Search-UnifiedAuditLog
SafeAudit log search
Search-UnifiedAuditLog -StartDate <d> -EndDate <d>
Searches sign-in and activity audit logs; for incident investigation.
Examples
Search-UnifiedAuditLog -StartDate (Get-Date).AddDays(-7) -EndDate (Get-Date) -Operations UserLoggedInLast 7 days of logins
Syntax
Search-UnifiedAuditLog -StartDate <d> -EndDate <d> [-Operations <op>]
Before you run it
Read-only.
Related commands
- Revoke-MgUserSignInSessionRevoke sign-ins
The same reference, with no signal at all
Every command and flow from this site, held on your device and searchable with no connection. Free to install, no ads.
Get it free on the App Store