Audit Log guides
Microsoft Purview's unified audit log of administrative and user actions across Microsoft 365. See the glossary entry →
7 guides touch on audit log.
- Handling an accidental external-sharing exposure
Runbook for a SharePoint or OneDrive folder shared with the wrong outside party: find every link and guest, cut access, establish what was opened, report.
- Handling an accidental mass delete of SharePoint files
Runbook for a mass delete of SharePoint files by a sync client, script, or user: stop the bleeding, pick the right restore tool, and recover it safely.
- How to search the audit log in Microsoft Purview
How to search the Microsoft 365 unified audit log in Purview: check it's on, search by activity, user, and date, export, and Search-UnifiedAuditLog at scale.
- Investigating a suspicious sign-in with Entra sign-in logs
How to work a suspicious sign-in in the Entra sign-in logs: which log, which columns matter, traveller vs attacker, and when to escalate to compromise.
- Microsoft 365 incident response runbook
A structured incident response runbook for Microsoft 365 — detection, triage, containment, eradication, recovery, lessons.
- Microsoft 365 monitoring and alerts
How to monitor a Microsoft 365 tenant — service health, audit logs, security alerts, and third-party tooling.
- Microsoft Purview audit retention
How long Microsoft 365 retains audit logs by default, what Audit (Premium) adds, and how to think about retention.