A record of what users and administrators do across numerous Microsoft 365 services, which can be searched with Microsoft Purview Audit. For core services, entries typically become available between one hour and an hour and a half after the activity.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Unified audit log in context, with comparison tables and the common traps.
Terms in this definition
- A record
Points a DNS name at an IPv4 address. A typical use is pointing a root (apex) domain at an app.
- Microsoft 365
Formerly Office 365, Microsoft's software-as-a-service productivity suite. A Microsoft Entra tenant provides its identity, and its data is not governed by Azure RBAC.
- Microsoft Purview Audit
Searches the unified audit log for admin and user activity across Microsoft services. The Standard tier keeps records for 180 days, while Premium adds longer retention and intelligent insights.
Related terms
- Activity explorer
A Microsoft Purview view of the last 30 days of events involving sensitive or labelled items, for example a label being added, altered or taken off, or a DLP rule being triggered. Its data comes from the unified audit log.
- Microsoft Entra audit logs
A record of changes made in a Microsoft Entra directory, covering things such as user, group, app and licence updates. Entries are held for a week on Entra Free or a month on P1 or P2, and this log is not the same thing as Purview's unified audit log.
- Microsoft Purview Audit (Standard)
Unified audit log tier you get by default, keeping records for 180 days; custom retention policies and intelligent insights aren't included.
- Office 365 Management Activity API
The recommended programmatic route for regular audit downloads: a REST API returning user, admin, system and policy events (Fabric activity among them) held in the unified audit log of Microsoft 365.
- View-Only Audit Logs
A role in Microsoft Purview, also found in Exchange Online, that allows searching and exporting the unified audit log (Fabric activities included) without permission to alter audit settings. Switching auditing on or off needs the Audit Logs role instead.