We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft Purview
  2. Audit
Microsoft Purview Audit, UAE

Changing your retention policy does not bring back the logs you already lost.

Microsoft states that audit item lifetime is set when the record is written, and that later changes to licensing or retention policies do not affect previously committed items. So the audit trail you will need during an investigation is the one you configured before it started, and by default that is one hundred and eighty days.

Book an audit readiness reviewSee what each tier retains
Microsoft Purview Audit configuration for UAE organisations
  • 180 daysAudit Standard default retention
  • One yearEntra, Exchange, OneDrive and SharePoint on Premium
  • Not retroactiveRetention changes apply only going forward
  • MailItemsAccessedThe event that scopes a mailbox compromise
The question to ask today

How far back can you search right now, and is that far enough?

Four things follow from Microsoft own statement that retention is fixed at the moment a record is written.

  • If you are on Audit Standard, your answer is one hundred and eighty days, and ninety days for anything generated before 17 October 2023. That is your investigation horizon, today, whatever your policy document says.
  • Breaches are frequently discovered long after they begin. An intrusion that started seven months ago is outside a Standard retention window entirely, which means the investigation cannot establish when it started or what was accessed, only that something is wrong now.
  • Upgrading after you discover a problem does not help with that problem. Microsoft is explicit that changes to licensing or retention policies do not affect previously committed items. The upgrade improves your position for the next incident and does nothing for the current one.
  • The same applies to the ten year add-on, which Microsoft states is not retroactive and cannot retain logs generated before the policy was created. If a regulatory or contractual retention obligation exists, the policy has to be in place before the period it is meant to cover, not created when somebody asks for the evidence.
Ask us to check your current retention position
What the audit log gives you

Eight things about Purview Audit that matter before an incident, not during one.

Microsoft describes the unified audit log as capturing, recording and retaining thousands of user and administrator operations across dozens of Microsoft services, for security events, forensic investigations, internal investigations and compliance obligations.

Retention is decided when the record is written

Microsoft states that audit item lifetime is determined when the auditing pipeline adds the data, based on licensing defaults or applicable retention policies, and that changes to licensing or policies change the expiration of audit data after the update but do not affect previously committed items. This is the single most important sentence on the subject. Upgrading during an investigation does not recover anything already expired.

One hundred and eighty days by default, and it used to be ninety

Audit Standard retains records for one hundred and eighty days, so you can search back six months. Worth knowing for older matters: Microsoft states that logs generated before 17 October 2023 are retained for ninety days, and the one hundred and eighty day default applies from that date onwards. Investigations reaching further back than six months hit a wall that no purchase will move.

Premium retention, and what it actually covers by default

On Audit Premium, Microsoft Entra ID, Exchange, OneDrive and SharePoint audit records are retained for one year by default, through a default retention policy keyed on the workload. Everything else stays at one hundred and eighty days unless you write a custom retention policy. That distinction catches organisations out, because they assume Premium means a year for everything.

Ten year retention, with three conditions

It requires an additional per-user add-on licence on top of Premium. It is not retroactive and cannot retain logs generated before the policy was created. And records generated by non-user entities such as service principal actions, system events and application activities are retained for a fixed one year, which is not configurable and which custom retention policies do not apply to. All three matter when planning around a regulatory retention requirement.

MailItemsAccessed, the event that scopes a compromise

Premium intelligent insights provide visibility such as the sensitivity label of mail items that were accessed, and when and what a user searched for in Exchange Online and SharePoint Online. Microsoft states these help investigate possible breaches and determine the scope of compromise more precisely. In a business email compromise, the difference between knowing an account was accessed and knowing which messages were read is the difference between a notification decision and a guess.

Teams activity properties, which are newly relevant

Premium adds properties to a set of Teams activities including chat creation, retrieval and update, message creation, reading, sending and deletion, and meeting participant detail. Properties include application access context, participating domain information and participant information. As more sensitive conversation moves into Teams, the ability to investigate it properly stops being optional.

Custom retention policies, keyed three ways

Premium lets you create policies retaining records based on the Microsoft service where activity occurs, specific audited activities, or the user performing them, with a priority so specific policies take precedence. Custom policies take precedence over the default, in both directions: you can retain more for a sensitive population, or less than a year where you have a reason to.

Getting the data out, and how fast

Both tiers offer the portal search tool, the Audit Search Graph API, the Search-UnifiedAuditLog cmdlet, CSV export and the Office 365 Management Activity API. Microsoft states all organisations start at a baseline of two thousand requests per minute, that this increases dynamically with seat count and subscription, and that E5, A5 and G5 organisations get about twice the bandwidth. That matters when pulling audit data into a SIEM at scale.

How we approach it

Four things we do that most organisations only think about after an incident.

Audit configuration is the least interesting security work available and one of the highest value, because it is the only control that determines what you can find out later.

We establish your actual horizon first, not your intended one

What tier you are on, what retention policies exist, and therefore how far back you could genuinely search today. In our experience the answer differs from what the security policy claims in a majority of cases, and the gap is only ever discovered during an incident, which is the worst possible time to learn it.

We map retention to obligations rather than to a tier

Premium retains Entra, Exchange, OneDrive and SharePoint for a year by default and everything else for one hundred and eighty days. If your obligation covers activity in another workload, the tier alone does not meet it and a custom retention policy is needed. That is a specific configuration task, not a licensing purchase.

We rehearse a search before you need one

Permission to search the audit log has to be assigned and is frequently held by nobody. We confirm who can search, walk through the searches that matter for a realistic incident, and make sure somebody has done it once. An audit capability nobody has ever used is not a capability, it is an assumption.

We set up export where the retention window is not enough

The Office 365 Management Activity API allows audit data to be retained beyond the default period and imported into a SIEM. Where a retention obligation exceeds what your licensing provides, or where you want the data alongside everything else, this is frequently a better answer than a licence upgrade and it is more useful operationally.

Where this matters most

Six UAE situations where audit retention decides the outcome.

Each of these is a case where the question arrives months after the activity, which is exactly when the default window has closed.

A business email compromise discovered weeks later

The critical question is which messages the attacker actually read, because that drives what you have to disclose and to whom. Premium intelligent insights provide the sensitivity label of accessed mail items and visibility of what a user searched for in Exchange Online and SharePoint Online, which is what turns a guess into a scoped answer.

A regulated firm with a specified retention period

Where a regulator specifies how long records must be kept, the audit retention policy has to have been in place across the whole period. Microsoft is explicit that policies are not retroactive. Establishing this early is a small configuration exercise, and discovering it late is a finding that cannot be remediated.

A departing employee dispute

Somebody left, took something, and it surfaces four months later when they turn up at a competitor. The relevant question is what they accessed and downloaded before leaving, and whether that activity is still within your search window. On Standard defaults, four months is inside six but the margin is thinner than anybody realises.

Litigation or a regulatory enquiry

Audit records and eDiscovery are different things and both may be needed. Audit tells you who did what and when across the services. The retention question is the same in both cases: whether the record still exists, which was decided at the moment it was written rather than at the moment somebody asks.

An organisation pulling audit into a SIEM

Microsoft states that the Management Activity API limit moved from a publisher level to a tenant level, that all organisations start at two thousand requests per minute, and that this scales with seat count and subscription, with E5, A5 and G5 organisations getting about twice as much. For a large tenant feeding a SIEM continuously, that bandwidth is a real design constraint.

An organisation whose sensitive conversation lives in Teams

Which is increasingly all of them. Premium adds properties to Teams activities covering chat creation and retrieval, message send, read, update and delete, and meeting participant detail, including application access context and participant information. Without those, an investigation into what happened in Teams is materially thinner than one into email.

Three positions

What organisations can actually reconstruct after an incident.

The right column is common and it is not usually a decision anybody made. Audit Standard is enabled by default, so most organisations have exactly what Microsoft gave them and have never looked at it.
Can search the last six months
Audit configured deliberatelyYes
Premium, unconfiguredYes
Standard defaultsYes
Can search back a year for core workloads
Audit configured deliberatelyYes
Premium, unconfiguredYes
Standard defaultsNo
Can search back a year for other workloads
Audit configured deliberatelyYes
Premium, unconfiguredNo
Standard defaultsNo
Retention aligned to a regulatory obligation
Audit configured deliberatelyYes
Premium, unconfiguredUnlikely
Standard defaultsNo
Knows which mail items an attacker read
Audit configured deliberatelyYes
Premium, unconfiguredYes
Standard defaultsNo
Sensitivity label of accessed mail visible
Audit configured deliberatelyYes
Premium, unconfiguredYes
Standard defaultsNo
Teams activity investigable in detail
Audit configured deliberatelyYes
Premium, unconfiguredYes
Standard defaultsNo
Audit data exported beyond the retention window
Audit configured deliberatelyYes
Premium, unconfiguredSometimes
Standard defaultsRarely
Somebody has actually run a search before
Audit configured deliberatelyYes
Premium, unconfiguredSometimes
Standard defaultsRarely
Frequency in the UAE market
Audit configured deliberatelyRare
Premium, unconfiguredCommon on E5
Standard defaultsVery common
Feature
Audit configured deliberately
Premium, unconfigured
Standard defaults
Can search the last six months
YesYesYes
Can search back a year for core workloads
YesYesNo
Can search back a year for other workloads
YesNoNo
Retention aligned to a regulatory obligation
YesUnlikelyNo
Knows which mail items an attacker read
YesYesNo
Sensitivity label of accessed mail visible
YesYesNo
Teams activity investigable in detail
YesYesNo
Audit data exported beyond the retention window
YesSometimesRarely
Somebody has actually run a search before
YesSometimesRarely
Frequency in the UAE market
RareCommon on E5Very common
Standard against Premium

What each tier gives you, on the points that decide an investigation.

Premium includes everything in Standard. Reproduced from the Microsoft capability comparison, with the retention detail that sits underneath it.
CapabilityAudit StandardAudit Premium
Enabled by defaultYesYes
Thousands of searchable audit eventsYesYes
Portal search, Graph API, PowerShell, CSV exportYesYes
Office 365 Management Activity API accessYesYes, at higher bandwidth
Default retention180 days1 year for Entra, Exchange, OneDrive, SharePoint
Retention for other workloads180 days180 days unless a custom policy exists
Custom audit log retention policiesNoYes
Ten year retentionNoWith a per-user add-on licence
Intelligent insightsNoYes
Sensitivity label on accessed mail itemsNoYes
Teams activity propertiesNoYes
How a review runs

Five steps, and it is quicker than most security work.

Typically one to three weeks. This is one of the highest value to effort ratios available in a Microsoft estate, precisely because nobody finds it interesting until they need it.
  1. 1

    Establish the current position

    Which tier you are on, what retention policies exist, whether any ten year add-ons are assigned, and therefore how far back a search could genuinely reach today for each workload. This is the number that matters and it is usually not the number people expect.

  2. 2

    Establish what you are obliged to keep

    Regulatory requirements, contractual commitments to clients, and any certification you hold or are pursuing. Then compare against the actual position. The gap, where there is one, is what the rest of the work addresses.

  3. 3

    Configure retention policies deliberately

    Where Premium is available, custom policies keyed on service, on specific activities or on user, with priority set so the important cases take precedence. Particularly for the workloads outside Entra, Exchange, OneDrive and SharePoint, which stay at one hundred and eighty days unless somebody acts.

  4. 4

    Set up export where retention alone is insufficient

    Through the Office 365 Management Activity API, into a SIEM or a retained store, where an obligation exceeds what licensing provides or where the data is more useful alongside everything else. Bandwidth is a design consideration for large tenants and we size for it.

  5. 5

    Assign permissions and rehearse a real search

    Confirm who can search, run the searches that a realistic incident would require, and document them so that the person doing it at two in the morning is following a note rather than learning the tool. This step takes an afternoon and it is the one that makes the rest real.

Straight answers

What organisations ask about Purview Audit.

On Audit Standard, one hundred and eighty days. Worth knowing for older matters that Microsoft states logs generated before 17 October 2023 are retained for ninety days, with the longer default applying from that date onwards. On Audit Premium, Microsoft Entra ID, Exchange, OneDrive and SharePoint records are retained for one year by default, and everything else remains at one hundred and eighty days unless a custom retention policy exists.

No, and this is the most important thing to understand about audit. Microsoft states that audit item lifetime is determined when the auditing pipeline adds the data, based on the licensing defaults or retention policies applicable at that moment, and that later changes to licensing or policies change the expiration of data after the update but do not affect previously committed items. An upgrade improves your position for the next incident and does nothing for the current one.

Almost certainly. Microsoft states that Audit Standard is enabled by default for all organisations with the appropriate subscription, capturing and making audited activities searchable. What you may not have is permission assigned to anybody to search it, a retention policy configured, or anybody who has ever run a search. Those three gaps are far more common than audit being switched off.

Microsoft lists four things: audit log retention policies, longer retention of audit records, high-value intelligent insights, and higher bandwidth access to the Office 365 Management Activity API. In investigation terms the intelligent insights are the significant part, because they include the sensitivity label of mail items that were accessed and what a user searched for in Exchange Online and SharePoint Online.

Because in a mailbox compromise it answers the question everything else depends on. Knowing an account was accessed tells you there is an incident. Knowing which mail items were accessed, and on Premium their sensitivity label, tells you the scope, which drives whether you have a notification obligation and to whom. Microsoft frames intelligent insights exactly this way, as helping determine the scope of compromise more precisely.

It requires an additional per-user add-on licence on top of Premium, assigned to specific users, with an appropriate ten year retention policy set for them. Microsoft states three limits worth planning around: the policy is not retroactive and cannot retain logs generated before it was created, it is per-user rather than tenant-wide, and records generated by non-user entities such as service principals, system events and application activities are held for a fixed one year that is not configurable.

No, and this catches organisations out regularly. The default retention policy in Premium covers records where the workload is Microsoft Entra ID, Exchange, OneDrive or SharePoint. Everything else remains at one hundred and eighty days unless you create a custom retention policy for it. If your obligation covers activity in another service, buying Premium alone does not meet it.

Through the Office 365 Management Activity API, which Microsoft notes also lets organisations retain auditing data for longer than the default period. On bandwidth, Microsoft states the limit moved from a publisher level to a tenant level, that all organisations start at a baseline of two thousand requests per minute, and that this increases dynamically with seat count and subscription, with E5, A5 and G5 organisations getting about twice as much.

Yes, on Premium. Custom retention policies can be keyed on the Microsoft service where activity occurs, on specific audited activities, or on the user performing them, with a priority so that specific policies take precedence over general ones. Microsoft notes that a custom policy takes precedence over the default policy in both directions, so you can retain longer for a sensitive population or shorter where you have a documented reason.

Only people you have granted the necessary permissions to, and Microsoft is explicit that assigning those permissions is something you need to do. In our experience this is the most common practical gap: audit is enabled by default and collecting data, and nobody in the organisation currently has permission to search it. That is discovered during an incident unless somebody checks beforehand.

Audit records who did what and when across the Microsoft services, which is what you need for a security investigation or to demonstrate a control operated. eDiscovery finds and preserves content itself, which is what you need for litigation or a regulatory production. They serve different purposes, they are retained differently, and an organisation facing a legal matter frequently needs both.

Premium adds activity properties for a set of Teams activities including chat created, retrieved and updated, message created, read, sent, updated and deleted, message hosted content access, and meeting participant detail. Properties include application access context, participating domain information and participant information. As more sensitive conversation moves out of email and into Teams, this becomes the difference between an investigation that reaches it and one that does not.

We confirm entitlement against your tenant rather than asserting it here, because the Microsoft page directs readers to the subscription requirements rather than enumerating them inline, and because Premium features additionally depend on individual users being licensed. Establishing what you already hold is the first step, and organisations on higher subscriptions frequently have Premium available and unconfigured.

Two things, and both are free. Find out how far back you can currently search, which is the number that determines what any future investigation can establish. And confirm that at least one named person has permission to run an audit search and has actually run one. Neither requires a purchase and both are frequently the difference between a scoped investigation and a guess.

We scope per organisation, and this is one of the smaller pieces of work we do. A retention and readiness review is typically one to three weeks including configuration and a rehearsed search. What we will tell you free in the first conversation is how far back you can search today, because that single fact usually determines whether anything else needs doing.
Before an incident

Fifteen questions worth answering while nothing is wrong.

The first group establishes your current horizon. The second is your obligations. The third is whether anybody could actually run the search, which is the part that gets discovered at the worst possible moment.

Your current horizon

  • How far back can you search today?
    180 days on Standard, and 90 before October 2023.
  • Are you on Audit Standard or Premium?
    Frequently nobody in IT knows.
  • If Premium, do custom retention policies exist?
    Non-core workloads stay at 180 days without one.
  • Do you have the ten year add-on for anybody?
    Per-user, and not retroactive.
  • Has audit ever been exported anywhere?
    The API route retains beyond the default.

Your obligations

  • Does a regulator specify a retention period?
    The policy must predate the period it covers.
  • Do client contracts specify one?
    Increasingly common in enterprise agreements.
  • Are you pursuing ISO 27001 or SOC 2?
    Both examine logging and monitoring directly.
  • Could you face litigation needing old records?
    eDiscovery and audit are different things.
  • Do you need records for non-user activity?
    Fixed at one year and not configurable.

Could anybody actually search

  • Who has permission to search the audit log?
    It needs assigning, it is not automatic.
  • Has anybody ever run a search?
    An untested capability is not a capability.
  • Do you know which activities you would search for?
    Worth rehearsing before you need it.
  • Is audit data flowing to a SIEM?
    Available through the Management Activity API.
  • Who would run an investigation at 2am?
    Decide before, not during.
Related reading

The pages around this one.

Microsoft Purview

The wider governance and compliance platform this sits inside, including classification, retention and eDiscovery.

Learn more

Microsoft 365 security audit

The broader assessment of tenant configuration, of which audit retention is one finding among many.

Learn more

Insider risk management

The behavioural detection layer that uses the same underlying activity signals for a different purpose.

Learn more
Next step

Find out how far back you can search. It takes ten minutes and it is free.

That number is fixed for every record already written, and it determines what any future investigation will be able to establish. If it is shorter than your obligations, the fix has to happen now rather than when somebody asks for the evidence.

Book an audit readiness reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Microsoft Purview

Data governance and compliance solutions

Learn more

Microsoft 365 Security Audit

Tenant review, and how far back your evidence really goes

Learn more

Insider Risk Management

Data theft by departing staff, detected with users pseudonymised

Learn more

Microsoft Sentinel

Cloud-native SIEM and threat intelligence

Learn more

IT General Controls

What your external auditor tests, and the evidence they sample

Learn more

ISO 27001 Certification UAE

The 2022 edition, and whether you should certify at all

Learn more

SOC 2 Readiness UAE

Type II preparation, and when ISO 27001 fits better

Learn more

Microsoft Security Dubai

Entra, Defender, Purview, Sentinel, and what you already own

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy