SKIP TO CONTENT
CLOUD AND SYNC36 / 36

Microsoft 365 Unified Audit Log

Also called unified audit log, Purview audit, Office 365 audit log, MailItemsAccessed, Search-UnifiedAuditLog.

PLATFORM
Cloud
CATEGORY
Cloud and Sync
INDEX
36 of 36
PROVES
5 findings
CANNOT PROVE
6 limits
QUESTIONS
4 answered
WHAT IT IS

The tenant-wide record of user and administrator activity across Microsoft 365 — file access and download, mailbox operations, sharing changes and administrative actions.

Where it lives

Microsoft Purview audit, searchable in the compliance portal and through the Exchange Online PowerShell audit search cmdlet

Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of microsoft 365 unified audit log” is neither.

What it records

The audit log holds one record per audited operation, naming the user, the workload, the operation, the affected object, a client address, and workload-specific detail. SharePoint and OneDrive record file access, download, sharing and deletion. Exchange records mailbox operations. What is captured depends on the tenant's licensing and configuration: the records showing which individual messages a mailbox read are available only at higher audit tiers, and are throttled for very high-volume mailboxes.

What it proves — and what it cannot

These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.

What it proves

FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.

  • That an account accessed, downloaded, shared or deleted a named file in SharePoint or OneDrive, at a recorded time
  • Changes to sharing configuration — an internal document made accessible by link, or shared to an external address
  • Administrative actions including mailbox delegation, rule creation, retention changes and audit configuration changes
  • Mail forwarding rules and their creation time, which is how quiet exfiltration through a mailbox is usually found
  • Which messages a mailbox read, where the tenant's audit tier captured that record

What it cannot prove

INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.

  • That the account is the person. The same attribution gap applies to cloud audit records as to any log, and shared, delegated and service accounts are routine in a tenant
  • What was not audited. Coverage depends on the licence and configuration in force at the time, and the record showing individual messages read is available only at higher tiers — the record insider-misconduct matters most need is frequently the one the tenant never bought
  • Complete mailbox-read history for a high-volume mailbox, because that record type is throttled above a threshold and gaps are created by design
  • That records still exist. Retention depends on licensing and record type and Microsoft has changed the defaults, so the tenant's actual configuration must be confirmed rather than assumed from any published figure
  • That an IP address in a record identifies a device or a location, for the same reasons it does not in any authentication log
  • That a download was exfiltration. Downloading one's own working files from a sanctioned system is ordinary behaviour, and volume and timing are what make it otherwise

How the finding is attacked

An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.

  • Establishing that the licence in force did not capture the record type the opinion depends on, so silence reflects configuration rather than conduct
  • Pointing to throttling of high-volume mailbox-read records to explain gaps the examiner characterised as suspicious
  • Showing the retention window closed before preservation, making the produced set partial
  • Attacking the account-to-person link, particularly where delegation or a shared mailbox was in use

What survives, and for how long

Retention is governed by the tenant's audit licensing and by record type, and Microsoft has changed the defaults over time — confirm what the tenant actually retains rather than relying on a figure. Longer retention requires a higher audit tier or an export to a SIEM configured before the events. Once the window closes, nothing on any endpoint reconstructs it.

More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.

Questions counsel ask

How long does Microsoft 365 keep audit logs?

It depends on the tenant's audit licensing and on the record type, and Microsoft has changed the defaults over time — so the only reliable answer is the one obtained from the tenant's own configuration. Longer retention requires a higher audit tier or an export to a SIEM set up before the events at issue. Once the window closes, no endpoint artifact reconstructs it.

Can Microsoft 365 show which emails someone read?

Only where the tenant's audit tier captures the record type that logs individual message access, which is not available at every licence level. Where it is available, it is also throttled for very high-volume mailboxes, so gaps exist by design. In many matters the record that would answer the question was never generated, and that is a licensing fact rather than evidence about conduct.

Does the audit log show files downloaded from SharePoint or OneDrive?

Yes. File access, download, sharing and deletion operations are recorded with the account, the affected file, a timestamp and a client address. That makes it the authoritative account of what left the tenant, far more complete than any endpoint artifact. What it cannot do is separate ordinary work from misappropriation — volume, timing and destination are what carry that argument.

What is the first thing to preserve in a Microsoft 365 matter?

The audit log export, along with sign-in logs and any mailbox rule configuration, because those windows close on their own while endpoints sit unchanged in a drawer. Confirming the tenant's audit tier and retention configuration at the same time is what tells you whether the records you want exist at all, and that answer shapes the rest of the examination.

Terms used on this page

Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.

No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.

A FINDING ON THIS ARTIFACT

Whether the microsoft 365 unified audit logevidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.

A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.

WEEKLY BRIEFING

Digital evidence, explained for litigators.

One email a week on forensic method, digital evidence, and expert testimony — written for counsel, not for technicians. No pitches.

DOUBLE OPT-IN · UNSUBSCRIBE ANY TIME · PRIVACY POLICY

  • Can This Artifact Prove That?

    Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.

  • Cloud forensics

    The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.

  • The artifact index

    All 36 entries, grouped by what they bear on and filterable by platform.

  • Daubert and digital evidence

    Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.

← BACK TO THE ARTIFACT INDEX

Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.