Glossary

What is an audit trail?

Also known as: audit log, activity log

Published
Definition

An audit trail is the chronological, tamper-evident record of who did what, when, and to which resource across a system. In Microsoft 365 governance it captures configuration changes, permission grants, sharing events, and administrative actions so an organization can reconstruct events and prove control to auditors. A complete audit trail is the evidence layer that regulations such as DORA and NIS2 expect, connecting policy on paper to what actually happened.

An audit trail answers a deceptively simple question after the fact: who did what, when, and to which resource. In Microsoft 365 governance it records configuration changes, permission grants, sharing events, and administrative actions so that an organization can reconstruct what happened and prove it.

The audit trail is the evidence layer that regulation expects. Frameworks such as DORA and NIS2 do not just require good configuration, they require you to demonstrate control over time. A complete, retained, tamper-evident trail is what connects a policy written on paper to what actually occurred inside the tenant.

Related terms

Trusted by

MAPALBAMVille de LuxembourgWACKERGRUNDFOSAMGENOsramLufthansaThyssenKruppSunrisePattern