Skip to content

This tool is not affiliated with, endorsed by or sponsored by Microsoft Corporation. Microsoft 365, Microsoft Entra ID, Exchange Online and Microsoft Purview are trademarks of the Microsoft group of companies. Other names are trademarks of their respective owners.

Glossary

Unified Audit Log (UAL)

Microsoft Purview's tenant-wide audit log of user and admin activity across Exchange Online, SharePoint, OneDrive, Entra ID, Teams and other Microsoft 365 services.

The Unified Audit Log is the audit trail of a Microsoft 365 tenant, searched and exported from the Audit solution in the Microsoft Purview portal or with the Search-UnifiedAuditLog cmdlet. It records operations such as New-InboxRule, Set-Mailbox, MailItemsAccessed, FileDownloaded or Consent to application, each with a JSON payload called AuditData.

Records are kept 180 days by default on Audit (Standard) and one year for Exchange, SharePoint, OneDrive and Entra ID activity of E5-licensed users. The UAL has no geolocation: IP addresses must be matched against Entra sign-in logs.

How to export it: export the Unified Audit Log and Entra sign-in logs. How to read it: Unified Audit Log investigation.