How long are audit logs maintained (30 / 90 / 1 year)?
Retention determines whether an investigation can establish when the intrusion began. If the window is shorter than the dwell time, the answer is that nobody knows.
What the carrier is actually asking
The carrier is asking for a retention period, usually offering thirty days, ninety days, or a year. It is asking about the period for which logs are actually available, not the period stated in a policy.
Why it is underwritten
Intrusions are frequently discovered months after they began. If logs cover thirty days, the investigation cannot determine the initial access vector or the scope of data accessed, which forces the most conservative notification position and increases the loss. Carriers have paid for that outcome often enough to ask directly.
Where the answer lives in Microsoft 365, Entra ID, and Azure
Retention settings are directly readable in the cloud, and they are frequently at defaults that nobody chose.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Azure | Log Analytics workspace retention and archive settings | Retention set deliberately, with archive tiers for the longer tail where cost matters |
| Azure | Activity log diagnostic setting destination retention | Beyond the ninety-day portal default, since the portal window cannot be extended |
| Entra ID | Sign-in and audit log export destination retention | Exported and retained, since portal retention is measured in weeks |
| Microsoft 365 | Audit log retention policy | Retention configured per record type, since the default varies by licence and is often shorter than assumed |
| Network | Firewall and flow log retention | Flow logs retained long enough to reconstruct network activity. Attested for on-premises |
Most estates have a mix: endpoint telemetry for six months, sign-in logs for thirty days, cloud activity for ninety, network flows for a week. The investigative window is the shortest one covering the source you need, not the longest one you can quote.
What a defensible yes requires
- Retention is stated per source, with the shortest one acknowledged.
- Security-relevant sources are retained for at least a year where cost allows.
- Retention matches what the incident response plan assumes.
- Archive tiers are used to make longer retention affordable rather than abandoning it.
- Any regulatory retention requirement is met separately and explicitly.
How this answer goes wrong
The answer is a year, based on the endpoint tooling, while identity sign-in logs are at their portal default of thirty days. Identity logs are the ones an investigation needs first, and they are the shortest window in the estate.
Frequently asked
Is 90 days enough?
It is the common minimum and it is often shorter than dwell time. A year for identity and control plane logs is a materially stronger position.
Is retention expensive?
Hot retention is; archive tiers are much cheaper and remain searchable with a delay. Cost is rarely a real barrier to a year of security logs.
What about regulatory requirements?
Some regimes set their own minimums that exceed what security investigation needs. Meet both and state them separately.
What should we retain longest?
Identity, privileged activity, and cloud control plane. They answer the largest number of investigative questions per gigabyte.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture