Purview Audit: Investigate & Retain
Microsoft Purview Audit logs every significant action in your M365 tenant. Understand Audit Standard vs Premium, investigate activities, and configure audit retention policies to keep records as long as regulations require.
What is Purview Audit?
Think of security camera footage for your entire digital office.
Every time someone opens a file, sends an email, changes a permission, or modifies a setting β it gets recorded. Microsoft Purview Audit is that camera system for your Microsoft 365 tenant. When something goes wrong (a data breach, an unauthorised access, a compliance investigation), you can rewind the tape and see exactly what happened, when, and by whom.
Audit Standard gives you 180 days of footage. Audit Premium gives you up to 10 years, plus faster access and smarter search.
Audit Standard vs Audit Premium
| Feature | Audit Standard | Audit Premium |
|---|---|---|
| Default retention | 180 days | 1 year (365 days) |
| Maximum retention | 180 days (not configurable) | Up to 10 years (via custom audit retention policies) |
| Custom retention policies | No | Yes β per-service, per-activity type, per-user |
| High-bandwidth API | Standard throughput | Higher throughput for large-volume log retrieval |
| Intelligent insights | No | Yes β MailItemsAccessed, SearchQueryInitiatedExchange, SearchQueryInitiatedSharePoint |
| Licensing | E3, E5 (included) | E5, E5 Compliance, E5 eDiscovery and Audit add-on |
| Per-user licensing? | No β tenant-wide | Yes β assign Audit Premium licenses to specific users for extended logging |
Assigning Audit Premium licenses
Audit Premium is a per-user license. Only users with the license get:
- Extended retention (beyond 180 days)
- Intelligent insights (MailItemsAccessed, search queries)
- Custom retention policy application
How to assign
- Microsoft 365 admin center β Users β Active users β Select user β Licenses β Enable βMicrosoft 365 Audit (Premium)β
- Or assign via group-based licensing in Entra ID β add the license to a security group
Exam tip: per-user licensing
The exam tests that Audit Premium is per-user. Key points:
- Only users WITH the Audit Premium license generate extended audit records
- Admin actions are logged regardless of the adminβs license
- If you need 10-year retention for a specific userβs mailbox activities, that user needs the license
- Group-based licensing is the scalable assignment method
Investigating with Audit
Search the unified audit log
In Microsoft Purview portal β Audit β Search:
| Search Parameter | What It Filters |
|---|---|
| Date range | Start and end date/time |
| Activities | Specific activity types (FileAccessed, MailSend, UserLoggedIn, etc.) |
| Users | Specific user(s) who performed the activity |
| File, folder, or site | Specific locations where the activity occurred |
| Record types | Filter by service (Exchange, SharePoint, Teams, Entra ID) |
Key audit activities for investigations
| Activity | What It Records | Investigation Use |
|---|---|---|
| FileAccessed | User opened a file in SharePoint/OneDrive | Who accessed sensitive documents |
| MailItemsAccessed (Premium) | User accessed email items | Compromised account investigation β was the mailbox accessed by an attacker? |
| FileModified | User edited a file | Track changes to sensitive documents |
| FileCopied | User copied a file to another location | Data movement tracking |
| SearchQueryInitiatedExchange (Premium) | User searched their mailbox | What was the user looking for? Useful for insider threat investigations |
| UserLoggedIn | User signed into M365 | Track access patterns, impossible travel |
| SensitivityLabelApplied | A sensitivity label was applied to an item | Label activity monitoring |
| DLPRuleMatch | A DLP rule was triggered | Correlate DLP events with user actions |
Custom audit retention policies
With Audit Premium, create policies that retain specific log types longer:
| Setting | What It Controls |
|---|---|
| Name | Policy name |
| Record type | Which serviceβs logs to retain (Exchange, SharePoint, Teams, etc.) |
| Activities | Specific activities within the service (optional β retain all or specific) |
| Users | Specific users or all users |
| Duration | 1 year, 3 years, 5 years, 7 years, or 10 years |
| Priority | Higher priority policies override lower ones for the same logs |
Scenario: Priya configures audit retention at Meridian
Meridian Financial must retain trading communication audit logs for 7 years (SEC requirement):
- Policy name: βSEC β Trading Communications β 7 Yearβ
- Record type: Exchange
- Activities: MailSend, MailReceive, MailItemsAccessed
- Users: Trading team security group (Audit Premium licensed)
- Duration: 7 years
- Priority: 10 (higher than the default 1-year policy)
For all other users, the default Audit Premium 1-year retention applies.
Meridian Financial suspects that a former employee's account was compromised after they left. Priya needs to see which emails were accessed in the compromised mailbox during the breach window. The former employee had an E5 license. Which audit activity should she search?
Dr. Liam needs to retain audit logs for patient record access at St. Harbour Health for 7 years. The clinical staff have E3 licenses. What must he do first?
π¬ Video coming soon
Next up: Activity Explorer & Content Search β investigate data activities and search for content across your entire M365 tenant.