Commands › Exchange Online

Write-AdminAuditLog

Exchange Online ExchangeOnlineManagement Write-*

Write a comment to the administrator audit log.

Quick start script

# Write-AdminAuditLog — quick start (serv365.ai)
# 1. Connect (app-only shown; interactive: omit the certificate parameters)
Connect-ExchangeOnline -CertificateThumbprint $thumb -AppId $appId -Organization $org

# 2. Run and inspect
Write-AdminAuditLog -Comment <String> | Format-List

# 3. Export for evidence / drift tracking
Write-AdminAuditLog | Export-Clixml .\AdminAuditLog-$(Get-Date -Format yyyyMMdd).xml

Syntax

Write-AdminAuditLog -Comment <String>
 [-Confirm]
 [-DomainController <Fqdn>]
 [-WhatIf]
 [<CommonParameters>]

Parameters (4)

ParameterTypeRequiredWhat it controls
-Comment String yes The Comment parameter specifies the comment to add to the administrator audit log. The maximum length is 500 characters.
-Confirm SwitchParameter The Confirm switch specifies whether to show or hide the confirmation prompt. How this switch affects the cmdlet depends on whether the cmdlet requires confirmation before proceeding.
-DomainController Fqdn This parameter is available only in on-premises Exchange.
-WhatIf SwitchParameter The WhatIf switch shows what the command does without making any changes. You don't need to specify a value with this switch.

Reference facts derived from Microsoft documentation, © Microsoft, licensed CC BY 4.0; restructured with original guidance by serv365.ai.