Search the audit log for user and admin activity in Office 365

The Office 365 audit log is a unified audit log. Why a unified audit log? Because events from most Office 365 services that you're organization subscribes to are recorded in a single audit log that you can search. That means you can search for user and admin activity in these services:

  • SharePoint

  • Exchange

  • Sway

  • Microsoft Teams

  • OneDrive

  • Azure Active Directory

  • Power BI

  • Yammer

Set up auditing

There's few things you have to do before you can search the Office 365 audit log.

  • Turn on audit log search to start recording events that you can search for

  • Enable mailbox auditing so you can search for mailbox-related events; such as when a user signs in to their mailbox or purges items from their Recoverable Items folder

Search the audit log

After you turn on auditing, you search for hundreds of individual types of events from multiple Office 365 services.

Expand your skills
Explore training
Get new features first
Join Office Insiders

Was this information helpful?

Thank you for your feedback!

Thank you for your feedback! It sounds like it might be helpful to connect you to one of our Office support agents.

×