Your Microsoft 365 tenant holds the evidence. For how long?
Most UAE organisations have never checked how far back their Microsoft 365 audit log actually reaches, and the answer is frequently 180 days. That gets discovered during an incident, when somebody asks what happened eight months ago. We audit the tenant and tell you what you can prove.

- 180 daysThe default many tenants actually have
- One yearOnly for E5 users, only some workloads
- Tenant-wideIdentity, mail, data, devices
- Evidence firstWhat you could prove, not just settings
Eight areas of the tenant, in the order attackers care about them.
Identity, because that is where the compromise starts
Who has accounts, which of them are stale, which have never had multi-factor authentication enforced, how administrators authenticate, and whether any authentication path still exists that cannot enforce a second factor. Nearly every Microsoft 365 compromise we have investigated in this market began with a credential rather than with an exploit, so this section is first for a reason.
Conditional access, and the gaps between the policies
Policies look reassuring in a list and the risk lives in what they do not cover: excluded accounts that were meant to be temporary, service accounts outside every policy, break-glass accounts that are neither monitored nor tested, and the combination of conditions that leaves one path open. We read them as a set rather than individually, because that is how an attacker encounters them.
Privileged roles and standing access
How many people hold privileged roles, whether that access is permanent or activated when needed, whether it is reviewed, and who granted it. Global administrator counts in UAE tenants are consistently higher than anyone expects, usually because a consultant, a former employee or a vendor was given the role during a project and nobody removed it afterwards.
Audit log retention, which is the one people have never checked
Microsoft retains Exchange Online, SharePoint, OneDrive and Entra audit records for one year under the Audit Premium default, but only for users licensed at E5 level. Everything else, and every non-E5 or guest user, defaults to 180 days. Most organisations do not know which applies to them until an investigation needs to look further back than they can see. This is the single most valuable finding we produce.
Mail flow, forwarding rules and what leaves the tenant
Transport rules, connectors, external forwarding, and the mailbox rules that quietly move messages to a folder nobody opens. Business email compromise in this region is overwhelmingly about invoice fraud, and the mechanism is almost always a forwarding or filing rule created after a mailbox was accessed. We look for the ones that exist now and for whether you would notice a new one.
Data, sharing and what is exposed by accident
SharePoint and OneDrive sharing settings, links that never expire, anonymous access, guest access to sites, and where sensitive material has been shared outside the organisation without anybody intending it. The finding here is rarely a deliberate act. It is an accumulation of individually reasonable decisions over several years that nobody has ever looked at as a whole.
Devices and whether compliance actually gates access
Which devices are enrolled, whether compliance state is connected to access or merely reported, and how many devices reach company data with no management at all. Reporting a device as non-compliant while still letting it read the mailbox is a very common configuration, and it means the control is informational rather than protective.
Guests, external identities and third parties
Guest accounts accumulate in every long-lived tenant: a contractor from a project that ended, a client contact who changed jobs, a supplier who was invited once. Each is a credential outside your control with a path into your data. We inventory them, establish which are live, and put a review cadence in place, because nobody removes guests without a prompt.
You may have 180 days of evidence and believe you have a year.
This is precise, it is verifiable in Microsoft documentation, and it catches organisations at the worst possible moment. The numbers below are Microsoft published defaults, not our estimates.
- The Audit Premium default policy retains Exchange Online, SharePoint, OneDrive and Microsoft Entra audit records for one year. Everything else defaults to 180 days. So even at the higher licence level, a whole year of history is not what you have across the board, it is what you have for four workloads.
- That one-year default only applies to activity by users assigned an Office 365 or Microsoft 365 E5 licence, or a Purview Suite or E5 eDiscovery and Audit add-on. Microsoft states directly that if you have non-E5 users or guest users, their audit records are retained for 180 days. Mixed licensing is normal in UAE organisations, which means retention is mixed too, per user.
- The Audit Standard default is 180 days. It used to be 90, and records generated before 17 October 2023 are still retained on the old 90-day basis. If your last audit was written against the old figure, it is out of date.
- The trap most people miss: custom retention policies take priority over the default, including custom policies that are shorter. An organisation can have quietly reduced its own retention below the default without anybody connecting that setting to the investigation it will one day prevent. We check what policies exist, not what the licence entitles you to.
Four things that separate an audit from a Secure Score screenshot.
We audit the tenant as configured, not against a generic baseline
A generic baseline produces two hundred findings, most of which do not apply to you, and the important five get lost. We assess how your organisation actually works first, then report what genuinely creates exposure in that context. A shorter report that gets acted on beats a comprehensive one that gets filed.
We tell you what you could evidence, not only what is switched on
The question that matters after an incident is what you can reconstruct. That depends on retention policies, licensing per user and whether anybody has ever run a search successfully. We check all three, and we run a real historical query so you know the capability works before the day you need it.
We do not recommend licence upgrades reflexively
It is easy to answer every finding with a suggestion to move to E5, and sometimes that is genuinely correct, particularly where audit retention or investigation capability is the gap. Often it is not, and the same risk closes with configuration you already own. We separate the two clearly so you can see which findings cost money and which cost attention.
We hand you findings your team can work
Each finding states what it is, why it matters in your context, what to change, and roughly what it takes. Your team can execute it, or we can, and either is fine. What we will not do is produce a report that requires us to interpret it, because that is a dependency rather than a deliverable.
Six situations that bring UAE businesses to a tenant audit.
A client or insurer has sent a security questionnaire
The most common trigger. Somebody needs to answer specific questions about multi-factor authentication, access control, logging and data handling, and nobody internally knows the current state well enough to answer honestly. An audit produces the answers and, more usefully, tells you which ones you should fix before answering.
After a suspicious email or a suspected compromise
A payment nearly went to the wrong account, or a mailbox behaved oddly, or somebody received a message that appeared to come from a colleague. The immediate question is what actually happened, and the answer depends entirely on what your audit log retained. This is where organisations discover their retention position, and it is far too late to change it then.
A regulated firm in DIFC or ADGM
Supervisory expectations cover access control, logging and the ability to investigate, and Microsoft 365 is where most of that evidence lives for a typical firm. The audit retention question is unusually important here, because the period a regulator or an external auditor may ask about can be longer than the period your tenant retains by default.
A business that has changed IT provider
A new provider inherits a tenant configured by somebody else, with administrator accounts, consented applications and conditional access exclusions whose reasons nobody remembers. An independent audit at handover establishes a baseline and, frequently, removes access that should have gone when the previous relationship ended.
An organisation with a data protection obligation
Healthcare entities, firms handling significant volumes of personal data, and anyone in scope of the federal data protection law or a free zone regime. Here the audit focuses on where data actually sits, who can reach it, what has been shared externally and whether you could evidence access if a subject or a regulator asked.
A company that has simply never looked
The healthiest reason, and the least common. The tenant has run for years, staff have joined and left, projects have come and gone, and somebody sensibly wants to know what state it is in. These audits nearly always find several things worth fixing and almost never find a crisis, which is exactly the outcome you want from looking early.
What we find when we audit a Microsoft 365 tenant in the UAE.
| Feature | Audited and maintained | Set up once, then drifted | Defaults, largely untouched |
|---|---|---|---|
Global administrator count controlled | Few, reviewed | Grown quietly | Whoever asked |
MFA enforced on all privileged accounts | Mostly | Partially | |
Conditional access exclusions justified | Forgotten | None exist | |
Audit retention known and deliberate | |||
External forwarding controlled | Sometimes | ||
Guest accounts reviewed | |||
Device compliance gates access | Reported only | ||
Third-party app consent governed | |||
Could reconstruct an incident from last year | Probably | Only within 180 days | Unlikely |
How common in the UAE market | Uncommon | The default | Smaller firms |
Audit evidence available in a Microsoft 365 tenant, by default.
| Situation | Default retention | |
|---|---|---|
| Audit Standard, logs on or after 17 October 2023 | 180 days | |
| Audit Standard, logs before 17 October 2023 | 90 days | |
| Audit Premium, Exchange Online records, E5 user | One year | |
| Audit Premium, SharePoint and OneDrive, E5 user | One year | |
| Audit Premium, Microsoft Entra records, E5 user | One year | |
| Audit Premium, all other activities | 180 days by default | |
| Any activity by a non-E5 user | 180 days | |
| Any activity by a guest user | 180 days | |
| With a 10-year audit retention add-on, plus E5 | Up to 10 years | |
| A custom policy shorter than the default | The shorter custom policy wins | |
| Maximum retention policies per organisation | 50 |
Five stages, typically one to two weeks.
- 1
Scope, access and context
What is in scope, what read access we need and how it is granted, and a conversation about how the business works: who travels, who uses personal devices, which third parties have access, what the compliance drivers are. Findings are worthless without this context, because whether a setting is a risk depends on what your people actually do.
- 2
Identity and access review
Accounts, privileged roles, authentication methods, conditional access as a set rather than as a list, stale accounts, guests and third-party application consent. This stage produces the highest-severity findings in most tenants, and it is where we spend the most time.
- 3
Data, mail and device review
Sharing configuration and what is currently shared externally, mail flow rules and forwarding, connectors, and how device compliance relates to access. We look at what exists now rather than only at what the policy allows, because the gap between the two is usually where the finding is.
- 4
Evidence and retention check
What your audit retention actually is, per licence and per custom policy, and a real historical search run to confirm the capability works. We tell you how far back you can genuinely see, which is frequently different from what people believe and is the finding clients most often say they are glad they got.
- 5
Report, prioritise, and fix
Findings by severity with the context that makes them severe, separated into what costs configuration effort and what would cost licensing. Then remediation, by your team or by us. We are happy either way, and where you want it we re-audit afterwards so the improvement is documented rather than assumed.
“The finding that mattered was not a misconfiguration. It was that we could only see 180 days back, and we had assumed a year. Three months later we had an incident that started before that window, and knowing the limit in advance completely changed how we handled the investigation.”
What organisations ask about a Microsoft 365 audit.
Fifteen things to check in your own tenant this week.
Identity, where it starts
- How many accounts hold Global Administrator?The number is nearly always higher than the answer people give.
- Is multi-factor authentication enforced on every one of them?Enforced, not enabled, not encouraged.
- Are there accounts excluded from conditional access?Check why, and whether the reason still exists.
- Do you have break-glass accounts, and have they been tested?Untested emergency access is not emergency access.
- How many accounts have not signed in for 90 days?Each one is a live credential nobody is watching.
What leaves the tenant
- Is external mail forwarding blocked or monitored?The classic business email compromise mechanism.
- Do any mailboxes have rules filing mail to obscure folders?Worth looking at directly, not just in policy.
- Can users create anonymous sharing links that never expire?Check the setting and check what already exists.
- How many guest accounts exist, and who owns each?They accumulate and nobody removes them unprompted.
- Which third-party applications have consent in your tenant?Consented apps are a standing access path.
Could you evidence it
- How far back does your audit log actually reach?Check the retention policies, not the licence brochure.
- Do you have any custom retention policies, and are any shorter than the default?Custom policies override the default in both directions.
- Are all your users E5, or is licensing mixed?Retention is per user. Mixed licensing means mixed evidence.
- Has anybody ever run a real audit log search?The first time should not be during an incident.
- Is device compliance connected to access, or only reported?Reported non-compliance changes nothing on its own.
The pages around this one.
IT audit services in Dubai
The wider audit practice, and how to tell which kind of engagement your situation actually calls for before anybody quotes for one.
Microsoft Entra
The identity layer underneath everything on this page: conditional access, privileged access and the controls that close the findings we most often report.
NIST CSF 2.0 assessment
If you want a picture across the whole security function rather than one platform, this is the broader framework a tenant audit feeds into.
Go and check how far back your audit log reaches.
It takes a few minutes, it is free, and for most organisations the answer is different from what they assumed. If you would like help checking it, or a full review of the tenant behind it, that is a short conversation and we will tell you what we would look at first.
Related Services
Explore more solutions that work great with this service
DMARC Audit UAE
Stop exact-domain spoofing, and keep your mail delivering
Active Directory Audit
Privilege paths, service accounts and local admin passwords
IT Audit Services Dubai
Assessment, technical test or certification, scoped properly
Microsoft Entra
Identity and access management solutions
Microsoft Security Dubai
Entra, Defender, Purview, Sentinel, and what you already own
NIST CSF 2.0 Assessment
Know where you stand, without committing to certification
Microsoft Defender
Advanced endpoint and email threat protection
UAE PDPL Compliance
Federal Decree-Law 45 of 2021 readiness and operations