Courseiva

Audit User Activities with Purview Audit (Standard) — Export CSV, 90-Day Retention

A security administrator needs to audit all activities related to a specific user in Exchange Online, SharePoint Online, and Microsoft Entra ID for the past 90 days. They also need to export the audit log as a CSV file. Which Microsoft Purview solution provides this capability without additional licensing beyond Microsoft 365 E3?

Quick Answer

Microsoft Purview Audit Standard covers this requirement completely within existing Microsoft 365 E3 licensing, because it already provides 90 days of searchable activity logging across Exchange Online, SharePoint Online, and Microsoft Entra ID, plus the ability to export search results as a CSV file for offline analysis or reporting. The 90-day window and the specific set of covered services are exactly what E3 includes at the Standard audit tier — no add-on or license upgrade is required to search a specific user's activity across those three services within that timeframe. This matters for the exam because Audit Premium exists as a separate, higher tier with extended retention beyond 90 days and access to additional high-value event types, and a scenario that specifically stays within the 90-day boundary and the standard set of services is deliberately testing whether you know Standard already covers it — recognising that boundary is what prevents over-licensing in a real deployment as well as on the exam.

⚠ Common exam trap

Many candidates confuse 'auditing user activities' with 'searching for content' and pick Content Search or eDiscovery, not realizing that audit logs track actions (like 'User logged in' or 'Deleted file') while Content Search finds the actual data files.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Purview Audit (Standard)

Microsoft Purview Audit (Standard) is included with Microsoft 365 E3 and provides the ability to search and export audit logs for user activities across Exchange Online, SharePoint Online, and Microsoft Entra ID for up to 90 days. This meets the administrator's requirement without needing additional licensing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Purview Audit (Standard)

    Why this is correct

    Microsoft Purview Audit (Standard) retains Exchange, SharePoint and Microsoft Entra ID activity for 90 days and supports CSV export of search results. It is included with Microsoft 365 E3, so no add-on licence is needed, satisfying the no-additional-licensing constraint.

  • ✗

    Microsoft Purview Audit (Premium)

    Why it's wrong here

    Audit (Premium) requires add-on licensing beyond Microsoft 365 E3, so it fails the stated licensing constraint even though it delivers the 90-day retention and cross-workload search required. It is tempting because it is the natural fit when longer retention or higher-bandwidth API access is genuinely needed.

  • ✗

    Microsoft Purview eDiscovery (Standard)

    Why it's wrong here

    eDiscovery (Standard) is built for identifying, holding and exporting content for legal cases, and its search targets mailbox and site content rather than the unified audit log of user activity. It is tempting because it also searches Exchange and SharePoint and exports results, but it does not report Entra ID sign-in or admin events.

  • ✗

    Microsoft Purview Content Search

    Why it's wrong here

    Content Search queries mailbox, SharePoint and OneDrive content for items matching keywords, returning documents rather than audit records of user and admin activity. It is tempting because it spans the same workloads and supports CSV export, but it cannot report Entra ID events or the 90-day activity trail required.

About these practice questions

This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on MS-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company needs to audit user activities in Microsoft 365 for compliance. Which tool should they use?

easy
  • A.Microsoft Defender XDR
  • B.Microsoft Sentinel
  • ✓ C.Microsoft Purview Audit (Premium)
  • D.Microsoft Intune

Why C: Microsoft Purview Audit (Premium) is specifically designed to retain and search audit logs for user and admin activities across Microsoft 365 services, meeting compliance and forensic investigation needs. It provides high-bandwidth access to the Office 365 Audit Log, supports custom retention policies (up to 10 years), and offers intelligent insights such as high-value events and access to critical events like MailItemsAccessed. This makes it the correct tool for auditing user activities for compliance.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.