How to Export the Unified Audit Log and Entra Sign-in Logs
Step-by-step export of the Purview Unified Audit Log and Entra ID sign-in and audit logs for a BEC case: roles, row limits, PowerShell paging, pitfalls.
TL;DR. Export three things, today: the Unified Audit Log from the Microsoft Purview portal (Audit → Search → Export), the Entra ID interactive and non-interactive user sign-ins (Entra admin center → Monitoring & health → Sign-in logs → Download), and the Entra audit logs (same place, JSON preferred). Start at least 30 days before the first suspicious event. Watch the limits: 50,000 rows per Purview export on Audit (Standard), 100,000 sign-in rows and 250,000 audit rows per Entra download. Keep the files untouched.
Most of the BEC investigations that go nowhere fail at this step, not at analysis. Someone exports only the victim's interactive sign-ins for the last week, the replay happened in the non-interactive log twelve days ago, and the conclusion becomes "we found nothing". Export broadly, then filter at analysis time.
Before you start: roles and time
| Source | Minimum role (least privilege) | Where |
|---|---|---|
| Unified Audit Log | Audit Logs or View-Only Audit Logs role in Purview | Microsoft Purview portal → Audit |
| Entra sign-in logs | Reports Reader | Microsoft Entra admin center |
| Entra audit logs | Reports Reader | Microsoft Entra admin center |
Roles are from Microsoft's audit search and log download documentation. Two timing facts matter. Audit records typically appear 60 to 90 minutes after the event for core services, sometimes later. And a broad Purview search on a large tenant can take hours; start it first and export the Entra logs while it runs.
1. Export the Unified Audit Log from Purview
- Sign in to the Microsoft Purview portal and open Audit.
- Set the date and time range (UTC). The maximum range per search is 180 days. Begin at least 30 days before the first suspicious e-mail.
- Leave Activities and Record types empty for the first pass. You want everything: mailbox, SharePoint, Entra ID events mirrored in the UAL.
- Optionally restrict Users to the suspected accounts. For a first incident I prefer the whole tenant: password sprays and consent phishing rarely hit one person.
- Run the search, wait for Completed, open it and select Export.
The export is a CSV whose AuditData column holds the full JSON record. That column is the evidence; the other columns are a summary. More on reading it in Unified Audit Log investigation.
Row limits. Export supports up to 50,000 rows for Audit (Standard) and up to 1,000,000 rows for Audit (Premium) (Microsoft Learn). If your export has exactly 50,000 rows, it is truncated. Split the search by week or by user and export each part. Overlapping exports are fine if your analysis tool deduplicates on RecordId / Id.
Alternative: Search-UnifiedAuditLog in PowerShell
When the portal times out or you need repeatable exports, use Exchange Online PowerShell. The cmdlet returns 100 records by default; -ResultSize goes up to 5,000 and paging with -SessionCommand ReturnLargeSet reaches up to 50,000 results per session (cmdlet reference):
Connect-ExchangeOnline
$sid = "bec-" + (Get-Date -Format yyyyMMddHHmmss)
$all = @()
do {
$page = Search-UnifiedAuditLog -StartDate "2026-08-15" -EndDate "2026-09-16" `
-SessionId $sid -SessionCommand ReturnLargeSet -ResultSize 5000
$all += $page
} while ($page.Count -gt 0)
$all | Export-Csv .\ual.csv -NoTypeInformation -Encoding UTF8
Three rules: keep the same SessionId for the whole loop, never mix ReturnLargeSet and ReturnNextPreviewPage in one session (output drops to 10,000), and split by date if you reach 50,000. Microsoft recommends the Office 365 Management Activity API for programmatic collection at scale.
Before you trust an empty result, check that auditing is on. In Exchange Online PowerShell, Get-AdminAuditLogConfig | Format-List UnifiedAuditLogIngestionEnabled must return True. An attacker with admin rights can turn it off; the tool flags Set-AdminAuditLogConfig changes as audit tampering.
2. Export the Entra ID sign-in logs
- In the Microsoft Entra admin center, go to Entra ID → Monitoring & health → Sign-in logs.
- Set the date filter. The portal only has what retention kept: 7 days on Entra ID Free, 30 days with P1/P2 (data retention).
- Select Download, choose CSV or JSON, and download both Interactive sign-ins and Non-interactive sign-ins. Application and managed identity sign-ins are worth taking too if an app is involved.
- Keep the original file names. They tell interactive from non-interactive, and some tools (including M365 Forensics) use them when a record does not say.
Limits. Up to 100,000 sign-in records per file. Larger sets time out in the browser: narrow the dates, filter on the users concerned, or use the Graph API (which requires a P1/P2 licence) or diagnostic settings to Log Analytics. If sign-ins already flow to Log Analytics, a KQL export of SigninLogs and AADNonInteractiveUserSignInLogs as JSON is the most complete option.
Why non-interactive matters. When a stolen cookie or refresh token is replayed, the user does not type anything. Entra ID records a non-interactive sign-in from the attacker's IP with the same Session ID as the original. That is the core of token replay detection.
The "authentication details" variants of the download are not needed for the analysis described here; the M365 Forensics tool skips them and says so.
3. Export the Entra ID audit logs
- Same admin center: Entra ID → Monitoring & health → Audit logs.
- Set the dates, Download, choose JSON if possible. The CSV flattens targets and modified properties into numbered columns and keeps only some of them; JSON keeps every
modifiedPropertiesentry, which is where the consented scopes and the new MFA method live. - Up to 250,000 audit records per file.
Many Entra audit events (consents, role assignments, app credentials) also appear in the UAL under the AzureActiveDirectory workload. MFA registration details are often clearer in the Entra audit log itself.
Export checklist
| File | Covers | Typical limit | Don't forget |
|---|---|---|---|
| Purview audit CSV | Mailbox, files, admin, Entra mirror | 50,000 rows (Standard) | Split if you hit the cap |
| Interactive sign-ins | Password / MFA sign-ins | 100,000 rows, 7–30 days | Whole tenant for spray |
| Non-interactive sign-ins | Token use, replay | 100,000 rows, 7–30 days | Usually the largest file |
| Entra audit logs | MFA, consent, roles, federation | 250,000 rows | JSON over CSV |
Optional, when you have them: Get-InboxRule -Mailbox <user> -IncludeHidden output for the current rule state, message trace for sent mail. The current version of M365 Forensics does not read those two yet.
Handling the files as evidence
- Hash each file (SHA-256) as soon as it is downloaded and record who exported it, when, and with which filters.
- Never edit the originals. Opening a UAL CSV in Excel and saving it can mangle the
AuditDataJSON and dates. - Store copies outside the compromised tenant (not in the victim's OneDrive).
- Note the time zone: Purview and Entra export timestamps are UTC.
Next step
Drop the files into M365 Forensics, or follow the step-by-step analysis walkthrough. If something you expected is missing, retention limits and missing logs explains the usual reasons.
Frequently asked questions
How many rows can I export from a Purview audit search?
Microsoft documents up to 50,000 rows per export for Audit (Standard) and up to 1,000,000 rows for Audit (Premium). If you hit the limit, split the search by date range or by user.
Do I need the non-interactive sign-in logs?
Yes. When a stolen session cookie or refresh token is replayed, Entra ID records non-interactive sign-ins, not interactive ones. Without that file, token replay is invisible.
How long are Entra ID sign-in logs kept?
Seven days on Microsoft Entra ID Free and 30 days with P1 or P2, unless they are routed to a storage account or Log Analytics. Export them first.
Further reading
- Microsoft Learn: Search the audit log, How to download logs in Microsoft Entra ID
- Glossary: Unified Audit Log, AuditData
- Azure subscription activity (control plane) is a different log family, covered on azureforensics.app.