Enable Microsoft 365 Audit Logging for Australian Businesses

▶ Watch the short explainer for this tip
Today's tech tip is about a fundamental security setting that often gets overlooked: turning on Microsoft 365 audit logging. This feature is your eyes and ears inside your Microsoft 365 environment, capturing crucial activity data. For any Australian small to medium business, understanding what's happening in your digital workspace is non-negotiable. Without proper audit logging, you're flying blind, especially when facing a cyber incident or needing to comply with data breach reporting requirements.
What is Microsoft 365 Audit Logging?
Microsoft 365 audit logging is a security setting that records user and admin activity across your Microsoft 365 services. Think of it as a comprehensive security camera for your cloud environment, capturing who did what, and when.
Why is Audit Logging Essential for Email Security?
You should change this setting because audit logs are indispensable for investigating email security incidents and potential breaches. If an account is compromised, the logs show what actions were taken, helping you understand the scope of the incident and respond effectively. Without these logs, pinpointing the source or impact of a breach is incredibly difficult, often impossible. You can book a complimentary 15-minute chat with Neil to discuss how an audit can help you secure your emails.
What are the Risks of Not Having Audit Logging?
If you leave audit logging as-is (disabled or with short retention), you'll have no forensic evidence to investigate a breach. This can lead to increased downtime, significant data loss, higher recovery costs, and potential regulatory fines under privacy laws like the Notifiable Data Breaches (NDB) scheme if you can't assess the breach's impact. Your cyber insurance might also require robust logging for claims.
How to Enable and Configure Microsoft 365 Audit Logging
Here are the verified steps to turn on Microsoft 365 audit logging and set up retention policies: 1. Sign in to purview.microsoft.com as a Global Administrator. 2. Open Solutions > Audit. 3. If you see the banner Start recording user and admin activity, select it to switch unified auditing on (on most tenants it is already on). 4. Open Audit > Audit retention policies and create a policy that keeps the audit log for at least one year for your admin and executive accounts.
Confirming It Works and What to Expect
To check it worked, run an Audit search for the last 24 hours filtered by activity UserLoggedIn — results should return, showing user login activity. Be aware that long retention beyond the default 180 days needs the right licence (E5 or the Audit add-on); nothing breaks for users, but you might hit licence limits for extended log storage. Neil can discuss the right licensing for your business in a complimentary 15-minute chat about an audit.
Important Disclaimer
These steps are accurate at the time of publishing, but email platform menus and defaults can change. If you're not confident, please don't change settings yourself, as incorrect modifications can disrupt email service. SecureMyEmail accepts no responsibility for loss or damage caused by changes made without our direct involvement.
Enabling and correctly configuring Microsoft 365 audit logging is a non-negotiable step for any Australian business serious about email security and incident response. It provides the necessary visibility to protect your data and meet compliance obligations.
Disclaimer: These steps are accurate at the time of publishing, but email platform menus and defaults can change. If you're not confident, please don't change settings yourself, as incorrect modifications can disrupt email service. SecureMyEmail accepts no responsibility for loss or damage caused by changes made without our direct involvement.
Frequently asked questions
- What is the benefit of Microsoft 365 audit logging for Australian small businesses?
- The primary benefit is forensic visibility into your Microsoft 365 environment, crucial for investigating security incidents or data breaches. This helps Australian small businesses understand what happened, who was involved, and what data might have been compromised, which is vital for regulatory compliance like the Notifiable Data Breaches (NDB) scheme.
- Do I need a special licence for extended audit log retention in Microsoft 365?
- Yes, for audit log retention beyond the default 180 days, you will typically need an Microsoft 365 E5 licence or an Audit add-on licence. Without the correct licensing, you won't be able to retain logs for longer periods, impacting your ability to conduct thorough post-breach investigations.
- How can I check if my Microsoft 365 audit logging is working correctly?
- You can verify that audit logging is working by running an Audit search in the Microsoft Purview portal for the last 24 hours, specifically filtering for 'UserLoggedIn' activity. If results are returned, it indicates that the logging is active and capturing user activities effectively.
- What happens if I don't turn on Microsoft 365 audit logging for my business?
- If you don't turn on Microsoft 365 audit logging, your business will lack crucial evidence to investigate any security breaches or suspicious activities. This can lead to increased recovery costs, potential regulatory non-compliance with privacy laws, and make it difficult to assess the scope of a data breach, potentially affecting cyber insurance claims.
Sources
Every reference below was link-checked when this article was published.
- 1.Notifiable Data Breaches schemeOffice of the Australian Information Commissioner
- 2.Data breach preparation and responseOffice of the Australian Information Commissioner
- 3.Microsoft Defender for Office 365 security recommendationsMicrosoft Learn
Want to know where your own tenant stands?
The audit answers these questions with a dated report on your actual settings — a few questions to start, under a minute.


