Changing the retention policy today does nothing whatsoever for the logs that already expired.
How long an audit record lives is fixed at the moment it is written, and no later change to licensing or retention touches anything already committed. So the trail you will need during an investigation is the one somebody configured before that investigation began, and by default it runs a hundred and eighty days.

- 180 daysAudit Standard default retention
- One yearEntra, Exchange, OneDrive and SharePoint on Premium
- Not retroactiveRetention changes apply only going forward
- MailItemsAccessedThe event that scopes a mailbox compromise
How far back could you search this morning, and would that be enough?
Four consequences follow from the fact that retention is fixed at the instant a record gets written.
- If you are on Audit Standard, your answer is 180 days, and 90 days for anything generated before October 17, 2023. That is your investigation horizon, today, whatever your security policy document says.
- A breach is very often discovered long after it began. An intrusion that started seven months ago sits entirely outside the standard retention window, which means the investigation cannot establish when it began or what was reached, only that something is wrong today. That distinction drives what you are obliged to tell your customers, your regulator and your insurance carrier.
- Upgrading after discovering a problem does nothing at all for that problem. Changes to licensing or to retention policy explicitly do not touch anything already committed. The upgrade improves your position for the next incident and contributes nothing whatsoever to the one in front of you.
- The same holds for the ten year add-on, which is not retroactive and cannot retain anything generated before the policy existed. Where a regulatory or contractual retention obligation applies to you, that policy has to be in place before the period it is supposed to cover, rather than created the week somebody asks to see the evidence.
Eight things about audit that matter before an incident rather than during one.
Retention is decided when the record is written
The lifetime of an audit item is determined at the moment the pipeline writes it, according to whatever licensing default or retention policy applied then. Changing the licensing or the policy alters the expiry of everything written afterward and touches nothing already committed. That is the single most important sentence anybody will read about this. Upgrading mid-investigation recovers precisely nothing that has already gone.
180 days by default, and it used to be 90
The standard tier keeps records for a hundred and eighty days, so you can search back six months and no further. Worth knowing on an older matter: anything generated before 17 October 2023 was kept for ninety days, with the longer default applying only from that date onward. An investigation that needs to reach further back than six months hits a wall no purchase order will move.
Premium retention, and what it actually covers by default
On the premium tier, records covering identity, mail, OneDrive and SharePoint are kept for a year by default, through a retention policy keyed to those particular workloads. Everything else stays at a hundred and eighty days unless somebody writes a custom policy. That distinction catches companies out constantly, because everybody assumes premium means a year across the board.
Ten year retention, with three conditions
Three things. It needs an additional per-person add-on sitting on top of premium. It is not retroactive and cannot retain anything generated before the policy existed. And records produced by things that are not people, meaning service principal actions, system events and application activity, are held for a fixed year that cannot be configured and that no custom policy touches. All three matter enormously when planning around a regulatory or contractual retention requirement.
MailItemsAccessed, the event that scopes a compromise
The premium insights show you things like the sensitivity label attached to whichever mail somebody opened, and both when and what a person searched for across mail and SharePoint. They exist to make investigating a possible breach easier and to establish the scope of a compromise more precisely. In a business email compromise, the gap between knowing an account was accessed and knowing exactly which messages were read is the gap between making a notification decision and guessing at one.
Teams activity properties, which are newly relevant
The premium tier adds properties to a range of Teams activity, covering chats being created, retrieved and updated, messages being written, read, sent and deleted, and detail about who attended a meeting. Those properties include the application access context, which domains were involved, and information about each participant. As more genuinely sensitive conversation migrates into Teams, being able to investigate it properly stops being a nice extra.
Custom retention policies, keyed three ways
On premium you can write policies retaining records according to which service the activity happened in, which specific activities occurred, or who performed them, with a priority so that the more specific policy wins. A custom policy overrides the default in both directions, which means keeping more for a sensitive group of people, or genuinely keeping less than a year where you have an actual reason to.
Getting the data out, and how fast
Both tiers give you the search tool in the portal, the search API, the command line equivalent, export to a spreadsheet, and the management activity API. Every organization starts at a baseline of two thousand requests a minute, that ceiling rises automatically with seat count and subscription, and the top academic, enterprise and government tiers get roughly double the bandwidth. That matters a great deal when pulling this data into a log platform at any scale.
Four things we do that most organizations only think about after an incident.
Your real horizon gets established first, rather than the one written in a policy
Which tier you hold, which retention policies exist, and therefore how far back somebody could genuinely search this afternoon. In our experience that answer differs from what the security policy claims in most cases, and the gap only ever surfaces during an incident, which is the single worst moment to learn it.
Retention gets mapped against your obligations rather than against a tier
Premium keeps identity, mail, OneDrive and SharePoint for a year by default, and everything else for a hundred and eighty days. Where your obligation reaches activity in some other workload, whether that obligation comes from HIPAA documentation expectations, from a parent company under NYDFS, from a customer contract or from your own insurance policy, the tier alone does not satisfy it and a custom retention policy is required. That is a configuration task rather than something to buy.
We rehearse a search before you need one
Permission to search the log has to be assigned deliberately, and it is frequently held by nobody at all. We confirm who can search, walk through the specific searches that would matter in a realistic incident, and make certain somebody has done it at least once. An audit capability nobody has ever used is not a capability. It is an assumption.
Where the retention window falls short, we set up an export instead
The management activity API lets audit data be kept beyond the default period and pulled into your log platform. Where a retention obligation exceeds what your licensing gives you, or where you simply want this data sitting alongside everything else, that is frequently a better answer than upgrading a license, and it is considerably more useful day to day.
Six US situations where audit retention decides the outcome.
A business email compromise discovered weeks later
The question that matters is which messages were actually read, because that determines what you must disclose and to whom under HIPAA and the state breach notification laws. The premium insights give you the sensitivity label on every mail item that was opened, along with what the person searched for across mail and SharePoint, and that is exactly what turns a guess into a scoped answer.
A regulated firm with a specified retention period
Financial firms under NYDFS Part 500 or sector supervision, and healthcare organizations working through a HIPAA risk analysis, all face expectations measured in years for the records that support an investigation. The retention policy has to have been in place across that entire period, because policies are explicitly not retroactive. Sorting this out early is a small configuration exercise. Discovering it late is a finding that cannot be remediated at all.
A departing employee dispute
Somebody resigned, took something with them, and it only surfaces four months afterward when they appear at a competitor. The question is what they opened and downloaded in the weeks before leaving, and whether that activity still sits inside your search window. On standard defaults four months falls comfortably inside six, and the margin is considerably thinner than anybody realizes.
Litigation or a regulatory inquiry
Audit records and discovery are genuinely different things, and a matter may well need both. Audit tells you who did what, and when, across every service. The retention question is identical either way: does the record still exist, and that was decided at the moment it was written rather than at the moment somebody comes asking.
A business pulling audit into a SIEM
The management API limit moved from being set per publisher to being set per tenant. Everybody starts at two thousand requests a minute, that scales with seat count and subscription, and the top enterprise, academic and government tiers get roughly double. For a large tenant feeding a log platform continuously, that bandwidth is a genuine design constraint rather than a footnote.
A business whose sensitive conversation lives in Teams
Which increasingly describes every company. The premium tier adds properties across Teams activity covering chats being created and retrieved, messages sent, read, edited and deleted, and detail on who attended a meeting, including the application access context and information about each participant. Without any of that, an investigation into what happened in Teams is materially thinner than the equivalent one into email.
What businesses can actually reconstruct after an incident.
| Feature | Audit configured deliberately | Premium, unconfigured | Standard defaults |
|---|---|---|---|
Can search the last six months | Yes | Yes | Yes |
Can search back a year for core workloads | Yes | Yes | No |
Can search back a year for other workloads | Yes | No | No |
Retention aligned to a regulatory obligation | Yes | Unlikely | No |
Knows which mail items an attacker read | Yes | Yes | No |
Sensitivity label of accessed mail visible | Yes | Yes | No |
Teams activity investigable in detail | Yes | Yes | No |
Audit data exported beyond the retention window | Yes | Sometimes | Rarely |
Somebody has actually run a search before | Yes | Sometimes | Rarely |
Breach notification decision backed by evidence | Yes | Partly | No |
What each tier actually gives you, on the points that decide an investigation.
Capability
Enabled by default
- Audit Standard
- Yes
- Audit Premium
- Yes
Capability
Thousands of searchable audit events
- Audit Standard
- Yes
- Audit Premium
- Yes
Capability
Portal search, Graph API, PowerShell, CSV export
- Audit Standard
- Yes
- Audit Premium
- Yes
Capability
Office 365 Management Activity API access
- Audit Standard
- Yes
- Audit Premium
- Yes, at higher bandwidth
Capability
Default retention
- Audit Standard
- 180 days
- Audit Premium
- 1 year for Entra, Exchange, OneDrive, SharePoint
Capability
Retention for other workloads
- Audit Standard
- 180 days
- Audit Premium
- 180 days unless a custom policy exists
Capability
Custom audit log retention policies
- Audit Standard
- No
- Audit Premium
- Yes
Capability
Ten year retention
- Audit Standard
- No
- Audit Premium
- With a per-user add-on license
Capability
Intelligent insights
- Audit Standard
- No
- Audit Premium
- Yes
Capability
Sensitivity label on accessed mail items
- Audit Standard
- No
- Audit Premium
- Yes
Capability
Teams activity properties
- Audit Standard
- No
- Audit Premium
- Yes
Five steps, and considerably quicker than most security work.
- 1
Establish the current position
Which tier you hold, which retention policies exist, whether any ten year add-ons have been assigned to anybody, and therefore how far back a search could genuinely reach right now. That is the number that matters, and it is very rarely the number people were expecting.
- 2
Establish what you are obliged to keep
Whatever your regulator requires, whatever you have promised customers contractually, the conditions attached to your insurance policy, and any certification you hold or are working toward. Then set all of that against the actual position. Whatever gap emerges is what the rest of the work exists to close.
- 3
Configure retention policies deliberately
Where premium is available, custom policies keyed to a service, to particular activities or to specific people, with the priority set so the important cases win. This matters most for the workloads outside identity, mail, OneDrive and SharePoint, all of which stay at a hundred and eighty days unless somebody deliberately intervenes.
- 4
Set up export where retention alone is insufficient
Out through the management activity API, into your log platform or a store you keep yourself, wherever an obligation exceeds what the licensing provides or the data is simply more useful sitting alongside everything else. Bandwidth becomes a design consideration on a large tenant, and it gets sized rather than assumed.
- 5
Assign permissions and rehearse a real search
Confirm who actually holds permission to search, run the searches a realistic incident would demand, and write them down so that whoever does this at two in the morning is following a note rather than learning an unfamiliar tool under pressure. An afternoon of work, and it is the step that makes everything before it real.
What US businesses ask about Purview Audit.
Fifteen questions worth answering while nothing is wrong.
Your current horizon
- How far back can you search today?180 days on Standard, and 90 before October 2023.
- Are you on Audit Standard or Premium?Frequently nobody in IT knows.
- If Premium, do custom retention policies exist?Non-core workloads stay at 180 days without one.
- Does anybody here hold the ten year add-on?Per-user, and not retroactive.
- Has audit ever been exported anywhere?The API route retains beyond the default.
Your obligations
- Does a regulator specify a retention period?NYDFS Part 500 and sector rules set multi-year expectations.
- Do customer contracts specify one?Increasingly common in enterprise agreements.
- Are you pursuing SOC 2 or ISO 27001?Both examine logging and monitoring directly.
- Could you face litigation needing old records?eDiscovery and audit are different things.
- Do you need records for non-user activity?Fixed at one year and not configurable.
Could anybody actually search
- Who has permission to search the audit log?It needs assigning, it is not automatic.
- Has anybody ever run a search?An untested capability is not a capability.
- Do you know which activities you would search for?Worth rehearsing before you need it.
- Is audit data flowing to a SIEM?Available through the Management Activity API.
- Who would run an investigation at 2am?Decide before, not during.
The pages around this one.
Microsoft Purview
The wider governance and compliance platform this sits inside, including classification, retention and eDiscovery.
Purview eDiscovery
The other half of an investigation: finding and preserving the content itself, with its own retention rules.
Microsoft Sentinel
The SIEM that audit data feeds through the Management Activity API when the window alone is not enough.
Find out how far back you can search. It takes ten minutes and it is free.
That number is fixed for every record already written, and it determines what any future investigation will be able to establish. If it is shorter than your obligations, the fix has to happen now rather than when somebody asks for the evidence.
Related Services
Explore more solutions that work great with this service
Microsoft Purview
Data governance and compliance solutions
Learn moreMicrosoft Purview eDiscovery
Legal hold and eDiscovery readiness done properly
Learn moreMicrosoft Sentinel
Cloud-native SIEM and threat intelligence
Learn moreMicrosoft 365 Security Audit
Independent Microsoft 365 tenant security audit for US organizations
Learn moreIT Compliance
HIPAA, SOC 2, NIST, CMMC, CCPA readiness
Learn more