As part of our ongoing efforts to improve the logging capabilities of Exchange Online, we are sharing our timeline for decommissioning the Search-MailboxAuditLog and New-MailboxAuditLogSearch cmdlets.
Updated Mar 06, 2025
Version 3.0This was all fine back when the initial post was made, but since then you've also announced the upcoming change to force Search-UnifiedAuditLog to always use -HighCompleteness. This effectively leaves without any option to query the audit log synchronously and in turn will break huge percentage of existing automations. What is the proposed solution for such scenarios?
I think this comment is critically under appreciated. I would also like to hear from Microsoft as to what the plan is here for allowing real time application integrations to this data. We have third party security platforms that are relying on this data to be synchronous.