How to Diagnose OneDrive Sync Issues Using Microsoft 365 Audit Logs
Question details
Users need to identify why files are unexpectedly moving, duplicating, or deleting in OneDrive for Business despite no user activity being recorded in the Microsoft Purview audit logs.

- Product
- OneDrive for Business
- Device & OS
- not provided
- Scenario
- Investigating unauthorized or automated file changes affecting multiple users when standard Microsoft 365 auditing tools do not show manual user activity.
- Observed behavior
- Folders and files are being moved, duplicated, or deleted without explicit user input, likely caused by sync client conflicts, third-party software, or Windows components.
Ensure you have Microsoft 365 Administrator privileges, as only an admin can create the necessary support request to investigate advanced sync log anomalies.
Collect Diagnostic Logs and Contact Microsoft 365 Support
Since the activity is not logged in Microsoft Purview, the issue is likely client-side. You must collect local diagnostic logs and escalate the issue to Microsoft Support.
When multiple users are affected and Purview audit logs show no corresponding file activity, the root cause is typically local. A Windows component, a third-party application, or a corrupted OneDrive sync client might be triggering automated file movements or deletions. To identify the exact cause, advanced diagnostic logs are required by the Microsoft development team.
Run the diagnostic tool on the affected users' machines to collect local OneDrive sync logs. This captures the client-side background tasks that pushed changes to the cloud.
Use Fiddler or a similar web debugging proxy to capture a network trace while reproducing or monitoring the erratic sync behavior.
Go to the Microsoft 365 admin center and log in with an administrator account.
Navigate to 'Support' > 'Help & support', briefly describe the missing Purview log issue, and submit a support ticket. Attach the OneDrive and Fiddler logs to the request.

Try WPS Office for a Seamless Cloud Document Experience
While resolving complex Microsoft OneDrive sync issues with your IT team, consider using WPS Office to maintain productivity. WPS Office is a powerful, lightweight suite that works perfectly alongside various cloud solutions without heavy synchronization conflicts.

Frequently Asked Questions
Why would files move or delete in OneDrive without showing up in Purview audit logs?
If Purview audit logs are empty, the file actions were likely not performed manually via the web interface. Instead, a local background process, an automated third-party app, or a sync client error on a connected device triggered the changes locally and synced them to the cloud.
How do I easily generate OneDrive diagnostic logs in Windows?
You can generate local OneDrive diagnostic logs by pressing Win + R to open the Run dialog, typing '%localappdata%\Microsoft\OneDrive\OneDrive.exe /collect_logs', and pressing Enter. This will create a .zip file containing the logs on your desktop.
Can standard users submit Fiddler and OneDrive logs directly to Microsoft?
No. While standard users can generate and collect the logs on their individual devices, opening a formal support ticket with Microsoft 365 Support requires administrator credentials. Users must pass the logs to their IT admin.




