The unified audit log, how long each audit tier keeps records, and what Audit (Premium) adds.
From Ultra Transcenders SC-900 by Tony Rough (publishing soon)
When something goes wrong, investigators need to know who did what and when. Microsoft Purview Audit records thousands of user and admin operations from dozens of Microsoft services in the organisation’s unified audit log, which security, IT, insider risk, compliance and legal teams can search.
| Capability | Audit (Standard) | Audit (Premium) |
|---|---|---|
| Enabled by default | Yes | Yes |
| Search in the Microsoft Purview portal, export to CSV | Yes | Yes |
| Audit Search Graph API and Office 365 Management Activity API | Yes | Yes, with about twice the bandwidth |
| Default retention | 180 days | One year for Microsoft Entra ID, Exchange, OneDrive and SharePoint records; 180 days for others |
| Custom audit log retention policies | No | Yes |
| 10-year retention | No | Yes, with a per-user 10-Year Audit Log Retention add-on licence |
| Intelligent insights (such as the sensitivity label of accessed mail items) | No | Yes |
Details worth knowing:
Common trap: Quoting 90 days as the Audit (Standard) retention period - it has been 180 days for records created since 17 October 2023; one-year default retention and 10-year retention belong to Audit (Premium), the latter needing an add-on licence.
This note is one section of Ultra Transcenders SC-900: Microsoft Security, Compliance, and Identity Fundamentals, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Publishing soon on Amazon in Kindle and paperback editions.
About the book · SC-900 terms in the glossary · All SC-900 study notes
How security duties move between customer and Microsoft across on-premises, IaaS, PaaS and SaaS, and the duties that never move.
Verify explicitly, use least privilege access and assume breach, and the areas a Zero Trust approach covers.
How Conditional Access combines signals into decisions after first-factor sign-in, and what it is not designed to stop.
The kinds of DDoS attack, what every public IP gets free, and what the paid tiers add.
What the free posture management tier includes and what the paid Defender CSPM plan adds.
What security information and event management and security orchestration, automation and response each do, and how they fit together.
The built-in mailbox protection every tenant has, and the protections each Defender for Office 365 plan adds.