Aug 06 2023 06:41 PM
Question about how Audit Logs work with mixed E5/E3 tenancies.
1) For events that are only supported by E5, for example MailItemsAccessed, does the Audit Log record such events only for those users that have E5 license? If that is the case, does that mean that the decision to log is made at the user-context level and not by the log; i.e., the log simply writes whatever it's told to? (I understand that MailItemsAccessed may be added to E3-level tenancies, but interested how the Log works.)
2) Following up on that, in a mixed E5/E3 tenancy, how does retention work. Does the Log selectively purge based on user license level or does the log support the highest of all levels in the tenancy (for example, if one user is E5, does the whole Log support E5 retention or just for that user)?
Thanks
Barry
Aug 08 2023 08:11 AM
Aug 08 2023 10:16 AM
Aug 09 2023 02:32 AM
Hi, @Barry Briggs,
Thank you for posting your question here. I understand you're looking for clarification on audit (premium) and whether or not the "E5" requirement is per user or a tenant-level requirement, to include the retention portion of the audit log.
For question 1, it is my understanding that you will only be able to collect logs that fall under the premium, E5 feature for users that are assigned the appropriate license. If user A is E5 licensed, they're logs should appear if you performed a tenant wide on a premium-only log, such as "Performed SharePoint Search" (SearchQueryInitiatedSharePoint), you would be able to see that User A had performed the action. User B, who does not have the premium license, would not appear in your search, even if they had performed the same action.
The information is the link details that the user must have the E5 license, as well as ensure the "Microsoft 365 Advanced Auditing" feature within the license is enable.
https://learn.microsoft.com/en-us/purview/audit-premium-setup#step-1-set-up-audit-premium-for-users
Fore question 2, regarding retention, the same as above applies here as well. Only users with an appropriate license may have their logs retained outside the default window.
Here are a couple Microsoft learn doc links that may help.
Manage audit log retention policies | Microsoft Learn
I hope this helps answer your questions, please do let me know if we were looking for different information.
Aug 09 2023 07:20 AM