Learn about auditing solutions in Microsoft Purview (2024)

  • Article

Microsoft Purview auditing solutions provide an integrated solution to help organizations effectively respond to security events, forensic investigations, internal investigations, and compliance obligations. Thousands of user and admin operations performed in dozens of Microsoft services and solutions are captured, recorded, and retained in your organization's unified audit log. Audit records for these events are searchable by security ops, IT admins, insider risk teams, and compliance and legal investigators in your organization. This capability provides visibility into the activities performed across your organization.

Tip

If you're not an E5 customer, use the 90-day Microsoft Purview solutions trial to explore how additional Purview capabilities can help your organization manage data security and compliance needs. Start now at the Microsoft Purview compliance portal trials hub. Learn details about signing up and trial terms.

Comparison of key capabilities

The following table compares the key capabilities available in Audit (Standard) and Audit (Premium). All Audit (Standard) functionality is included in Audit (Premium).

CapabilityAudit (Standard)Audit (Premium)
Enabled by defaultLearn about auditing solutions in Microsoft Purview (1)Learn about auditing solutions in Microsoft Purview (2)
Thousands of searchable audit eventsLearn about auditing solutions in Microsoft Purview (3)Learn about auditing solutions in Microsoft Purview (4)
Audit search tool in the Microsoft Purview portal and compliance portalLearn about auditing solutions in Microsoft Purview (5)Learn about auditing solutions in Microsoft Purview (6)
Search-UnifiedAuditLog cmdletLearn about auditing solutions in Microsoft Purview (7)Learn about auditing solutions in Microsoft Purview (8)
Export audit records to CSV fileLearn about auditing solutions in Microsoft Purview (9)Learn about auditing solutions in Microsoft Purview (10)
Access to audit logs via Office 365 Management Activity API 1Learn about auditing solutions in Microsoft Purview (11)Learn about auditing solutions in Microsoft Purview (12)
180-day audit log retentionLearn about auditing solutions in Microsoft Purview (13)Learn about auditing solutions in Microsoft Purview (14)
1-year audit log retentionLearn about auditing solutions in Microsoft Purview (15)
10-year audit log retention 2Learn about auditing solutions in Microsoft Purview (16)
Audit log retention policiesLearn about auditing solutions in Microsoft Purview (17)
Intelligent insightsLearn about auditing solutions in Microsoft Purview (18)

Note

1 Audit (Premium) includes higher bandwidth access to the Office 365 Management Activity API, which provides faster access to audit data.
2 In addition to the required licensing for Audit (Premium) (described in the next section), a user must be assigned a 10-Year Audit Log Retention add-on license to retain their audit records for 10 years.

Audit (Standard)

Microsoft Purview Audit (Standard) provides with you with the ability to log and search for audited activities and power your forensic, IT, compliance, and legal investigations.

  • Enabled by default. Audit (Standard) is turned on by default for all organizations with the appropriate subscription. That means records for audited activities are captured and searchable. The only setup that required is to assign the necessary permissions to access the audit log search tool (and the corresponding cmdlet) and make sure that user's are assigned the right license for Microsoft Purview Audit (Premium) features.

  • Thousands of searchable audit events. You can search for a wide-range of audited activities that occur is most of the Microsoft services in your organization. For a list of the activities you can search for, see Audit log activities. For a list of the services and features that support audited activities, see Audit log record type.

  • Audit search tool in the Microsoft Purview portal or the compliance portal. Use the Audit log search tool in the portals to search for audit records. You can search for specific activities, for activities performed by specific users, and activities that occurred with a date range.

  • Search-UnifiedAuditLog cmdlet. You can also use the Search-UnifiedAuditLog cmdlet in Exchange Online PowerShell (the underlying cmdlet for the search tool) to search for audit events or to use in a script. For more information, see:

    • Search-UnifiedAuditLog cmdlet reference
    • Use a PowerShell script to search the audit log
  • Export audit records to a CSV file. After running the Audit log search tool in the Microsoft Purview portal or the compliance portal, you can export the audit records returned by the search to a CSV file. This lets you use Microsoft Excel sort and filter on different audit record properties. You can also use Excel Power Query transform functionality to split each property in the AuditData JSON object into its own column. This lets you effectively view and compare similar data for different events. For more information, see Export, configure, and view audit log records.

  • Access to audit logs via Office 365 Management Activity API. A third method for accessing and retrieving audit records is to use the Office 365 Management Activity API. This lets organizations retain auditing data for longer periods than the default 180 days and lets them import their auditing data to a SIEM solution. For more information, see Office 365 Management Activity API reference.

  • 180-day audit log retention. When an audited activity is performed by a user or admin, an audit record is generated and stored in the audit log for your organization. In Audit (Standard), records are retained for 180 days, which means you can search for activities that occurred within the past six months.

Important

The default retention period for Audit (Standard) has changed from 90 days to 180 days. Audit (Standard) logs generated before October 17, 2023 are retained for 90 days. Audit (Standard) logs generated on or after October 17, 2023 follow the new default retention of 180 days.

Audit (Premium)

Important

Classic Search has been retired as of November 30, 2023. New Search includes enhancements such as faster search times, additional search options, ability to save searches, and more.

Audit (Premium) builds on the capabilities of Audit (Standard) by providing audit log retention policies, longer retention of audit records, high-value intelligent insights, and higher bandwidth access to the Office 365 Management Activity API.

  • Audit log retention policies. You can create customized audit log retention policies to retain audit records for longer periods of time up to one year (and up to 10 years for users with required add-on license). You can create a policy to retain audit records based the service where the audited activities occur, specific audited activities, or the user who performs an audited activity.
  • Longer retention of audit records. Microsoft Entra ID, Exchange, OneDrive, and SharePoint audit records are retained for one year by default. Audit records for all other activities are retained for 180 days by default, or you can use audit log retention policies to configure longer retention periods.
  • Audit (Premium) intelligent insights. Audit records for intelligent insights can help your organization conduct forensic and compliance investigations by providing visibility to events such as when mail items were accessed, or when mail items were replied to and forwarded, or when and what a user searched for in Exchange Online and SharePoint Online. These intelligent insights can help you investigate possible breaches and determine the scope of compromise.
  • Higher bandwidth to the Office 365 Management Activity API. Audit (Premium) provides organizations with more bandwidth to access auditing logs through the Office 365 Management Activity API. Although all organizations (that have Audit (Standard) or Audit (Premium)) are initially allocated a baseline of 2,000 requests per minute, this limit will dynamically increase depending on an organization's seat count and their licensing subscription. This results in organizations with Audit (Premium) getting about twice the bandwidth as organizations with Audit (Standard).

Long-term retention of audit logs

Audit (Premium) retains all Exchange, SharePoint, and Microsoft Entra audit records for one year. This is accomplished by a default audit log retention policy that retains any audit record that contains the value of AzureActiveDirectory, Exchange, OneDrive, or SharePoint, for the Workload property (which indicates the service in which the activity occurred) for one year. Retaining audit records for longer periods can help with on-going forensic or compliance investigations. For more information, see the "Default audit log retention policy" section in Manage audit log retention policies.

In addition to the one-year retention capabilities of Audit (Premium), we've also released the capability to retain audit logs for 10 years. The 10-year retention of audit logs helps support long running investigations and respond to regulatory, legal, and internal obligations.

Note

Retaining audit logs for 10 years requires an additional per-user add-on license. After this license is assigned to a user and an appropriate 10-year audit log retention policy is set for that user, audit logs covered by that policy will start to be retained for the 10-year period. This policy is not retroactive and can't retain audit logs that were generated before the 10-year audit log retention policy was created.

Audit log retention policies

All audit records generated in other services that aren't covered by the default audit log retention policy (described in the previous section) are retained for 180 days. But you can create customized audit log retention policies to retain other audit records for longer periods of time up to 10 years. You can create a policy to retain audit records based on one or more of the following criteria:

  • The Microsoft service where the audited activities occur.

  • Specific audited activities.

  • The user who performs an audited activity.

Important

The default retention period for Audit (Standard) has changed from 90 days to 180 days. Audit (Standard) logs generated before October 17, 2023 are retained for 90 days. Audit (Standard) logs generated on or after October 17, 2023 follow the new default retention of 180 days.

You can also specify how long to retain audit records that match the policy and a priority level so that specific policies take priority over other policies. Also note that any custom audit log retention policy takes precedence over the default audit retention policy in case you need retain Exchange, SharePoint, or Azure Active Directory audit records for less than a year (or for 10 years) for some or all users in your organization. For more information, see Manage audit log retention policies.

Important

The audit item lifetime for data is determined when it is added to the auditing pipeline and is based on the licensing defaults or applicable retention policies. Any changes to licensing or applicable retention policies change the expiration time of the audit data after updating. These change don't change any previously committed items.

Audit (Premium) activity properties

Audit (Premium) helps organizations to conduct forensic and compliance investigations by providing access to important events such as when mail items were accessed, when mail items were replied to and forwarded, and when and what a user searched for in Exchange Online and SharePoint Online. These events can help you investigate possible breaches and determine the scope of compromise. In addition to these events in Exchange and SharePoint, there are events in other Microsoft services that are considered important events and require that users are assigned the appropriate Audit (Premium) license. Users must be assigned an Audit (Premium) license so that audit logs are generated when users perform these events.

These activities require that users are assigned the appropriate Audit (Premium) license. Users must be assigned an Audit (Premium) license so that audit logs are generated when users perform these activities and properties.

Audit (Premium) provides access to the following activity properties:

Exchange Online

ActivityProperty
MailItemsAccessedSensitivityLabel

Microsoft Teams

ActivityProperty
ChatCreatedAppAccessContext
ChatRetrievedAppAccessContext
ChatUpdatedAppAccessContext
MeetingParticipantDetailIsJoinedFromLobby ArtifactShared
MessageCreatedNotificationAppAccessContext
MessageDeletedNotificationAppAccessContext
MessageHostedContentsListedAppAccessContext
MessageHostedContentReadAppAccessContext
MessagesListedAppAccessContext
MessageReadAppAccessContext
MessageSentAppAccessContext ParticipatingDomainInformation ParticipantInfo
MessageUpdatedParticipantInfo AppAccessContext
MessageUpdatedNotificationAppAccessContext
SubscribedToMessagesAppAccessContext

High-bandwidth access to the Office 365 Management Activity API

Organizations that access auditing logs through the Office 365 Management Activity API were restricted by throttling limits at the publisher level. This means that for a publisher pulling data on behalf of multiple customers, the limit was shared by all those customers.

With Audit (Premium), this has changed from a publisher-level limit to a tenant-level limit. The result is that each organization get their own fully allocated bandwidth quota to access their auditing data. The bandwidth isn't a static, predefined limit but is modeled on a combination of factors including the number of seats in the organization and that E5/A5/G5 organizations get more bandwidth than non-E5/A5/G5 organizations.

All organizations are initially allocated a baseline of 2,000 requests per minute. This limit dynamically increases depending on an organization's seat count and licensing subscription. E5/A5/G5 organizations get about twice as much bandwidth as non-E5/A5/G5 organizations. There's a cap on the maximum bandwidth to protect the health of the service.

For more information, see the API throttling section in Office 365 Management Activity API reference.

Licensing requirements

Before you get started, review the subscription requirements for Audit (Standard) and Audit (Premium).

Training

Training your security operations team, IT administrators, and compliance investigators team in the fundamentals for Audit (Standard) and Audit (Premium) can help your organization get started more quickly using auditing to help with your investigations. Microsoft Purview provides the following resource to help these users in your organization getting started with auditing: Describe the eDiscovery and audit capabilities of Microsoft Purview.

Learn about auditing solutions in Microsoft Purview (2024)

FAQs

What is purview audit? ›

Microsoft Purview Audit Standard in Microsoft 365 lets you search for audit records for activities performed in your Microsoft 365 services by users and admins: Enabled by default. Thousands of searchable audit events. 90-day audit log retention. Accessed by GUI, cmdlet, and API.

Does Microsoft have an audit tool? ›

Microsoft Purview Audit (Standard) and Audit (Premium) allow you to search for audit records for activities performed in the different Microsoft services by users and admins.

What is Microsoft Purview used for? ›

Microsoft Purview solutions provide integrated coverage and help address the fragmentation of data across organizations, the lack of visibility that hampers data protection and governance, and the blurring of traditional IT management roles.

How long does a purview audit take? ›

180-day audit log retention.

The default retention period for Audit (Standard) has changed from 90 days to 180 days. Audit (Standard) logs generated before October 17, 2023 are retained for 90 days. Audit (Standard) logs generated on or after October 17, 2023 follow the new default retention of 180 days.

What is an audit solution? ›

Audit management solutions are designed to streamline the process of auditing, while reducing human time and resource. This is achieved, in a large part, through automation. Overall, this reduces the time that audits take, as well as managing costs and the necessity for human oversight.

What are the two types of classification in Microsoft purview? ›

The Microsoft Purview scanner applies data sampling rules for deep scans (subject to classification) for both system and custom classifications. The sampling rule is based on the type of data sources.

What did Microsoft purview replace? ›

In April 2022 Microsoft rebranded the compliance and risk management tools under the Microsoft Purview name. There are no feature changes, this is just a rebranding. Click here for more information. In most cases, this is just replacing Microsoft 365 Compliance with Microsoft Purview in the product names.

Is Microsoft Purview a DLP solution? ›

In Microsoft Purview, you implement data loss prevention by defining and applying DLP policies. With a DLP policy, you can identify, monitor, and automatically protect sensitive items across: Microsoft 365 services such as Teams, Exchange, SharePoint, and OneDrive accounts.

What step should be taken first before searching the audit log in Microsoft Purview? ›

Before you can look at audit data, you have to first turn on auditing in the Microsoft Purview portal or the Microsoft Purview compliance portal. For more information, see Turn auditing on or off. Audit data is only available from the point at which you turned on auditing.

How to maintain audit logs? ›

Maintain Integrity: Protect your audit logs from unauthorized changes to maintain their integrity. One way to do this is through write-once-read-many (WORM) solutions. Real-time Analysis: Implement real-time analysis of logs to provide alerts of potentially malicious activity or system behavior.

How to access purview logs? ›

You have to be assigned the Audit Logs or View-Only Audit Logs roles in the Microsoft Purview portal or Microsoft Purview compliance portal to search the audit log. By default, these roles are assigned to the Audit Manager and Audit Reader role groups on the Permissions page in the compliance portal.

What is purview vs oversight? ›

purview is substantial and wide-ranging. appropriations process to review executive authority. Oversight is an implicit constitutional power of Congress.

What is purview compliance? ›

The Microsoft Purview compliance portal is your platform for accessing all the risk and compliance solutions in Microsoft Purview. The portal provides access to the data and tools for managing your organization's compliance needs.

What is PMS audit? ›

Performance management system audits can be conducted at a corporate level, a program level, or at a category of cost level, such as capital expenditure. All that is necessary is that there is a need to define objectives for intended or desired performance.

What are the three other types of IT audits? ›

Types of IT Audits
  • Compliance Audits. Compliance audits focus on assessing the organization's adherence to relevant laws, regulations, and industry-specific standards. ...
  • Security Audits. ...
  • Operational Audits. ...
  • Performance Audits. ...
  • Privacy Audits. ...
  • Business Continuity Audits. ...
  • Risk Assessments. ...
  • Software Development Lifecycle Audit.
Feb 16, 2024

Top Articles
Rhodium Plating FAQs | Diamond Engagement Rings | Ben Garelick
How Much Do IT Certifications Cost?
Jack Doherty Lpsg
Hometown Pizza Sheridan Menu
Overnight Cleaner Jobs
Directions To 401 East Chestnut Street Louisville Kentucky
Paula Deen Italian Cream Cake
Moe Gangat Age
Alaska Bücher in der richtigen Reihenfolge
Cool Math Games Bucketball
Cooking Fever Wiki
Jalapeno Grill Ponca City Menu
Craigslist Sparta Nj
Jbf Wichita Falls
Airrack hiring Associate Producer in Los Angeles, CA | LinkedIn
Kashchey Vodka
Ein Blutbad wie kein anderes: Evil Dead Rise ist der Horrorfilm des Jahres
Cvs El Salido
Providence Medical Group-West Hills Primary Care
Seeking Arrangements Boston
Buying Cars from Craigslist: Tips for a Safe and Smart Purchase
Bòlèt Florida Midi 30
Hellraiser 3 Parents Guide
Mdt Bus Tracker 27
Harbor Freight Tax Exempt Portal
Firefly Festival Logan Iowa
Section 408 Allegiant Stadium
The Posturepedic Difference | Sealy New Zealand
Package Store Open Near Me Open Now
Mark Ronchetti Daughters
Kempsville Recreation Center Pool Schedule
Tire Pro Candler
A Small Traveling Suitcase Figgerits
Justin Mckenzie Phillip Bryant
Royals op zondag - "Een advertentie voor Center Parcs" of wat moeten we denken van de laatste video van prinses Kate?
Family Fare Ad Allendale Mi
Crystal Mcbooty
Acadis Portal Missouri
In Polen und Tschechien droht Hochwasser - Brandenburg beobachtet Lage
Raising Canes Franchise Cost
Chatropolis Call Me
Trizzle Aarp
Gary Lezak Annual Salary
Davis Fire Friday live updates: Community meeting set for 7 p.m. with Lombardo
All-New Webkinz FAQ | WKN: Webkinz Newz
Directions To Cvs Pharmacy
Southwest Airlines Departures Atlanta
Avance Primary Care Morrisville
Conan Exiles Colored Crystal
Mejores páginas para ver deportes gratis y online - VidaBytes
Who Is Nina Yankovic? Daughter of Musician Weird Al Yankovic
Loss Payee And Lienholder Addresses And Contact Information Updated Daily Free List Bank Of America
Latest Posts
Article information

Author: Dan Stracke

Last Updated:

Views: 6028

Rating: 4.2 / 5 (43 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Dan Stracke

Birthday: 1992-08-25

Address: 2253 Brown Springs, East Alla, OH 38634-0309

Phone: +398735162064

Job: Investor Government Associate

Hobby: Shopping, LARPing, Scrapbooking, Surfing, Slacklining, Dance, Glassblowing

Introduction: My name is Dan Stracke, I am a homely, gleaming, glamorous, inquisitive, homely, gorgeous, light person who loves writing and wants to share my knowledge and understanding with you.