📖 What is Microsoft 365 Unified Audit Log?
The Microsoft 365 Unified Audit Log is a centralized repository that records activities across all Microsoft 365 services, including Exchange, SharePoint, Teams, and Entra ID. It allows administrators to search for specific events to investigate security incidents or track user activity.
"Audit logging must be explicitly enabled in the Microsoft Purview portal before events begin to be captured and stored."
📚 Certification: Microsoft 365 Administrator (MS-102)
🔑 What are the Key Concepts of Microsoft 365 Unified Audit Log?
- ▸ Centralized Aggregation: Consolidates activity data from Exchange Online, SharePoint, OneDrive, Microsoft Teams, and Entra ID into a single searchable interface within Microsoft Purview.
- ▸ Activation Requirement: Audit logging is not always active by default; administrators must explicitly enable it in the Purview portal to begin capturing events.
- ▸ Retention Policies: Default retention is typically 90 days for most licenses, but E5 licenses allow for extended retention periods up to 10 years.
- ▸ Search and Filtering: Provides granular filtering by date, user, and operation, allowing administrators to perform forensic investigations or compliance audits across the tenant.
- ▸ Event Schema: Each entry captures critical metadata, including the timestamp, the user who performed the action, the specific operation, and the affected workload.
🎯 How does Microsoft 365 Unified Audit Log appear on the MS-102 Exam?
You may be asked to identify the correct tool for investigating a security incident where a user is suspected of downloading sensitive files from both SharePoint and OneDrive.
A scenario might describe an administrator who cannot find audit records for a specific date range; you must determine if audit logging was enabled prior to those events.
Expect questions regarding data retention requirements, where you must choose the appropriate license tier to extend audit log storage beyond the standard 90-day window.
❓ Frequently Asked Questions
Does enabling the Unified Audit Log retroactively capture events that occurred before activation?
No, the Unified Audit Log only records activities that occur after the feature has been enabled. Any events that took place before activation are not captured and cannot be recovered.
What is the primary difference between the Unified Audit Log and Entra ID sign-in logs?
Entra ID sign-in logs focus exclusively on authentication and access attempts, while the Unified Audit Log tracks the actual actions users perform within M365 services after they have authenticated.