Audit log: retention durations, roles, and search limits

Verdict: Default retention is one year and cannot be edited. Custom policies override it for shorter windows. 10-year retention needs a per-user add-on on E5. View-Only Audit Logs searches without config rights. Search jobs cap at 180 days.

CriterionDefault policyCustom policy10-Year add-onView-Only Audit Logs role
What it controlsRetention duration for Entra, Exchange, OneDrive, SharePoint recordsRetention duration for a scoped set of users or locationsRetention ceiling per user, on top of Audit (Premium) E5Permission to run audit log searches
Default durationOne yearSet by the admin, e.g. 6 months10 yearsN/A, a role assignment
Can it be edited or scopedNo, fixed and cannot be modifiedYes, takes priority over the default policyApplies per assigned user, not tenant-wideGrants search only, no config rights
Choose whenNo action needed, this is the baselineA group needs shorter or longer retention than one yearSpecific users must keep records a full decadeAn analyst must search but not change retention settings

Rules

Traps