{"id":269,"date":"2026-08-22T12:21:35","date_gmt":"2026-08-22T19:21:35","guid":{"rendered":"https:\/\/gozera.ai\/blog\/?p=269"},"modified":"2026-08-22T12:21:35","modified_gmt":"2026-08-22T19:21:35","slug":"copilot-audit-logs","status":"publish","type":"post","link":"https:\/\/gozera.ai\/blog\/copilot-audit-logs\/","title":{"rendered":"Copilot Audit Logs: Where to Find and Read Them"},"content":{"rendered":"<\/p>\n<p>Copilot audit events land in Microsoft Purview\u2019s Unified Audit Log (UAL) by default, and prompt\/response content becomes visible separately through Purview DSPM for AI once your team enables that capture layer. If you administer Microsoft 365 Copilot, GitHub Copilot, or Security Copilot at a law firm, accounting practice, or consulting shop, this is where your investigation starts, and where most gaps get discovered too late.<\/p>\n<p>Before anything else, run two checks:<\/p>\n<ul>\n<li>Confirm Audit (Standard) is capturing Copilot activity in your tenant and hasn\u2019t been quietly disabled.<\/li>\n<li>Verify you hold the Purview Audit or DSPM role needed to actually view <code>CopilotInteraction<\/code> records, not just the license to run Copilot itself.<\/li>\n<\/ul>\n<p>Retention on many Business plans defaults to 180 days, and non-Microsoft AI auditing runs on a <a href=\"https:\/\/learn.microsoft.com\/en-us\/purview\/audit-copilot\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">pay-as-you-go billing model<\/a>. For SIEM-bound teams, Microsoft Sentinel is the common downstream target once records are exportable.<\/p>\n<p><strong>Pro Tip:<\/strong> <em>Generate one throwaway Copilot prompt right now, then search Purview for that user and the last hour. If <code>AccessedResources<\/code>, <code>Messages<\/code>, and <code>AppHost<\/code> all show up, your logging pipeline works. If any field is missing, you have a configuration problem, not a Copilot problem.<\/em><\/p>\n<h2 id=\"key-takeaways\" tabindex=\"-1\">Key Takeaways<\/h2>\n<p>Copilot audit visibility depends on enabling the right Purview and DSPM configurations before an incident forces the question, not after.<\/p>\n<table>\n<thead>\n<tr>\n<th>Point<\/th>\n<th>Details<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Check Purview access first<\/td>\n<td>Confirm Audit Standard is capturing <code>CopilotInteraction<\/code> events and that your role can view them.<\/td>\n<\/tr>\n<tr>\n<td>Prioritize <code>AccessedResources<\/code><\/td>\n<td>This field proves exactly what files or sites Copilot touched during an interaction.<\/td>\n<\/tr>\n<tr>\n<td>Enable DSPM for prompt content<\/td>\n<td>Standard audit rows don\u2019t include prompt\/response text without separate DSPM or eDiscovery setup.<\/td>\n<\/tr>\n<tr>\n<td>Map fields into your SIEM<\/td>\n<td>Route <code>AppHost<\/code>, <code>ClientRegion<\/code>, and <code>AccessedResources<\/code> into Sentinel for correlation and alerting.<\/td>\n<\/tr>\n<tr>\n<td>Get a governance baseline from Gozera<\/td>\n<td>An audit sprint pairs logging configuration with adoption telemetry to show real Copilot ROI.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 id=\"table-of-contents\" tabindex=\"-1\">Table of Contents<\/h2>\n<ul>\n<li><a href=\"#where-copilot-audit-logs-live-and-how-to-get-in\">Where Copilot Audit Logs Live and How to Get In<\/a><\/li>\n<li><a href=\"#what-the-copilot-audit-schema-actually-tells-you\">What the Copilot Audit Schema Actually Tells You<\/a><\/li>\n<li><a href=\"#running-targeted-searches-and-pulling-exports\">Running Targeted Searches and Pulling Exports<\/a><\/li>\n<li><a href=\"#retention-windows-sensitivity-labels-and-privacy-boundaries\">Retention Windows, Sensitivity Labels, and Privacy Boundaries<\/a><\/li>\n<li><a href=\"#feeding-copilot-logs-into-a-siem\">Feeding Copilot Logs Into a SIEM<\/a><\/li>\n<li><a href=\"#what-copilot-audit-logs-wont-show-you\">What Copilot Audit Logs Won\u2019t Show You<\/a><\/li>\n<li><a href=\"#a-short-playbook-for-a-suspected-data-exposure\">A Short Playbook for a Suspected Data Exposure<\/a><\/li>\n<li><a href=\"#turn-audit-visibility-into-measurable-copilot-roi\">Turn Audit Visibility Into Measurable Copilot ROI<\/a><\/li>\n<li><a href=\"#sources\">Sources<\/a><\/li>\n<\/ul>\n<h2 id=\"where-copilot-audit-logs-live-and-how-to-get-in\" tabindex=\"-1\">Where Copilot Audit Logs Live and How to Get In<\/h2>\n<p>Four surfaces matter, and most admins only know about one of them.<\/p>\n<ol>\n<li><strong>Microsoft Purview Audit (UAL)<\/strong> captures <code>CopilotInteraction<\/code> events for Microsoft 365 Copilot automatically once Audit Standard is on.<\/li>\n<li><strong>Purview DSPM for AI<\/strong> surfaces the actual prompt and response text, but only after you configure it separately. Purview UAL alone shows that a conversation happened, not what was said.<\/li>\n<li><strong>Security Copilot<\/strong> requires an explicit opt-in in owner settings before Microsoft Purview even receives its audit data. Miss this toggle, and you have zero visibility, not partial visibility.<\/li>\n<li><strong>Copilot Studio<\/strong> and <strong>GitHub Enterprise\u2019s audit log<\/strong> run on their own tracks. Copilot Studio activity flows into Purview audit, while GitHub Copilot events live in the GitHub organization or enterprise audit log, searchable with <code>action:copilot<\/code> filters.<\/li>\n<\/ol>\n<p>To read your first record: sign into the <a href=\"https:\/\/purview.microsoft.com\/audit\/auditlogsearch\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">Purview audit search portal<\/a>, open Audit, filter activities to \u201cInteracted with Copilot,\u201d set a date range, and run the search.<\/p>\n<table>\n<thead>\n<tr>\n<th>Role<\/th>\n<th>What it unlocks<\/th>\n<th>Typically granted by<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Compliance Administrator<\/td>\n<td>Full Purview Audit search access<\/td>\n<td>Global admin<\/td>\n<\/tr>\n<tr>\n<td>View-Only Audit Logs<\/td>\n<td>Read-only search results<\/td>\n<td>Compliance admin<\/td>\n<\/tr>\n<tr>\n<td>DSPM for AI Data Access<\/td>\n<td>Prompt\/response visibility<\/td>\n<td>Purview admin<\/td>\n<\/tr>\n<tr>\n<td>eDiscovery Manager<\/td>\n<td>Legal hold and mailbox-backed content retrieval<\/td>\n<td>Global admin<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Two things trip up mid-market IT teams every time: Security Copilot\u2019s toggle sits buried in owner settings and is off by default, and non-Microsoft AI auditing (things like third-party AI plugins) bills on a pay-as-you-go basis with its own retention clock, separate from standard Copilot events.<\/p>\n<h2 id=\"what-the-copilot-audit-schema-actually-tells-you\" tabindex=\"-1\">What the Copilot Audit Schema Actually Tells You<\/h2>\n<p>A single <code>CopilotInteraction<\/code> record carries more forensic value than most admins realize, but only if you know which fields to read. The Copilot audit schema documents dozens of properties; a handful do the heavy lifting.<\/p>\n<table>\n<thead>\n<tr>\n<th>Field<\/th>\n<th>What it shows<\/th>\n<th>Investigative value<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><code>AccessedResources<\/code><\/td>\n<td>Files\/sites Copilot pulled from, with <code>SensitivityLabelId<\/code> and action type<\/td>\n<td>Proves exactly what data was exposed or read<\/td>\n<\/tr>\n<tr>\n<td><code>Messages<\/code> \/ <code>MessageIds<\/code><\/td>\n<td>Prompt and response identifiers<\/td>\n<td>Links a conversation thread to its content (via DSPM)<\/td>\n<\/tr>\n<tr>\n<td><code>AppHost<\/code><\/td>\n<td>Surface Copilot ran in (Word, Teams, admin console)<\/td>\n<td>Flags unexpected usage contexts<\/td>\n<\/tr>\n<tr>\n<td><code>ThreadId<\/code><\/td>\n<td>Groups related interactions<\/td>\n<td>Reconstructs a full conversation sequence<\/td>\n<\/tr>\n<tr>\n<td><code>ModelTransparencyDetails<\/code><\/td>\n<td>Which model\/version handled the request<\/td>\n<td>Useful for model-behavior audits<\/td>\n<\/tr>\n<tr>\n<td><code>ClientIP<\/code> \/ <code>ClientRegion<\/code><\/td>\n<td>Origin of the request<\/td>\n<td>Detects anomalous geography or shared credentials<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>A sanitized event looks something like this:<\/p>\n<pre><code>{\n  &quot;Operation&quot;: &quot;CopilotInteraction&quot;,\n  &quot;AppHost&quot;: &quot;Word&quot;,\n  &quot;ThreadId&quot;: &quot;b3f1...&quot;,\n  &quot;AccessedResources&quot;: [\n    {&quot;Name&quot;: &quot;Q4_Client_Contract.docx&quot;, &quot;SensitivityLabelId&quot;: &quot;highly-confidential&quot;, &quot;Action&quot;: &quot;Read&quot;}\n  ],\n  &quot;Messages&quot;: [{&quot;MessageId&quot;: &quot;msg-0091&quot;, &quot;IsPrompt&quot;: true}]\n}\n<\/code><\/pre>\n<p>You can also query this schema directly through the Office 365 Management API or Microsoft Graph, useful when you need programmatic pulls rather than one-off UI searches. The <code>AccessedResources<\/code> array is worth reading closely: it separates content Copilot used to \u201cground\u201d its answer from content the user typed directly, a distinction that matters when you\u2019re deciding whether a data leak originated from Copilot\u2019s retrieval or from the person prompting it.<\/p>\n<blockquote>\n<p><code>AccessedResources<\/code> is the single highest-value field in the entire schema, because it names the exact file or site Copilot touched, alongside its sensitivity label. That\u2019s the difference between suspecting a data exposure and proving one.<\/p>\n<\/blockquote>\n<p>Watch for <code>XPIADetected<\/code> and <code>PolicyDetails<\/code> too. Both flag potential prompt injection or policy-blocked actions during triage, often before a human reviewer would catch the pattern manually.<\/p>\n<h2 id=\"running-targeted-searches-and-pulling-exports\" tabindex=\"-1\">Running Targeted Searches and Pulling Exports<\/h2>\n<p>Start in the Purview UI: Audit \u2192 Workload filter set to Copilot \u2192 narrow by user and date range \u2192 run search.<\/p>\n<p>For repeatable or scripted work, use PowerShell against the Office 365 Management API or Graph endpoints, including the Copilot usage report APIs for adoption metrics alongside security queries.<\/p>\n<ul>\n<li>Search by user + Copilot workload for individual incident review.<\/li>\n<li>Filter by <code>SensitivityLabelId<\/code> inside <code>AccessedResources<\/code> to surface high-risk file touches.<\/li>\n<li>Export results to CSV directly from the Purview search results pane for evidence packages or audit committee reports.<\/li>\n<li>Route prompt\/response retrieval through DSPM or eDiscovery when the standard audit row isn\u2019t enough.<\/li>\n<\/ul>\n<p>A <a href=\"https:\/\/blog.ciaops.com\/2026\/06\/11\/copilot-audit-logs-in-purview\/\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">community-documented smoke test<\/a> that works well: pick one user, generate a single interaction, search a narrow window, and confirm <code>AccessedResources<\/code>, <code>Messages<\/code>, and <code>AppHost<\/code> all populate. If they don\u2019t, fix the pipeline before you trust it for a real investigation.<\/p>\n<p><strong>Pro Tip:<\/strong> <em>Run your smoke test against a test account, not a partner\u2019s mailbox. Real client data has no business in a configuration check.<\/em><\/p>\n<p>Roughly 180 days is the default retention window on many Business plans before records age out, which is exactly why export-and-archive habits matter more than most teams assume.<\/p>\n<h2 id=\"retention-windows-sensitivity-labels-and-privacy-boundaries\" tabindex=\"-1\">Retention Windows, Sensitivity Labels, and Privacy Boundaries<\/h2>\n<p>Audit Standard keeps Copilot and AI application events for a default 180 days on many Business plans, while E5 tenants often carry longer or configurable retention. Non-Microsoft AI auditing runs on separate pay-as-you-go billing, with its own retention behavior for <code>AIAppInteraction<\/code> and <code>ConnectedAIAppInteraction<\/code> events, distinct from standard <code>CopilotInteraction<\/code> records.<\/p>\n<ul>\n<li>Sensitivity labels travel with <code>AccessedResources<\/code>, so a blocked or restricted access attempt shows up in <code>PolicyDetails<\/code> and <code>Status<\/code>.<\/li>\n<li>Prompt and response content lives in a hidden folder inside the user\u2019s Exchange Online mailbox, and <a href=\"https:\/\/www.aguidetocloud.com\/blog\/auditing-microsoft-365-copilot\/\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">retrieving it properly requires Purview eDiscovery permissions<\/a>, not just DSPM viewing rights.<\/li>\n<li>Legal hold on a mailbox preserves that hidden content the same way it preserves email, which matters the moment litigation or a regulatory inquiry touches a client matter.<\/li>\n<\/ul>\n<p><strong>Pro Tip:<\/strong> <em>If your firm handles privileged client communications, set legal hold policies before an incident, not during one. Retroactive holds can\u2019t recover what already aged out.<\/em><\/p>\n<h2 id=\"feeding-copilot-logs-into-a-siem\" tabindex=\"-1\">Feeding Copilot Logs Into a SIEM<\/h2>\n<p>Once logging is confirmed, the real value comes from correlation, not isolated searches. Purview export flows, Office Management API pulls, or Graph reports can feed a blob store that Microsoft Sentinel or another SIEM ingests, a pattern Microsoft\u2019s own guidance describes for Security Copilot specifically.<\/p>\n<table>\n<thead>\n<tr>\n<th>SIEM field<\/th>\n<th>Copilot schema source<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><code>event.time<\/code><\/td>\n<td><code>CreationTime<\/code><\/td>\n<\/tr>\n<tr>\n<td><code>host.application<\/code><\/td>\n<td><code>AppHost<\/code><\/td>\n<\/tr>\n<tr>\n<td><code>asset.resource<\/code><\/td>\n<td><code>AccessedResources[].SiteUrl<\/code><\/td>\n<\/tr>\n<tr>\n<td><code>user.id<\/code><\/td>\n<td><code>UserId<\/code><\/td>\n<\/tr>\n<tr>\n<td><code>geo.region<\/code><\/td>\n<td><code>ClientRegion<\/code><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Alert rules worth building early:<\/p>\n<ol>\n<li>Copilot accessed a resource carrying a \u201chighly confidential\u201d sensitivity label.<\/li>\n<li><code>AppHost<\/code> shows Copilot running somewhere unexpected, like an admin console rather than Word or Teams.<\/li>\n<li><code>Messages<\/code> flags <code>XPIADetected<\/code> or <code>JailbreakDetected<\/code> as true.<\/li>\n<li>A single user\u2019s <code>AccessedResources<\/code> count spikes well past their normal baseline.<\/li>\n<\/ol>\n<p>Tune thresholds against your firm\u2019s actual usage pattern before going live. A litigation team pulling dozens of documents a day looks nothing like a bookkeeper doing the same, and treating both the same way just buries you in false positives.<\/p>\n<h2 id=\"what-copilot-audit-logs-wont-show-you\" tabindex=\"-1\">What Copilot Audit Logs Won\u2019t Show You<\/h2>\n<p>Standard audit rows don\u2019t include prompt or response text. That lives behind DSPM or eDiscovery, not in the row you first pull. Third-party or unmanaged AI tools that resemble Copilot may also bill and log differently, and won\u2019t necessarily surface in a default Copilot search.<\/p>\n<p>GitHub Copilot\u2019s local IDE plugin is the biggest blind spot. Prompts typed directly into VS Code often never reach the enterprise audit log without additional endpoint telemetry, meaning a developer could paste proprietary code into a local Copilot session and leave no organizational trace.<\/p>\n<ul>\n<li>Instrument endpoint telemetry where local Copilot usage is a realistic exposure path.<\/li>\n<li>Enable DSPM capture before you need it, not after an incident forces the question.<\/li>\n<li>Correlate <code>CopilotInteraction<\/code> events against DLP, proxy, and endpoint logs rather than treating any single log as complete on its own.<\/li>\n<\/ul>\n<p>When <code>AccessedResources<\/code> points to an internal URL with no clear owner, or <code>MessageIds<\/code> exist but content is gated behind permissions you don\u2019t hold, escalate rather than guess. Ambiguous entries are exactly where governance teams either catch something real or waste a week chasing a dead end.<\/p>\n<h2 id=\"a-short-playbook-for-a-suspected-data-exposure\" tabindex=\"-1\">A Short Playbook for a Suspected Data Exposure<\/h2>\n<p>Sample queries worth keeping on hand: search <code>CopilotInteraction<\/code> by user across a 24-hour window, filter by <code>SensitivityLabelId<\/code> set to your highest classification, and pull all events where <code>AppHost<\/code> doesn\u2019t match expected applications.<\/p>\n<ol>\n<li><strong>Triage.<\/strong> Validate the event and pull the full <code>AccessedResources<\/code> list.<\/li>\n<li><strong>Contain.<\/strong> Revoke access where warranted and snapshot the evidence before anything changes.<\/li>\n<li><strong>Investigate.<\/strong> Cross-reference with DLP and endpoint logs to build the full picture.<\/li>\n<li><strong>Remediate.<\/strong> Correct permissions and notify affected clients or partners if required.<\/li>\n<li><strong>Review.<\/strong> Document what happened and adjust policy so it doesn\u2019t repeat.<\/li>\n<\/ol>\n<table>\n<thead>\n<tr>\n<th>Escalation trigger<\/th>\n<th>Threshold<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Sensitivity label<\/td>\n<td>Highest classification touched<\/td>\n<\/tr>\n<tr>\n<td>Resource count<\/td>\n<td>Unusually high <code>AccessedResources<\/code> volume for that user<\/td>\n<\/tr>\n<tr>\n<td>Security flag<\/td>\n<td><code>JailbreakDetected<\/code> or <code>XPIADetected<\/code> = true<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3 id=\"when-to-bring-in-a-specialist\" tabindex=\"-1\">When to Bring In a Specialist<\/h3>\n<p>Most firms can run the smoke test and basic searches internally. Bring in outside help when you\u2019re facing multi-user exposure of sensitive data, a regulatory inquiry, or an inability to retrieve prompt\/response content that a court or client demands.<\/p>\n<p>A focused engagement typically delivers: a full audit of your current Purview logging configuration, a SIEM connector with field mapping already built, an incident playbook tailored to your firm\u2019s data types, DSPM policy configuration, and a documented evidence-export procedure for legal requests.<\/p>\n<ul>\n<li>Audit sprint: 1 to 2 weeks to assess current state.<\/li>\n<li>Integration sprint: 2 to 6 weeks for SIEM and DSPM buildout.<\/li>\n<li>Optional monthly retainer for ongoing monitoring and adoption metrics.<\/li>\n<\/ul>\n<p>Gozera works specifically with mid-market law, accounting, and consulting firms on exactly this kind of engagement, pairing governance configuration with the adoption telemetry that shows whether Copilot licenses are actually earning their cost.<\/p>\n<h3 id=\"why-this-matters-more-at-professional-services-firms\" tabindex=\"-1\">Why this matters more at professional-services firms<\/h3>\n<p>Client confidentiality isn\u2019t abstract in a law or accounting firm. Every <code>AccessedResources<\/code> entry pointing at a client matter file is also a billable-hour and malpractice exposure question. Run the smoke test today. Export a CSV of <code>AccessedResources<\/code> for one high-sensitivity user and confirm the coverage is real before you assume it is.<\/p>\n<h2 id=\"turn-audit-visibility-into-measurable-copilot-roi\" tabindex=\"-1\">Turn Audit Visibility Into Measurable Copilot ROI<\/h2>\n<p>Knowing where your Copilot audit logs live solves a compliance problem. It doesn\u2019t solve the bigger one most mid-market firms actually have: licenses sitting idle while partners assume adoption is happening. Gozera builds on the same telemetry this article walks through to show exactly which Copilot licenses are earning their cost and which ones aren\u2019t.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/gozera.ai\/blog\/wp-content\/uploads\/2026\/07\/1783398003486_gozera.jpg\" alt=\"Gozera\"><\/p>\n<p>A typical audit sprint delivers:<\/p>\n<ul>\n<li>A usage and audit-log baseline showing real Copilot activity by user and practice group.<\/li>\n<li>Identification of dormant licenses draining budget with zero adoption.<\/li>\n<li>SIEM and DSPM policy configuration mapped to your existing security stack.<\/li>\n<li>A workflow rebuild plan targeting the highest-value use cases in your firm, not generic AI use cases.<\/li>\n<\/ul>\n<p>If your firm has 50 to 500 employees and Copilot licenses that may or may not be paying for themselves, start with a <a href=\"https:\/\/gozera.ai\" target=\"_blank\" rel=\"noopener\">Copilot audit and adoption consulting engagement<\/a> built around exactly the logging and governance groundwork covered here.<\/p>\n<h2 id=\"sources\" tabindex=\"-1\">Sources<\/h2>\n<ul>\n<li><a href=\"https:\/\/learn.microsoft.com\/en-us\/purview\/audit-copilot\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">audit-copilot<\/a><\/li>\n<li><a href=\"https:\/\/purview.microsoft.com\/audit\/auditlogsearch\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">purview auditlogsearch<\/a><\/li>\n<\/ul>\n<h2 id=\"recommended\" tabindex=\"-1\">Recommended<\/h2>\n<ul>\n<li><a href=\"https:\/\/gozera.ai\" target=\"_blank\" rel=\"noopener\">Microsoft 365 Copilot ROI &amp; Adoption Consulting | Zera<\/a><\/li>\n<li><a href=\"https:\/\/gozera.ai\/blog\/copilot-adoption-services\" target=\"_blank\" rel=\"noopener\">Copilot Adoption Services: Your 2026 Practical Guide<\/a><\/li>\n<li><a href=\"https:\/\/gozera.ai\/blog\/copilot-workflows-for-professional-services-2026-guide\" target=\"_blank\" rel=\"noopener\">Copilot Workflows for Professional Services: 2026 Guide<\/a><\/li>\n<li><a href=\"https:\/\/gozera.ai\/blog\/microsoft-copilot-telemetry-it-managers-2026-guide\" target=\"_blank\" rel=\"noopener\">Microsoft Copilot Telemetry: IT Manager\u2019s 2026 Guide \u2013 Zera Consulting<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Discover how to locate and interpret your Copilot audit logs effectively in Microsoft Purview, ensuring compliance and security for your team.<\/p>\n","protected":false},"author":1,"featured_media":270,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-269","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Copilot Audit Logs: Where to Find and Read Them<\/title>\n<meta name=\"description\" content=\"Discover how to locate and interpret your Copilot audit logs effectively in Microsoft Purview, ensuring compliance and security for your team.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/gozera.ai\/blog\/copilot-audit-logs\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Copilot Audit Logs: Where to Find and Read Them\" \/>\n<meta property=\"og:description\" content=\"Discover how to locate and interpret your Copilot audit logs effectively in Microsoft Purview, ensuring compliance and security for your team.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/gozera.ai\/blog\/copilot-audit-logs\/\" \/>\n<meta property=\"og:site_name\" content=\"Zera Consulting\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-22T19:21:35+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/gozera.ai\/blog\/wp-content\/uploads\/2026\/08\/1787044070204_Hands-testing-audit-log-setup-on-laptop.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"1080\" \/>\n\t<meta property=\"og:image:height\" content=\"720\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"zeraconsulting\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"zeraconsulting\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/copilot-audit-logs\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/copilot-audit-logs\\\/\"},\"author\":{\"name\":\"zeraconsulting\",\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/#\\\/schema\\\/person\\\/7777d5b5b3475c673677bf0a07ecb4b0\"},\"headline\":\"Copilot Audit Logs: Where to Find and Read Them\",\"datePublished\":\"2026-08-22T19:21:35+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/copilot-audit-logs\\\/\"},\"wordCount\":2057,\"image\":{\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/copilot-audit-logs\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/1787044070204_Hands-testing-audit-log-setup-on-laptop.jpeg\",\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/copilot-audit-logs\\\/\",\"url\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/copilot-audit-logs\\\/\",\"name\":\"Copilot Audit Logs: Where to Find and Read Them\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/copilot-audit-logs\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/copilot-audit-logs\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/1787044070204_Hands-testing-audit-log-setup-on-laptop.jpeg\",\"datePublished\":\"2026-08-22T19:21:35+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/#\\\/schema\\\/person\\\/7777d5b5b3475c673677bf0a07ecb4b0\"},\"description\":\"Discover how to locate and interpret your Copilot audit logs effectively in Microsoft Purview, ensuring compliance and security for your team.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/copilot-audit-logs\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/gozera.ai\\\/blog\\\/copilot-audit-logs\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/copilot-audit-logs\\\/#primaryimage\",\"url\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/1787044070204_Hands-testing-audit-log-setup-on-laptop.jpeg\",\"contentUrl\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/1787044070204_Hands-testing-audit-log-setup-on-laptop.jpeg\",\"width\":1080,\"height\":720,\"caption\":\"Hands testing audit log setup on laptop\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/copilot-audit-logs\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Copilot Audit Logs: Where to Find and Read Them\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/\",\"name\":\"Zera Consulting\",\"description\":\"Microsoft 365 Copilot ROI and adoption insights for mid-market professional services\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/#\\\/schema\\\/person\\\/7777d5b5b3475c673677bf0a07ecb4b0\",\"name\":\"zeraconsulting\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4ba8b1ba6b449ed5c82c9b2b89716ea683b319e8ca3e9f626179384748b7b775?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4ba8b1ba6b449ed5c82c9b2b89716ea683b319e8ca3e9f626179384748b7b775?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4ba8b1ba6b449ed5c82c9b2b89716ea683b319e8ca3e9f626179384748b7b775?s=96&d=mm&r=g\",\"caption\":\"zeraconsulting\"},\"sameAs\":[\"https:\\\/\\\/gozera.ai\\\/blog\"],\"url\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/author\\\/zeraconsulting\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Copilot Audit Logs: Where to Find and Read Them","description":"Discover how to locate and interpret your Copilot audit logs effectively in Microsoft Purview, ensuring compliance and security for your team.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/gozera.ai\/blog\/copilot-audit-logs\/","og_locale":"en_US","og_type":"article","og_title":"Copilot Audit Logs: Where to Find and Read Them","og_description":"Discover how to locate and interpret your Copilot audit logs effectively in Microsoft Purview, ensuring compliance and security for your team.","og_url":"https:\/\/gozera.ai\/blog\/copilot-audit-logs\/","og_site_name":"Zera Consulting","article_published_time":"2026-08-22T19:21:35+00:00","og_image":[{"width":1080,"height":720,"url":"https:\/\/gozera.ai\/blog\/wp-content\/uploads\/2026\/08\/1787044070204_Hands-testing-audit-log-setup-on-laptop.jpeg","type":"image\/jpeg"}],"author":"zeraconsulting","twitter_card":"summary_large_image","twitter_misc":{"Written by":"zeraconsulting","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/gozera.ai\/blog\/copilot-audit-logs\/#article","isPartOf":{"@id":"https:\/\/gozera.ai\/blog\/copilot-audit-logs\/"},"author":{"name":"zeraconsulting","@id":"https:\/\/gozera.ai\/blog\/#\/schema\/person\/7777d5b5b3475c673677bf0a07ecb4b0"},"headline":"Copilot Audit Logs: Where to Find and Read Them","datePublished":"2026-08-22T19:21:35+00:00","mainEntityOfPage":{"@id":"https:\/\/gozera.ai\/blog\/copilot-audit-logs\/"},"wordCount":2057,"image":{"@id":"https:\/\/gozera.ai\/blog\/copilot-audit-logs\/#primaryimage"},"thumbnailUrl":"https:\/\/gozera.ai\/blog\/wp-content\/uploads\/2026\/08\/1787044070204_Hands-testing-audit-log-setup-on-laptop.jpeg","inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/gozera.ai\/blog\/copilot-audit-logs\/","url":"https:\/\/gozera.ai\/blog\/copilot-audit-logs\/","name":"Copilot Audit Logs: Where to Find and Read Them","isPartOf":{"@id":"https:\/\/gozera.ai\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/gozera.ai\/blog\/copilot-audit-logs\/#primaryimage"},"image":{"@id":"https:\/\/gozera.ai\/blog\/copilot-audit-logs\/#primaryimage"},"thumbnailUrl":"https:\/\/gozera.ai\/blog\/wp-content\/uploads\/2026\/08\/1787044070204_Hands-testing-audit-log-setup-on-laptop.jpeg","datePublished":"2026-08-22T19:21:35+00:00","author":{"@id":"https:\/\/gozera.ai\/blog\/#\/schema\/person\/7777d5b5b3475c673677bf0a07ecb4b0"},"description":"Discover how to locate and interpret your Copilot audit logs effectively in Microsoft Purview, ensuring compliance and security for your team.","breadcrumb":{"@id":"https:\/\/gozera.ai\/blog\/copilot-audit-logs\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/gozera.ai\/blog\/copilot-audit-logs\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/gozera.ai\/blog\/copilot-audit-logs\/#primaryimage","url":"https:\/\/gozera.ai\/blog\/wp-content\/uploads\/2026\/08\/1787044070204_Hands-testing-audit-log-setup-on-laptop.jpeg","contentUrl":"https:\/\/gozera.ai\/blog\/wp-content\/uploads\/2026\/08\/1787044070204_Hands-testing-audit-log-setup-on-laptop.jpeg","width":1080,"height":720,"caption":"Hands testing audit log setup on laptop"},{"@type":"BreadcrumbList","@id":"https:\/\/gozera.ai\/blog\/copilot-audit-logs\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/gozera.ai\/blog\/"},{"@type":"ListItem","position":2,"name":"Copilot Audit Logs: Where to Find and Read Them"}]},{"@type":"WebSite","@id":"https:\/\/gozera.ai\/blog\/#website","url":"https:\/\/gozera.ai\/blog\/","name":"Zera Consulting","description":"Microsoft 365 Copilot ROI and adoption insights for mid-market professional services","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/gozera.ai\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/gozera.ai\/blog\/#\/schema\/person\/7777d5b5b3475c673677bf0a07ecb4b0","name":"zeraconsulting","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/4ba8b1ba6b449ed5c82c9b2b89716ea683b319e8ca3e9f626179384748b7b775?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/4ba8b1ba6b449ed5c82c9b2b89716ea683b319e8ca3e9f626179384748b7b775?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4ba8b1ba6b449ed5c82c9b2b89716ea683b319e8ca3e9f626179384748b7b775?s=96&d=mm&r=g","caption":"zeraconsulting"},"sameAs":["https:\/\/gozera.ai\/blog"],"url":"https:\/\/gozera.ai\/blog\/author\/zeraconsulting\/"}]}},"_links":{"self":[{"href":"https:\/\/gozera.ai\/blog\/wp-json\/wp\/v2\/posts\/269","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gozera.ai\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gozera.ai\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gozera.ai\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/gozera.ai\/blog\/wp-json\/wp\/v2\/comments?post=269"}],"version-history":[{"count":1,"href":"https:\/\/gozera.ai\/blog\/wp-json\/wp\/v2\/posts\/269\/revisions"}],"predecessor-version":[{"id":271,"href":"https:\/\/gozera.ai\/blog\/wp-json\/wp\/v2\/posts\/269\/revisions\/271"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gozera.ai\/blog\/wp-json\/wp\/v2\/media\/270"}],"wp:attachment":[{"href":"https:\/\/gozera.ai\/blog\/wp-json\/wp\/v2\/media?parent=269"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gozera.ai\/blog\/wp-json\/wp\/v2\/categories?post=269"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gozera.ai\/blog\/wp-json\/wp\/v2\/tags?post=269"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}