Commands › Exchange Online

Get-UnifiedAuditLogRetentionPolicy

Exchange Online ExchangeOnlineManagement Get-*

For more information, see Security & Compliance PowerShell. Use the Get-UnifiedAuditLogRetentionPolicy cmdlet to view the properties of the audit log retention policies in the Microsoft Defender portal or the Microsoft Purview compliance portal.

Quick start script

# Get-UnifiedAuditLogRetentionPolicy — quick start (serv365.ai)
# 1. Connect (app-only shown; interactive: omit the certificate parameters)
Connect-ExchangeOnline -CertificateThumbprint $thumb -AppId $appId -Organization $org

# 2. Run and inspect
Get-UnifiedAuditLogRetentionPolicy | Format-List

# 3. Export for evidence / drift tracking
Get-UnifiedAuditLogRetentionPolicy | Export-Clixml .\UnifiedAuditLogRetentionPolicy-$(Get-Date -Format yyyyMMdd).xml

Syntax

Get-UnifiedAuditLogRetentionPolicy
 [-Operation <String>]
 [-RecordType <AuditRecordType>]
 [-RetentionDuration <UnifiedAuditLogRetentionDuration>]
 [-UserId <String>]
 [<CommonParameters>]

Parameters (4)

ParameterTypeRequiredWhat it controls
-Operation String The Operations parameter filters the results by the operations that are specified in the policy. For a list of the available values for this parameter, see [Audited...
-RecordType AuditRecordType The RecordType parameter filters the results by the record types that are defined in the policy. For details about the available values, see...
-RetentionDuration UnifiedAuditLogRetentionDuration The RetentionDuration parameter filters the policy results by the retention duration specified in the policy. Valid values are:
-UserId String The UserIds parameter filters the policy results by the ID of the users who are specified in the policy.

Reference facts derived from Microsoft documentation, © Microsoft, licensed CC BY 4.0; restructured with original guidance by serv365.ai.