Home > Glossary > Microsoft 365 Administrator > Microsoft 365 Unified Audit Log

📖 What is Microsoft 365 Unified Audit Log?

The Microsoft 365 Unified Audit Log is a centralized repository that records activities across all Microsoft 365 services, including Exchange, SharePoint, Teams, and Entra ID. It allows administrators to search for specific events to investigate security incidents or track user activity.

🥋 Sensei Says:

"Audit logging must be explicitly enabled in the Microsoft Purview portal before events begin to be captured and stored."

📚 Certification: Microsoft 365 Administrator (MS-102)

🔑 What are the Key Concepts of Microsoft 365 Unified Audit Log?

  • Centralized Aggregation: Consolidates activity data from Exchange Online, SharePoint, OneDrive, Microsoft Teams, and Entra ID into a single searchable interface within Microsoft Purview.
  • Activation Requirement: Audit logging is not always active by default; administrators must explicitly enable it in the Purview portal to begin capturing events.
  • Retention Policies: Default retention is typically 90 days for most licenses, but E5 licenses allow for extended retention periods up to 10 years.
  • Search and Filtering: Provides granular filtering by date, user, and operation, allowing administrators to perform forensic investigations or compliance audits across the tenant.
  • Event Schema: Each entry captures critical metadata, including the timestamp, the user who performed the action, the specific operation, and the affected workload.

🎯 How does Microsoft 365 Unified Audit Log appear on the MS-102 Exam?

You may be asked to identify the correct tool for investigating a security incident where a user is suspected of downloading sensitive files from both SharePoint and OneDrive.

A scenario might describe an administrator who cannot find audit records for a specific date range; you must determine if audit logging was enabled prior to those events.

Expect questions regarding data retention requirements, where you must choose the appropriate license tier to extend audit log storage beyond the standard 90-day window.

❓ Frequently Asked Questions

Does enabling the Unified Audit Log retroactively capture events that occurred before activation?

No, the Unified Audit Log only records activities that occur after the feature has been enabled. Any events that took place before activation are not captured and cannot be recovered.


What is the primary difference between the Unified Audit Log and Entra ID sign-in logs?

Entra ID sign-in logs focus exclusively on authentication and access attempts, while the Unified Audit Log tracks the actual actions users perform within M365 services after they have authenticated.

Related Terms from Microsoft 365 Administrator

📝 Related Study Guides

Comparison 8 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

Choose CISSP if you want broad technical security expertise across eight domains, including cryptography, network security, and software development. Choose CISM if you're focused on information security management, governance, and risk management from a leadership perspective. CISSP is ideal for hands-on security architects, while CISM is designed for security managers and directors.

Career Guide 9 min read

The IT Certification Roadmap: Where to Start in 2026

Start your IT certification journey in 2026 with CompTIA A+ for general IT foundations, then branch into networking (Network+), cybersecurity (Security+), or cloud computing (AWS Cloud Practitioner or Azure Fundamentals) based on your career goals. Each path leads to advanced certifications like CISSP, AWS Solutions Architect, or CISM within 2-3 years of focused progression.

Comparison 10 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

The CISSP is a broad, technical-to-managerial certification focusing on security operations and architecture across eight domains. In contrast, CISM is a specialized management certification centered on governance, risk management, and program development. Choose CISSP for comprehensive security expertise and CISM if you are pivoting specifically into security leadership and governance roles.

🧠

Test Your Knowledge

Think you understand Microsoft 365 Unified Audit Log? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium