Audit logs

Audit logs record user and admin activity across Microsoft 365 and Microsoft Entra, providing a searchable history for security investigations and compliance.

Audit logs capture timestamped records of user and administrator actions across Microsoft 365, surfaced through two distinct stores. The Microsoft Purview audit log (in the Purview compliance portal) covers workload activity such as SharePoint file access, Exchange mail actions, and Copilot interaction events. The Microsoft Entra audit log separately records identity changes — role assignments, group modifications, and consent grants — while Entra sign-in logs track authentication. A common exam trap is treating these as one unified log; they are separate systems with separate retention defaults, and Purview Audit (Premium), available with E5, extends retention well beyond the standard defaults.

PlayPrepHQ study notes are written and reviewed against primary exam sources. How we create & review content →

Related terms

Back to Core Microsoft 365 Services & Identity