How to Retrieve Microsoft 365 Audit Logs for Up to 365 Days
Question details
Administrators need to retrieve Microsoft audit logs beyond the standard 90-day window, up to 365 days, for compliance, security tracking, and long-term data retention.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Administering Microsoft 365 compliance and security tracking.
- Observed behavior
- The standard audit log search interface typically displays only up to 90 days of data, requiring alternative methods to access older logs.
Ensure you have the necessary administrator permissions (such as View-Only Audit Logs or Audit Logs roles) and verify that your Microsoft 365 licensing tier supports a 365-day audit log retention period (e.g., Microsoft 365 E5 or a compliance add-on).
Use Exchange Online PowerShell to Retrieve Extended Audit Logs
The most reliable method to access extended audit logs is by running the Search-UnifiedAuditLog cmdlet via Exchange Online PowerShell, which allows querying custom date ranges up to one year.
The standard Microsoft Purview compliance portal often restricts the graphical search interface to 90 or 180 days, depending on your configuration. To pull data for up to a full year, administrators can leverage PowerShell commands.
Note that retrieving long-term audit data can take significant processing time. It is highly recommended to export these results directly into a CSV file for easier analysis.
Open your PowerShell terminal as an administrator and run the command 'Connect-ExchangeOnline' to securely authenticate with your Microsoft 365 admin credentials.
Execute the search command using the specific date range you need. For example: Search-UnifiedAuditLog -StartDate '01/01/2023' -EndDate '12/31/2023'.
To save the results for long-term retention and review, pipe the output to a CSV file. Run: Search-UnifiedAuditLog -StartDate '01/01/2023' -EndDate '12/31/2023' | Export-Csv -Path 'C:\AuditLogs.csv' -NoTypeInformation.

Analyze Exported Audit Logs with WPS Office
While retrieving Microsoft 365 audit logs requires administrative access to PowerShell, analyzing the resulting large CSV files is much easier with a robust spreadsheet tool. WPS Office offers a free, lightweight, and highly compatible alternative to Microsoft Office for processing complex datasets.
- 1. Download and Install WPS Office: Visit the official WPS Office website to download and install the free suite on your computer.
- 2. Open WPS Spreadsheets: Launch the application and select WPS Spreadsheets from the main dashboard.
- 3. Open Your Audit Log CSV: Click 'File', select 'Open', and browse to the location where you exported your Microsoft 365 AuditLogs.csv file.
- 4. Filter and Analyze: Use the Data tab to apply filters, sort by date or user, and analyze your compliance records effortlessly.

Frequently Asked Questions
Why can I only see 90 days of audit logs in Microsoft 365?
By default, the standard Microsoft 365 Audit (Standard) only retains audit records for 90 to 180 days, depending on your foundational subscription (like E3). To see up to 365 days, you need an Audit (Premium) license typically included in E5 plans.
Do I need a special license for 1-year audit log retention?
Yes, Microsoft requires an Audit (Premium) license (found in Microsoft 365 E5, Compliance add-ons, or G5 licenses) to retain and search audit logs for up to 365 days, or even up to 10 years with additional add-ons.
Can I search for specific activities using the PowerShell cmdlet?
Yes, you can narrow down your search using the -RecordType, -Operations, or -UserIds parameters alongside the -StartDate and -EndDate parameters to pinpoint specific activities or users.
How do I view the exported CSV file properly?
You can open the exported CSV file using any spreadsheet software, such as WPS Spreadsheets or Microsoft Excel, which will automatically organize the comma-separated data into readable rows and columns for filtering.




