Create customized audit log retention policies to retain audit records based on the service where the audited activities occur, specific audited activities, or the user who performs an audited activity.
Retain Audit (Premium) users' audit log records of Exchange, SharePoint, OneDrive, and Microsoft Entra ID for one year by default and 180 days for all other activities. Retain audit log records for up to 10 years with an add-on license.
Support investigations by providing visibility to events such as when mail items were accessed, replied to and forwarded, or when and what a user searched for in Exchange Online and SharePoint Online.
Organizations are initially allocated a baseline of 2,000 requests to the Office 365 Management Activity API per minute, where this limit will dynamically increase depending on an organization's seat count and their licensing subscription, resulting in about twice the bandwidth as organizations with Audit (Standard).
Audit provides crucial event data that can help you investigate possible breaches and determine the scope of compromise. This diagram illustrates the five user-focused events for investigations which include: user events, email events, Microsoft Teams events, files, and searches.
Microsoft Purview Audit is a part of the Microsoft Purview Suite
Microsoft offers comprehensive compliance and data governance solutions to help your organization manage risks, protect and govern sensitive data, and respond to regulatory requirements.
* Customers currently licensed with Enterprise Mobility Security + Office E3, Microsoft 365 E3, or a version of these suites that does not include Microsoft Teams, are eligible to purchase or try Purview Suite. You must be a global, compliance, or billing admin to initiate this trial.Â
Resources
Additional Resources
Get more information about Microsoft Purview Audit—formerly Advanced Audit in Microsoft 365.
News
Latest news on changes coming to Audit
Learn more about the changes coming to Audit, including longer default retention and additional audit logging events.
Follow Microsoft Security