SOLVED
Home

Roles required for Search-UnifiedAuditLog

%3CLINGO-SUB%20id%3D%22lingo-sub-148218%22%20slang%3D%22en-US%22%3ERoles%20required%20for%20Search-UnifiedAuditLog%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-148218%22%20slang%3D%22en-US%22%3E%3CP%3EWe're%20setting%20up%20a%20scheduled%20script%20to%20export%20logs%20through%20the%20Powershell%20cmd%20Search-UnifiedAuditLog.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHowever%2C%20since%20all%20our%20Administrators%20use%20MFA%2C%20we%20need%20to%20use%20a%20separate%20user%20with%20no%20MFA%2C%20but%20restricted%20permissions.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20noticed%20there's%20a%20role%20%22Audit%20Logs%22%20in%20the%20Security%20%26amp%3B%20Compliancy%20section%2C%20but%20those%20permissions%20don't%20seem%20adequate.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWhat%20roles%20are%20required%20to%20fully%20use%20the%20Search-UnifiedAuditLog%3F%20I%20couldn't%20find%20anything%20in%20documentation.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-148293%22%20slang%3D%22en-US%22%3ERe%3A%20Roles%20required%20for%20Search-UnifiedAuditLog%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-148293%22%20slang%3D%22en-US%22%3E%3CP%3EDon't%20assign%20the%20service%20account%20Exchange%20admin%20permissions.%20This%20is%20only%20for%20the%20configuration%20in%20Exchange%20Online.%20It%20can%20take%20up%20to%2030%20minutes%20if%20the%20assigned%20user%20can%20use%20this%20cmdlet%20or%20view%20audit%20logs%20in%20the%20Security%20%26amp%3B%20Compliance%20Center.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFor%20example%2C%20if%20you%20add%20the%20user%20to%20the%20View-Only%20Audit%20Logs%20role%20entry%2C%20then%20the%20cmdlets%20and%20Security%20%26amp%3B%20Compliance%20Center%20should%20be%20available.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAlso%20not%20the%20information%20from%20TechNet%3A%20If%20you%20want%20to%20programmatically%20download%20data%20from%20the%20Office%20365%20audit%20log%2C%20we%20recommend%20that%20you%20use%20the%20Office%20365%20Management%20Activity%20API%20instead%20of%20using%20the%20%3CSTRONG%3ESearch-UnifiedAuditLog%3C%2FSTRONG%3E%20cmdlet%20in%20a%20PowerShell%20script.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-148290%22%20slang%3D%22en-US%22%3ERe%3A%20Roles%20required%20for%20Search-UnifiedAuditLog%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-148290%22%20slang%3D%22en-US%22%3E%3CP%3EIndeed.%20I%20created%20a%20Security%20role%20for%20Audit%20Only%2C%20and%20did%20the%20same%20in%20Exchange%20Online.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EStill%20didn't%20get%20the%20cmdlet.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAfter%20adding%20the%20user%20to%20the%20Exchange%20Administrator%20role%2C%20it%20works%20as%20expected.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EMy%20only%20fear%20is%2C%20did%20I%20give%20too%20many%20permissions%20for%20simply%20an%20interface%20user%20that%20will%20export%20Powershell%20logs%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-148268%22%20slang%3D%22en-US%22%3ERe%3A%20Roles%20required%20for%20Search-UnifiedAuditLog%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-148268%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%20maybe%20not%20needed%20any%20longer%2C%20but%20below%20is%20a%20section%20from%20our%20documentation%20about%20this%20matter.%20I%20used%20it%20to%20build%20a%20Power%20BI%20reporting%20for%20SharePoint%20activity.%20Some%20bits%20could%20be%20outdated%2C%20but%20I%20think%20you%20should%20find%20most%20answers%20in%20the%20first%20reference%20link.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E-----------------------------------------------------------------------------------------------------------%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20service%20account%20would%20need%20sufficient%20access%20in%20order%20to%20be%20able%20to%20run%20the%26nbsp%3B%20SearchUnifiedAuditLog%20command.%20As%20per%20Microsoft's%20recommendations%20(%3CA%20href%3D%22https%3A%2F%2Fsupport.office.com%2Fen-us%2Farticle%2FSearch-the-audit-log-in-the-Office-365-Security-Compliance-Center-0d4d0f35-390b-4518-800e-0c7ec95e946c%3Fui%3Den-US%26amp%3Brs%3Den-US%26amp%3Bad%3DUS%26amp%3BfromAR%3D1%23ID0EABAAA%3DBefore_you_begin%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ereference%3C%2FA%3E%20%22Before%20you%20begin%22%20tab)%2C%20a%20specific%20group%20has%20been%20created%20and%20given%20the%20role%20needed%20for%20permissions.%20The%20service%20account%20was%20added%20to%20this%20Exchange%20Online%20group.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EImportant%3C%2FSTRONG%3E%3A%20the%20group%20needs%20to%20be%20created%20in%20Exchange%20Online%2C%20and%20not%20in%20the%20Security%20%26amp%3B%20Compliance%20Center%20Permissions%20because%20the%20cmdlet%20(SearchUnifiedAuditLog)%20belongs%20to%20Exchange%20Online.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EProcess%20used%20for%20setting%20up%20minimum%20access%20to%20the%20service%20account%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3COL%3E%0A%3CLI%3EGo%20to%20the%20Security%20and%20Compliance%20Center%20in%20via%20the%20Office%20365%20Admin%20Center%20or%20(%3CA%20href%3D%22https%3A%2F%2Fprotection.office.com%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fprotection.office.com%3C%2FA%3E)%3C%2FLI%3E%0A%3CLI%3EUnder%20the%20tab%20%22Permissions%22%2C%20follow%20the%20instructions%3A%20%22To%20assign%20permissions%20for%20archiving%2C%20auditing%2C%20and%20retention%20policies%2C%26nbsp%3Bgo%20to%20the%20Exchange%20admin%20center.%22%3C%2FLI%3E%0A%3CLI%3EClicking%20the%20link%20take%20you%20directly%20to%20the%20Role%20Groups%20editor%20for%20Exchange%20Online%3C%2FLI%3E%0A%3CLI%3EClick%20the%20plus%20to%20create%20new%20group.%3C%2FLI%3E%0A%3COL%3E%0A%3CLI%3EName%3A%20%5Baccount%20name%5D%3C%2FLI%3E%0A%3CLI%3EDescription%3A%20Custom%20group%20exclusive%20to%20the%20service%20account%20%5Baccount.name%5D%20to%20give%20minimum%20permissions%20for%20searching%20the%20unified%20audit%20log%20via%20PowerShell.%3C%2FLI%3E%0A%3CLI%3EAssigned%20Roles%3A%20View-Only%20Audit%20Logs%20(as%20per%20%3CA%20href%3D%22https%3A%2F%2Fsupport.office.com%2Fen-us%2Farticle%2FSearch-the-audit-log-in-the-Office-365-Security-Compliance-Center-0d4d0f35-390b-4518-800e-0c7ec95e946c%3Fui%3Den-US%26amp%3Brs%3Den-US%26amp%3Bad%3DUS%26amp%3BfromAR%3D1%23ID0EABAAA%3DBefore_you_begin%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3EMicrosoft%20recommendation%3C%2FA%3E)%3C%2FLI%3E%0A%3CLI%3EAdd%20user%20account%20to%20group%20%5Bx%40x.com%5D%3C%2FLI%3E%0A%3CLI%3EClick%20save%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3C%2FOL%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-148261%22%20slang%3D%22en-US%22%3ERe%3A%20Roles%20required%20for%20Search-UnifiedAuditLog%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-148261%22%20slang%3D%22en-US%22%3EHi%20Ruben%2C%3CBR%20%2F%3E%3CBR%20%2F%3ENo%20license%20is%20required%20but%20you%20need%20the%20%E2%80%9CExchange%20admin%E2%80%9D%20Office%20365%20admin%20role%20to%20get%20all%20cmdlets.%20It%20could%20be%20a%20cloud%20only%20or%20synchronized%20identity%20with%20the%20proper%20permissions.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-148237%22%20slang%3D%22en-US%22%3ERe%3A%20Roles%20required%20for%20Search-UnifiedAuditLog%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-148237%22%20slang%3D%22en-US%22%3EHi%20Dominik%2C%3CBR%20%2F%3E%3CBR%20%2F%3EThanks%2C%20that%20clarifies%20a%20lot.%3CBR%20%2F%3E%3CBR%20%2F%3EI'm%20still%20getting%20an%20error%20that%20the%20cmdlet%20isn't%20existing.%20Do%20I%20need%20to%20assign%20specific%20O365%20licenses%20for%20this%20to%20work%20to%20the%20user%3F%20(which%20would%20be%20a%20shame)%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-148225%22%20slang%3D%22en-US%22%3ERe%3A%20Roles%20required%20for%20Search-UnifiedAuditLog%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-148225%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYou%20can%20check%20it%20with%20this%20cmdlet%20in%20Exchange%20Online%20PowerShell%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EPS%20C%3A%5CUsers%5Cdomin%26gt%3B%20Get-ManagementRoleEntry%20%22*%5CSearch-UnifiedAuditLog%22%3C%2FP%3E%0A%3CP%3EName%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20Role%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20Parameters%3CBR%20%2F%3E----%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20----%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20----------%3CBR%20%2F%3ESearch-UnifiedAuditLog%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20View-Only%20Audit%20Logs%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%7BDebug%2C%20EndDate%2C%20ErrorAction%2C%20ErrorVariable...%7D%3CBR%20%2F%3ESearch-UnifiedAuditLog%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20Audit%20Logs%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%7BDebug%2C%20EndDate%2C%20ErrorAction%2C%20ErrorVariable...%7D%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYou%20can%20modifiy%20the%20permissions%20via%20RBAC%20and%20only%20grab%20the%20necessary%20cmdlet's%20that%20you%20will%20need.%20Both%20roles%20are%20the%20default%20roles%20in%20Exchange%20Online.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Ruben Demey
New Contributor

We're setting up a scheduled script to export logs through the Powershell cmd Search-UnifiedAuditLog.

 

However, since all our Administrators use MFA, we need to use a separate user with no MFA, but restricted permissions.

 

I noticed there's a role "Audit Logs" in the Security & Compliancy section, but those permissions don't seem adequate.

 

What roles are required to fully use the Search-UnifiedAuditLog? I couldn't find anything in documentation.

6 Replies
Solution

Hi,

 

You can check it with this cmdlet in Exchange Online PowerShell:

 

PS C:\Users\domin> Get-ManagementRoleEntry "*\Search-UnifiedAuditLog"

Name                           Role                      Parameters
----                           ----                      ----------
Search-UnifiedAuditLog         View-Only Audit Logs      {Debug, EndDate, ErrorAction, ErrorVariable...}
Search-UnifiedAuditLog         Audit Logs                {Debug, EndDate, ErrorAction, ErrorVariable...}

 

You can modifiy the permissions via RBAC and only grab the necessary cmdlet's that you will need. Both roles are the default roles in Exchange Online.

Hi Dominik,

Thanks, that clarifies a lot.

I'm still getting an error that the cmdlet isn't existing. Do I need to assign specific O365 licenses for this to work to the user? (which would be a shame)
Hi Ruben,

No license is required but you need the “Exchange admin” Office 365 admin role to get all cmdlets. It could be a cloud only or synchronized identity with the proper permissions.

Hi, maybe not needed any longer, but below is a section from our documentation about this matter. I used it to build a Power BI reporting for SharePoint activity. Some bits could be outdated, but I think you should find most answers in the first reference link.

 

-----------------------------------------------------------------------------------------------------------

 

The service account would need sufficient access in order to be able to run the  SearchUnifiedAuditLog command. As per Microsoft's recommendations (reference "Before you begin" tab), a specific group has been created and given the role needed for permissions. The service account was added to this Exchange Online group.

 

Important: the group needs to be created in Exchange Online, and not in the Security & Compliance Center Permissions because the cmdlet (SearchUnifiedAuditLog) belongs to Exchange Online.

 

Process used for setting up minimum access to the service account

 

  1. Go to the Security and Compliance Center in via the Office 365 Admin Center or (https://protection.office.com)
  2. Under the tab "Permissions", follow the instructions: "To assign permissions for archiving, auditing, and retention policies, go to the Exchange admin center."
  3. Clicking the link take you directly to the Role Groups editor for Exchange Online
  4. Click the plus to create new group.
    1. Name: [account name]
    2. Description: Custom group exclusive to the service account [account.name] to give minimum permissions for searching the unified audit log via PowerShell.
    3. Assigned Roles: View-Only Audit Logs (as per Microsoft recommendation)
    4. Add user account to group [x@x.com]
    5. Click save

Indeed. I created a Security role for Audit Only, and did the same in Exchange Online.

 

Still didn't get the cmdlet.

 

After adding the user to the Exchange Administrator role, it works as expected.

 

My only fear is, did I give too many permissions for simply an interface user that will export Powershell logs?

Don't assign the service account Exchange admin permissions. This is only for the configuration in Exchange Online. It can take up to 30 minutes if the assigned user can use this cmdlet or view audit logs in the Security & Compliance Center.

 

For example, if you add the user to the View-Only Audit Logs role entry, then the cmdlets and Security & Compliance Center should be available.

 

Also not the information from TechNet: If you want to programmatically download data from the Office 365 audit log, we recommend that you use the Office 365 Management Activity API instead of using the Search-UnifiedAuditLog cmdlet in a PowerShell script.

Related Conversations
Extentions Synchronization
Deleted in Discussions on
3 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
36 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
9 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies