Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Purview complianceMedium

A legal department needs to ensure that all audit logs generated by Microsoft 365 services, particularly those related to administrator activities and eDiscovery searches, are retained for a minimum of 7 years for regulatory compliance. They also require the ability to search these logs for investigative purposes. Which Microsoft Purview feature should be configured?

  1. ACommunication Compliance policies
  2. BRetention policies for user-generated content
  3. CAudit log retention policies
  4. DData Loss Prevention (DLP) policies
Show answer & explanation

Correct answer: C. Audit log retention policies

Audit log retention policies in Microsoft Purview are specifically designed to specify how long audit logs for various Microsoft 365 services are retained, including administrator activities and eDiscovery searches, and they support searching these logs.

Why the other options are wrong

  • A. Communication Compliance policies monitor communications, unrelated to audit log retention.
  • B. Retention policies for user-generated content apply to emails, documents, etc., not system audit logs.
  • D. DLP policies prevent data loss, unrelated to audit log retention.

Audit Log Retention Policies

Microsoft Purview audit log retention policies allow organizations to define how long audit logs generated by various Microsoft 365 services are retained, beyond the default retention periods, to meet specific compliance or legal requirements.

  • Manages retention for Microsoft 365 audit logs.
  • Extends default retention periods.
  • Supports searchability of retained logs.

Memory trick: Audit logs for 7 years, banish all compliance fears.

More Implement and manage Microsoft Purview compliance questions