A user reports a project folder is gone. Your first question is not "can we get it back?" but "who deleted it, and when?" The answer is usually somewhere in SharePoint - in the Recycle Bin if the deletion is recent, or in the Microsoft Purview audit log if more time has passed or the bin has been cleared.
This guide covers all four methods in order of effort, from the quickest check (Recycle Bin) to the most thorough investigation (audit log export).
Step 1: Check the First-Stage Recycle Bin
The Recycle Bin is your first stop. It shows a Deleted By column alongside the item name, original location, and deletion timestamp. As long as the item is still in the bin (within the 93-day window and not yet manually emptied by a site owner), you can identify who performed the deletion in seconds.
- Navigate to the SharePoint site where the content was deleted.
- Click the cog icon and choose Site contents, then click Recycle Bin in the left navigation. Alternatively, append
/_layouts/15/RecycleBin.aspxto the site URL to go there directly. - Locate the missing file or folder. The Deleted By column shows the user account that performed the deletion, and the Time Deleted column shows exactly when.
- Click the item name to see its full original path under Original Location.
For investigations spanning many sites (for example, a suspected malicious deletion or a migration incident), the Recycle Bin is the wrong starting point, because bins are scoped per site collection and the SharePoint interface has no view that searches them all at once. Use the Purview audit log in Step 3 to establish which sites were touched, then filter those sites' bins with ShareMaster's Recycle Master by deleted-by user, item name, original path, or date range.
Step 2: Check the Second-Stage (Site Collection) Recycle Bin
If a site owner has already emptied the first-stage bin, or if the item was deleted by a site-level automated process, the file moves to the second-stage Recycle Bin. Only site collection administrators can see this stage.
Navigate there directly using this URL pattern:
/sites/<your-site>/_layouts/15/AdminRecycleBin.aspx
The second-stage bin shows the same Deleted By column as the first stage. SharePoint preserves the original deletion timestamp: the date shown is when the item was first deleted, not when it was moved from stage one to stage two.
If you find the item here and want to restore it, see the bulk restore guide if multiple items need to come back at once. If the folder the item lived in was deleted as well, SharePoint re-creates that folder in its original location when you restore the item.
See how Recycle Master filters a site's deletions by user and dateStep 3: Search the Microsoft Purview Unified Audit Log
Once an item has been permanently deleted (second-stage bin emptied, or 93 days have expired), the Recycle Bin no longer holds it. The Microsoft Purview audit log is now the only source for the Deleted By information.
- Sign in to the Microsoft Purview portal at
purview.microsoft.comwith an account that holds the Audit Logs or View-Only Audit Logs role. - Open the Audit solution (under View all solutions if the card is not shown) to reach the Search page.
- Set the date and time range (UTC) to cover the suspected deletion window. A single search can cover at most 180 days.
- Under Activities - friendly names, choose Deleted file (found under the file and folder activities).
- Under File, folder, or site, enter the URL of the relevant SharePoint site (a trailing
*works as a wildcard) to narrow results. Leave it blank to search the entire tenant. - Select Search. The search runs as a job that keeps going if you close the browser; narrow searches finish quickly, but Microsoft notes broad searches on large tenants can take up to 48 hours.
- Open the finished job. Each result shows the Date, User (the account that deleted), Activity and Item. Select any row to see the full event detail, including the file's original URL path.
The audit log entry URL path is especially useful when a user says "a whole folder disappeared": search for all deletions matching a folder path within a given time window to see every file that was removed and by whom.
Step 4: Export the Audit Log for Multi-Site or Legal Review
For incidents spanning multiple sites, or when you need to pass the deletion record to legal, HR, or compliance teams, an Excel export is the most practical format.
From the Purview audit search results, select Export. This downloads a CSV with the raw event data: user, timestamp, operation, item and the full JSON event payload. An export holds up to 50,000 rows on Audit (Standard), so split a large incident into shorter date ranges. See how to export the SharePoint audit log to Excel for the full process.
Audit Log Retention by Microsoft 365 Plan
| Licence of the person who deleted the file | Default retention of SharePoint audit records | Extended option |
|---|---|---|
| Business Basic, Business Standard, Business Premium, E3 and other non-E5 licences | 180 days (records created before 17 October 2023 were kept for 90 days) | Adding the E5 Compliance or E5 eDiscovery and Audit add-on brings the user up to one year |
| Office 365 E5 or Microsoft 365 E5 | 1 year | Up to 10 years with the 10-year audit log retention add-on |
Retention follows the licence of the user who performed the action, not the licence of the person searching, so a deletion by a guest or a non-E5 user is kept for 180 days even in an E5 tenant.
If the deletion occurred outside your audit log retention window and the item is no longer in the Recycling Bin, the deletion record is not available through standard SharePoint tooling. Microsoft 365 Backup (if your tenant subscribes) may hold a snapshot of the content from before the deletion.
When the Audit Log Shows No Results
Two common causes:
- Audit logging was not active at the time of deletion. Audit log search is on by default for Microsoft 365 enterprise organisations, but it can be turned off. Running
Get-AdminAuditLogConfig | Format-List UnifiedAuditLogIngestionEnabledin Exchange Online PowerShell shows whether it is on now. If auditing was off when the deletion occurred, there is no event to retrieve. - The deletion was performed by a service account or application. Deletions via Microsoft Graph API or SharePoint REST API are attributed to the service principal or app identity, not a named user. The event still appears in the audit log, but the "user" field shows an application display name rather than a person's name. Filter by the date range and file path to find these events.
Frequently Asked Questions
How long does SharePoint keep a record of who deleted a file?
The Recycle Bin shows the Deleted By field for items still in the bin (up to 93 days from deletion). The Microsoft Purview audit log keeps SharePoint deletion events for 180 days when the person who deleted the file has a Business, E3 or other non-E5 licence, one year when they have E5, and up to 10 years with the 10-year audit log retention add-on on top of E5.
Can a site owner see who deleted files in SharePoint?
Yes. A site owner can open the first-stage Recycle Bin and see the Deleted By column for any item still in the bin. To see items that have been emptied from the first stage, the owner must also be a site collection administrator, which grants access to the second-stage bin. For items beyond the 93-day window, the owner needs access to the Microsoft Purview audit log.
What if the SharePoint audit log shows no deletion results?
Audit log search must have been turned on at the time of the deletion for events to be recorded. It is on by default for Microsoft 365 enterprise organisations, but if it was off, there is no record of the event in Purview. The Recycle Bin is still the fallback source if the item is within its 93-day retention window.
Finding out who deleted a file is usually the smaller half of the problem. Getting it back is the other half, and the clock matters more than the culprit does: recovering deleted SharePoint files covers the recovery path, and searching the recycle bin explains what the search box actually matches, which is not what most people assume.
Two things worth knowing before you trial anything for this. Recycle Master reads one site collection at a time, so if you do not know which site the file was in, the audit log is the faster route. And a trial licence cannot restore from the recycle bin at all, which is a deliberate anti-abuse limit rather than a fault, so a trial tests the workflow and not the outcome. PowerShell or buy covers the rest of the decision.