Glossary
Unified Audit Log (UAL)
Microsoft Purview's tenant-wide audit log of user and admin activity across Exchange Online, SharePoint, OneDrive, Entra ID, Teams and other Microsoft 365 services.
The Unified Audit Log is the audit trail of a Microsoft 365 tenant, searched and exported from the Audit solution in the Microsoft Purview portal or with the Search-UnifiedAuditLog cmdlet. It records operations such as New-InboxRule, Set-Mailbox, MailItemsAccessed, FileDownloaded or Consent to application, each with a JSON payload called AuditData.
Records are kept 180 days by default on Audit (Standard) and one year for Exchange, SharePoint, OneDrive and Entra ID activity of E5-licensed users. The UAL has no geolocation: IP addresses must be matched against Entra sign-in logs.
How to export it: export the Unified Audit Log and Entra sign-in logs. How to read it: Unified Audit Log investigation.