{"id":15910,"date":"2026-02-12T07:00:56","date_gmt":"2026-02-12T06:00:56","guid":{"rendered":"https:\/\/coreit.se\/okategoriserad\/how-do-audit-logs-work-in-microsoft-365"},"modified":"2026-03-26T07:15:27","modified_gmt":"2026-03-26T06:15:27","slug":"how-do-audit-logs-work-in-microsoft-365","status":"publish","type":"post","link":"https:\/\/coreit.se\/en\/faq\/how-do-audit-logs-work-in-microsoft-365","title":{"rendered":"How do audit logs work in Microsoft 365?"},"content":{"rendered":"\n<div class=\"custom-ai-wrapper\">\n  <h2 class=\"ai-question\">How do audit logs work in Microsoft 365?<\/h2>\n\n  <div class=\"ai-summary\">\n    <p>Audit logs in Microsoft 365 record and track activities in your organization&#8217;s cloud environment. They include user logins, file access, document changes, administrative actions, and security events. Administrators can search, filter, and analyze logs to detect unusual behavior, support compliance, and conduct security audits.  <\/p>\n  <\/div>\n\n  <div class=\"ai-columns\">\n    <div class=\"ai-background\">\n      <h2>Background and overview<\/h2>\n      <p>Audit logs are central to security and compliance. Microsoft 365 offers comprehensive activity logging, providing visibility into how users and administrators interact with systems and data. <\/p>\n\n      <h3>Activity logging<\/h3>\n      <p>Microsoft 365 logs events such as logins, file changes, shares, email activity, and administrative actions, providing a complete picture of user behavior.<\/p>\n\n      <h3>Search and filtering<\/h3>\n      <p>Administrators can filter logs by user, date, event type and service to quickly find relevant information.<\/p>\n\n      <h3>Analysis and reporting<\/h3>\n      <p>Logs can be analyzed to detect unusual or suspicious activities and generate reports for audit and security review.<\/p>\n\n      <h3>Integration with security services<\/h3>\n      <p>Audit logs can be integrated with Microsoft Purview, Sentinel and other security tools for centralized monitoring and alarm management.<\/p>\n\n      <h3>Compliance and legal evidence<\/h3>\n      <p>Logs support compliance with standards and laws, such as the GDPR and ISO, and can be used as documentation for audits or legal requirements.<\/p>\n\n      <h3>Long-term storage<\/h3>\n      <p>Microsoft 365 offers the ability to retain logs for longer periods, which is important for historical analysis and compliance.<\/p>\n\n      <h3>Alerting and notifications<\/h3>\n      <p>Administrators can set alerts for unusual activities, enabling a quick response to security incidents.<\/p>\n    <\/div>\n\n    <div class=\"ai-right\">\n      <div class=\"ai-details\">\n        <h2>Key features for audit logs<\/h2>\n        <ul>\n          <li><strong>Activity logging:<\/strong> records user and administrator events.<\/li>\n          <li><strong>Search and filtering:<\/strong> Quick access to relevant information.<\/li>\n          <li><strong>Analysis and reporting:<\/strong> Identifies anomalies and supports audit.<\/li>\n          <li><strong>Integration:<\/strong> Connection to security solutions such as Sentinel and Purview.<\/li>\n          <li><strong>Compliance:<\/strong> Supports legal requirements and standards like GDPR.<\/li>\n          <li><strong>Alerts:<\/strong> Sends alerts for unusual or suspicious activities.<\/li>\n        <\/ul>\n      <\/div>\n\n      <div class=\"ai-faq\">\n        <h2>Related questions<\/h2>\n\n        <div>\n          <h3>What is logged in Microsoft 365 audit logs?<\/h3>\n          <p>Logins, file changes, shares, email activity and administrative actions are continuously logged.<\/p>\n        <\/div>\n\n        <div>\n          <h3>How to search audit logs?<\/h3>\n          <p>Administrators can filter by user, date, event type and service to find specific activity.<\/p>\n        <\/div>\n\n        <div>\n          <h3>Can audit logs be integrated with security tools?<\/h3>\n          <p>Yes, logs can be linked to Microsoft Sentinel, Purview and other monitoring systems for alerts and analysis.<\/p>\n        <\/div>\n\n        <div>\n          <h3>How are audit logs used in compliance?<\/h3>\n          <p>They are used to document activities, support audits and meet legal requirements such as GDPR.<\/p>\n        <\/div>\n\n        <div>\n          <h3>Can you receive notifications from audit logs?<\/h3>\n          <p>Yes, administrators can configure alerting to receive alerts for unusual or suspicious activities.<\/p>\n        <\/div>\n\n      <\/div>\n    <\/div>\n  <\/div>\n<\/div>\n\n<script type=\"application\/ld+json\">\n{\n  \"@context\": \"https:\/\/schema.org\",\n  \"@type\": \"FAQPage\",\n  \"mainEntity\": [\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Vad loggas i Microsoft 365 audit-loggar?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Inloggningar, fil\u00e4ndringar, delningar, e-postaktivitet och administrativa \u00e5tg\u00e4rder loggas kontinuerligt.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Hur s\u00f6ker man i audit-loggar?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Administrat\u00f6rer kan filtrera efter anv\u00e4ndare, datum, h\u00e4ndelsetyp och tj\u00e4nst f\u00f6r att hitta specifik aktivitet.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Kan audit-loggar integreras med s\u00e4kerhetsverktyg?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Ja, loggar kan kopplas till Microsoft Sentinel, Purview och andra \u00f6vervakningssystem f\u00f6r larm och analys.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Hur anv\u00e4nds audit-loggar vid efterlevnad?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"De anv\u00e4nds f\u00f6r att dokumentera aktiviteter, st\u00f6dja revisioner och uppfylla juridiska krav som GDPR.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Kan man f\u00e5 aviseringar fr\u00e5n audit-loggar?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Ja, administrat\u00f6rer kan konfigurera alerting f\u00f6r att f\u00e5 varningar vid ovanliga eller misst\u00e4nkta aktiviteter.\"\n      }\n    }\n  ]\n}\n<\/script>\n\n","protected":false},"excerpt":{"rendered":"<p>How do audit logs work in Microsoft 365? Audit logs in Microsoft 365 record and track activities in your organization&#8217;s cloud environment. They include user logins, file access, document changes, administrative actions, and security events. Administrators can search, filter, and analyze logs to detect unusual behavior, support compliance, and conduct security audits. Background and overview [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":15862,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[178,181],"tags":[],"class_list":["post-15910","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-faq","category-microsoft-365"],"acf":[],"_links":{"self":[{"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/posts\/15910","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/comments?post=15910"}],"version-history":[{"count":0,"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/posts\/15910\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/media\/15862"}],"wp:attachment":[{"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/media?parent=15910"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/categories?post=15910"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/tags?post=15910"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}