Audit Log Retention and Coverage Validator
TL;DR: This skill reads your Microsoft Purview audit settings to confirm the Unified Audit Log is on, retention meets ISM event logging needs, and Microsoft 365 Copilot interactions are captured, then returns a scored gap report. It changes nothing.
What the Microsoft Purview Unified Audit Log records across your tenant
The Microsoft Purview unified audit log captures and retains user and admin operations across dozens of Microsoft services, including Exchange Online, SharePoint, OneDrive, Microsoft Teams, Microsoft Entra and Microsoft 365 Copilot. Audit (Standard) retains records for 180 days. Audit (Premium) adds audit log retention policies and longer retention: one year by default for Microsoft Entra, Exchange, OneDrive and SharePoint records of E5-licensed users, and up to 10 years with an add-on licence. This skill checks whether auditing is enabled, how long records are kept, and whether Microsoft 365 Copilot interaction records are retained long enough for an investigator to reconstruct events later.
When should you run this skill?
- “Is the Unified Audit Log actually turned on in our tenant?”
- “Will our audit records survive long enough to meet the ISM’s 12-month event log retention requirement?”
- “Are Microsoft 365 Copilot interactions being captured in the audit log, and for how long?”
- “We are preparing for an Essential Eight uplift and need to show our event logs are protected from tampering.”
- “How long do we retain Exchange, SharePoint, OneDrive and Microsoft Entra audit records?”
- “Did someone shorten or add an audit log retention policy recently?”
- “Show me which workloads fall back to the 180-day default.”
How this skill works, step by step
- Connect read-only to Exchange Online PowerShell and Security & Compliance PowerShell using an account with the Audit Logs role.
- Confirm the unified audit log ingestion state by running
Get-AdminAuditLogConfig | Format-List UnifiedAuditLogIngestionEnabledin Exchange Online PowerShell (the value is always False in Security & Compliance PowerShell). - Establish the retention baseline per user licence: Audit (Standard) at 180 days, or Audit (Premium) with the default one-year policy for Microsoft Entra, Exchange, OneDrive and SharePoint records.
- Enumerate custom audit log retention policies with
Get-UnifiedAuditLogRetentionPolicyin Security & Compliance PowerShell, noting record types, priority and retention duration. This cmdlet does not return the default policy, so the skill reports that separately. - Check that Microsoft 365 Copilot interaction records (the
CopilotInteractionoperation) are captured, and that no custom policy shortens their retention below your requirement. - Compare retention durations against your target, for example ISM-1988 (event logs retained in a searchable manner for at least 12 months), and flag any shortfall.
- Identify gaps such as auditing turned off, non-E5 or guest users limited to 180 days, or records relying on the default only.
- Derive a weighted risk score from coverage, retention length and Copilot findings.
- Compile the findings into a prioritised, read-only report with remediation guidance.
Output format
The skill returns a findings table followed by a summary. Each row maps a check to its status, observed value and recommended action. The values below are illustrative.
| Check | Status | Observed value | Recommended action |
|---|---|---|---|
| Unified audit log ingestion | Pass | UnifiedAuditLogIngestionEnabled is True | None |
| Audit licence tier | Warning | Audit (Standard), 180 days | Evaluate Audit (Premium) for one-year retention |
| Copilot interaction records | Warning | CopilotInteraction captured, 180-day retention | Add a retention policy if your requirement exceeds 180 days |
| Exchange, SharePoint, OneDrive and Microsoft Entra records | Pass | One year (default policy, E5-licensed users) | None |
- Overall risk score is presented as Low, Medium or High with a short rationale.
- A prioritised remediation list orders gaps by compliance impact.
- Each finding references the relevant control so owners can act with context.
- Counts of compliant versus non-compliant workloads are summarised at the top.
Scope and safety
This skill is read-only by default and makes no changes to your tenant, policies or audit configuration. It only reads configuration and reports findings.
This skill does NOT:
- Turn the unified audit log on or off, or create, edit or delete any audit log retention policy.
- Create, edit or delete audit records or compliance policies.
- Export, retain or relocate audit event content outside your tenant.
- Assign licences or change subscription tiers.
Licensing and permissions
Licences and add-ons
| Capability used | Licence requirement |
|---|---|
| Audit (Standard): unified audit log search and 180-day retention | Eligible Microsoft 365 or Office 365 enterprise subscription |
| Audit (Premium): one-year default retention and custom audit log retention policies | Audit (Premium) user licence: Office 365 E5, Microsoft 365 E5, Microsoft Purview Suite (formerly Microsoft 365 E5 Compliance) or the E5 eDiscovery and Audit add-on |
| 10-year retention | 10-Year Audit Log Retention add-on, in addition to the Audit (Premium) licence |
| Microsoft 365 Copilot interaction auditing | Included in Audit (Standard); no extra audit configuration |
| Auditing of non-Microsoft AI applications | Pay-as-you-go billing, 180-day retention |
Retention follows the licence of the user who performed the activity. Records for non-E5 users and guests are retained for 180 days, and records from non-user entities such as service principals are retained for a fixed one year.
Least-privilege roles
- Audit Logs role (in the Compliance Management and Organization Management role groups): search the audit log and use the audit cmdlets, assigned in the Microsoft Purview portal and the Exchange admin center.
- Microsoft Entra role for Graph reads: Reports Reader, Security Reader or Security Administrator.
- Note: the Organization Configuration role is needed only to create or modify retention policies, which this skill never does.
Microsoft Graph permissions (read-only)
AuditLog.Read.All(delegated or application): reads Microsoft Entra directory audit logs.
Related skills
- Admin Action and Audit Trail Review: run after this to review privileged admin events in the audit log
- Copilot Interaction Compliance Audit: run after this to inspect Copilot audit logs for sensitive data exposure
- Retention and Records Management Audit: run after this to review how content is kept and disposed of
- Threat Hunting Readiness Baseline: run after this to check the tenant is ready for proactive threat hunting
- Australian Compliance for Microsoft 365 Copilot and AI: the pillar guide to Australian compliance for Microsoft 365 Copilot and AI
Sources
- Learn about auditing solutions in Microsoft Purview
- Manage audit log retention policies
- Turn auditing on or off
- Audit logs for Copilot and AI applications
- Get-UnifiedAuditLogRetentionPolicy
- Audit log considerations for the Australian Government : maps the audit log to ISM-1988 (12-month retention) and ISM-1989 (retention per AFDA Express)
- Essential Eight restrict administrative privileges : covers protecting event logs from unauthorised modification and deletion at Maturity Level 3
- List directoryAudits (Microsoft Graph)
Licensed under CC BY 4.0 by EDUC4TE .
SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload▸ View skill file▾ Hide skill file
How to use this skill
- Get the file. Download or copy the
SKILL.mdfrom the SKILL.md panel on this page. - Load it into your host:
- Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
- Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
- Any chat host — paste the file contents as your prompt.
- Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions section of this article.
- Provide your tenant scope and run it (a site, a collection, or the whole tenant).
- Review the report and action the risk-ranked recommendations.
This skill is read-only by default — it inspects and reports, and never changes your tenant.
Last reviewed 2026-10-01 · Published 2026-06-02