Microsoft Purview Audit (Premium) Capabilities
Which THREE capabilities are included in Microsoft Purview Audit (Premium)?
Quick Answer
The answer is longer retention of audit logs (up to 1 year), high-value events, and higher bandwidth. These three capabilities form the core of Microsoft Purview Audit (Premium), which extends beyond the standard 90-day retention to a full year for all audit records, captures critical events like mailbox access and elevated privilege usage, and provides increased API bandwidth for ingesting logs at scale. On the SC-900 exam, this question tests your ability to distinguish Audit (Premium) from adjacent security features; a common trap is confusing custom alerts (part of Microsoft 365 Defender) or trainable classifiers (part of data classification) with audit capabilities. To remember the three, think of the acronym LHB: Logs last longer, High-value events are captured, and Bandwidth is boosted.
⚠ Common exam trap
Watch out — candidates often confuse trainable classifiers or custom alert policies as audit-specific features, when in fact they belong to other compliance solutions like Information Protection or Defender, not Audit (Premium).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Access to high-value critical events
Microsoft Purview Audit (Premium) provides access to high-value critical events, such as when mailbox items are accessed or when administrative actions are performed on sensitive data. These events are not logged in Audit (Standard) and require Premium licensing to capture, enabling deeper forensic investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Trainable classifiers
Why it's wrong here
Trainable classifiers are for data classification.
- ✓
Access to high-value critical events
Why this is correct
Audit (Premium) logs high-value events like admin actions.
- ✗
Custom alert policies
Why it's wrong here
Custom alerts are part of Microsoft 365 Defender.
- ✓
Higher bandwidth for API access
Why this is correct
Premium provides increased API bandwidth.
- ✓
Longer retention of audit logs (up to 1 year)
Why this is correct
Audit (Premium) extends retention to 1 year.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization needs to audit all changes to sensitive files in SharePoint Online for at least 180 days. Which Microsoft Purview feature should be enabled?
easy- A.Microsoft Purview eDiscovery
- ✓ B.Microsoft Purview Audit (Premium)
- C.Microsoft Purview Data Loss Prevention
- D.Microsoft Purview Data Lifecycle Management
Why B: Microsoft Purview Audit (Premium) provides the extended retention of audit logs (up to 10 years) and the ability to search for high-value events such as changes to sensitive files. For a requirement of at least 180 days, Audit (Premium) is necessary because standard audit logs are retained for only 90 days. This feature logs all modifications to SharePoint Online files, including who changed what and when, meeting the auditing requirement.
Variation 2. Which TWO of the following are required to use Microsoft Purview Audit (Premium)?
hard- ✓ A.Unified audit log enabled in the Microsoft 365 Defender portal
- ✓ B.An E5 or A5 license for each user
- C.An Azure subscription for log storage
- D.Power BI Pro licenses for all users
- E.Microsoft Sentinel enabled
Why A: Microsoft Purview Audit (Premium) requires the unified audit log to be enabled in the Microsoft 365 Defender portal. This setting activates the underlying audit pipeline that captures and stores all audited events, which is a prerequisite for both standard and premium audit features. Without the unified audit log enabled, no audit records are generated, making premium capabilities like high-value events and longer retention unavailable. Additionally, an E5 or A5 license (or an equivalent add-on) is required for each user to access the advanced features and longer retention periods offered by Audit (Premium).
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.