported and within the applicable retention period before concluding it did not occur.
Recommended Free Tools
Best Value
Understand retention before relying on a record
Retention depends on the audit tier, event, user licensing, and any configured retention policy. Microsoft’s current guidance gives these policy durations:
| Audit record scope | Retention described by Microsoft | Important qualification |
|---|---|---|
| Standard audit records | 180 days by default | Generally applies to covered records generated on or after October 17, 2023. |
| Selected Entra ID, Exchange, OneDrive, and SharePoint records for qualifying users | One year by default | Requires appropriate E5 or add-on licensing for the users whose activity is covered; it does not apply to every workload or user. |
| Eligible records with the required add-on license | Up to 10 years | Requires the applicable additional retention license and policy conditions. |
These are Microsoft service-policy durations, not guarantees that every event will be retained for the stated period. Confirm the applicable user licenses and policies for the workloads and people in scope. Microsoft’s auditing overview and retention policy documentation explain current eligibility and configuration.
Quick Recap
Practical setup checklist
- Verify the tenant’s subscription and the licenses assigned to users whose activity needs longer retention.
- Check ingestion status in Exchange Online PowerShell, not Security & Compliance PowerShell.
- Enable auditing only if it is off and you are authorized to do so.
- Assign Audit Reader or View-Only Audit Logs for search and export; reserve Audit Logs for setting changes.
- Run a narrowly scoped test search and account for the typical 60–90-minute availability delay in core workloads.
- Review retention rules by workload and user rather than assuming an organization-wide E5 plan gives every record longer retention.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

