About this article
This article was generated using an automated workflow leveraging generative AI. It reviews current Microsoft Learn documentation on Audit to clarify the differences between Standard and Premium, as well as the safest initial verification methods.Verification Status: 📘 Confirmed with official Microsoft documentation / Not verified on a physical device
Microsoft Purview Audit is an audit log feature in Microsoft 365 used to investigate "who did what and when." It allows you to search administrator actions, file operations, and email-related activities for security investigations and compliance verification.
Standard and Premium
Audit (Standard) also allows you to search audit logs, with a current default retention period of 180 days. Standard logs generated on or after October 17, 2023, are retained for 180 days by default.
Audit (Premium) provides users assigned the appropriate E5 or matching add-on license with advanced auditing features, long-term retention, and intelligent insights. Premium features may require the Advanced Auditing service plan to be enabled.
| Perspective | Audit Standard | Audit Premium |
|---|---|---|
| Audit Log Search | Yes | Yes |
| Standard Retention | 180 days | Advanced retention features available |
| Intelligent insights | – | Target |
| Primary Positioning | Eligible Microsoft 365 including E3 | E5 / Eligible add-on |
Try This First: Read-Only Audit Search
Open Audit in the Purview portal, specify a test user, and select a short time range.
Users: test-user@example.com Date range: 過去24時間 Activities: まずは指定なし
What to Look For
Verify that the results display the date and time, user, operation, and target resource. The trick is to narrow down the target user and timeframe rather than searching a large period from the start.
Try Changing One Thing
Change the timeframe from 24 hours to 7 days. By keeping the user fixed and observing the difference in the number of records, you can check the scope of the retained history.
Before Using PowerShell
Audit-related cmdlets require permissions. There are also cases where you need to check audit settings on the Exchange Online side. For initial learning, it is safer to stop at reading search results in the Purview portal and avoid changing audit settings.
Pay Attention to Pay-As-You-Go Conditions for AI Data
Certain scenarios that treat AI data outside of Microsoft 365 as audit targets require pay-as-you-go billing. Be careful not to design licenses assuming only traditional Microsoft 365 auditing.
Points for Administrators to Verify
Roles such as Audit Reader / Audit Manager
Licenses eligible for Standard/Premium
Advanced Auditing service plan
License assignment to target users
Audit log retention period
Pay-as-you-go requirements for AI data and other services
Storage rules for exported audit data
Official Microsoft Information
Get started with auditing solutions: https://learn.microsoft.com/en-us/purview/audit-get-started
Auditing solutions overview: https://learn.microsoft.com/en-us/purview/audit-solutions-overview
Purview service description: https://learn.microsoft.com/en-us/office365/servicedescriptions/microsoft-365-service-descriptions/microsoft-365-tenantlevel-services-licensing-guidance/microsoft-purview-service-description
Audit is not simply a matter of "logs exist so we are safe"; it only becomes useful once you verify that the required period, users, and operations are actually recorded. We recommend starting with a short-term read-only search.

