Microsoft 365 audit logs sit across Unified Audit Log, Purview, and Sentinel. Retention, ingestion, and visibility depend on the license and the SKU stack. Most estates pay too much because of license drift.
Microsoft 365 audit logs live in three places. License tier, retention add ons, and Sentinel ingestion drive cost more than the security team usually realizes.
Microsoft 365 produces audit signal in many places. The official log layer is the Unified Audit Log inside Purview.
Purview Audit Standard ships with most E3 and E5 plans. Purview Audit Premium adds longer retention and richer event types.
Sentinel can ingest the Unified Audit Log as another data source. That ingest is billed in Azure, which is where most surprise cost shows up.
Audit data flows through three Microsoft surfaces in most enterprise tenants.
The Unified Audit Log is the foundational layer. It captures activity across Exchange Online, SharePoint, OneDrive, Teams, Entra ID, Defender, and many other services.
Purview Audit packages the Unified Audit Log with retention, search, and event types.
Sentinel ingests the Office 365 Audit Log as a data source through a built in connector.
Retention is the most misunderstood part of the audit log stack.
Microsoft has shifted retention defaults over the past two years. The numbers in legacy documentation are often out of date.
Retention can be extended through add on policies and licensed retention SKUs.
Audit log surfaces, retention, and license requirement
| Surface | Default retention | Premium retention | License required |
|---|---|---|---|
| Unified Audit Log via Purview | 180 to 365 days | Up to 10 years | E3 or E5 plus add on |
| Purview Audit Premium events | 365 days | Up to 10 years | Audit Premium add on, or E5 |
| Sentinel Office 365 connector | Per Sentinel retention | Up to 7 years on Sentinel | Sentinel licensed separately |
| Defender XDR audit events | 30 to 180 days | Up to 2 years archive | Defender Plan 2 or E5 Security |
The buyer side challenge is that audit logging is bundled into several different licenses and add ons.
E3 includes Purview Audit Standard. Premium can be added per user.
E5 includes Purview Audit Premium for most workloads.
Audit log retention is a procurement decision, not just a security decision. Right size it before the next EA renewal, not after.
A small set of decisions drives most of the cost. Each one is reversible.
Ingesting every audit event into Sentinel is expensive and often unnecessary.
Different data classes need different retention windows. A single 10 year retention for everything is rarely justified.
Re evaluate retention, ingestion, and license mix every quarter. The technology evolves faster than annual renewals.
Most audit log overspend traces back to a small number of recurring decisions.
Both Purview Audit Premium and Sentinel can store the same data. Many estates pay for both without intent.
Applying 10 year retention to every workload inflates cost without proportional value.
Audit log ingest to Sentinel can grow quietly. Without anomaly alerts, it surfaces a quarter late on the bill.
Microsoft 365 audit logs are retained for 180 days at E3 and 365 days at E5 under Purview Audit Standard in 2026. Purview Audit Premium extends retention up to 10 years with the appropriate add on.
Standard ships with E3 and E5 and covers basic audit events with up to 365 days of retention. Premium adds high value events such as MailItemsAccessed, supports retention up to 10 years, and is included in E5.
Yes, or another archive platform. Native Purview retention caps at 10 years. Sentinel supports archive tiers and longer retention through long term storage, but the cost model is different.
It depends on volume. Purview retention is licensed per user and per workload. Sentinel retention is billed by data volume. For large estates with selective ingest, Sentinel can be cheaper. For broad retention on all users, Purview is usually cheaper.
E3 provides 180 day Unified Audit Log retention plus Purview Audit Standard. For many regulated industries this is insufficient. The Premium add on or E5 is usually needed for adequate retention and event coverage.
Some Defender events, third party SaaS audit data, and infrastructure level logs are not in Purview. These typically require Defender XDR, Sentinel connectors, or third party SIEM connectors to retain.
Microsoft renewal moves, the EA framework, the M365 SKU framework, the Copilot framework, and the buyer side moves across the full Microsoft estate.
Used across more than five hundred enterprise engagements. Independent. Buyer side. Built for procurement leaders running the next renewal cycle.
Microsoft 365 audit logs are sold three different ways inside the same suite. Most security teams pay twice for the same retention window without knowing it.
500+ enterprise clients. 11 vendor practices. Industry recognized. One conversation can change what you pay for the next three years.
Monthly briefings on Microsoft EA renewals, security baselines, and audit log governance for the Microsoft estate.
Once a month. Audit patterns, renewal benchmarks, vendor commercial signals across Oracle, Microsoft, SAP, Salesforce, IBM, Broadcom, AWS, Google Cloud, ServiceNow, Workday, Cisco, and the GenAI vendors. No follow up sales pressure.
Free providers (Gmail, Yahoo, Outlook) cannot subscribe. Work email only. Unsubscribe in one click.