Glossary

Audit Log

Microsoft Purview's unified audit log of administrative and user actions across Microsoft 365.

The Microsoft Purview audit log records administrative and user actions across Microsoft 365 — mailbox access, file activity, sign-ins, permission changes, sharing, eDiscovery operations, Copilot interactions. Searchable in the Purview portal and via the Office 365 Management Activity API. Retention is 180 days on Microsoft 365 E3 and 1 year on E5, extensible to 10 years with the Audit (Premium) add-on. The first stop for compliance investigations, incident forensics, and answering "who did what when." Different from Defender XDR logs (security-event focused) and Entra ID sign-in logs (auth focused), though signals cross-reference between systems.