How far back can Avvi look?
Every kind of history has a different window, and the shortest one usually decides whether a question can be answered.
Different kinds of history reach back different distances, and the answer to “what happened” depends on which kind you need.
The shortest window usually decides. Sharing activity is the tightest at seven days, and it clamps silently rather than refusing.
Where a window has passed, the honest answer is that it cannot be confirmed rather than that nothing happened.
| What you are asking about | How far back |
|---|---|
| Quarantined messages | Whatever the client’s own quarantine policy still holds |
| Delivery history for a message | About 90 days, but the last two days unless you give a period |
| Sharing activity across a client | 7 days at most |
| What Avvi did, for reads and sign-ins | Stamped to keep for a year |
| What Avvi did, for support escalations | Stamped to keep for three years |
| What Avvi did, for anything that changed something | Stamped to keep for seven years |
| Deleted users and groups | Restorable for 30 days |
Good to know
Avvi’s own record of what it did is the longest-reaching of these by a wide margin, and it is the one people forget to use. A change made two years ago is still there.
The sharing audit’s seven days is the shortest and the most surprising. Asking for a longer period returns seven days rather than an error, so an empty result is not evidence of nothing.
A tenant without Microsoft Entra ID P1 or P2 has no sign-in history available at all, which is a different answer from a window having passed.
Quarantine is the exception to this table. Avvi searches whatever the client’s quarantine currently holds and applies no window of its own, so how far back it reaches is that client’s retention policy rather than a figure Avvi sets.
Related pages
Finding a missing email, and checking what somebody shared externally, each explain how to work within these windows.