We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft Purview
  2. Audit
Microsoft Purview Audit for US businesses

Changing the retention policy today does nothing whatsoever for the logs that already expired.

How long an audit record lives is fixed at the moment it is written, and no later change to licensing or retention touches anything already committed. So the trail you will need during an investigation is the one somebody configured before that investigation began, and by default it runs a hundred and eighty days.

Book an audit readiness reviewSee what each tier retains
Microsoft Purview Audit configuration for US businesses
  • 180 daysAudit Standard default retention
  • One yearEntra, Exchange, OneDrive and SharePoint on Premium
  • Not retroactiveRetention changes apply only going forward
  • MailItemsAccessedThe event that scopes a mailbox compromise
The question to ask today

How far back could you search this morning, and would that be enough?

Four consequences follow from the fact that retention is fixed at the instant a record gets written.

  • If you are on Audit Standard, your answer is 180 days, and 90 days for anything generated before October 17, 2023. That is your investigation horizon, today, whatever your security policy document says.
  • A breach is very often discovered long after it began. An intrusion that started seven months ago sits entirely outside the standard retention window, which means the investigation cannot establish when it began or what was reached, only that something is wrong today. That distinction drives what you are obliged to tell your customers, your regulator and your insurance carrier.
  • Upgrading after discovering a problem does nothing at all for that problem. Changes to licensing or to retention policy explicitly do not touch anything already committed. The upgrade improves your position for the next incident and contributes nothing whatsoever to the one in front of you.
  • The same holds for the ten year add-on, which is not retroactive and cannot retain anything generated before the policy existed. Where a regulatory or contractual retention obligation applies to you, that policy has to be in place before the period it is supposed to cover, rather than created the week somebody asks to see the evidence.
Ask us to check your current retention position
What the audit log gives you

Eight things about audit that matter before an incident rather than during one.

The unified log captures, records and retains thousands of operations by ordinary users and administrators alike, spanning dozens of services, and exists for security events, forensic work, internal investigations and whatever compliance obligations you carry.

Retention is decided when the record is written

The lifetime of an audit item is determined at the moment the pipeline writes it, according to whatever licensing default or retention policy applied then. Changing the licensing or the policy alters the expiry of everything written afterward and touches nothing already committed. That is the single most important sentence anybody will read about this. Upgrading mid-investigation recovers precisely nothing that has already gone.

180 days by default, and it used to be 90

The standard tier keeps records for a hundred and eighty days, so you can search back six months and no further. Worth knowing on an older matter: anything generated before 17 October 2023 was kept for ninety days, with the longer default applying only from that date onward. An investigation that needs to reach further back than six months hits a wall no purchase order will move.

Premium retention, and what it actually covers by default

On the premium tier, records covering identity, mail, OneDrive and SharePoint are kept for a year by default, through a retention policy keyed to those particular workloads. Everything else stays at a hundred and eighty days unless somebody writes a custom policy. That distinction catches companies out constantly, because everybody assumes premium means a year across the board.

Ten year retention, with three conditions

Three things. It needs an additional per-person add-on sitting on top of premium. It is not retroactive and cannot retain anything generated before the policy existed. And records produced by things that are not people, meaning service principal actions, system events and application activity, are held for a fixed year that cannot be configured and that no custom policy touches. All three matter enormously when planning around a regulatory or contractual retention requirement.

MailItemsAccessed, the event that scopes a compromise

The premium insights show you things like the sensitivity label attached to whichever mail somebody opened, and both when and what a person searched for across mail and SharePoint. They exist to make investigating a possible breach easier and to establish the scope of a compromise more precisely. In a business email compromise, the gap between knowing an account was accessed and knowing exactly which messages were read is the gap between making a notification decision and guessing at one.

Teams activity properties, which are newly relevant

The premium tier adds properties to a range of Teams activity, covering chats being created, retrieved and updated, messages being written, read, sent and deleted, and detail about who attended a meeting. Those properties include the application access context, which domains were involved, and information about each participant. As more genuinely sensitive conversation migrates into Teams, being able to investigate it properly stops being a nice extra.

Custom retention policies, keyed three ways

On premium you can write policies retaining records according to which service the activity happened in, which specific activities occurred, or who performed them, with a priority so that the more specific policy wins. A custom policy overrides the default in both directions, which means keeping more for a sensitive group of people, or genuinely keeping less than a year where you have an actual reason to.

Getting the data out, and how fast

Both tiers give you the search tool in the portal, the search API, the command line equivalent, export to a spreadsheet, and the management activity API. Every organization starts at a baseline of two thousand requests a minute, that ceiling rises automatically with seat count and subscription, and the top academic, enterprise and government tiers get roughly double the bandwidth. That matters a great deal when pulling this data into a log platform at any scale.

How we approach it

Four things we do that most organizations only think about after an incident.

Configuring audit is comfortably the least interesting security work available and among the highest value, because it is the only control determining what you will be able to find out afterward.

Your real horizon gets established first, rather than the one written in a policy

Which tier you hold, which retention policies exist, and therefore how far back somebody could genuinely search this afternoon. In our experience that answer differs from what the security policy claims in most cases, and the gap only ever surfaces during an incident, which is the single worst moment to learn it.

Retention gets mapped against your obligations rather than against a tier

Premium keeps identity, mail, OneDrive and SharePoint for a year by default, and everything else for a hundred and eighty days. Where your obligation reaches activity in some other workload, whether that obligation comes from HIPAA documentation expectations, from a parent company under NYDFS, from a customer contract or from your own insurance policy, the tier alone does not satisfy it and a custom retention policy is required. That is a configuration task rather than something to buy.

We rehearse a search before you need one

Permission to search the log has to be assigned deliberately, and it is frequently held by nobody at all. We confirm who can search, walk through the specific searches that would matter in a realistic incident, and make certain somebody has done it at least once. An audit capability nobody has ever used is not a capability. It is an assumption.

Where the retention window falls short, we set up an export instead

The management activity API lets audit data be kept beyond the default period and pulled into your log platform. Where a retention obligation exceeds what your licensing gives you, or where you simply want this data sitting alongside everything else, that is frequently a better answer than upgrading a license, and it is considerably more useful day to day.

Where this matters most

Six US situations where audit retention decides the outcome.

Every one of these is a situation where the question arrives months after the activity, which is precisely the point at which the default window has already shut.

A business email compromise discovered weeks later

The question that matters is which messages were actually read, because that determines what you must disclose and to whom under HIPAA and the state breach notification laws. The premium insights give you the sensitivity label on every mail item that was opened, along with what the person searched for across mail and SharePoint, and that is exactly what turns a guess into a scoped answer.

A regulated firm with a specified retention period

Financial firms under NYDFS Part 500 or sector supervision, and healthcare organizations working through a HIPAA risk analysis, all face expectations measured in years for the records that support an investigation. The retention policy has to have been in place across that entire period, because policies are explicitly not retroactive. Sorting this out early is a small configuration exercise. Discovering it late is a finding that cannot be remediated at all.

A departing employee dispute

Somebody resigned, took something with them, and it only surfaces four months afterward when they appear at a competitor. The question is what they opened and downloaded in the weeks before leaving, and whether that activity still sits inside your search window. On standard defaults four months falls comfortably inside six, and the margin is considerably thinner than anybody realizes.

Litigation or a regulatory inquiry

Audit records and discovery are genuinely different things, and a matter may well need both. Audit tells you who did what, and when, across every service. The retention question is identical either way: does the record still exist, and that was decided at the moment it was written rather than at the moment somebody comes asking.

A business pulling audit into a SIEM

The management API limit moved from being set per publisher to being set per tenant. Everybody starts at two thousand requests a minute, that scales with seat count and subscription, and the top enterprise, academic and government tiers get roughly double. For a large tenant feeding a log platform continuously, that bandwidth is a genuine design constraint rather than a footnote.

A business whose sensitive conversation lives in Teams

Which increasingly describes every company. The premium tier adds properties across Teams activity covering chats being created and retrieved, messages sent, read, edited and deleted, and detail on who attended a meeting, including the application access context and information about each participant. Without any of that, an investigation into what happened in Teams is materially thinner than the equivalent one into email.

Three positions

What businesses can actually reconstruct after an incident.

The right hand column is common, and it almost never represents a decision anybody consciously took. The standard tier is enabled by default, so most companies have precisely what arrived with the tenant and have never once opened it.
Can search the last six months
Audit configured deliberatelyYes
Premium, unconfiguredYes
Standard defaultsYes
Can search back a year for core workloads
Audit configured deliberatelyYes
Premium, unconfiguredYes
Standard defaultsNo
Can search back a year for other workloads
Audit configured deliberatelyYes
Premium, unconfiguredNo
Standard defaultsNo
Retention aligned to a regulatory obligation
Audit configured deliberatelyYes
Premium, unconfiguredUnlikely
Standard defaultsNo
Knows which mail items an attacker read
Audit configured deliberatelyYes
Premium, unconfiguredYes
Standard defaultsNo
Sensitivity label of accessed mail visible
Audit configured deliberatelyYes
Premium, unconfiguredYes
Standard defaultsNo
Teams activity investigable in detail
Audit configured deliberatelyYes
Premium, unconfiguredYes
Standard defaultsNo
Audit data exported beyond the retention window
Audit configured deliberatelyYes
Premium, unconfiguredSometimes
Standard defaultsRarely
Somebody has actually run a search before
Audit configured deliberatelyYes
Premium, unconfiguredSometimes
Standard defaultsRarely
Breach notification decision backed by evidence
Audit configured deliberatelyYes
Premium, unconfiguredPartly
Standard defaultsNo
Feature
Audit configured deliberately
Premium, unconfigured
Standard defaults
Can search the last six months
YesYesYes
Can search back a year for core workloads
YesYesNo
Can search back a year for other workloads
YesNoNo
Retention aligned to a regulatory obligation
YesUnlikelyNo
Knows which mail items an attacker read
YesYesNo
Sensitivity label of accessed mail visible
YesYesNo
Teams activity investigable in detail
YesYesNo
Audit data exported beyond the retention window
YesSometimesRarely
Somebody has actually run a search before
YesSometimesRarely
Breach notification decision backed by evidence
YesPartlyNo
Standard against Premium

What each tier actually gives you, on the points that decide an investigation.

Premium contains everything standard does. Taken from the published capability comparison, with the retention detail sitting underneath it added in.

Capability

Enabled by default

Audit Standard
Yes
Audit Premium
Yes

Capability

Thousands of searchable audit events

Audit Standard
Yes
Audit Premium
Yes

Capability

Portal search, Graph API, PowerShell, CSV export

Audit Standard
Yes
Audit Premium
Yes

Capability

Office 365 Management Activity API access

Audit Standard
Yes
Audit Premium
Yes, at higher bandwidth

Capability

Default retention

Audit Standard
180 days
Audit Premium
1 year for Entra, Exchange, OneDrive, SharePoint

Capability

Retention for other workloads

Audit Standard
180 days
Audit Premium
180 days unless a custom policy exists

Capability

Custom audit log retention policies

Audit Standard
No
Audit Premium
Yes

Capability

Ten year retention

Audit Standard
No
Audit Premium
With a per-user add-on license

Capability

Intelligent insights

Audit Standard
No
Audit Premium
Yes

Capability

Sensitivity label on accessed mail items

Audit Standard
No
Audit Premium
Yes

Capability

Teams activity properties

Audit Standard
No
Audit Premium
Yes
CapabilityAudit StandardAudit Premium
Enabled by defaultYesYes
Thousands of searchable audit eventsYesYes
Portal search, Graph API, PowerShell, CSV exportYesYes
Office 365 Management Activity API accessYesYes, at higher bandwidth
Default retention180 days1 year for Entra, Exchange, OneDrive, SharePoint
Retention for other workloads180 days180 days unless a custom policy exists
Custom audit log retention policiesNoYes
Ten year retentionNoWith a per-user add-on license
Intelligent insightsNoYes
Sensitivity label on accessed mail itemsNoYes
Teams activity propertiesNoYes
How a review runs

Five steps, and considerably quicker than most security work.

One to three weeks, delivered remotely. The ratio of value to effort here is among the best available anywhere in a Microsoft estate, precisely because nobody finds any of it interesting until the day they need it.
  1. 1

    Establish the current position

    Which tier you hold, which retention policies exist, whether any ten year add-ons have been assigned to anybody, and therefore how far back a search could genuinely reach right now. That is the number that matters, and it is very rarely the number people were expecting.

  2. 2

    Establish what you are obliged to keep

    Whatever your regulator requires, whatever you have promised customers contractually, the conditions attached to your insurance policy, and any certification you hold or are working toward. Then set all of that against the actual position. Whatever gap emerges is what the rest of the work exists to close.

  3. 3

    Configure retention policies deliberately

    Where premium is available, custom policies keyed to a service, to particular activities or to specific people, with the priority set so the important cases win. This matters most for the workloads outside identity, mail, OneDrive and SharePoint, all of which stay at a hundred and eighty days unless somebody deliberately intervenes.

  4. 4

    Set up export where retention alone is insufficient

    Out through the management activity API, into your log platform or a store you keep yourself, wherever an obligation exceeds what the licensing provides or the data is simply more useful sitting alongside everything else. Bandwidth becomes a design consideration on a large tenant, and it gets sized rather than assumed.

  5. 5

    Assign permissions and rehearse a real search

    Confirm who actually holds permission to search, run the searches a realistic incident would demand, and write them down so that whoever does this at two in the morning is following a note rather than learning an unfamiliar tool under pressure. An afternoon of work, and it is the step that makes everything before it real.

Straight answers

What US businesses ask about Purview Audit.

On the standard tier, a hundred and eighty days. Worth knowing on an older matter that anything generated before 17 October 2023 was kept for ninety, with the longer default applying only from that point forward. On the premium tier, identity, mail, OneDrive and SharePoint records are kept for a year by default, while everything else remains at a hundred and eighty days unless somebody wrote a custom policy.

No, and this is the single most important thing to grasp about any of it. How long an audit item lives is decided at the moment the pipeline writes it, according to whichever licensing default or retention policy applied right then. A later change to either alters the expiry of everything written afterward and leaves anything already committed entirely untouched. An upgrade improves your position for the next incident and contributes nothing at all to the current one.

Almost certainly yes. The standard tier is enabled by default for anybody with an appropriate subscription, capturing activity and making it searchable. What you may well be missing is permission assigned to any human to search it, a retention policy anybody configured, or a single person who has ever run a search. Those three gaps are considerably more common than audit having been switched off.

Four things are listed. Retention policies you can write yourself, longer retention of the records, the high-value insights, and more bandwidth through the management activity API. In investigation terms it is the insights that matter, because they include the sensitivity label of every mail item that was opened, and what the person searched for across mail and SharePoint.

Because in a mailbox compromise it answers the one question everything else hangs on. Knowing an account was accessed tells you an incident occurred. Knowing which specific mail items were opened, and on premium the sensitivity label attached to each, tells you the scope, and the scope determines whether you carry a notification obligation under HIPAA or a state breach law, and to whom. That is precisely how these insights are framed: helping establish the scope of a compromise more precisely.

It needs an additional per-person add-on sitting on top of premium, assigned to named individuals, with a ten year retention policy written for them. Three limits are worth planning around. The policy is not retroactive and cannot retain anything generated before it existed. It applies per person rather than across the tenant. And records produced by things that are not people, meaning service principals, system events and application activity, are held for a fixed year nobody can configure.

No, and this catches companies out with great regularity. The default policy on premium reaches records where the workload is identity, mail, OneDrive or SharePoint. Everything else stays at a hundred and eighty days unless somebody writes a custom policy covering it. Where your obligation extends to activity in any other service, buying premium on its own does not satisfy it.

Through the management activity API, which is also the documented route for keeping audit data beyond the default period. On bandwidth, the limit moved from being set per publisher to being set per tenant, everybody begins at a baseline of two thousand requests a minute, and that rises automatically with seat count and subscription, with the top enterprise, academic and government tiers getting roughly twice as much.

Yes, on premium. A custom policy can be keyed to whichever service the activity happened in, to particular audited activities, or to the specific people performing them, with a priority so that the narrower policy beats the broader one. A custom policy overrides the default in both directions, which means keeping things longer for a sensitive group or genuinely shorter where you have a documented reason for doing so.

Only whoever you have granted the permissions to, and assigning those permissions is explicitly something you have to do rather than something that happens. In our experience this is the most common practical gap of all. Audit is enabled by default and quietly collecting data, and nobody in the entire company currently holds permission to search any of it. That gets discovered during an incident unless somebody checks first.

Audit records who did what and when across the services, which is what a security investigation needs and what demonstrates to a SOC 2 auditor that a control genuinely operated. Discovery finds and preserves the content itself, which is what litigation or a regulatory production needs. Different purposes, different retention, and a business facing a legal matter very often needs both at once.

Directly, in both cases. SOC 2 examines logging and monitoring controls, and an auditor will ask how long audit records are retained and who reviews them. Cyber insurance carriers increasingly ask about logging in the application and at claim time expect the insured to be able to establish the scope of an incident, which is exactly what the audit log exists to do. A retention window shorter than your dwell-time risk is a gap in both conversations.

The premium tier adds properties across a range of Teams activity: a chat being created, retrieved or updated, a message written, read, sent, edited or deleted, hosted content being accessed, and detail about who attended a meeting. Those properties cover the application access context, which domains were involved and information about each participant. As more genuinely sensitive conversation moves out of email and into Teams, that becomes the difference between an investigation that reaches it and one that stops at the door.

We confirm entitlement against your tenant rather than asserting it here, because the Microsoft page directs readers to the subscription requirements rather than enumerating them inline, and because Premium features additionally depend on individual users being licensed. Establishing what you already hold is the first step, and organizations on higher subscriptions frequently have Premium available and unconfigured.

Two things, and both are free. Find out how far back you can currently search, which is the number that determines what any future investigation can establish. And confirm that at least one named person has permission to run an audit search and has actually run one. Neither requires a purchase and both are frequently the difference between a scoped investigation and a guess.
Before an incident

Fifteen questions worth answering while nothing is wrong.

The first block establishes how far you can currently see. The second covers what you are obliged to keep. The third asks whether anybody could actually run the search, which is invariably discovered at the least convenient moment available.

Your current horizon

  • How far back can you search today?
    180 days on Standard, and 90 before October 2023.
  • Are you on Audit Standard or Premium?
    Frequently nobody in IT knows.
  • If Premium, do custom retention policies exist?
    Non-core workloads stay at 180 days without one.
  • Does anybody here hold the ten year add-on?
    Per-user, and not retroactive.
  • Has audit ever been exported anywhere?
    The API route retains beyond the default.

Your obligations

  • Does a regulator specify a retention period?
    NYDFS Part 500 and sector rules set multi-year expectations.
  • Do customer contracts specify one?
    Increasingly common in enterprise agreements.
  • Are you pursuing SOC 2 or ISO 27001?
    Both examine logging and monitoring directly.
  • Could you face litigation needing old records?
    eDiscovery and audit are different things.
  • Do you need records for non-user activity?
    Fixed at one year and not configurable.

Could anybody actually search

  • Who has permission to search the audit log?
    It needs assigning, it is not automatic.
  • Has anybody ever run a search?
    An untested capability is not a capability.
  • Do you know which activities you would search for?
    Worth rehearsing before you need it.
  • Is audit data flowing to a SIEM?
    Available through the Management Activity API.
  • Who would run an investigation at 2am?
    Decide before, not during.
Related reading

The pages around this one.

Microsoft Purview

The wider governance and compliance platform this sits inside, including classification, retention and eDiscovery.

Learn more

Purview eDiscovery

The other half of an investigation: finding and preserving the content itself, with its own retention rules.

Learn more

Microsoft Sentinel

The SIEM that audit data feeds through the Management Activity API when the window alone is not enough.

Learn more
Next step

Find out how far back you can search. It takes ten minutes and it is free.

That number is fixed for every record already written, and it determines what any future investigation will be able to establish. If it is shorter than your obligations, the fix has to happen now rather than when somebody asks for the evidence.

Book an audit readiness reviewSee Microsoft Purview services

Related Services

Explore more solutions that work great with this service

Microsoft Purview

Data governance and compliance solutions

Learn more

Microsoft Purview eDiscovery

Legal hold and eDiscovery readiness done properly

Learn more

Microsoft Sentinel

Cloud-native SIEM and threat intelligence

Learn more

Microsoft 365 Security Audit

Independent Microsoft 365 tenant security audit for US organizations

Learn more

IT Compliance

HIPAA, SOC 2, NIST, CMMC, CCPA readiness

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA