Network, logging and monitoring

How long are audit logs maintained (30 / 90 / 1 year)?

Retention determines whether an investigation can establish when the intrusion began. If the window is shorter than the dwell time, the answer is that nobody knows.

Partly verifiable from your tenant

What the carrier is actually asking

The carrier is asking for a retention period, usually offering thirty days, ninety days, or a year. It is asking about the period for which logs are actually available, not the period stated in a policy.

Why it is underwritten

Intrusions are frequently discovered months after they began. If logs cover thirty days, the investigation cannot determine the initial access vector or the scope of data accessed, which forces the most conservative notification position and increases the loss. Carriers have paid for that outcome often enough to ask directly.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Retention settings are directly readable in the cloud, and they are frequently at defaults that nobody chose.

PlatformWhere the setting livesWhat has to be true
AzureLog Analytics workspace retention and archive settingsRetention set deliberately, with archive tiers for the longer tail where cost matters
AzureActivity log diagnostic setting destination retentionBeyond the ninety-day portal default, since the portal window cannot be extended
Entra IDSign-in and audit log export destination retentionExported and retained, since portal retention is measured in weeks
Microsoft 365Audit log retention policyRetention configured per record type, since the default varies by licence and is often shorter than assumed
NetworkFirewall and flow log retentionFlow logs retained long enough to reconstruct network activity. Attested for on-premises
Different sources, different windows

Most estates have a mix: endpoint telemetry for six months, sign-in logs for thirty days, cloud activity for ninety, network flows for a week. The investigative window is the shortest one covering the source you need, not the longest one you can quote.

What a defensible yes requires

  • Retention is stated per source, with the shortest one acknowledged.
  • Security-relevant sources are retained for at least a year where cost allows.
  • Retention matches what the incident response plan assumes.
  • Archive tiers are used to make longer retention affordable rather than abandoning it.
  • Any regulatory retention requirement is met separately and explicitly.

How this answer goes wrong

The answer is a year, based on the endpoint tooling, while identity sign-in logs are at their portal default of thirty days. Identity logs are the ones an investigation needs first, and they are the shortest window in the estate.

Frequently asked

Is 90 days enough?

It is the common minimum and it is often shorter than dwell time. A year for identity and control plane logs is a materially stronger position.

Is retention expensive?

Hot retention is; archive tiers are much cheaper and remain searchable with a delay. Cost is rarely a real barrier to a year of security logs.

What about regulatory requirements?

Some regimes set their own minimums that exceed what security investigation needs. Meet both and state them separately.

What should we retain longest?

Identity, privileged activity, and cloud control plane. They answer the largest number of investigative questions per gigabyte.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture