Changing your retention policy does not bring back the logs you already lost.
Microsoft states that audit item lifetime is set when the record is written, and that later changes to licensing or retention policies do not affect previously committed items. So the audit trail you will need during an investigation is the one you configured before it started, and by default that is one hundred and eighty days.

- 180 daysAudit Standard default retention
- One yearEntra, Exchange, OneDrive and SharePoint on Premium
- Not retroactiveRetention changes apply only going forward
- MailItemsAccessedThe event that scopes a mailbox compromise
How far back can you search right now, and is that far enough?
Four things follow from Microsoft own statement that retention is fixed at the moment a record is written.
- If you are on Audit Standard, your answer is one hundred and eighty days, and ninety days for anything generated before 17 October 2023. That is your investigation horizon, today, whatever your policy document says.
- Breaches are frequently discovered long after they begin. An intrusion that started seven months ago is outside a Standard retention window entirely, which means the investigation cannot establish when it started or what was accessed, only that something is wrong now.
- Upgrading after you discover a problem does not help with that problem. Microsoft is explicit that changes to licensing or retention policies do not affect previously committed items. The upgrade improves your position for the next incident and does nothing for the current one.
- The same applies to the ten year add-on, which Microsoft states is not retroactive and cannot retain logs generated before the policy was created. If a regulatory or contractual retention obligation exists, the policy has to be in place before the period it is meant to cover, not created when somebody asks for the evidence.
Eight things about Purview Audit that matter before an incident, not during one.
Retention is decided when the record is written
Microsoft states that audit item lifetime is determined when the auditing pipeline adds the data, based on licensing defaults or applicable retention policies, and that changes to licensing or policies change the expiration of audit data after the update but do not affect previously committed items. This is the single most important sentence on the subject. Upgrading during an investigation does not recover anything already expired.
One hundred and eighty days by default, and it used to be ninety
Audit Standard retains records for one hundred and eighty days, so you can search back six months. Worth knowing for older matters: Microsoft states that logs generated before 17 October 2023 are retained for ninety days, and the one hundred and eighty day default applies from that date onwards. Investigations reaching further back than six months hit a wall that no purchase will move.
Premium retention, and what it actually covers by default
On Audit Premium, Microsoft Entra ID, Exchange, OneDrive and SharePoint audit records are retained for one year by default, through a default retention policy keyed on the workload. Everything else stays at one hundred and eighty days unless you write a custom retention policy. That distinction catches organisations out, because they assume Premium means a year for everything.
Ten year retention, with three conditions
It requires an additional per-user add-on licence on top of Premium. It is not retroactive and cannot retain logs generated before the policy was created. And records generated by non-user entities such as service principal actions, system events and application activities are retained for a fixed one year, which is not configurable and which custom retention policies do not apply to. All three matter when planning around a regulatory retention requirement.
MailItemsAccessed, the event that scopes a compromise
Premium intelligent insights provide visibility such as the sensitivity label of mail items that were accessed, and when and what a user searched for in Exchange Online and SharePoint Online. Microsoft states these help investigate possible breaches and determine the scope of compromise more precisely. In a business email compromise, the difference between knowing an account was accessed and knowing which messages were read is the difference between a notification decision and a guess.
Teams activity properties, which are newly relevant
Premium adds properties to a set of Teams activities including chat creation, retrieval and update, message creation, reading, sending and deletion, and meeting participant detail. Properties include application access context, participating domain information and participant information. As more sensitive conversation moves into Teams, the ability to investigate it properly stops being optional.
Custom retention policies, keyed three ways
Premium lets you create policies retaining records based on the Microsoft service where activity occurs, specific audited activities, or the user performing them, with a priority so specific policies take precedence. Custom policies take precedence over the default, in both directions: you can retain more for a sensitive population, or less than a year where you have a reason to.
Getting the data out, and how fast
Both tiers offer the portal search tool, the Audit Search Graph API, the Search-UnifiedAuditLog cmdlet, CSV export and the Office 365 Management Activity API. Microsoft states all organisations start at a baseline of two thousand requests per minute, that this increases dynamically with seat count and subscription, and that E5, A5 and G5 organisations get about twice the bandwidth. That matters when pulling audit data into a SIEM at scale.
Four things we do that most organisations only think about after an incident.
We establish your actual horizon first, not your intended one
What tier you are on, what retention policies exist, and therefore how far back you could genuinely search today. In our experience the answer differs from what the security policy claims in a majority of cases, and the gap is only ever discovered during an incident, which is the worst possible time to learn it.
We map retention to obligations rather than to a tier
Premium retains Entra, Exchange, OneDrive and SharePoint for a year by default and everything else for one hundred and eighty days. If your obligation covers activity in another workload, the tier alone does not meet it and a custom retention policy is needed. That is a specific configuration task, not a licensing purchase.
We rehearse a search before you need one
Permission to search the audit log has to be assigned and is frequently held by nobody. We confirm who can search, walk through the searches that matter for a realistic incident, and make sure somebody has done it once. An audit capability nobody has ever used is not a capability, it is an assumption.
We set up export where the retention window is not enough
The Office 365 Management Activity API allows audit data to be retained beyond the default period and imported into a SIEM. Where a retention obligation exceeds what your licensing provides, or where you want the data alongside everything else, this is frequently a better answer than a licence upgrade and it is more useful operationally.
Six UAE situations where audit retention decides the outcome.
A business email compromise discovered weeks later
The critical question is which messages the attacker actually read, because that drives what you have to disclose and to whom. Premium intelligent insights provide the sensitivity label of accessed mail items and visibility of what a user searched for in Exchange Online and SharePoint Online, which is what turns a guess into a scoped answer.
A regulated firm with a specified retention period
Where a regulator specifies how long records must be kept, the audit retention policy has to have been in place across the whole period. Microsoft is explicit that policies are not retroactive. Establishing this early is a small configuration exercise, and discovering it late is a finding that cannot be remediated.
A departing employee dispute
Somebody left, took something, and it surfaces four months later when they turn up at a competitor. The relevant question is what they accessed and downloaded before leaving, and whether that activity is still within your search window. On Standard defaults, four months is inside six but the margin is thinner than anybody realises.
Litigation or a regulatory enquiry
Audit records and eDiscovery are different things and both may be needed. Audit tells you who did what and when across the services. The retention question is the same in both cases: whether the record still exists, which was decided at the moment it was written rather than at the moment somebody asks.
An organisation pulling audit into a SIEM
Microsoft states that the Management Activity API limit moved from a publisher level to a tenant level, that all organisations start at two thousand requests per minute, and that this scales with seat count and subscription, with E5, A5 and G5 organisations getting about twice as much. For a large tenant feeding a SIEM continuously, that bandwidth is a real design constraint.
An organisation whose sensitive conversation lives in Teams
Which is increasingly all of them. Premium adds properties to Teams activities covering chat creation and retrieval, message send, read, update and delete, and meeting participant detail, including application access context and participant information. Without those, an investigation into what happened in Teams is materially thinner than one into email.
What organisations can actually reconstruct after an incident.
| Feature | Audit configured deliberately | Premium, unconfigured | Standard defaults |
|---|---|---|---|
Can search the last six months | Yes | Yes | Yes |
Can search back a year for core workloads | Yes | Yes | No |
Can search back a year for other workloads | Yes | No | No |
Retention aligned to a regulatory obligation | Yes | Unlikely | No |
Knows which mail items an attacker read | Yes | Yes | No |
Sensitivity label of accessed mail visible | Yes | Yes | No |
Teams activity investigable in detail | Yes | Yes | No |
Audit data exported beyond the retention window | Yes | Sometimes | Rarely |
Somebody has actually run a search before | Yes | Sometimes | Rarely |
Frequency in the UAE market | Rare | Common on E5 | Very common |
What each tier gives you, on the points that decide an investigation.
| Capability | Audit Standard | Audit Premium | |
|---|---|---|---|
| Enabled by default | Yes | Yes | |
| Thousands of searchable audit events | Yes | Yes | |
| Portal search, Graph API, PowerShell, CSV export | Yes | Yes | |
| Office 365 Management Activity API access | Yes | Yes, at higher bandwidth | |
| Default retention | 180 days | 1 year for Entra, Exchange, OneDrive, SharePoint | |
| Retention for other workloads | 180 days | 180 days unless a custom policy exists | |
| Custom audit log retention policies | No | Yes | |
| Ten year retention | No | With a per-user add-on licence | |
| Intelligent insights | No | Yes | |
| Sensitivity label on accessed mail items | No | Yes | |
| Teams activity properties | No | Yes |
Five steps, and it is quicker than most security work.
- 1
Establish the current position
Which tier you are on, what retention policies exist, whether any ten year add-ons are assigned, and therefore how far back a search could genuinely reach today for each workload. This is the number that matters and it is usually not the number people expect.
- 2
Establish what you are obliged to keep
Regulatory requirements, contractual commitments to clients, and any certification you hold or are pursuing. Then compare against the actual position. The gap, where there is one, is what the rest of the work addresses.
- 3
Configure retention policies deliberately
Where Premium is available, custom policies keyed on service, on specific activities or on user, with priority set so the important cases take precedence. Particularly for the workloads outside Entra, Exchange, OneDrive and SharePoint, which stay at one hundred and eighty days unless somebody acts.
- 4
Set up export where retention alone is insufficient
Through the Office 365 Management Activity API, into a SIEM or a retained store, where an obligation exceeds what licensing provides or where the data is more useful alongside everything else. Bandwidth is a design consideration for large tenants and we size for it.
- 5
Assign permissions and rehearse a real search
Confirm who can search, run the searches that a realistic incident would require, and document them so that the person doing it at two in the morning is following a note rather than learning the tool. This step takes an afternoon and it is the one that makes the rest real.
What organisations ask about Purview Audit.
Fifteen questions worth answering while nothing is wrong.
Your current horizon
- How far back can you search today?180 days on Standard, and 90 before October 2023.
- Are you on Audit Standard or Premium?Frequently nobody in IT knows.
- If Premium, do custom retention policies exist?Non-core workloads stay at 180 days without one.
- Do you have the ten year add-on for anybody?Per-user, and not retroactive.
- Has audit ever been exported anywhere?The API route retains beyond the default.
Your obligations
- Does a regulator specify a retention period?The policy must predate the period it covers.
- Do client contracts specify one?Increasingly common in enterprise agreements.
- Are you pursuing ISO 27001 or SOC 2?Both examine logging and monitoring directly.
- Could you face litigation needing old records?eDiscovery and audit are different things.
- Do you need records for non-user activity?Fixed at one year and not configurable.
Could anybody actually search
- Who has permission to search the audit log?It needs assigning, it is not automatic.
- Has anybody ever run a search?An untested capability is not a capability.
- Do you know which activities you would search for?Worth rehearsing before you need it.
- Is audit data flowing to a SIEM?Available through the Management Activity API.
- Who would run an investigation at 2am?Decide before, not during.
The pages around this one.
Microsoft Purview
The wider governance and compliance platform this sits inside, including classification, retention and eDiscovery.
Microsoft 365 security audit
The broader assessment of tenant configuration, of which audit retention is one finding among many.
Insider risk management
The behavioural detection layer that uses the same underlying activity signals for a different purpose.
Find out how far back you can search. It takes ten minutes and it is free.
That number is fixed for every record already written, and it determines what any future investigation will be able to establish. If it is shorter than your obligations, the fix has to happen now rather than when somebody asks for the evidence.
Related Services
Explore more solutions that work great with this service
Microsoft Purview
Data governance and compliance solutions
Microsoft 365 Security Audit
Tenant review, and how far back your evidence really goes
Insider Risk Management
Data theft by departing staff, detected with users pseudonymised
Microsoft Sentinel
Cloud-native SIEM and threat intelligence
IT General Controls
What your external auditor tests, and the evidence they sample
ISO 27001 Certification UAE
The 2022 edition, and whether you should certify at all
SOC 2 Readiness UAE
Type II preparation, and when ISO 27001 fits better
Microsoft Security Dubai
Entra, Defender, Purview, Sentinel, and what you already own