Investigating compliance activities by using audit logs
The Microsoft Purview compliance portal grants administrators the ability to search the unified audit log to view user and administrator activity in your organization. This is a Purview feature that provides further and deeper insight into Microsoft 365 activities. So, as an example, if you need to find out whether a user deleted an email or accessed a specific document, the unified audit log should be your first port of call.
It is often asked why this is known as the unified audit log. This is simply due to the fact that you can use it to search for activities across different Microsoft 365 services and features. A few examples of these features include the following:
- Azure Active Directory
- Data Loss Prevention (DLP)
- eDiscovery
- Exchange Online
- Microsoft 365 Defender
- Microsoft Teams
- Sensitivity labels
- Threat Intelligence
- Yammer
Note
These are only a few of the locations available...