Microsoft Purview: Update to ResultCount parameter in the Search-UnifiedAuditLog cmdlet
Microsoft Purview updates the Search-UnifiedAuditLog cmdlet’s ResultCount parameter to show a running count of results in real time, adding a new boolean property, AuditSearchRequestMetadata.moreRecordsAvailable, to indicate if more records remain. This improves query progress visibility and affects scripts relying on ResultCount as a final total. To improve performance and provide better visibility into query progress, we are updating the behavior of the ResultCount parameter for the Search-UnifiedAuditLog cmdlet in Microsoft Purview Audit. Previously, the ResultCount parameter returned the total number of results expected from a query. With this update, ResultCount will display a running count of results as they are retrieved in real time. We are also introducing a new boolean property, AuditSearchRequestMetadata.moreRecordsAvailable, which indicates whether additional records are still being retrieved. Together, these updates provide administrators with improved transparency into audit log search progress and better support for script and automation scenarios. When this will happen General Availability (Worldwide, GCC): We began rolling out in mid-May 2026 and expect to complete by late May 2026. General Availability (GCC High, DoD): We will begin rolling out in early June 2026 and expect to complete by late June 2026. How this affects your organization Who is affected Administrators who use Microsoft Purview Audit Administrators running the Search-UnifiedAuditLog cmdlet in PowerShell Organizations with scripts or automation that rely on audit log search results What will happen The ResultCount parameter will now display a running count of results as they are retrieved during query execution. A new boolean property, AuditSearchRequestMetadata.moreRecordsAvailable, will indicate whether additional records are still being retrieved. While the query is running: ResultCount shows the number of records retrieved so far. moreRecordsAvailable is set to true. When the query completes: ResultCount reflects the final total number of results. moreRecordsAvailable is set to false. This feature is enabled by default. There is no change to audit log data or retention. Existing scripts that rely on ResultCount representing a final total before completion may require updates. What you can do to prepare Review existing scripts and automation that rely on ResultCount to determine total results. Update scripts to use AuditSearchRequestMetadata.moreRecordsAvailable to confirm when […]
The post Microsoft Purview: Update to ResultCount parameter in the Search-UnifiedAuditLog cmdlet appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Purview: Update to ResultCount parameter in the Search-UnifiedAuditLog cmdlet
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Dynamics 365 Contact Center – Manage overnight shifts as a single continuous schedule
We are announcing the ability to manage overnight shifts as a single continuous schedule in Dynamics 365 Contact Center. This feature will rea...
Manage who can upload advanced agents and plugins
Starting September 25, Microsoft 365 admins can control who uploads advanced Copilot agents and plugins, limiting access to specific users or ...
Microsoft 365 Copilot: Insights Copilot Analytics cowork adoption impact
Microsoft 365 Copilot now includes Cowork adoption and impact insights in the Consumption dashboard and Viva Insights Advanced Insights. Avail...
Writing Blocks in M365 Copilot
Microsoft 365 Copilot will introduce Writing blocks by mid-September 2026, enabling users to create and refine longer-form content like emails...
Outlook: Change the organizer of meetings
Microsoft is introducing a feature to change the organizer of eligible Outlook meetings, allowing transfer of meeting ownership within an orga...
Code Blocks in M365 Copilot
Microsoft 365 Copilot will support inline previews of code blocks, charts, and diagrams within conversations, eliminating the need for a separ...
Microsoft SharePoint: PowerShell support for brand fonts deletion
Microsoft SharePoint will introduce the Remove-SPOFontFile PowerShell cmdlet by mid-October 2026, allowing admins to delete brand fonts across...
[Outlook Mobile] Purview Data Loss Prevention support for Calendar Events
Outlook for iOS and Android will support Microsoft Purview Data Loss Prevention for calendar events, helping prevent sensitive data sharing in...
[Outlook Mac] Purview Data Loss Prevention support for Calendar Events
Outlook for Mac will support Microsoft Purview Data Loss Prevention for calendar events, detecting sensitive info in meeting details to preven...
[Outlook Mobile] Purview DLP Wait-on-Send Support
Outlook for iOS and Android will support Microsoft Purview DLP wait-on-send policies, allowing organizations to require and configure a wait t...