Audit Logging SHALL Be Enabled
Description
To view data in threat protection reports, email security reports, and Explorer, audit logging must be turned on. By default, Microsoft retains the audit logs for only 90 days.
Policy
Audit logging SHALL be enabled.
Licensing Considerations
By default, Microsoft retains the audit logs for only 90 days for every Microsoft Tenant
Advanced audit capabilities, including the creation of a custom audit log retention policy, requires E5/G5 licenses or E3/G3 licenses with add-on compliance licenses. Additionally, maintaining logs in the Microsoft 365 environment for longer than one year requires an add-on license. For more information, see Licensing requirements | Microsoft Docs.
Set Up Instructions
Auditing can be enabled from the Microsoft 365 compliance admin center and the Exchange Online PowerShell. Follow the instructions listed on Turn on auditing.
Sign in to the Microsoft 365 compliance admin center.
Under Solutions, select Audit.
If auditing is not enabled, a banner displays and prompts that the user and admin activity start being recorded.
Click the Start recording user and admin activity banner.
To set up advanced audit, see Set up Advanced Audit in Microsoft 365 | Microsoft Docs.
To create an audit retention policy, follow the instructions listed on Create an audit log retention policy.
End-User Impact
Level: None
There is no end-user impact for this setting
Tips
None Currently
PowerShell Scripts
To check the current logging status via PowerShell:
Connect to Exchange Online
Run the following command
To enable logging via PowerShell
Videos
Last updated