Search the audit log for user and admin activity in Office 365

The Office 365 audit log is a unified audit log. Why a unified audit log? Because events from most Office 365 services that you're organization subscribes to are recorded in a single audit log that you can search. That means you can search for user and admin activity in these services:

  • SharePoint
  • OneDrive
  • Exchange
  • Azure Active Directory
  • Microsoft Teams
  • eDiscovery
  • Power BI
  • Yammer
  • Sway
  • Microsoft Stream

Set up auditing

There's few things you have to do before you can search the Office 365 audit log.

  • Turn on audit log search to start recording events that you can search for

  • Enable mailbox auditing so you can search for mailbox-related events; such as when a user signs in to their mailbox or purges items from their Recoverable Items folder

Search the audit log

After you turn on auditing, you search for hundreds of individual types of events from multiple Office 365 services.