What Audit (Premium) adds over Audit (Standard): default retention periods, 10-year retention, intelligent insights and the licences each needs.
From Ultra Transcenders SC-401 by Tony Rough (coming December 2026)
Microsoft Purview Audit records user and admin operations from dozens of Microsoft services in a single unified audit log. It comes in two tiers, and the tier that applies depends on the licence of the user who performs the activity.
| Capability | Audit (Standard) | Audit (Premium) |
|---|---|---|
| Enabled by default | Yes | Yes |
| Audit search in the Microsoft Purview portal, Audit Search Graph API, Search-UnifiedAuditLog | Yes | Yes |
| Export search results to CSV | Up to 50,000 rows | Up to 1,000,000 rows |
| Office 365 Management Activity API | Yes (baseline 2,000 requests per minute) | Yes, with about twice the bandwidth of non-E5 organisations |
| Default retention | 180 days | One year for Microsoft Entra ID, Exchange, OneDrive and SharePoint records; 180 days for others |
| Audit log retention policies | No | Yes, up to one year, or 3, 5, 7 or 10 years with the 10-Year Audit Log Retention add-on |
| Intelligent insights (extra events and properties) | No | Yes |
Key retention facts:
Audit (Premium) features such as intelligent insights need an appropriate E5 or add-on licence on each user and the Microsoft 365 Advanced Auditing app (service plan) turned on. In the Microsoft 365 admin center, open Users > Active users, select the user, choose Licenses and apps, confirm the licence, select Microsoft 365 Advanced Auditing under Apps and save; logging of Premium insights begins within 24 hours.
Intelligent insights add events and properties useful for compromise investigations, such as the SensitivityLabel property on MailItemsAccessed records, Teams properties such as AppAccessContext on message events, and search events (SearchQueryInitiatedExchange, which must be turned on per user, and SearchQueryInitiatedSharePoint, which is on by default):
```powershell
This note is one section of Ultra Transcenders SC-401: Administering Information Security in Microsoft 365, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in December 2026, in Kindle and paperback editions.
About the book · SC-401 terms in the glossary · All SC-401 study notes
How EDM SITs match your own records: schema, primary and supporting elements, new and classic experiences, and hashing and uploading data.
How to design sensitivity labels: the four label scopes, label priority and order, sublabels and label groups, and label limits.
How to roll out a DLP policy safely with simulation mode and policy tips, and the four policy states with their PowerShell Mode values.
Which Windows, Windows Server and macOS devices Endpoint DLP supports, the prerequisites, and how to onboard devices to Microsoft Purview.
Which setting wins when several retention policies and labels apply to one item, with worked examples, and how to use Policy lookup.
Which Insider Risk Management policy template fits each scenario, with its triggering event, prerequisites and user limit.
How to build Microsoft Purview eDiscovery searches with the condition builder and KeyQL, with example queries and the search limits to know.