| title | Audit log search in the Microsoft Defender portal | |||
|---|---|---|---|---|
| f1.keywords |
|
|||
| author | chrisda | |||
| ms.author | chrisda | |||
| manager | bagol | |||
| audience | ITPro | |||
| ms.topic | how-to | |||
| ms.collection |
|
|||
| ms.localizationpriority | medium | |||
| ms.assetid | ||||
| ms.custom |
|
|||
| description | Admins can use the Audit page in the Microsoft Defender portal to search the unified audit log for user and admin actions in the organization. | |||
| ms.service | defender-office-365 | |||
| search.appverid | met150 | |||
| ms.date | 10/9/2023 | |||
| appliesto |
|
[!INCLUDE MDO Trial banner]
In all organizations with cloud mailboxes, the unified audit log records supported user and admin operations. Audit records for these events are searchable by security ops, IT admins, insider risk teams, and compliance and legal investigators in the organization. This capability provides visibility into the activities performed across your Microsoft 365 organization.
Tip
Audit log search in Microsoft Defender portal is identical to audit log search in the Microsoft Purview portal at https://purview.microsoft.com/auditlogsearch.
- You need to be assigned permissions before you can do the procedures in this article. You have the following options:
-
Exchange Online permissions: Membership in the Organization Management or Compliance Management role groups.
-
Microsoft Entra permissions: Membership in the Global Administrator* or Compliance Administrator roles gives users the required permissions and permissions for other features in Microsoft 365.
[!IMPORTANT] * Microsoft strongly advocates for the principle of least privilege. Assigning accounts only the minimum permissions necessary to perform their tasks helps reduce security risks and strengthens your organization's overall protection. Global Administrator is a highly privileged role that you should limit to emergency scenarios or when you can't use a different role.
-
In the Microsoft Defender portal at https://security.microsoft.com, go to Audit. Or, to go directly to the Audit page, use https://security.microsoft.com/auditlogsearch.
On the Audit page, create the audit log search. For instructions, see the following articles: