Skip to content

Commit

Permalink
Update turn-audit-log-search-on-or-off.md
Browse files Browse the repository at this point in the history
  • Loading branch information
sujitnaray committed Jan 22, 2021
1 parent e8c2d96 commit 1c0000a
Showing 1 changed file with 2 additions and 2 deletions.
4 changes: 2 additions & 2 deletions microsoft-365/compliance/turn-audit-log-search-on-or-off.md
Expand Up @@ -24,7 +24,7 @@ description: How to turn on or off the Audit log search feature in the Security

# Turn audit log search on or off

You (or another admin) must turn on audit logging before you can start searching the audit log. When audit log search in the Security & Compliance Center is turned on, user and admin activity from your organization is recorded in the audit log and retained for 90 days, and up to one year depending on the license assigned to users. However, your organization may have reasons for not wanting to record and retain audit log data. In those cases, a global admin may decide to turn off auditing in Microsoft 365.
Audit Logging is turned on for enterprise customers, by default. When audit log search in the Security & Compliance Center is turned on, user and admin activity from your organization is recorded in the audit log and retained for 90 days, and up to one year depending on the license assigned to users. However, your organization may have reasons for not wanting to record and retain audit log data. In those cases, a global admin may decide to turn off auditing in Microsoft 365.

> [!IMPORTANT]
> If you turn off audit log search in Microsoft 365, you can't use the Office 365 Management Activity API or Azure Sentinel to access auditing data for your organization. Turning off audit log search by following the steps in this article means that no results will be returned when you search the audit log using the Security & Compliance Center or when you run the **Search-UnifiedAuditLog** cmdlet in Exchange Online PowerShell. This also means that audit logs won't be available through the Office 365 Management Activity API or Azure Sentinel.
Expand Down Expand Up @@ -92,4 +92,4 @@ You have to use remote PowerShell connected to your Exchange Online organization

- In the [Security & Compliance Center](https://protection.office.com), go to **Search** \> **Audit log search**.

A banner is displayed saying that auditing has to be turned on in order to record user and admin activity.
A banner is displayed saying that auditing has to be turned on in order to record user and admin activity.

0 comments on commit 1c0000a

Please sign in to comment.