Skip to Content

MC1473155 Microsoft Purview permissions audit log improvements

Summary

Microsoft Purview is updating audit logging for role based access control permission checks between late September 2026 and late October 2026. The update introduces two new audit operations to improve visibility into access evaluation decisions. The feature is enabled by default with no configuration required. Administrators should update internal monitoring procedures and inform security teams about the new audit data.

Administrator impact: No direct administrator action is required.
End user impact: No direct end user impact is expected.
Score rationale: This is an informational update adding new audit capabilities without disrupting existing services.

Microsoft 365 Roadmap | Permissions in the Microsoft Purview portal

Microsoft Purview will enhance audit logging for RBAC permission checks starting late September 2026, adding two new audit operations for better access investigation and troubleshooting. This feature is enabled by default, requires no action, and improves administrators’ visibility into role-based access decisions without impacting existing systems.

Published: 17 Sept 2026
Expires: 27 Nov 2026
Last updated: 17 Sept 2026
Roadmap ID: 569363
Platforms: Web
Category: Stay informed
Tags: Microsoft Purview, New feature, User impact, Admin impact

Microsoft Message

To improve transparency and troubleshooting for Microsoft Purview role-based access control (RBAC), we are enhancing audit logging for permission checks performed in the Microsoft Purview portal. These new audit records will provide administrators with clearer visibility into role and scoped-role authorization decisions, helping them investigate access issues and better understand how access evaluations are performed.

This message is associated with Microsoft 365 Roadmap ID 569363.

Rollout schedule

General Availability (Worldwide): Beginning in late September 2026 and expected to complete by late October 2026

Impact on your organization

Who is affected

Microsoft Purview administrators and compliance administrators who review audit logs for access investigations and troubleshooting

Platforms and services

  • Microsoft Purview portal
  • Microsoft Purview Audit

What will happen

  • New audit records will be generated when access checks are performed in the Microsoft Purview portal.
  • Two new audit operations will be available:
    • CheckUsersInRoles
    • CheckUserInRolesWithScopes
  • Administrators will be able to review these audit records as part of SecurityComplianceRBAC audit activities.
  • The enhancement is enabled by default and requires no configuration.
  • Audit records will only be generated for access checks that occur after the feature is deployed.
  • No historical or retroactive audit records will be created for prior access checks.
  • There is no impact for organizations.

RBAC audit-CheckUserInRolesWithScopes:

RBAC audit-checkusersinroles:

Action required and recommendations

No action is required. We recommend that administrators:

  • Review internal monitoring and audit procedures to determine whether the new audit activities should be included in access investigations.
  • Inform compliance and security teams about the availability of the new audit operations.
  • Update any internal documentation or reporting processes that reference Microsoft Purview RBAC audit data.

Learn more

  • Permissions in the Microsoft Purview portal | Microsoft Learn

Compliance considerations

Question: Does the change modify, interrupt, or disable audit logging capabilities?

Answer:  The change enhances audit logging capabilities by adding two new audit operations.

Question: Does the change alter how admins can monitor, report on, or demonstrate compliance activities?

Answer: Administrators gain additional audit visibility into RBAC access evaluation outcomes, improving monitoring and troubleshooting capabilities.