Now openThe whole vendor lifecycle in one workspace. Benchmarking, negotiations, contracts, invoices, renewals. Free 30 day trial, no card.Start the trial →
Now openThe whole vendor lifecycle in one workspace. Benchmarking, negotiations, contracts, invoices, renewals. Free 30 day trial, no card.Start the trial →
Editorial photograph of a data governance team reviewing Microsoft 365 audit and retention settings on screen
Microsoft / Microsoft 365 Audit Logs

Microsoft 365 audit logs, cost and license clarity.

Purview Standard and Premium, retention tiers, and what each Microsoft 365 license actually unlocks. This guide shows where the audit cost hides and how to license the evidence trail without buying E5 for every seat.

Contact Us Microsoft Practice
500+Enterprise clients
$2B+Under advisory
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Buyer Side Independent

Microsoft 365 audit logs are often the reason a tenant buys E5 everywhere. The cost question is which users genuinely need Premium audit, and how long the records must actually be kept.

Key takeaways

  • Audit logs record user and admin activity and are the evidence trail for security and compliance.
  • Purview audit comes in two tiers, Standard and Premium, gated by your Microsoft 365 license.
  • Standard retention now defaults to 180 days, while Premium defaults to one year.
  • Premium audit is tied to E5 and equivalent add on plans.
  • Blanket E5 to get Premium audit is a common and avoidable cost.
  • Set retention policies by record type and regulation, not one blanket period.
  • License the audit trail where the risk sits, then govern retention to control the bill.
Try Vera AI · free trial
How many of your E5 seats are actually used? Vera knows.
  • Usage exports analyzed: inactive accounts, E1, E3, and E5 right sizing, per user reassignment
  • The July 2026 price increase modeled on your real seat mix
  • Your renewal quote benchmarked against real closed Microsoft deals
Try Vera AI free →30 day free trial · no card needed

What are Microsoft 365 audit logs and who needs them?

Microsoft 365 audit logs record user and admin activity across the tenant. They are the evidence trail for security investigations, compliance, and insider risk.

Every organization with a compliance or security obligation needs them. What differs is how long you can keep them and how rich the data is.

Common uses

  • Security investigation: trace who accessed what, and when, after an incident.
  • Compliance evidence: show regulators a verifiable record of activity.
  • Insider risk: spot unusual mailbox, file, or sharing behavior.

The Microsoft Purview audit solution is where these logs live and where retention is configured.

How do Purview audit retention tiers and licenses compare?

Audit comes in two tiers, Standard and Premium. The tier you get depends on your Microsoft 365 license, and it sets your default retention.

The table compares the two on the points that drive cost.

Microsoft Purview audit Standard versus Premium

DimensionAudit StandardAudit Premium
Default retention180 daysOne year
Maximum retention180 daysUp to ten years with add on
License gateMost commercial plansE5 and equivalent add ons
Event richnessCore eventsHigh value events included
Access bandwidthStandardHigher for investigations

Reading the tiers

Standard gives a longer default window than it used to, while Audit Premium adds longer retention, richer events, and higher bandwidth access. The split decides what you can investigate a year later.

What does each Microsoft license actually unlock?

The license question is the cost question. Premium audit features ride on specific Microsoft 365 plans, and buying the wrong plan to get them is a common waste.

Standard audit

Standard audit ships with most commercial Microsoft 365 subscriptions. The Audit Standard documentation sets out the default retention and the events captured.

Premium audit

  • License gate: Premium audit is tied to E5 and equivalent add on plans.
  • Longer retention: one year by default, with a multi year add on available.
  • Richer events: high value events that Standard does not capture.

Where the common advice on Microsoft 365 audit logging is wrong

The common advice is to buy E5 across the whole tenant so everyone has Premium audit. We disagree. In most of the 40 to 55 Microsoft 365 governance reviews we ran in 2024 and 2025, only a fraction of users ever needed Premium audit events, yet many tenants paid E5 rates for every seat. The buyer side move is to license Premium audit where the risk and the regulatory need actually sit, use targeted retention policies for the rest, and treat blanket E5 as a procurement default to challenge, not accept. The audit feature rarely justifies the full E5 premium across the entire seat base.

Editorial photograph of a security analyst reviewing Microsoft 365 activity logs on a monitoring dashboard
Retention is set per record type, not per tenant. Mapping each event class to the rule that governs it is what keeps the audit bill defensible.
180 days
Standard audit retention
1 year
Premium default retention
10 yr
Maximum retention with add on

Source: Redress Compliance advisory engagement file, 2024 to 2025.

Audit logging is sold as a reason to buy E5 everywhere. In practice the obligation sits on a subset of users. License the evidence trail where the risk lives, not across every seat by default.
Cover of the Microsoft 365 Audit Logging (2026) white paper from Redress Compliance

White Paper · Microsoft

Microsoft 365 Audit Logging (2026)

License the trail, not every seat: what E3 already covers, the Storm-0558 de-gating, and where the 10-year add-on and Sentinel each win. Read it free.

Read the white paper

How do you govern Microsoft 365 audit log cost?

Audit cost hides in the license mix and in retention add ons. Govern both and the bill stays predictable.

The cost levers

  • Right size the license: match Premium audit to the users who actually need it.
  • Tune retention: set retention policies by record type, not one blanket period.
  • Plan ingestion: watch the bandwidth and export model so investigation cost stays in budget.

The Microsoft 365 plan reference shows which features ride on which plan, so you can avoid buying a whole tier for one capability.

Put your own numbers on this. The free Microsoft calculator prices your seat mix at the July 2026 list prices, the E5 step up against add ons, and the Copilot math, then hands you a two page executive summary you can forward to your CFO. No account, no sales call. Run the Microsoft calculator →

How do you retain audit logs beyond the default window?

Default retention rarely matches a regulatory record requirement. Extending it is a policy and a license decision, not a switch.

Retention policies

  • By record type: keep high value events longer and routine events shorter.
  • By regulation: map the period to the rule that governs the data, not a round number.
  • By add on: use the multi year retention add on only where the rule demands it.

Suggested reading

Do you really need "E5 everywhere" for audit logging?

The most expensive mistake buyers make is assuming meaningful audit logging requires Microsoft 365 E5 on every seat. It does not. E3, A3, G3, F1 and F3 — plus Business Basic, Standard and Premium — all include Audit (Standard), which since 17 October 2023 retains logs for 180 days by default (up from 90) and covers thousands of searchable events across Exchange, SharePoint, OneDrive, Teams and Entra ID. The E3-to-E5 delta buys only three things: retention beyond 180 days, custom retention policies, and intelligent insights. The search UI, the Management Activity API, Search-UnifiedAuditLog and CSV export are identical on both tiers.

Audit Standard vs Audit Premium

CapabilityStandardPremium
Searchable events, audit UI, Activity API, PowerShell/CSV exportYesYes
MailItemsAccessed, Send, SearchQueryInitiatedYes (de-gated 2024)Yes
Default retention180 days1 year
Custom audit log retention policiesNoYes
10-year retentionNoYes — with add-on

That matters because the list gap between E3 and E5 is roughly $21 per user per month (list, pre-discount: E3 about $36, E5 about $57). For a 2,000-seat tenant, blanket E5 "for the audit logs" is a roughly $500,000-a-year decision. Buyer move: unless every user genuinely needs the E5 security, analytics and compliance stack, do not justify a fleet-wide upgrade on audit logging alone. When a reseller frames E5 as "required for audit," ask precisely which of the three Premium-only capabilities you need, and for how many users.

Which high-value events were de-gated after Storm-0558?

After the 2023 Storm-0558 intrusion — where an actor forged tokens to read Exchange Online mailboxes — Microsoft was criticised because the forensic event that would have caught it, MailItemsAccessed, was locked behind E5. Under pressure from CISA and customers, Microsoft de-gated three previously Premium-only mailbox events to Audit Standard (E3) at no extra license cost: MailItemsAccessed (records when mail data is accessed), Send (records messages sent), and SearchQueryInitiated (records mailbox search queries). The rollout completed broadly in April 2024, alongside the lift to 180-day Standard retention.

Two things every buyer should verify. First, these events are available to Standard but not always enabled by default on every mailbox — SearchQueryInitiated in particular must be turned on per mailbox, and audit config drift is common, so budget a small configuration project rather than a license upgrade. Second, do not let a reseller quote E5 "so you get MailItemsAccessed" — that justification expired in 2024. The remaining honest reason to buy Premium is retention duration and retention policies, not access to these events.

How do you license 10-year retention for only the users who need it?

Retention beyond 180 days is where the money lives, and it is licensed per user — which is exactly what lets you avoid over-buying. Audit Premium (in E5/A5/G5, E5 Compliance, the F5 and eDiscovery & Audit add-ons, and the Purview suites) gives 1-year retention. To reach 10 years, the user who generates the log must hold both an E5 base license and the separately purchased 10-Year Audit Log Retention add-on.

Which licenses include Audit Premium

License / SKUAudit tier
M365 / O365 E3, A3, G3, F3, F1; Business Basic/Standard/PremiumStandard
M365 / O365 E5, A5, G5Premium
M365 E5 Compliance add-on; E5/F5 eDiscovery & Audit add-onPremium
Microsoft Purview suitesPremium
10-Year Audit Log Retention add-onRequires E5 + this add-on, per user

Retention is evaluated against the license of the user who produced the event and applied through audit log retention policies (max 50 per tenant, lower priority number wins). So you can scope a 10-year policy to only the handful of high-risk identities — executives, admins, finance approvers, regulated-role staff — and license only those users for the add-on. Buyer move: never buy the 10-year add-on tenant-wide. A common, defensible pattern is E3 baseline for the fleet, Premium (1-year) for the investigators, and the 10-year add-on for a named 5 to 10 percent subset. A stranded add-on with no underlying E5 on the same user is wasted spend.

Is exporting to Sentinel or Log Analytics a cheaper long-retention path?

For long horizons the 10-year add-on is not the only option, and often not the cheapest. Because Audit Standard exposes the full stream through the Office 365 Management Activity API, you can continuously ingest audit events into Microsoft Sentinel or Azure Log Analytics and control retention there independently of your M365 tier. Log Analytics supports interactive retention up to 2 years and low-cost archive retention up to 12 years, priced on ingested GB plus per-GB storage rather than per user.

The 10-year add-on is priced per user and E5-only; Sentinel or Log Ana
The 10-year add-on is priced per user and E5-only; Sentinel or Log Analytics archive is priced per GB regardless of whether the seat is E3 or E5.

Run the population-versus-volume math. If you need long retention for a large population but modest event volume, the GB-based path can be dramatically cheaper — and it keeps forensic data in a SIEM where it is queryable during an incident. The trade-offs: you own the pipeline, ingestion and egress costs are variable, and the schema differs from native Purview search. A pragmatic split: keep 180-day Standard for day-to-day search, stream everything to Sentinel or Log Analytics archive for the long tail, and reserve the native 10-year add-on only for records that must stay inside Purview for eDiscovery workflow reasons.

What should a buyer do next on Microsoft 365 audit logs?

  1. List the users and record types with a real security or regulatory need for Premium audit.
  2. Confirm your current tier and default retention in the Purview portal.
  3. Map each regulatory requirement to a retention period by record type.
  4. Right size Premium audit to the users who need it, not the whole tenant.
  5. Run the Microsoft 365 license optimizer against the estate.
  6. Set retention policies and add the multi year retention only where required.
  7. Challenge any blanket E5 proposal that rests on audit logging alone.
  8. Engage independent Microsoft advisory before the next renewal.
Need help? Try our AI agents. Ask the Microsoft licensing AI agent → Scoped to one vendor and one problem. Runs in your browser.

Frequently asked questions

Do E3 users get MailItemsAccessed and other breach-detection events?

Yes — since 2024 Microsoft de-gated MailItemsAccessed, Send and SearchQueryInitiated to Audit Standard (E3), so these forensic events no longer require E5, though some must be enabled per mailbox rather than relying on defaults.

Is the 10-year audit retention add-on required for every user?

No — it is a per-user add-on on top of E5, so you assign it only to the specific high-risk or regulated identities whose logs must be kept for years, and scope a retention policy to just that group.

What are Microsoft 365 audit logs?

Microsoft 365 audit logs are a record of user and admin activity across the tenant. They form the evidence trail for security investigations, compliance reporting, and insider risk, and they live in the Microsoft Purview audit solution.

What is the difference between Audit Standard and Audit Premium?

Audit Standard ships with most commercial plans and defaults to 180 days of retention, while Audit Premium adds one year default retention, higher value events, and faster investigation access. Premium is gated to E5 and equivalent add on plans.

How long are Microsoft 365 audit logs retained by default?

Audit Standard retains logs for 180 days by default, and Audit Premium retains them for one year. Premium can be extended up to ten years with a separate retention add on where a regulation requires it.

Do I need E5 for Microsoft 365 audit logs?

Not for basic auditing. Standard audit comes with most commercial Microsoft 365 plans, and only Premium audit features require E5 or an equivalent add on. Buying E5 across the tenant just for audit is usually avoidable cost.

Which license unlocks Premium audit features?

Premium audit features ride on Microsoft 365 E5 and equivalent add on plans. The richer events and longer retention are tied to that license gate, so the question is which users actually need them rather than the whole seat base.

How do I control Microsoft 365 audit log cost?

Right size the license so Premium audit covers only users who need it, tune retention by record type rather than one blanket period, and plan ingestion and export so investigation cost stays inside budget.

How do I keep audit logs longer than the default?

Extending retention is a policy and license decision. Use Purview retention policies set by record type and regulation, and apply the multi year retention add on only to the records a rule actually requires you to keep.

Should I use an advisor to license audit logging?

An independent buyer side advisor maps your real audit need against the license tiers and challenges blanket E5 proposals. That review routinely finds that the audit obligation sits on a subset of users, not the entire tenant.

Microsoft EA Renewal Playbook

The full microsoft ea renewal playbook from the Microsoft Practice.

Microsoft renewal moves, the EA framework, the M365 SKU framework, the Copilot framework, and the buyer side moves across the full Microsoft estate.

Used across more than five hundred enterprise engagements. Independent. Buyer side. Built for procurement and IT asset leaders facing a Microsoft review.

Get the white paper →
Opens the white paper landing page. We only email you about this download.
Run the Microsoft 365 license optimizer against your estate in under five minutes.
Open the Tool →
180 days
Standard Retention
1 year
Premium Default
10 yr
Max With Add On
$2B+
Under Advisory
100%
Buyer Side

Almost every tenant I review bought E5 partly for audit. When I ask how many users ever needed a one year evidence trail, the honest answer is a small slice. That gap is where the overspend lives.

Fredrik Filipsson
Co Founder and Group CEO, Redress Compliance