Higher audit tier that retains SharePoint, OneDrive, Exchange and Entra ID records for a year and offers intelligent insights like MailItemsAccessed, plus retention policies reaching 10 years with an add-on.
Also called Advanced Audit.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Microsoft Purview Audit (Premium) in context, with comparison tables and the common traps.
Terms in this definition
- Audit
Policy effect that lets a request proceed but flags the resource as non-compliant and logs a warning to the activity log. Microsoft suggests beginning there and later moving to something enforcing, like Deny.
- Archive
Offline access tier for blobs, cheapest to store yet dearest to access. Reading a blob means rehydrating it first, which can take as long as 15 hours.
- Microsoft Entra ID
Cloud identity service from Microsoft, previously named Azure AD, which provides the tenant behind Microsoft 365 and Azure.
- Intelligent insights
Extra-valuable audit records that Microsoft Purview Audit (Premium) captures to support forensic and compliance investigations into a possible breach, for example around access to mail items.
- LIKE
Compares strings with a pattern that can contain the % and _ wildcards. Because it only understands character patterns, searching big volumes of text this way is much slower than using full-text search.
- MailItemsAccessed
When an account is compromised, this Exchange Online audit record helps establish which messages were read, because it captures sync and bind access through every mail protocol.
Related terms
- Audit: Force audit policy subcategory settings
Makes advanced audit subcategories win over the basic categories, avoiding conflicts between the two; a security option.
- Audit Security Group Management
An advanced audit subcategory recording when security groups are created, modified or deleted, and when their members change.