Build a repeatable Microsoft Purview audit-search procedure before an incident

Microsoft Purview Audit can investigate activity across Microsoft 365, but reliable evidence depends on verified ingestion, licensing-based retention, precise UTC queries, least-privileged access, and preserved exports.

Executive summary

What you need to know

Microsoft Purview Audit can investigate activity across Microsoft 365, but reliable evidence depends on verified ingestion, licensing-based retention, precise UTC queries, least-privileged access, and preserved exports.

Potentially affected

Microsoft 365 and Office 365 organizations using Purview Audit Standard or Premium for security, operational, compliance, or incident investigations.

DSE recommendation

Verify audit ingestion and retention before an event, assign limited audit roles, create narrow named searches, preserve criteria and exports, and document the expected ingestion delay and evidence chain.

Source fact: what Microsoft documents

Microsoft Purview Audit Standard and Premium provide searchable user and administrator activity across Microsoft 365 workloads. Microsoft states that unified audit search is enabled by default for Microsoft 365 and Office 365 enterprise organizations, but documents an Exchange Online PowerShell check for the actual ingestion setting. Audit searches started in the portal continue after the browser closes, and completed search jobs remain available for 30 days.

Each audit user can run up to 10 search jobs concurrently, with one unfiltered job. A portal search can span up to 180 days. Broad searches in large tenants can require up to 48 hours. Microsoft says core-service records such as Exchange, SharePoint, OneDrive, and Teams are typically available in 60–90 minutes, but does not guarantee a specific ingestion time.

Microsoft documents 180-day default retention for users with supported non-E5 Microsoft 365 or Office 365 licensing. Eligible E5, Purview Suite, or Audit add-on licensing provides one-year default retention for specified Entra, Exchange, and SharePoint activities, with retention-policy options dependent on licensing. The license assigned to the relevant user and the event workload affect what remains searchable.

Permissions and applicability

Searching requires Audit Logs or View-Only Audit Logs roles in the appropriate portal or role group. Export size, long-term retention, high-value events, APIs, and Premium features depend on subscription and configuration. Audit availability is not instantaneous, and absence from a result is not proof that an action did not occur.

DSE recommendation: production-safe operational steps

  1. Verify unified audit ingestion from Exchange Online PowerShell and record the result, date, tenant, operator, and expected retention for each licensed user class.
  2. Assign the least-privileged audit role to named investigators and test access before an incident. Separate routine readers from administrators who can change audit configuration.
  3. Create a search worksheet using UTC range, users, workloads, activities, record types, sites or files, keywords, and a unique search name.
  4. Start narrow searches first, allow for ingestion, and expand one dimension at a time. Record every query change.
  5. Export results and preserve the original file, search criteria, completion time, administrator, source portal, and hash when evidence integrity matters.
  6. Correlate audit events with Entra sign-ins, Exchange trace, endpoint, network, application, and support evidence as appropriate.
  7. Run a quarterly validation that generates a known benign event, waits for ingestion, locates it, exports it, and verifies authorized access.

DSE recommends escalating before retention expires when an investigation may require older events. Retention policy, litigation hold, mailbox audit, and application logging are distinct controls; confirm the source needed for each question rather than assuming the unified audit log contains every relevant event.

Official reference

Search the audit log — ingestion, roles, retention, concurrency, time ranges, search behavior, and export workflow.

Primary reference

Review the official source

Microsoft Learn: Search the audit log · Published June 19, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE