How to Handle Split Large License Assignment Events in Microsoft Graph Audit Logs
Question details
Administrators observe that large Microsoft Graph audit events, such as bulk license assignments, are being split into multiple fragmentary records.

- Product
- Microsoft Graph API
- Device & OS
- not provided
- Scenario
- Retrieving and analyzing large-scale license assignment events through Microsoft Graph audit logs.
- Observed behavior
- Oversized audit events are split into multiple separate records containing sequence metadata, rather than returning a single complete payload.
Ensure you have the necessary administrative permissions in Microsoft Entra ID and access to query the Microsoft Graph API or Office 365 Management Activity API.
Reconstruct Fragmented Audit Records Using Sequence Metadata
Since Microsoft Graph may split oversized payloads, you can manually correlate and concatenate the fragments to reconstruct the full event.
While Microsoft documentation does not explicitly detail an internal per-record size limit, large-scale license assignment events often exceed these invisible thresholds. The most reliable workaround is to piece the fragments back together on the client side.
Use the Microsoft Graph API or Office 365 Management Activity API to retrieve the audit events for your desired timeframe.
Scan the returned JSON payload and look for matching `correlationId` values spread across multiple audit log entries.
Locate the sequence metadata within each related record to determine the exact chronological order of the fragments.
Sort the related records sequentially based on their metadata and concatenate the fragmented payload fields to reconstruct the original large event.
Parse the newly reconstructed JSON payload to ensure it is structurally valid and that no fragments are missing.
Simplify Your Document Workflow with WPS Office
While managing complex Microsoft 365 enterprise environments and API limits can be challenging for IT admins, providing a reliable daily office suite for your users doesn't have to be. WPS Office is a lightweight, highly compatible, and free alternative to Microsoft Office that easily handles all standard business documentation.
- 1. Download the installer: Visit the official WPS Office website and click the Free Download button.
- 2. Install the software: Run the downloaded executable file and follow the brief on-screen instructions to complete the setup.
- 3. Open existing files: Launch WPS Office and directly open your existing Microsoft Office documents without losing any formatting.

Frequently Asked Questions
Why are my Microsoft Graph audit logs split into multiple records?
Oversized audit events, such as assigning licenses to a massive number of users simultaneously, may exceed internal per-record size limits. Consequently, the system splits the payload into multiple fragments, each sharing the same correlation ID.
Is there a way to force Microsoft Graph to return a single audit record for large events?
Currently, no supported method or official documentation identifies a way to bypass this event-splitting behavior and force the API to return the complete payload in a single record. Reconstructing them manually is the only reliable workaround.
How can I get official confirmation on Microsoft Graph audit log size limits?
For product-level confirmation regarding maximum payload sizes and whether event-splitting is a permanent behavior, you should open a direct Microsoft support request or consult the latest Office 365 Management Activity API documentation.




