Export Microsoft 365 Tenant Reports and Audit Logs with PowerShell
Export the unified audit log, sign-in logs, MFA status, risky users, inactive users, license inventory, and service health with one repeatable Microsoft 365 reporting workflow.
You cannot govern what you cannot see, and Microsoft 365 produces an enormous amount of signal — sign-ins, audit events, MFA coverage, license usage, and service health — spread across multiple admin centers.
Pulling these reports by hand from different portals is slow and inconsistent, and it rarely happens on a regular cadence. As a result, security and compliance teams work with stale or incomplete data.
A repeatable PowerShell workflow turns tenant reporting into a scheduled export you can trust. PSForge helps you assemble it from ready-made Microsoft 365 tasks.
Why tenant visibility is hard
The data you need lives in different places — Entra ID for sign-ins and risky users, the compliance portal for the unified audit log, the licensing center for usage. Gathering it manually each time is tedious and error-prone.
Because it is manual, it tends not to be done regularly. Security reviews, compliance evidence, and license true-ups all suffer when the underlying reports are out of date.
What a reporting workflow looks like
A good workflow exports the unified audit log and sign-in logs for security and compliance review, and exports MFA status and risky users so identity gaps are visible.
It also exports inactive users for cleanup and license reclamation, a license inventory for cost management, and service health status so you have a record of platform incidents — all on a consistent schedule.
Schedule it, don't chase it Run these exports on a fixed cadence so security, compliance, and licensing teams always work from current data instead of scrambling to assemble reports on demand.
How PSForge helps
PSForge provides the Microsoft 365 reporting building blocks — audit and sign-in log exports, MFA and risky-user reports, inactive-user and license inventory, and service health — so you can assemble one repeatable reporting workflow.
Generate the PowerShell, schedule the exports, and feed consistent data to the teams that need it.
- Current security and audit data
- Visible MFA and identity-risk gaps
- License inventory for cost control
- A record of service health
Example security reporting workflow
- Export the unified audit log
- Export sign-in logs
- Export the MFA status report
- Export risky users
Example governance reporting workflow
- Export an inactive users report
- Export the license inventory
- Export service health status
Final thoughts
Tenant reporting is recurring, evidence-driven work that only adds value when it is current — which is exactly what a scheduled, repeatable workflow delivers.
Build it once in PSForge and keep every Microsoft 365 tenant visible and well-governed.