Purview Standard and Premium, retention tiers, and what each Microsoft 365 license actually unlocks. This guide shows where the audit cost hides and how to license the evidence trail without buying E5 for every seat.
Microsoft 365 audit logs are often the reason a tenant buys E5 everywhere. The cost question is which users genuinely need Premium audit, and how long the records must actually be kept.
Microsoft 365 audit logs record user and admin activity across the tenant. They are the evidence trail for security investigations, compliance, and insider risk.
Every organization with a compliance or security obligation needs them. What differs is how long you can keep them and how rich the data is.
The Microsoft Purview audit solution is where these logs live and where retention is configured.
Audit comes in two tiers, Standard and Premium. The tier you get depends on your Microsoft 365 license, and it sets your default retention.
The table compares the two on the points that drive cost.
Microsoft Purview audit Standard versus Premium
| Dimension | Audit Standard | Audit Premium |
|---|---|---|
| Default retention | 180 days | One year |
| Maximum retention | 180 days | Up to ten years with add on |
| License gate | Most commercial plans | E5 and equivalent add ons |
| Event richness | Core events | High value events included |
| Access bandwidth | Standard | Higher for investigations |
Standard gives a longer default window than it used to, while Audit Premium adds longer retention, richer events, and higher bandwidth access. The split decides what you can investigate a year later.
The license question is the cost question. Premium audit features ride on specific Microsoft 365 plans, and buying the wrong plan to get them is a common waste.
Standard audit ships with most commercial Microsoft 365 subscriptions. The Audit Standard documentation sets out the default retention and the events captured.
The common advice is to buy E5 across the whole tenant so everyone has Premium audit. We disagree. In most of the 40 to 55 Microsoft 365 governance reviews we ran in 2024 and 2025, only a fraction of users ever needed Premium audit events, yet many tenants paid E5 rates for every seat. The buyer side move is to license Premium audit where the risk and the regulatory need actually sit, use targeted retention policies for the rest, and treat blanket E5 as a procurement default to challenge, not accept. The audit feature rarely justifies the full E5 premium across the entire seat base.
Source: Redress Compliance advisory engagement file, 2024 to 2025.
Audit logging is sold as a reason to buy E5 everywhere. In practice the obligation sits on a subset of users. License the evidence trail where the risk lives, not across every seat by default.
White Paper · Microsoft
Microsoft 365 Audit Logging (2026)
License the trail, not every seat: what E3 already covers, the Storm-0558 de-gating, and where the 10-year add-on and Sentinel each win. Read it free.
Audit cost hides in the license mix and in retention add ons. Govern both and the bill stays predictable.
The Microsoft 365 plan reference shows which features ride on which plan, so you can avoid buying a whole tier for one capability.
Default retention rarely matches a regulatory record requirement. Extending it is a policy and a license decision, not a switch.
The most expensive mistake buyers make is assuming meaningful audit logging requires Microsoft 365 E5 on every seat. It does not. E3, A3, G3, F1 and F3 — plus Business Basic, Standard and Premium — all include Audit (Standard), which since 17 October 2023 retains logs for 180 days by default (up from 90) and covers thousands of searchable events across Exchange, SharePoint, OneDrive, Teams and Entra ID. The E3-to-E5 delta buys only three things: retention beyond 180 days, custom retention policies, and intelligent insights. The search UI, the Management Activity API, Search-UnifiedAuditLog and CSV export are identical on both tiers.
Audit Standard vs Audit Premium
| Capability | Standard | Premium |
|---|---|---|
| Searchable events, audit UI, Activity API, PowerShell/CSV export | Yes | Yes |
| MailItemsAccessed, Send, SearchQueryInitiated | Yes (de-gated 2024) | Yes |
| Default retention | 180 days | 1 year |
| Custom audit log retention policies | No | Yes |
| 10-year retention | No | Yes — with add-on |
That matters because the list gap between E3 and E5 is roughly $21 per user per month (list, pre-discount: E3 about $36, E5 about $57). For a 2,000-seat tenant, blanket E5 "for the audit logs" is a roughly $500,000-a-year decision. Buyer move: unless every user genuinely needs the E5 security, analytics and compliance stack, do not justify a fleet-wide upgrade on audit logging alone. When a reseller frames E5 as "required for audit," ask precisely which of the three Premium-only capabilities you need, and for how many users.
After the 2023 Storm-0558 intrusion — where an actor forged tokens to read Exchange Online mailboxes — Microsoft was criticised because the forensic event that would have caught it, MailItemsAccessed, was locked behind E5. Under pressure from CISA and customers, Microsoft de-gated three previously Premium-only mailbox events to Audit Standard (E3) at no extra license cost: MailItemsAccessed (records when mail data is accessed), Send (records messages sent), and SearchQueryInitiated (records mailbox search queries). The rollout completed broadly in April 2024, alongside the lift to 180-day Standard retention.
Two things every buyer should verify. First, these events are available to Standard but not always enabled by default on every mailbox — SearchQueryInitiated in particular must be turned on per mailbox, and audit config drift is common, so budget a small configuration project rather than a license upgrade. Second, do not let a reseller quote E5 "so you get MailItemsAccessed" — that justification expired in 2024. The remaining honest reason to buy Premium is retention duration and retention policies, not access to these events.
Retention beyond 180 days is where the money lives, and it is licensed per user — which is exactly what lets you avoid over-buying. Audit Premium (in E5/A5/G5, E5 Compliance, the F5 and eDiscovery & Audit add-ons, and the Purview suites) gives 1-year retention. To reach 10 years, the user who generates the log must hold both an E5 base license and the separately purchased 10-Year Audit Log Retention add-on.
Which licenses include Audit Premium
| License / SKU | Audit tier |
|---|---|
| M365 / O365 E3, A3, G3, F3, F1; Business Basic/Standard/Premium | Standard |
| M365 / O365 E5, A5, G5 | Premium |
| M365 E5 Compliance add-on; E5/F5 eDiscovery & Audit add-on | Premium |
| Microsoft Purview suites | Premium |
| 10-Year Audit Log Retention add-on | Requires E5 + this add-on, per user |
Retention is evaluated against the license of the user who produced the event and applied through audit log retention policies (max 50 per tenant, lower priority number wins). So you can scope a 10-year policy to only the handful of high-risk identities — executives, admins, finance approvers, regulated-role staff — and license only those users for the add-on. Buyer move: never buy the 10-year add-on tenant-wide. A common, defensible pattern is E3 baseline for the fleet, Premium (1-year) for the investigators, and the 10-year add-on for a named 5 to 10 percent subset. A stranded add-on with no underlying E5 on the same user is wasted spend.
For long horizons the 10-year add-on is not the only option, and often not the cheapest. Because Audit Standard exposes the full stream through the Office 365 Management Activity API, you can continuously ingest audit events into Microsoft Sentinel or Azure Log Analytics and control retention there independently of your M365 tier. Log Analytics supports interactive retention up to 2 years and low-cost archive retention up to 12 years, priced on ingested GB plus per-GB storage rather than per user.
Run the population-versus-volume math. If you need long retention for a large population but modest event volume, the GB-based path can be dramatically cheaper — and it keeps forensic data in a SIEM where it is queryable during an incident. The trade-offs: you own the pipeline, ingestion and egress costs are variable, and the schema differs from native Purview search. A pragmatic split: keep 180-day Standard for day-to-day search, stream everything to Sentinel or Log Analytics archive for the long tail, and reserve the native 10-year add-on only for records that must stay inside Purview for eDiscovery workflow reasons.
Yes — since 2024 Microsoft de-gated MailItemsAccessed, Send and SearchQueryInitiated to Audit Standard (E3), so these forensic events no longer require E5, though some must be enabled per mailbox rather than relying on defaults.
No — it is a per-user add-on on top of E5, so you assign it only to the specific high-risk or regulated identities whose logs must be kept for years, and scope a retention policy to just that group.
Microsoft 365 audit logs are a record of user and admin activity across the tenant. They form the evidence trail for security investigations, compliance reporting, and insider risk, and they live in the Microsoft Purview audit solution.
Audit Standard ships with most commercial plans and defaults to 180 days of retention, while Audit Premium adds one year default retention, higher value events, and faster investigation access. Premium is gated to E5 and equivalent add on plans.
Audit Standard retains logs for 180 days by default, and Audit Premium retains them for one year. Premium can be extended up to ten years with a separate retention add on where a regulation requires it.
Not for basic auditing. Standard audit comes with most commercial Microsoft 365 plans, and only Premium audit features require E5 or an equivalent add on. Buying E5 across the tenant just for audit is usually avoidable cost.
Premium audit features ride on Microsoft 365 E5 and equivalent add on plans. The richer events and longer retention are tied to that license gate, so the question is which users actually need them rather than the whole seat base.
Right size the license so Premium audit covers only users who need it, tune retention by record type rather than one blanket period, and plan ingestion and export so investigation cost stays inside budget.
Extending retention is a policy and license decision. Use Purview retention policies set by record type and regulation, and apply the multi year retention add on only to the records a rule actually requires you to keep.
An independent buyer side advisor maps your real audit need against the license tiers and challenges blanket E5 proposals. That review routinely finds that the audit obligation sits on a subset of users, not the entire tenant.
Microsoft renewal moves, the EA framework, the M365 SKU framework, the Copilot framework, and the buyer side moves across the full Microsoft estate.
Used across more than five hundred enterprise engagements. Independent. Buyer side. Built for procurement and IT asset leaders facing a Microsoft review.
Almost every tenant I review bought E5 partly for audit. When I ask how many users ever needed a one year evidence trail, the honest answer is a small slice. That gap is where the overspend lives.