Audit Logging SHALL Be Enabled
Last updated
Last updated
To view data in threat protection reports, email security reports, and Explorer, audit logging must be turned on. By default, Microsoft retains the audit logs for only 90 days.
Audit logging SHALL be enabled.
By default, Microsoft retains the audit logs for only 90 days for every Microsoft Tenant
Advanced audit capabilities, including the creation of a custom audit log retention policy, requires E5/G5 licenses or E3/G3 licenses with add-on compliance licenses. Additionally, maintaining logs in the Microsoft 365 environment for longer than one year requires an add-on license. For more information, see
Auditing can be enabled from the Microsoft 365 compliance admin center and the Exchange Online PowerShell. Follow the instructions listed on
Sign in to the Microsoft 365 compliance admin center.
Under Solutions, select Audit.
If auditing is not enabled, a banner displays and prompts that the user and admin activity start being recorded.
Click the Start recording user and admin activity banner.
There is no end-user impact for this setting
To check the current logging status via PowerShell:
Connect to Exchange Online
Run the following command
To enable logging via PowerShell
To set up advanced audit, see Docs.
To create an audit retention policy, follow the instructions listed on