Editorial photograph of a data governance team reviewing Microsoft 365 audit and retention settings on screen
Microsoft / Microsoft 365 Audit Logs

Microsoft 365 audit logs, cost and license clarity.

Purview Standard and Premium, retention tiers, and what each Microsoft 365 license actually unlocks. This guide shows where the audit cost hides and how to license the evidence trail without buying E5 for every seat.

Contact Us Microsoft Practice
500+Enterprise clients
$2B+Under advisory
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Buyer Side Independent

Microsoft 365 audit logs are often the reason a tenant buys E5 everywhere. The cost question is which users genuinely need Premium audit, and how long the records must actually be kept.

Key takeaways

  • Audit logs record user and admin activity and are the evidence trail for security and compliance.
  • Purview audit comes in two tiers, Standard and Premium, gated by your Microsoft 365 license.
  • Standard retention now defaults to 180 days, while Premium defaults to one year.
  • Premium audit is tied to E5 and equivalent add on plans.
  • Blanket E5 to get Premium audit is a common and avoidable cost.
  • Set retention policies by record type and regulation, not one blanket period.
  • License the audit trail where the risk sits, then govern retention to control the bill.

What are Microsoft 365 audit logs and who needs them?

Microsoft 365 audit logs record user and admin activity across the tenant. They are the evidence trail for security investigations, compliance, and insider risk.

Every organization with a compliance or security obligation needs them. What differs is how long you can keep them and how rich the data is.

Common uses

  • Security investigation: trace who accessed what, and when, after an incident.
  • Compliance evidence: show regulators a verifiable record of activity.
  • Insider risk: spot unusual mailbox, file, or sharing behavior.

The Microsoft Purview audit solution is where these logs live and where retention is configured.

How do Purview audit retention tiers and licenses compare?

Audit comes in two tiers, Standard and Premium. The tier you get depends on your Microsoft 365 license, and it sets your default retention.

The table compares the two on the points that drive cost.

Microsoft Purview audit Standard versus Premium

DimensionAudit StandardAudit Premium
Default retention180 daysOne year
Maximum retention180 daysUp to ten years with add on
License gateMost commercial plansE5 and equivalent add ons
Event richnessCore eventsHigh value events included
Access bandwidthStandardHigher for investigations

Reading the tiers

Standard gives a longer default window than it used to, while Audit Premium adds longer retention, richer events, and higher bandwidth access. The split decides what you can investigate a year later.

What does each Microsoft license actually unlock?

The license question is the cost question. Premium audit features ride on specific Microsoft 365 plans, and buying the wrong plan to get them is a common waste.

Standard audit

Standard audit ships with most commercial Microsoft 365 subscriptions. The Audit Standard documentation sets out the default retention and the events captured.

Premium audit

  • License gate: Premium audit is tied to E5 and equivalent add on plans.
  • Longer retention: one year by default, with a multi year add on available.
  • Richer events: high value events that Standard does not capture.

Where the common advice on Microsoft 365 audit logging is wrong

The common advice is to buy E5 across the whole tenant so everyone has Premium audit. We disagree. In most of the 40 to 55 Microsoft 365 governance reviews we ran in 2024 and 2025, only a fraction of users ever needed Premium audit events, yet many tenants paid E5 rates for every seat. The buyer side move is to license Premium audit where the risk and the regulatory need actually sit, use targeted retention policies for the rest, and treat blanket E5 as a procurement default to challenge, not accept. The audit feature rarely justifies the full E5 premium across the entire seat base.

Editorial photograph of a security analyst reviewing Microsoft 365 activity logs on a monitoring dashboard
Retention is set per record type, not per tenant. Mapping each event class to the rule that governs it is what keeps the audit bill defensible.
180 days
Standard audit retention
1 year
Premium default retention
10 yr
Maximum retention with add on

Source: Redress Compliance advisory engagement file, 2024 to 2025.

Audit logging is sold as a reason to buy E5 everywhere. In practice the obligation sits on a subset of users. License the evidence trail where the risk lives, not across every seat by default.
Cover of the Redress Compliance Microsoft white paper

White Paper ยท Microsoft

The Microsoft EA Renewal Playbook

The buyer side framework for the 2024 to 2026 EA cycle. Read it in your browser.

Read the white paper

How do you govern Microsoft 365 audit log cost?

Audit cost hides in the license mix and in retention add ons. Govern both and the bill stays predictable.

The cost levers

  • Right size the license: match Premium audit to the users who actually need it.
  • Tune retention: set retention policies by record type, not one blanket period.
  • Plan ingestion: watch the bandwidth and export model so investigation cost stays in budget.

The Microsoft 365 plan reference shows which features ride on which plan, so you can avoid buying a whole tier for one capability.

How do you retain audit logs beyond the default window?

Default retention rarely matches a regulatory record requirement. Extending it is a policy and a license decision, not a switch.

Retention policies

  • By record type: keep high value events longer and routine events shorter.
  • By regulation: map the period to the rule that governs the data, not a round number.
  • By add on: use the multi year retention add on only where the rule demands it.

Suggested reading

What should a buyer do next on Microsoft 365 audit logs?

  1. List the users and record types with a real security or regulatory need for Premium audit.
  2. Confirm your current tier and default retention in the Purview portal.
  3. Map each regulatory requirement to a retention period by record type.
  4. Right size Premium audit to the users who need it, not the whole tenant.
  5. Run the Microsoft 365 license optimizer against the estate.
  6. Set retention policies and add the multi year retention only where required.
  7. Challenge any blanket E5 proposal that rests on audit logging alone.
  8. Engage independent Microsoft advisory before the next renewal.

Frequently asked questions

What are Microsoft 365 audit logs?

Microsoft 365 audit logs are a record of user and admin activity across the tenant. They form the evidence trail for security investigations, compliance reporting, and insider risk, and they live in the Microsoft Purview audit solution.

What is the difference between Audit Standard and Audit Premium?

Audit Standard ships with most commercial plans and defaults to 180 days of retention, while Audit Premium adds one year default retention, higher value events, and faster investigation access. Premium is gated to E5 and equivalent add on plans.

How long are Microsoft 365 audit logs retained by default?

Audit Standard retains logs for 180 days by default, and Audit Premium retains them for one year. Premium can be extended up to ten years with a separate retention add on where a regulation requires it.

Do I need E5 for Microsoft 365 audit logs?

Not for basic auditing. Standard audit comes with most commercial Microsoft 365 plans, and only Premium audit features require E5 or an equivalent add on. Buying E5 across the tenant just for audit is usually avoidable cost.

Which license unlocks Premium audit features?

Premium audit features ride on Microsoft 365 E5 and equivalent add on plans. The richer events and longer retention are tied to that license gate, so the question is which users actually need them rather than the whole seat base.

How do I control Microsoft 365 audit log cost?

Right size the license so Premium audit covers only users who need it, tune retention by record type rather than one blanket period, and plan ingestion and export so investigation cost stays inside budget.

How do I keep audit logs longer than the default?

Extending retention is a policy and license decision. Use Purview retention policies set by record type and regulation, and apply the multi year retention add on only to the records a rule actually requires you to keep.

Should I use an advisor to license audit logging?

An independent buyer side advisor maps your real audit need against the license tiers and challenges blanket E5 proposals. That review routinely finds that the audit obligation sits on a subset of users, not the entire tenant.

Microsoft EA Renewal Playbook

The full microsoft ea renewal playbook from the Microsoft Practice.

Microsoft renewal moves, the EA framework, the M365 SKU framework, the Copilot framework, and the buyer side moves across the full Microsoft estate.

Used across more than five hundred enterprise engagements. Independent. Buyer side. Built for procurement and IT asset leaders facing a Microsoft review.

No spam. We will only email you about this download. Privacy.
Run the Microsoft 365 license optimizer against your estate in under five minutes.
Open the Tool →
180 days
Standard Retention
1 year
Premium Default
10 yr
Max With Add On
$2B+
Under Advisory
100%
Buyer Side

Almost every tenant I review bought E5 partly for audit. When I ask how many users ever needed a one year evidence trail, the honest answer is a small slice. That gap is where the overspend lives.

Fredrik Filipsson
Co Founder and Group CEO, Redress Compliance