Commands › Exchange Online
Get-UnifiedAuditLogRetentionPolicy
For more information, see Security & Compliance PowerShell. Use the Get-UnifiedAuditLogRetentionPolicy cmdlet to view the properties of the audit log retention policies in the Microsoft Defender portal or the Microsoft Purview compliance portal.
Quick start script
# Get-UnifiedAuditLogRetentionPolicy — quick start (serv365.ai)
# 1. Connect (app-only shown; interactive: omit the certificate parameters)
Connect-ExchangeOnline -CertificateThumbprint $thumb -AppId $appId -Organization $org
# 2. Run and inspect
Get-UnifiedAuditLogRetentionPolicy | Format-List
# 3. Export for evidence / drift tracking
Get-UnifiedAuditLogRetentionPolicy | Export-Clixml .\UnifiedAuditLogRetentionPolicy-$(Get-Date -Format yyyyMMdd).xml
Syntax
Get-UnifiedAuditLogRetentionPolicy
[-Operation <String>]
[-RecordType <AuditRecordType>]
[-RetentionDuration <UnifiedAuditLogRetentionDuration>]
[-UserId <String>]
[<CommonParameters>]
Parameters (4)
Reference facts derived from Microsoft documentation, © Microsoft, licensed CC BY 4.0; restructured with original guidance by serv365.ai.