Microsoft 365 Logging and Monitoring: Why 90 Days of Audit Data Is Not Enough
Microsoft 365 provides extensive audit logging, but default retention is typically limited. For many standard licences, audit data is retained for 90 to 180 days, which may not align with investigation timelines or compliance requirements.
If suspicious activity is detected months after initial access, earlier audit events may no longer be available. This reduces the ability to confirm how access was obtained, what actions were performed, and which accounts or data were impacted.
Investigation Timelines and Retention Gaps
In cybersecurity, "dwell time" refers to the duration an attacker remains undetected within an environment. Many incidents are detected well after initial access.
A common pattern is credential compromise (for example, via phishing) followed by low-noise activity such as mailbox rule creation, internal reconnaissance, and gradual privilege escalation. If detection occurs months later, earlier Microsoft 365 audit events may already be outside the retained window.

Instructional Diagram: The Forensic Blind Spot. A flat-design timeline showing initial access (Day 1), default log expiry (Day 90), and detection (Day 200). The gap between Day 90 and Day 200 is highlighted in MBIT Yellow (#FEF600).
Licensing and Retention Constraints
Microsoft 365 audit retention varies by audit tier and licensing. Retention capabilities are not uniform across all tenants and can also depend on the event type being recorded.
- Audit (Standard): Provides 90 days of audit log retention by default. For some audit events, Microsoft has provided up to 180 days of retention (changes introduced from October 2023). This does not equate to full one-year coverage across all event types.
- Audit (Premium): Provides 1-year audit log retention by default. This requires eligible licensing (for example Microsoft 365 E5/G5/A5) or an Audit (Premium) add-on where available.
- Longer retention (up to 10 years): Retention beyond one year (including up to 10 years) requires additional licensing and configuration. This is typically implemented using advanced retention capabilities and should be validated against the specific audit data types and compliance requirements.
Without a defined retention strategy, historical audit evidence is continuously overwritten as the retention window expires.
Compliance Retention Requirements
For organisations handling sensitive data (medical, financial, legal, or client records), log retention can be a compliance requirement rather than an operational preference.
As an example, HIPAA requires audit logs to be retained for six years. Many Australian-aligned governance expectations and insurance requirements increasingly reference one to two years of logging retention. If an insurer or regulator requests historical audit evidence, an inability to produce logs can materially impact outcomes.
What Exactly is Being Logged (And What Are You Missing?)
When discussing "audit data," this is not limited to sign-in events. The Unified Audit Log in Microsoft 365 captures a broad range of activity, including:
- File Access: Who viewed, downloaded, or deleted that sensitive budget spreadsheet?
- Mailbox Activity: Was a new forwarding rule created? Did someone access a mailbox they weren't supposed to?
- Admin Changes: Who granted "Global Admin" rights to a new user?
- Teams Interactions: Were files shared externally through a Teams chat?
When these logs are no longer retained (for example, after 90 or 180 days), investigation context is lost. This is particularly relevant when comparing backup and retention concepts. While a backup may preserve files, audit logs preserve context (who did what, when, and from where). Both are typically required for effective incident response and assurance.
Options for Extending Audit Retention
Extending audit retention requires aligning licensing and configuration to the audit data types required. Where user-level licensing applies, audit records associated with users who do not have the required entitlement may not be retained for the longer period, even if tenant-wide settings are configured.
1. Microsoft 365 Audit Log Retention Policies
If you have the appropriate licensing (like Business Premium or E5), you can set up custom retention policies within the Microsoft Purview compliance portal. This allows you to specify that certain types of logs (like Exchange or SharePoint activity) should be kept for a year or longer.
2. Exporting Logs to a SIEM
Exporting logs to a Security Information and Event Management (SIEM) platform moves audit data into a system designed for longer retention, correlation, and investigation workflows. This supports multi-year retention where required.
3. Third-Party Monitoring Tools
Specialised monitoring tools can collect Microsoft 365 audit data and store it in an external repository, often with detection, alerting, and reporting features.

Instructional Diagram: Secure Log Archiving Workflow. A flat-design flow using MBIT Blue (#153379) and MBIT Yellow (#FEF600), showing Microsoft 365 Tenant logs exported to SIEM/Log Analytics and stored in an immutable archive with retention aligned to compliance.
Proactive vs. Reactive: Operational Guidance
Log retention is often reviewed only after suspicious activity is identified. At that stage, investigation depends on whether historical audit records still exist.
A proactive approach is to validate retention and investigation readiness in advance:
- What licence level is in place, and what audit retention does it provide?
- What retention period is required by regulation, contracts, or cyber insurance?
- If an incident is identified today, how far back can audit activity be reconstructed?
Final Thoughts
Microsoft 365 provides strong security capabilities, but default audit retention may be insufficient for incident investigation and compliance evidence. Relying on a 90 to 180-day window can leave gaps between initial access and detection.
Extending audit retention (via eligible Purview retention policies and/or external log archiving to a SIEM or equivalent platform) improves investigation capability, supports compliance requirements, and reduces reliance on time-limited default data.
