Three methods exist for pulling SharePoint Online audit activity out of Microsoft 365 and into a file you can analyse. Here is how they compare at a glance:
| Method | Access Required | Max Date Range | Multi-Site | Export Format | Cost |
|---|---|---|---|---|---|
| Native admin center export | Audit Logs role | 180 days (Standard) / 1 year (E5) | Yes | CSV | Included |
| PowerShell (Search-UnifiedAuditLog) | Audit Logs role | 180 days (Standard) / 1 year (E5) | Yes | CSV (via Export-Csv) | Included |
| Microsoft Purview Compliance portal | Compliance Admin role | 180 days to 10 years (licence dependent) | Yes | CSV | E5 or add-on licence required beyond 180 days |
How SharePoint Online Audit Logging Works
SharePoint Online activity is captured in the Microsoft 365 unified audit log, the same log that records events from Exchange Online, Microsoft Teams, OneDrive for Business, and other M365 services. Every time a user or administrator takes an action that SharePoint is configured to log - viewing a file, downloading a document, changing permissions, deleting an item, accessing a site - an event record is written to the audit log with the user's identity, timestamp, site URL, item path, and activity type.
Audit logging is enabled by default for all Microsoft 365 Business and Enterprise subscriptions. You do not need to turn it on. What varies between plans is how long those records are retained: 180 days for Audit (Standard), which covers every user without an E5 licence, one year for the SharePoint records of E5 users, and up to ten years with an audit log retention policy and the 10-Year Audit Log Retention add-on.
The data source is the same regardless of which export method you use. The differences between methods lie in scope, filtering, volume limits, and the format of what you get out.
Option 1: Native Audit Log Export from the Microsoft 365 Admin Center
What it covers
The Microsoft 365 compliance portal (compliance.microsoft.com) provides a built-in audit search UI at Audit > Search. Select an activity type, a date range, and optionally a user or site URL, then run the search and export the results to CSV directly from the results page.
This is the right starting point for one-off investigations: "What happened to this document on this date?" or "Which user accessed this library last week?" The interface is interactive and requires no scripting knowledge.
Limitations
- 150-result UI preview. The audit search UI shows up to 150 results in the preview pane. The export file contains the full result set, but you must export to see all records beyond the first 150.
- 50,000-row export limit. A single search export is capped at 50,000 records. For large tenants where high-volume activities (file views, sync operations) are included, a single day's activity across all sites can easily exceed this limit.
- Manual date range selection. Each export covers one search query. Retrieving 90 days of activity across a large tenant requires multiple exports and manual stitching in Excel.
- No scheduling. The native UI does not support automated or scheduled exports. Every export is a manual action.
Option 2: PowerShell - Search-UnifiedAuditLog
When it works well
The Search-UnifiedAuditLog cmdlet from the Exchange Online PowerShell module gives you programmatic access to the same audit data. You can loop through date ranges, filter by RecordType, and pipe output to Export-Csv to build larger datasets than the UI allows.
PowerShell is the right choice when you need to automate a regular extract, build a custom report combining SharePoint events with data from another source, or retrieve more than 50,000 records by splitting date ranges into smaller windows. PnP PowerShell provides additional SharePoint-specific cmdlets that complement the unified audit log access.
Limitations
- 5,000-result ceiling per call. A single call to
Search-UnifiedAuditLogreturns a maximum of 5,000 results. To retrieve more, you must loop through the date range in smaller windows or use theSessionIdandSessionCommandparameters to page through large result sets. - Throttling. The API applies throttling under sustained high-volume queries. Scripts that loop too aggressively will encounter 429 responses and need retry logic with exponential back-off.
- Scripting knowledge required. This approach is not suitable for administrators without PowerShell experience. Setup, session management, and error handling add complexity.
- JSON-in-AuditData field. The detail of each event is returned as a JSON string in the AuditData property, which must be parsed separately to extract fields like site URL, file name, or specific operation details.
Option 3: Microsoft Purview Compliance Portal
Microsoft Purview Audit (available inside the compliance portal) goes beyond the basic audit search to offer retention up to ten years (with the appropriate add-on licence) and access to a broader range of events including high-value security events not available in standard audit.
Purview Audit is the right tool for regulated industries that require long audit trails, or for security teams conducting forensic investigations that need events from months or years ago. For a picture of who can reach what today, rather than what happened in the past, a purpose-built report tool handles this better.
The export format from Purview is CSV, identical to the native admin center export. It requires Compliance Administrator or higher in Entra ID and, for retention beyond 180 days, a Microsoft 365 E5 licence or the E5 eDiscovery and Audit add-on (ten years also needs the 10-Year Audit Log Retention add-on).
See what Report Master exportsWhere ShareMaster Report Master fits
Report Master is the SharePoint-specific reporting module in ShareMaster, and it is not an audit log export: it cannot tell you who opened, changed or deleted a file. It answers the other half of most audit requests, the current state, in Excel rather than CSV.
Key differences from the raw audit log approaches:
- Excel output with named columns. No JSON parsing or CSV cleanup required. The exported workbook has readable column headings and data already shaped for pivot tables or direct sharing with stakeholders.
- Current state, not events. The Security Matrix lists, for one site, the permissions each user, SharePoint group and Microsoft 365 group holds on the site, its lists, libraries, files and items. Storage, recycle bin and version trimming reports show where space goes.
- Tenant-wide where it says so. The Tenant Storage Metric, Tenant Recycling Bin Report and Bulk Version Trimming Report walk every site in one run; the Security Matrix covers one site per run.
- No Purview licence required. Report Master reads SharePoint directly and is free on the Community licence. The Security Matrix needs site collection admin and the tenant reports need SharePoint Administrator.
For the full list of available report types, see the guide to exporting SharePoint permissions to Excel.
Decision: Which Method for Which Scenario
| Scenario | Best Option |
|---|---|
| One-off investigation: who deleted a specific file? | Native admin center audit search |
| Recurring weekly or monthly activity report for management | PowerShell (scheduled Search-UnifiedAuditLog extract) |
| Large-scale extract: 30 days of all activity across all sites | PowerShell (Search-UnifiedAuditLog with date-range loops) |
| Forensic investigation requiring events from 6-12 months ago | Microsoft Purview (requires E5 or Purview Audit Premium) |
| Compliance audit: current permissions on each site in scope | Report Master (Security Matrix, one site per run) |
| Security operations team needing real-time alert data | Microsoft Purview with alert policies |
| Admin with no scripting skills, needs a quick CSV of last week's file deletions | Native admin center export |
| Regular activity export to Excel without PowerShell scripting | Native admin center export (run manually, open the CSV in Excel) |
Frequently Asked Questions
How long does SharePoint Online keep audit logs?
SharePoint Online audit log retention depends on your Microsoft 365 plan. Audit (Standard), which covers every user without an E5 licence and guests, keeps records for 180 days. E5, A5 and G5 users, or users with the E5 eDiscovery and Audit add-on, keep SharePoint records for one year by default. Ten years needs an audit log retention policy plus the 10-Year Audit Log Retention add-on licence. You cannot retrieve events older than your tenant's retention period regardless of which export method you use.
What admin role do I need to export the SharePoint audit log?
Exporting from the Microsoft 365 compliance center or via Search-UnifiedAuditLog requires the Audit Logs or Compliance Administrator role in Entra ID. Global Administrators also have access. SharePoint Administrator alone is not sufficient for unified audit log access.
Can I export SharePoint audit logs to Excel?
Yes. All three methods produce data that opens in Excel. The native export, PowerShell, and Purview produce CSV files. ShareMaster's Report Master does not read the audit log; its Excel reports cover current permissions and storage instead.
Does the SharePoint audit log track who deleted a file?
Yes. SharePoint Online logs a FileDeleted event whenever a user or administrator deletes a file. The event includes the user's UPN, the file name and path, the site URL, and a timestamp. This event is captured even if the file is subsequently restored from the recycle bin.
For a detailed walkthrough of running your first audit log export, see how to export the SharePoint audit log to Excel.
Try ShareMaster free for 14 days