How to Review Microsoft 365 Audit Logs for ISO 27001 Compliance
Question details
The organization needs to define and implement a risk-based process to periodically review Microsoft 365 administrator and user activity logs to maintain ISO 27001 compliance.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Establishing user and administrator log review procedures for ISO 27001 compliance audits.
- Observed behavior
- Administrative and user activities need to be systematically monitored, searched, and reviewed according to the organization's risk assessment and security controls.
Ensure you have the Global Reader or Compliance Administrator roles assigned in your Microsoft 365 tenant, and verify that audit logging is turned on in the Microsoft Purview compliance portal.
Search the Microsoft 365 Unified Audit Log
The primary method to review administrative and user activities across Microsoft 365 services for compliance auditing.
The unified audit log allows compliance officers to view user administration, site management, configuration changes, and other security-relevant events essential for ISO 27001 certification.
Log in to the Microsoft Purview compliance portal using your authorized administrator credentials.
On the left navigation pane, select 'Audit' to open the unified audit log search tool.
Specify the required date range and select the specific user or administrator activities that align with your ISO 27001 controls, then click 'Search'.
Once the search query completes, click 'Export' to download the log results as a CSV file for compliance evidence and offline review.

Review Exchange Mailbox Activity via PowerShell
Use the Search-MailboxAuditLog cmdlet to specifically audit Exchange Online mailbox access and modification activities.
Looking for a Lightweight, Compliant Office Alternative?
While securing your Microsoft 365 environment is critical for enterprise compliance, individual users and teams may need a secure, cost-effective alternative for daily document creation. WPS Office provides excellent compatibility with Microsoft Office formats in a highly secure, lightweight suite.
- 1. Download WPS Office: Visit the official WPS website and click the download button for your operating system.
- 2. Install the Software: Run the downloaded installer file and follow the on-screen instructions to complete the setup.
- 3. Open and Edit Documents: Launch WPS Office to instantly open and edit your Office documents without any formatting loss.

Frequently Asked Questions
How long does Microsoft 365 retain audit logs?
By default, Microsoft 365 retains audit logs for 180 days. Organizations with E5 licenses or Audit (Premium) can retain logs for up to one year, with options to extend retention policies up to 10 years to meet specific ISO 27001 requirements.
Who has permissions to access the unified audit log?
To search the unified audit log, users must be assigned the 'View-Only Audit Logs' or 'Audit Logs' role in Exchange Online. These are typically granted to Compliance Administrators and Global Administrators.
Is mailbox auditing enabled by default in Exchange Online?
Yes, Microsoft enables mailbox audit logging by default for all organizations. However, it is highly recommended to verify your configuration during a compliance review to ensure the specific actions you need tracked are being actively logged.




