FREE STUDY NOTES · SC-401

Microsoft Purview Audit (Standard) vs Audit (Premium): retention and licences

What Audit (Premium) adds over Audit (Standard): default retention periods, 10-year retention, intelligent insights and the licences each needs.

From Ultra Transcenders SC-401 by Tony Rough (coming December 2026)

Microsoft Purview Audit records user and admin operations from dozens of Microsoft services in a single unified audit log. It comes in two tiers, and the tier that applies depends on the licence of the user who performs the activity.

Capability Audit (Standard) Audit (Premium)
Enabled by default Yes Yes
Audit search in the Microsoft Purview portal, Audit Search Graph API, Search-UnifiedAuditLog Yes Yes
Export search results to CSV Up to 50,000 rows Up to 1,000,000 rows
Office 365 Management Activity API Yes (baseline 2,000 requests per minute) Yes, with about twice the bandwidth of non-E5 organisations
Default retention 180 days One year for Microsoft Entra ID, Exchange, OneDrive and SharePoint records; 180 days for others
Audit log retention policies No Yes, up to one year, or 3, 5, 7 or 10 years with the 10-Year Audit Log Retention add-on
Intelligent insights (extra events and properties) No Yes

Key retention facts:

Assigning Audit (Premium) licences

Audit (Premium) features such as intelligent insights need an appropriate E5 or add-on licence on each user and the Microsoft 365 Advanced Auditing app (service plan) turned on. In the Microsoft 365 admin center, open Users > Active users, select the user, choose Licenses and apps, confirm the licence, select Microsoft 365 Advanced Auditing under Apps and save; logging of Premium insights begins within 24 hours.

Intelligent insights add events and properties useful for compromise investigations, such as the SensitivityLabel property on MailItemsAccessed records, Teams properties such as AppAccessContext on message events, and search events (SearchQueryInitiatedExchange, which must be turned on per user, and SearchQueryInitiatedSharePoint, which is on by default):

```powershell

Get the whole book

This note is one section of Ultra Transcenders SC-401: Administering Information Security in Microsoft 365, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in December 2026, in Kindle and paperback editions.

About the book · SC-401 terms in the glossary · All SC-401 study notes

More SC-401 study notes