Here's the call nobody plans for: a client asks what an intruder saw in your email six months ago, and the honest answer is that the record is already gone.
Microsoft 365 keeps an audit log — who signed in, from where, what mailbox rules got created, what files moved. Most owners assume it's kept forever. It isn't. On standard licensing that history ages out at 180 days. On E5, sign-in, email and SharePoint activity is kept for a year.
Six months sounds generous until you think about how these things actually surface. A client calls in February about a message they received in September. An advisor leaves and their book turns up somewhere else. The question is always the same — what did they actually see? — and the answer may have already expired.
There's a second gap. The event that records which individual messages someone opened sits in the premium audit tier. Without it, your log can tell you an account was accessed from overseas and nothing at all about what was read.
Neither of these is expensive. They're a licensing choice and a retention setting, made before you need them — not during the week you're explaining a wire transfer to a client and a claim to your carrier.
Worth confirming what your tenant actually keeps, ahead of your next renewal.
Want the next one in your inbox?
One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.
Subscribe via email