Unified Audit Log Retention, Licensing and Missing Logs
What Microsoft 365 and Entra ID logs keep, for how long, on which licence, and what a BEC investigation cannot see when a source is missing or disabled.
TL;DR. The Unified Audit Log keeps 180 days on Audit (Standard) and one year for E5-licensed users' Exchange, SharePoint, OneDrive and Entra ID records; Entra ID sign-in and audit logs keep only 7 days on Free and 30 days on P1/P2. MailItemsAccessed is on by default for E3/E5 users, but SearchQueryInitiated* is off by default, and some business plans did not have auditing on by default. Before concluding "clean", check which sources, which period and which operations you actually had.
"We found nothing" is a finding only if you can say what you looked at. This article lists the gaps I check before writing that sentence.
Retention at a glance
| Log | Default retention | With more licensing | Source |
|---|---|---|---|
| Unified Audit Log, Audit (Standard) | 180 days (records from 2023-10-17; 90 days before) | n/a | Microsoft Learn |
| Unified Audit Log, Audit (Premium) | 1 year for Exchange, SharePoint, OneDrive, Entra ID records of E5-licensed users; 180 days for other records | Custom policies; up to 10 years with the add-on licence | same |
| Entra ID sign-in logs | 7 days (Free) | 30 days (P1/P2) | Microsoft Learn |
| Entra ID audit logs | 7 days (Free) | 30 days (P1/P2) | same |
| Risky sign-ins (ID Protection) | 7 days (Free) | 30 days (P1), 90 days (P2) | same |
Two consequences. First, Entra retention is the binding constraint: a BEC reported three weeks late on a tenant without P1 has already lost the sign-ins that show how the attacker got in. The Entra audit events mirrored into the UAL (consents, role changes, some sign-ins as UserLoggedIn) survive longer, but they are not the full sign-in log. Second, retention changes are not retroactive: upgrading a licence during the incident does not bring back expired data. Routing Entra logs to a storage account or Log Analytics through diagnostic settings is the only way to keep them longer, and it only helps from the day it is configured.
Is auditing even on?
- Unified audit log ingestion. On by default for enterprise organisations. Verify with
Get-AdminAuditLogConfig | Format-List UnifiedAuditLogIngestionEnabledin Exchange Online PowerShell (the same cmdlet in Security & Compliance PowerShell always showsFalse, per Microsoft Learn). - Business plans. CISA's expanded cloud logs playbook (January 2025) notes that Microsoft 365 Business Basic, Standard and Premium provide access to Audit but did not then have auditing enabled by default, and explains how to verify it.
- Mailbox auditing. Can be disabled per mailbox (
Set-Mailbox -AuditEnabled $false) or bypassed (Set-MailboxAuditBypassAssociation). Both are attacker techniques (T1562.008), and M365 Forensics raises a critical audit tampering finding when it sees them in the log.
Operation-level gaps
| Operation | Gap | Consequence |
|---|---|---|
MailItemsAccessed | Enabled by default for E3/E5 users as part of Audit (Standard) (Microsoft Learn); other plans may need configuration. Throttled after more than 1,000 records in 24 hours according to a Microsoft hunting query | You cannot say which messages were read; assume the mailbox is exposed |
SearchQueryInitiatedExchange / SharePoint | Disabled by default; must be enabled per mailbox for the owner sign-in type (CISA playbook) | No record of what the attacker searched for |
Send | Part of the expanded Standard logging; check it is in the mailbox audit set | Use message trace for sent mail |
| Sync access | Only recorded for Outlook desktop clients, one record per folder | A synced folder must be treated as fully exposed |
| Linkable identifiers | Missing on some aggregated or background records | Fall back to IP correlation |
Why sync is special is explained in MailItemsAccessed: what it proves.
Export-level gaps
- Truncated exports: exactly 50,000 rows from a Purview Standard export, or 100,000 rows from an Entra sign-in download, usually means the cap was hit.
- Interactive only: the most common mistake. Token replay lives in the non-interactive file.
- Victim only: password spray, consent phishing and lateral phishing to colleagues are invisible in a single-user export.
- Too short: exports starting on the day of the fraud miss the initial access, often days earlier.
- Too early: audit records typically arrive 60 to 90 minutes after the event; an export taken during containment misses the latest actions.
What the M365 Forensics tool itself does not cover
Honest limits of the in-browser analyser, as of this version:
- It reads the UAL, Entra sign-ins and Entra audit logs. It does not yet read
Get-InboxRuleoutput,Get-MailboxAuditLogoutput, message trace, risky users exports or Defender alerts. Current rule state (a hidden rule that still exists) needsGet-InboxRule -IncludeHidden. - It keeps up to 400,000 events in memory per analysis. Split very large exports by date.
- The UAL carries no location; country and ASN are borrowed from sign-ins of the same IP. Without a sign-in file, hosting-network and travel checks cannot run on UAL events.
- The hosting-ASN list is heuristic and hand-maintained; there is no bundled IP-to-ASN database.
- There is no per-user baseline ("first time this user signs in from this country"): exports rarely contain enough history.
- Service principal and managed identity sign-in CSV headers are not verified against real samples; the Entra "authentication details" download is skipped on purpose.
The tool's coverage panel spells out which sources are missing and warns when no MailItemsAccessed record is present, so a "clean" verdict is never silent about its blind spots.
Writing the limitation into the report
A defensible report has a short "scope and limitations" section: sources received with their periods and row counts, sources requested but unavailable, operations known to be absent (for example "SearchQueryInitiated not enabled"), and the resulting blind spots ("which messages were read before 2026-08-20 cannot be established"). It protects the conclusion, and it tells the client what to change before the next incident.
Reducing the gaps before the next incident
- Route Entra sign-in (interactive and non-interactive) and audit logs to a storage account or Log Analytics.
- Confirm unified audit ingestion and mailbox auditing on every licence type you use.
- Enable
SearchQueryInitiatedfor the owner sign-in type where you need it. - Document how to export everything in a hurry: the export guide is a starting point.
Frequently asked questions
How long does the Unified Audit Log keep records?
180 days by default for Audit (Standard) records created since 17 October 2023 (90 days before that). Users with E5-level audit licences get one year for Exchange, SharePoint, OneDrive and Entra ID records, and up to 10 years with the add-on.
Why is there no MailItemsAccessed in my audit export?
MailItemsAccessed is part of Audit (Standard) and enabled by default for Office 365 and Microsoft 365 E3/E5 users. On other plans mailbox auditing may need to be enabled, the action may be missing from the mailbox audit configuration, or the mailbox may have been throttled.
Does a clean result mean the account was not compromised?
Only for the period and the sources analysed. A missing non-interactive sign-in file, expired sign-in retention or disabled auditing can hide a compromise completely.
Further reading
- Microsoft 365 BEC investigation guide
- Glossary: Unified Audit Log, non-interactive sign-in
- Log retention questions look similar in AWS CloudTrail: awsforensics.com.