Skip to content
Würfel
Michael FreulerAug 10, 2026, 8:00:02 AM7 min read

Configuring M365 environments correctly for audits

Configuring M365 environments correctly for audits
6:12
Key takeaways

Missing log data cannot be recreated retrospectively, which is why an audit-ready M365 environment must be in place well before an audit is announced. The Unified Audit Log is at the heart of traceability; for 12-month retention, at least E3/E5 or Business Premium is required, whilst for 10-year retention in accordance with OR Art. 958f, Microsoft Purview Audit Premium is required. Retention policies ensure the preservation of content, eDiscovery enables targeted searches during audits, and a clear separation of roles with minimal administrator rights is a common audit point. Important: Audit logs and retention policies serve different regulatory purposes and must not be confused. Audit readiness is an ongoing operational state, not a one-off project. 

The email often arrives at short notice: your supervisory body has announced an audit. Over the coming weeks, an auditor will be scrutinising your ICT governance, your data protection measures and your security arrangements.

Anyone who starts configuring the M365 environment at this stage has already lost out – not because it is too late, but because missing log data cannot be generated retrospectively. The audit log must have been active for months. Retention policies must already have archived documents. Access rights must have been properly structured for some time.

This article explains what makes a Microsoft 365 environment audit-ready and which settings you should configure today – not tomorrow.

Typical questions asked by auditors during audits

Supervisory organisations and auditors examining asset managers do not just look at contracts and policies. They ask concrete technical questions:

  • «Can you show me who accessed this client file in the last 12 months?»

  • «How do you ensure that deleted emails remain archived?»

  • «Who in your organisation has administrator rights, and when were they granted?»

  • «Can you provide your ICT status report along with the corresponding control evidence?»

FINMA states clearly: control evidence must be filed in an orderly manner and ready for review. Logs, records and access reviews are not optional documents. They are mandatory.

Unified Audit Log: the cornerstone of traceability

The Unified Audit Log in Microsoft 365 records all relevant activities in your environment: logins, document access, email activity, administrative changes, file downloads and shares with external users.

Important to know:

  • The audit log is active by default in most M365 plans. Microsoft currently states a retention period of 180 days for Audit Standard.

  • For 12-month retention and extended retention configurations, Microsoft Purview Audit (Standard) with the corresponding licence (at minimum E3/E5 or Business Premium) is required.

  • For 10-year retention, as required under Art. 958f CO for business records, Microsoft Purview Audit Premium is needed.

  • Note: audit logs and retention policies serve different regulatory purposes and should not be confused. Audit logs document activities and access; retention policies ensure the preservation of content.

Activating and correctly configuring the audit log should be one of the first measures every asset manager takes.

Screenshot from Microsoft Purview: Creation of an audit log report

Retention Policies: Retention as a Governance Tool

The Swiss Code of Obligations (Art. 958f CO) mandates a 10-year retention obligation for business records. The FADP, conversely, requires that personal data not be retained longer than the purpose requires. Both can be addressed with correctly configured retention policies in Microsoft Purview:

  • Emails with business relevance: retain for 10 years

  • Internal chat messages: depending on content and classification

  • Temporary working documents: delete after a defined period, unless a retention label has been applied

These rules also apply when a user manually deletes an email or a document. Microsoft 365 preserves the content in a protected area, which remains retrievable for audits. 

eDiscovery: targeted searches for audit situations

Imagine an auditor asking for all emails and documents exchanged in connection with a specific client during a specific period. With the eDiscovery function in Microsoft Purview, you can process this request in a structured and complete manner.

eDiscovery is also useful for internal investigations: did a former employee copy or delete data shortly before resigning? What was shared during a specific period? Prerequisite: the audit log must be active and configured for a sufficient retention period.

Download tip: ICT checklist for asset managers

Developed from practical experience with FINMA-regulated asset managers and family offices: Our checklist provides a concise summary of the key ICT requirements and helps identify gaps in governance, security, and documentation.

Role separation and administrator access

A common audit finding: too many users have global administrator rights. This is a security risk and contradicts the principle of segregation of duties, which FINMA regards as an important governance requirement, although it accepts compensating measures for smaller asset managers provided these are documented in writing. Best practices:

  • Use dedicated admin accounts (not the regular work account)

  • Principle of least privilege: everyone receives only the rights required for their task

  • Privileged Identity Management (PIM): elevated rights are granted only when needed and for a limited time

  • All administrator activity is logged in the audit log

Annual ICT Status Report to the Management Board

FINMA expects executive management to be demonstrably involved in material ICT decisions. A documented reporting rhythm together with an annual ICT status report is considered the minimum standard. Microsoft 365 offers Compliance Manager, a dashboard that provides a clear overview of the environment's current security status, useful as a basis for exactly this report.

Audit readiness as a permanent state of operation

Audit preparation is not a project phase that gets completed once. Configurations change, new employees join, licences get switched. What is correctly configured today can have gaps in six months.

At Dinotronic, audit readiness is a fixed component of our managed services for FINMA-regulated asset managers and family offices. As a Microsoft partner with ISO 27001:2022 certification and over 30 years of experience, we continuously review the relevant settings, inform you of changes, and ensure that your environment is audit-ready at all times.

Would you like to know how audit-ready your current M365 environment is? We are happy to conduct a non-binding ICT readiness check.

FAQ on audit-compliant configuration of M365 environments

Our exam is in four weeks’ time. Can we still make up for any missing log data? No, and this is the crucial point: log data cannot be created retroactively. What the audit log has not recorded over the past months does not exist. What retention policies have not archived is gone. The environment can be correctly configured for the future on short notice, but the gap in the past remains visible. This is exactly why audit readiness is a permanent state, not a project phase before an audit.
How long does Microsoft 365 retain audit logs by default? Microsoft generally specifies a retention period of 180 days for Audit Standard. For 12-month retention and extended retention configurations, Microsoft Purview Audit (Standard) with the appropriate licence (at least E3/E5 or Business Premium) is required. For a 10-year retention period, as stipulated in Article 958f of the Swiss Code of Obligations for business records, Microsoft Purview Audit Premium is required. It is therefore essential that the appropriate licensing is included in the audit planning.
What is the difference between audit logs and retention policies? Both serve different regulatory purposes and must not be confused: audit logs document activities and access – in other words, who did what and when. Retention policies ensure that content is retained – in other words, that emails and documents are preserved even if users delete them manually. An audit-ready environment requires both, correctly configured and coordinated with one another.
What is eDiscovery in Purview? eDiscovery in Microsoft Purview enables structured and comprehensive searches of emails and documents, for example when an auditor requests all records relating to a specific customer within a defined time period. The feature is also suitable for internal investigations, for example to determine whether a former employee copied or deleted data shortly before their dismissal. In both cases, the audit log must be active and have been configured for a sufficiently long period.
How do we organise administrator access correctly? A common audit finding is that too many users have global administrator rights. Best practices include: using dedicated admin accounts instead of the regular work account, applying the principle of least privilege, and using Privileged Identity Management (PIM), where elevated rights are granted only when needed and for a limited time. FINMA regards segregation of duties as an important governance requirement, but accepts compensating measures for smaller asset managers provided these are documented in writing.
Do we need to report on IT to executive management on a regular basis? Yes. FINMA expects executive management to be demonstrably involved in material ICT decisions. A documented reporting rhythm together with an annual ICT status report is considered the minimum standard. Compliance Manager in Microsoft 365 is well suited as a basis for this, providing a clear dashboard overview of the environment's current security status. Important: the report and the corresponding control evidence must be filed in an orderly manner and ready for review.
Michael Freuler

Michael Freuler

Head of Solution Consulting and Marketing

Abonnieren Sie unsere monatlichen Newsletter

Unsere Newsletter geben interessante Einblicke in neue Trends.

Sie haben Fragen? Kommen Sie gerne direkt auf uns zu! Wir freuen uns von Ihnen zu hören

Kommen Sie gerne direkt auf uns zu!