Search the audit log for user and admin activity in Office 365
The Office 365 audit log is a unified audit log. Why a unified audit log? Because events from most Office 365 services that you're organization subscribes to are recorded in a single audit log that you can search. That means you can search for user and admin activity in these services:
- Azure Active Directory
- Microsoft Teams
- Power BI
- Microsoft Stream
Set up auditing
There's few things you have to do before you can search the Office 365 audit log.
Turn on audit log search to start recording events that you can search for
Enable mailbox auditing so you can search for mailbox-related events; such as when a user signs in to their mailbox or purges items from their Recoverable Items folder
Search the audit log
After you turn on auditing, you search for hundreds of individual types of events from multiple Office 365 services.