logo
search
Compliance Problems

Fix Unable to Enable Audit Logging in Microsoft 365 Security and Compliance

Ayan MasoodAyan Masood Oct 10, 2026 869 views

Question details

The user is trying to activate audit logging but the interface fails to respond when interacting with the activation banner.

How to Fix Unable to Enable Audit Logging in Microsoft 365
Product
Microsoft 365 Security and Compliance Center
Device & OS
not provided
Scenario
Attempting to activate audit logging to track user and administrator activities across Microsoft 365 services.
Observed behavior
Clicking the audit logging banner in the Security and Compliance Center does nothing, and the feature remains disabled.
Before you start

Ensure you are logged into the Microsoft 365 portal with an account that possesses Global Administrator privileges before attempting to modify compliance settings.

Solution 1Recommended

Verify Required Administrator Permissions

Audit logging can only be enabled if your Microsoft 365 account is explicitly assigned to specific compliance or management role groups.

Even Global Administrators sometimes need to ensure their account is properly recognized within the Compliance Center roles. Without the correct Exchange Online or Compliance permissions, the activation banner script may silently fail.

1
Access the Admin Center

Sign in to the Microsoft 365 admin center using your administrator credentials.

2
Navigate to Role Management

Go to the 'Roles' section in the left navigation pane and select 'Role assignments'.

3
Check Role Group Memberships

Verify that your account is a member of either the 'Compliance Management' or 'Organization Management' role group.

4
Assign Permissions

If you lack these permissions, add your account to the required role group and wait for the permissions to sync before clicking the audit logging banner again.

Verify Required Administrator Permissions
Permission Synchronization Delay: It may take up to 24 hours for newly assigned role permissions to fully propagate across the Microsoft 365 compliance portal.
Free Microsoft Office alternative

Looking for a Hassle-Free, Lightweight Office Suite?

While Microsoft 365 provides robust enterprise administration tools like audit logging, managing it can sometimes be overly complex for standard document creation. If you want a fast, reliable, and completely free alternative for your daily document productivity, WPS Office is an excellent choice. It bypasses complex administrative setups while offering seamless compatibility with all major document formats.

  1. 1. Download the Installer: Visit the official WPS Office website and download the free installation package for your operating system.
  2. 2. Install the Software: Run the installer and follow the quick on-screen instructions to set up WPS Office on your computer.
  3. 3. Open Your Office Files: Launch WPS Office and directly open your existing Microsoft Office documents without any conversion or complex configuration.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats.Lightweight design that installs quickly and runs smoothly on older devices.No complex admin center setups required for standard offline and online editing.Free to use with a familiar, easy-to-navigate tabbed user interface.
microsoft office alternative - wps office

Frequently Asked Questions

How long does it take for audit logging to start working after it is enabled?

Once successfully enabled, it can take up to 60 minutes or longer for the preparation process to complete and for audit events to begin appearing in your unified audit log search results.

Can I enable Microsoft 365 audit logging using PowerShell instead of the admin interface?

Yes. You can connect to Exchange Online PowerShell and run the command 'Set-AdminAuditLogConfig -UnifiedAuditLogIngestionEnabled $true' to force enable the auditing feature manually.

Why is the audit logging banner still showing after I clicked it?

If the banner remains visible, it usually indicates that the activation command did not process successfully. This is typically due to a lack of specific Exchange Online permissions or temporary backend synchronization delays.