A unified data governance solution that helps manage, protect, and discover data across your organization
No Microsoft service degradation is documented in the available material.
The supported checks are:
- Verify the setting in Exchange Online PowerShell, not Security & Compliance PowerShell:
Get-AdminAuditLogConfig | Format-List UnifiedAuditLogIngestionEnabledTruemeans audit log search is turned on. - Confirm the change history for auditing status:
In the returned records, check theSearch-UnifiedAuditLog -Operations Set-AdminAuditLogConfigAuditDataproperty forUnifiedAuditLogIngestionEnabledto see whether auditing was turned on or off, when it changed, which admin changed it, and the source IP address. - Confirm permissions. To search the audit log, the required roles are Audit Logs or View-Only Audit Logs in Microsoft Purview, and to access audit cmdlets, the same roles are required in Exchange admin permissions.
- If needed, re-enable unified audit log ingestion in Exchange Online PowerShell:
Set-AdminAuditLogConfig -UnifiedAuditLogIngestionEnabled $true
Important: UnifiedAuditLogIngestionEnabled always appears as False in Security & Compliance PowerShell, even when audit log search is actually enabled. Also, Set-AdminAuditLogConfig for this setting is not available there.
References: