What audit and logging gaps should I check in a SaaS-heavy company?

Entra sign-in logs last 7 days on the free tier. Purview Audit keeps 180 days, Google Workspace 6 months. Know your numbers, then prove you can find last month's event.

Prove the whole logging path. Generate. Collect and retain. Retrieve and review. Working guide.
In this guide

Updated September 29, 2026

A prime, the larger contractor you work under, calls and says a drawing it sent you on the 3rd showed up somewhere it shouldn't. Who opened it, who downloaded it, and who shared it? If your admin can't answer that within an hour, you have a logging gap, whatever your settings page says.

Logs are the record your software keeps of who signed in, which file they opened, and what they changed. When your company runs on Microsoft 365 or Google Workspace rather than servers in a closet (what IT people call "SaaS-heavy"), those logs live with Microsoft or Google, and each keeps them for a fixed time before deleting them. If the answer the prime needs was deleted last week, you can't show them what happened. That's a bad call to lose with a customer who controls your next award, and CMMC, the Defense Department's security program for suppliers who handle its drawings and technical data, expects you to have the answer.

The gaps usually sit in three places: how long each log is kept, whether the account you care about is even logged, and whether anyone would notice if logging stopped.

How long your logs actually last

Most owners have never looked, and the first row catches a lot of small companies. The left column names the log the way your admin will recognize it.

Log Kept by default In plain terms Source
Entra ID sign-in and audit logs, free tier 7 days Microsoft's login records, on the free version that comes with Business Basic and Standard Microsoft
Entra ID sign-in and audit logs, P1 or P2 30 days The same records on the paid tiers, included in Business Premium and E3 Microsoft, licensing
Purview Audit (Standard) 180 days What people did across Microsoft 365: email, files, Teams Microsoft
Purview Audit (Premium): Exchange, SharePoint, OneDrive, and Entra records for E5 users 1 year; up to 10 with an add-on The same, for people on Microsoft's top license tier Microsoft
Google Workspace Admin, Drive, Gmail, and user login events 6 months Google's records of logins, file activity, email, and admin changes Google

Two things stand out. On Entra's free tier, a sign-in from last Tuesday is gone by next Wednesday. And in a company that pays for the one-year tier, people without that license, and guest accounts from outside the company, still fall back to 180 days. So the contractor account you most want to investigate may have the shortest history.

How long should you keep them? The standard behind CMMC, NIST SP 800-171, asks you to keep logs long enough to investigate problems (requirement 3.3.1) and leaves the number to you. We'd set it at one year and send anything that can't hold a year to storage you control. CISA, the federal cybersecurity agency, tells managed IT providers to keep critical logs at least six months. CISA MSP advisory · NIST SP 800-171 Rev. 2

If you copy logs somewhere to keep them longer, whether a SIEM (a security tool that collects logs from everywhere into one place) or a cloud storage account, that destination now holds security records. Put it in your scope and limit who can delete from it. For the IT lead, that's 3.3.8, protecting audit information from deletion.

The retrieval drill

A screenshot of a settings page proves a switch is on. Assessors want to see you use the logs, and the quickest way to show that is to plant an event and find it.

Pick a test account. At a time you write down, say 2:05 pm, have it open a harmless file on the site where your controlled drawings live, download it, and share it with a colleague. Then have whoever would really run an investigation, your MSP (outside IT provider) or the office manager, find all three events.

Write down how long it took, what search they ran, and whether the events also showed up in your SIEM, if you have one. Google says Drive events are searchable within a couple of minutes and account events within tens of minutes. So if the search at 2:30 comes back empty, the usual reasons are a search filter, a user excluded from logging, or a broken feed into the SIEM. Google: Drive log events

Then run it again on an older event. A setting that says 180 days doesn't prove you can pull something from 170 days ago until someone does it.

When logging stops

The standard also asks for an alert when logging fails (3.3.4). For cloud logs, that usually means your SIEM or MSP sends an alert when a source goes quiet for a set number of hours. Ask your MSP what that number is, and who gets the alert at 2 am on a Saturday. If the answer is a shared mailbox nobody reads on weekends, change it.

Keep the drill's results with the settings screenshots: the search, the events it returned, the time it took, and who ran it. That folder answers the logging requirements better than a logging policy ever will.

The searches, for whoever runs the drill: in Microsoft 365, the Purview portal under Audit; in Google, the Admin console under Reporting → Audit and investigation → Drive log events.

Mock assessment

Know what your logs can show before someone asks.

Garde1 pulls evidence from the tools you already run and checks your audit controls in a mock assessment.

Or start a 14-day trial

HOSTED ON FEDRAMP MODERATE AWS · ITAR-AWARE