Microsoft 365 Unified Audit Log
Also called unified audit log, Purview audit, Office 365 audit log, MailItemsAccessed, Search-UnifiedAuditLog.
- PLATFORM
- Cloud
- CATEGORY
- Cloud and Sync
- INDEX
- 36 of 36
- PROVES
- 5 findings
- CANNOT PROVE
- 6 limits
- QUESTIONS
- 4 answered
The tenant-wide record of user and administrator activity across Microsoft 365 — file access and download, mailbox operations, sharing changes and administrative actions.
Where it lives
Microsoft Purview audit, searchable in the compliance portal and through the Exchange Online PowerShell audit search cmdlet
Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of microsoft 365 unified audit log” is neither.
What it records
The audit log holds one record per audited operation, naming the user, the workload, the operation, the affected object, a client address, and workload-specific detail. SharePoint and OneDrive record file access, download, sharing and deletion. Exchange records mailbox operations. What is captured depends on the tenant's licensing and configuration: the records showing which individual messages a mailbox read are available only at higher audit tiers, and are throttled for very high-volume mailboxes.
What it proves — and what it cannot
These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.
What it proves
FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.
- That an account accessed, downloaded, shared or deleted a named file in SharePoint or OneDrive, at a recorded time
- Changes to sharing configuration — an internal document made accessible by link, or shared to an external address
- Administrative actions including mailbox delegation, rule creation, retention changes and audit configuration changes
- Mail forwarding rules and their creation time, which is how quiet exfiltration through a mailbox is usually found
- Which messages a mailbox read, where the tenant's audit tier captured that record
What it cannot prove
INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.
- That the account is the person. The same attribution gap applies to cloud audit records as to any log, and shared, delegated and service accounts are routine in a tenant
- What was not audited. Coverage depends on the licence and configuration in force at the time, and the record showing individual messages read is available only at higher tiers — the record insider-misconduct matters most need is frequently the one the tenant never bought
- Complete mailbox-read history for a high-volume mailbox, because that record type is throttled above a threshold and gaps are created by design
- That records still exist. Retention depends on licensing and record type and Microsoft has changed the defaults, so the tenant's actual configuration must be confirmed rather than assumed from any published figure
- That an IP address in a record identifies a device or a location, for the same reasons it does not in any authentication log
- That a download was exfiltration. Downloading one's own working files from a sanctioned system is ordinary behaviour, and volume and timing are what make it otherwise
How the finding is attacked
An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.
- Establishing that the licence in force did not capture the record type the opinion depends on, so silence reflects configuration rather than conduct
- Pointing to throttling of high-volume mailbox-read records to explain gaps the examiner characterised as suspicious
- Showing the retention window closed before preservation, making the produced set partial
- Attacking the account-to-person link, particularly where delegation or a shared mailbox was in use
What survives, and for how long
Retention is governed by the tenant's audit licensing and by record type, and Microsoft has changed the defaults over time — confirm what the tenant actually retains rather than relying on a figure. Longer retention requires a higher audit tier or an export to a SIEM configured before the events. Once the window closes, nothing on any endpoint reconstructs it.
More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.
Questions counsel ask
How long does Microsoft 365 keep audit logs?
It depends on the tenant's audit licensing and on the record type, and Microsoft has changed the defaults over time — so the only reliable answer is the one obtained from the tenant's own configuration. Longer retention requires a higher audit tier or an export to a SIEM set up before the events at issue. Once the window closes, no endpoint artifact reconstructs it.
Can Microsoft 365 show which emails someone read?
Only where the tenant's audit tier captures the record type that logs individual message access, which is not available at every licence level. Where it is available, it is also throttled for very high-volume mailboxes, so gaps exist by design. In many matters the record that would answer the question was never generated, and that is a licensing fact rather than evidence about conduct.
Does the audit log show files downloaded from SharePoint or OneDrive?
Yes. File access, download, sharing and deletion operations are recorded with the account, the affected file, a timestamp and a client address. That makes it the authoritative account of what left the tenant, far more complete than any endpoint artifact. What it cannot do is separate ordinary work from misappropriation — volume, timing and destination are what carry that argument.
What is the first thing to preserve in a Microsoft 365 matter?
The audit log export, along with sign-in logs and any mailbox rule configuration, because those windows close on their own while endpoints sit unchanged in a drawer. Confirming the tenant's audit tier and retention configuration at the same time is what tells you whether the records you want exist at all, and that answer shapes the rest of the examination.
Terms used on this page
Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.
Related artifacts
No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.
Entra ID Sign-in Logs
Tenant-side records of every authentication to Microsoft 365 and connected applications, with the application, IP address, device state, and conditional-access outcome — retained for days unless exported.
OneDrive Sync Artifacts
Client-side logs and databases recording which files the OneDrive client synchronised, when, and in which direction — including files that were only ever placeholders locally.
Dropbox and Google Drive Sync Databases
Local databases maintained by consumer sync clients recording the files in a synchronised account, their state, and a bounded history of sync events.
EDR Telemetry
Security-agent telemetry recording process execution with command lines and hashes, file operations, and outbound network connections — the richest endpoint record available, retained on the vendor's terms.
Whether the microsoft 365 unified audit logevidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.
A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.
- Can This Artifact Prove That?
Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.
- Cloud forensics
The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.
- The artifact index
All 36 entries, grouped by what they bear on and filterable by platform.
- Daubert and digital evidence
Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.
Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.